# Disable loading external script - Pendo.io

**URL:** <https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100>\
**Category:** Experience Manager (PaaS/OnPrem)\
**Created:** [September 13, 2020, 3:21am UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100 "2020-09-13T03:21:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [September 13, 2020, 3:21am UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/1 "2020-09-13T03:21:14Z")

</div>

Hey all,

I was playing around with the CMS on my machine when my wifi dropped out. For some reason the CMS kept hanging on an external script that was trying to load. Looking into it more, some kind of logging/analytics script is being loaded out-of-the-box by the navapp belonging to this site: [https://www.pendo.io/](https://www.pendo.io/).

The script being loaded:

```auto
!function(e, n, t, a, i) {
    var c, o, s, d, p;
    for ((i = e[a] = e[a] || {})._q = [],
    o = 0,
    s = (c = ["initialize", "identify", "updateOptions", "pageLoad"]).length; o < s; ++o)
        !function(e) {
            i[e] = i[e] || function() {
                i._q[e === c[0] ? "unshift" : "push"]([e].concat([].slice.call(arguments, 0)))
            }
        }(c[o]);
    (d = n.createElement(t)).async = !0,
    d.src = "https://cdn.pendo.io/agent/static/e65bf8ab-aad1-48b6-521a-3f558e16c979/pendo.js",
    (p = n.getElementsByTagName(t)[0]).parentNode.insertBefore(d, p)
}(window, document, "script", "pendo");
//# sourceMappingURL=scripts.6cc58785376a86301f9b.js.map

```

Reading the code it seems like I could remove `scripts.6cc58785376a86301f9b.js` from `angular/navapp/filelist.json` in the hippo-cms-engine jar to make it not load, but I wouldn’t want to overlay that webfragment every release.

It would be great to be able to disable this script being loaded by default, is there a configuration for that anywhere?

In general, I would say that a product such as this, should strive to minimise its external dependencies so that when they are deployed in restricted environments (either by design or not) they can work predictably. Not to mention the apprehension some people (or security teams) might have regarding their backends reaching out to not necessarily trusted 3rd party sites. But maybe that’s just me.

Please let me know if I’m missing or misunderstanding something, keen to hear back from you.

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![jeroen.hoffman](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/jeroen.hoffman/32/43_2.png) [@jeroen.hoffman](https://community.bloomreach.com/u/jeroen.hoffman)\
**Post date:** [September 14, 2020, 7:29am UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/2 "2020-09-14T07:29:56Z")

</div>

Hi,

Pendo is used in our CMS Usage Statistics functionality. For more information, and how to disable, see

> **[CMS Usage Statistics - Bloomreach Experience - Open Source CMS](https://documentation.bloomreach.com/14/library/concepts/usage-statistics/usage-statistics.html)**
>
> Open Source Enterprise Content Management

Cheers,  
Jeroen

---

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [September 14, 2020, 8:22am UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/3 "2020-09-14T08:22:08Z")

</div>

Hi Jeroen,

Thanks for the link! I had accidentally stumbled across that option previously and disabled it. However, even if it is disabled the script still loads – I guess the behaviour is for it to not send any information if it’s disabled.

For now I’m overriding the filelist.json to exclude script.js from rendering, but it’s not ideal.

Thanks again, I appreciate you getting back to me!

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![rvriel](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/rvriel/32/1321_2.png) [@rvriel](https://community.bloomreach.com/u/rvriel)\
**Post date:** [September 29, 2020, 10:50am UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/4 "2020-09-29T10:50:53Z")

</div>

Hi Marnix,

I’m encountering the same issue while upgrading to Hippo 14. Could you please tell me where the filelist.json should be placed in order to overwrite the original one? (I’ve tried some locations, but no luck so far). 🙄

---

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [September 29, 2020, 9:43pm UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/5 "2020-09-29T21:43:09Z")

</div>

Heya!

Because the `hippo-cms-engine jar` seems to be structured like a webfragment (servlet 3.0 spec stuff), the public facing assets in that webfragment are subject to the resource finding rules that apply to webfragments. Which means that you can serve up a different file from the main project when you put it in the `cms` module at: `src/main/java/resources/angular/navapp/filelist.json`.

So now, when the browser requests filelist.json, it won’t serve the file from the webfragment, but from the main resources folder. The contents of mine looks like this:

```auto
{
  "main.js": "main.39766d137d76941d6d26.js",
  "polyfills.js": "polyfills.b3b4640e1e6332436593.js",
  "runtime.js": "runtime.a8ef3a8272419c2e2c66.js",
  "styles.css": "styles.62262ab71bf6a5cbb667.css"
}

```

But depending on your version the hashes may have to be different (which is the downside of this approach). I’d still much prefer the script not being loaded at all when the sending usage statistics has been disabled. It’d be wise to document this somewhere as a step to consider when updating between versions.

Hope that helps!

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![rvriel](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/rvriel/32/1321_2.png) [@rvriel](https://community.bloomreach.com/u/rvriel)\
**Post date:** [October 2, 2020, 1:03pm UTC](https://community.bloomreach.com/t/disable-loading-external-script-pendo-io/2100/6 "2020-10-02T13:03:46Z")

</div>

Thanks a bunch! Worked like a charm.
