TapCub does not bypass a browser blocker or Do Not Track. The chat and identity scripts are inserted later, so a policy that allows only the main file still blocks them.
Parameters
With no collect URL, hits go to the script origin plus /api/v1/pulse. Chat, identity, autocapture, errors, and replay load from that same directory. Do Not Track or Global Privacy Control makes the script return immediately unless you set data-respect-dnt="false". localhost does not send unless you add data-allow-local="true" or set a collect URL with data-api.
Defaults & limits
A content security policy must allow scripts and connections to that origin. If connect-src blocks it, both sendBeacon and fetch fail, and the page still shows no error. If you serve w.js from your own site origin and point the collect URL at the receiver, write the policy for your origin. That does not guarantee a blocker will allow it. It only stops the request from using a different hostname.
The collector returns 202 for drops and for stored hits. When the browser blocks the call, the network panel has no POST at all.
Example
<script async src="https://YOUR_ORIGIN/w.js" data-site="YOUR_SITE_KEY"></script>Allow scripts from YOUR_ORIGIN and connections to YOUR_ORIGIN. data-chat="false" skips the widget only. It does not stop analytics.
Errors
Two copies of the script: only the first runs. If an extension script fails to load, events held for it are released so the page does not go silent. If a blocker drops the script hostname, realtime never shows the visit. See Verify your installation.