TagAudit visits your site in a real browser, watches every tag fire, tests clicks and forms, and checks whether your cookie banner actually blocks anything. You get a scored report with a fix list — most scans finish in under two minutes.
No signup for the free scan. Interaction testing requires domain verification. See a sample report.
Three things no source-code scanner can tell you.
GA4, GTM, ad pixels, session replay, A/B tools, CDPs, consent platforms — 120+ signatures, with account IDs and whether each one actually fired or is dead weight from an old agency.
We decline your cookie banner like a first-time EU visitor and watch what fires anyway. Most sites leak. Some record full sessions of users who said no.
We scroll, click and fill your forms (never submitting), then show which visitor actions your analytics receives — and hand you the exact events to add, in priority order.
One URL in, one work order out.
A clean headless browser visits your site — fresh profile, no cookies, EU-style consent conditions.
Network beacons, cookies, dataLayer, consent state — at load and while interacting with your page. Forms are filled but never submitted.
Health score, stack inventory, consent behaviour, interaction gap map, and a prioritized fix list your developer can start today.
Most tools need a script on your site or a configured journey before they can tell you anything. We start at none — and only ask for more when it buys you something.
Any public URL. Nothing to install, nothing to configure, and it works on sites you don't own — prospect research, competitor teardowns, a client who hasn't onboarded yet. Bot protection in front of the site can block it.
Verify the domain, allowlist one address, and the scanner reaches your real site instead of a bot challenge. It's the only change we ask for, it's scoped to your hostname, and it's reversible in the same click that made it. How to allowlist us →
Logged-in journeys, checkout and purchase confirmation can't be reached from outside at all. Covering them means collecting inside your own session — so we do it only when you ask. Never the default, never switched on quietly.
Start free. One-off — nothing recurring, nothing to cancel.
Prices are loading. If this persists, the pricing service is unavailable — nothing here is out of date, it just isn't showing yet.
The free scan loads publicly accessible pages exactly like a normal browser visit and analyzes only what any visitor's browser receives — the same category of analysis as BuiltWith or Wappalyzer. Interaction testing (clicking, filling forms) goes further, so we only run it on domains you've verified you control.
Add a DNS TXT record or a meta tag we give you. Takes two minutes, proves you control the site, and unlocks interaction testing and the consent diff.
Sometimes not — bot protection can't distinguish our scanner from any other automated client, so it may serve a challenge page instead of your site. When that happens the scan says so and withholds the score rather than reporting a near-empty stack as if it were real. On a domain you've verified, one allowlist rule fixes it permanently: how to allowlist us.
Never. Forms are filled and abandoned to observe field-level tracking; submit buttons are not pressed; checkouts are never completed.
Server-to-server integrations — Meta CAPI, offline conversion uploads, warehouse syncs — aren't externally observable. The report flags where these likely exist and tells you exactly what to verify in your own accounts.
Often not. The most common finding across audits is a properly installed banner that only gates half the stack. Having a CMP is not the same as enforcing it — that's precisely what we test.