Your site has analytics.
Is it measuring anything?

TagAudit visits your site in a real browser, watches every tag fire, tests clicks and forms, and checks whether your cookie banner actually blocks anything. You get a scored report with a fix list — most scans finish in under two minutes.

Free scan only while we finish beta

No signup for the free scan. Interaction testing requires domain verification. See a sample report.

Optional: attach your GTM container (Admin → Export Container) and we'll compare what's configured against what actually fires — and check it matches this site.
Starting…

What the audit covers

Three things no source-code scanner can tell you.

Every tag, named & verified

GA4, GTM, ad pixels, session replay, A/B tools, CDPs, consent platforms — 120+ signatures, with account IDs and whether each one actually fired or is dead weight from an old agency.

Consent, enforced or decorative?

We decline your cookie banner like a first-time EU visitor and watch what fires anyway. Most sites leak. Some record full sessions of users who said no.

The measurement gap map

We scroll, click and fill your forms (never submitting), then show which visitor actions your analytics receives — and hand you the exact events to add, in priority order.

How it works

One URL in, one work order out.

Enter your URL

A clean headless browser visits your site — fresh profile, no cookies, EU-style consent conditions.

We watch everything

Network beacons, cookies, dataLayer, consent state — at load and while interacting with your page. Forms are filled but never submitted.

Get the report

Health score, stack inventory, consent behaviour, interaction gap map, and a prioritized fix list your developer can start today.

How much cooperation each tier needs

Most tools need a script on your site or a configured journey before they can tell you anything. We start at none — and only ask for more when it buys you something.

No cooperation

Free scan

Any public URL. Nothing to install, nothing to configure, and it works on sites you don't own — prospect research, competitor teardowns, a client who hasn't onboarded yet. Bot protection in front of the site can block it.

One firewall rule

Paid audit

Verify the domain, allowlist one address, and the scanner reaches your real site instead of a bot challenge. It's the only change we ask for, it's scoped to your hostname, and it's reversible in the same click that made it. How to allowlist us →

Opt-in, on request

Deep scan

Logged-in journeys, checkout and purchase confirmation can't be reached from outside at all. Covering them means collecting inside your own session — so we do it only when you ask. Never the default, never switched on quietly.

Pricing

Start free. One-off — nothing recurring, nothing to cancel.

FAQ

Is it legal to scan any website?

The free scan loads publicly accessible pages exactly like a normal browser visit and analyzes only what any visitor's browser receives — the same category of analysis as BuiltWith or Wappalyzer. Interaction testing (clicking, filling forms) goes further, so we only run it on domains you've verified you control.

How does domain verification work?

Add a DNS TXT record or a meta tag we give you. Takes two minutes, proves you control the site, and unlocks interaction testing and the consent diff.

My site is behind Cloudflare / a WAF. Will the scan work?

Sometimes not — bot protection can't distinguish our scanner from any other automated client, so it may serve a challenge page instead of your site. When that happens the scan says so and withholds the score rather than reporting a near-empty stack as if it were real. On a domain you've verified, one allowlist rule fixes it permanently: how to allowlist us.

Will the audit submit my forms or buy anything?

Never. Forms are filled and abandoned to observe field-level tracking; submit buttons are not pressed; checkouts are never completed.

What can't you see?

Server-to-server integrations — Meta CAPI, offline conversion uploads, warehouse syncs — aren't externally observable. The report flags where these likely exist and tells you exactly what to verify in your own accounts.

My consent banner is from a big vendor. Am I safe?

Often not. The most common finding across audits is a properly installed banner that only gates half the stack. Having a CMP is not the same as enforcing it — that's precisely what we test.