Free · no login · no code on your site
Tracking Check
The Google Analytics checker for GA4, GTM, Consent Mode and server-side.
One URL, one scan: see whether GA4 and GTM are set up cleanly, what fires before consent, and where signals break on their way to Google Ads and Meta.
Including the deep scan: answers the cookie banner once with accept and once with reject and compares the requests. Continues in the background after the first result.
Scope
What the check covers.
39 individual checks in 6 modules, all against the publicly reachable page. The scan covers the start page and up to two more pages, not the whole site; on detected shops it adds a sample of up to five product pages.
Every check has an explainer page with causes and fix: all 39 checks in detail →
Consent Mode V2
Default and update calls, ad_user_data / ad_personalization, TCF v2.2, CMP detection.
Cookies & scripts before / after consent
Cookies and scripts before consent; the deep scan clicks the banner to accept and reject, then diffs the requests.
Tracking core
GA4, GTM, dataLayer, server-side endpoints, conversion APIs such as Meta CAPI.
Product & price data
For shops: visible price against dataLayer, JSON-LD and view_item, on a sample of real product pages.
Script inventory & performance
Third-party scripts, tracking payload, Privacy Sandbox.
Security & bots
HTTPS, security headers, meta tags, JSON-LD, robots.txt, AI bot policy, llms.txt.
What it cannot do
No inside view of your accounts: GA4 configuration, BigQuery models and attribution logic stay invisible. Server-side endpoints show up only indirectly. That takes the audit.
Frequently asked
What does the tool check?
39 technical checks across 6 modules, all derived from the HTML, cookies, and network requests of a publicly reachable URL. It samples up to three representative pages (the entry page plus one content and one form page, when discoverable), not the whole site; on detected shops it adds a sample of up to five product pages. No login, no tracking code on your site.
- C01 Consent Mode V2: default and update calls, ad_user_data / ad_personalization, IAB TCF v2.2, CMP detection
- C02 Cookies & scripts before / after consent: pre-consent cookies & scripts, 3rd-party cookies; the deep scan clicks the banner to accept and reject, then diffs the requests
- C03 Tracking core: analytics tag, dataLayer, tag manager, duplicate Google IDs, server-side tracking and tracking architecture, server-side event APIs
- C04 Product & price data (on detected shops): visible price against dataLayer, JSON-LD and view_item events on up to five product pages
- C05 Script inventory & performance: tracking payload, loading mode, third-party scripts, Privacy Sandbox (Core Web Vitals + Lighthouse audit are part of the Audit Sprint, not the free scan)
- C06 Security & bots: HTTPS, security headers (HSTS, CSP, XFO), meta tags, JSON-LD, robots.txt, AI bot policy, llms.txt
Can I share the result?
Yes. 'Copy link' creates a stable permalink with a social preview image that stays available for 7 days, then deletes itself automatically.
Which analytics tools are checked?
GA4 and GTM in detail. Plausible, Matomo, Piwik PRO, Fathom, Pirsch, Simple Analytics, Mixpanel, PostHog and Adobe Analytics are detected. Server-side tracking (sGTM, stape.io, first-party loaders) is recognised by loader paths and measurement pings on your own domain; the deep scan watches in the browser whether the pings go through your endpoint or straight to Google.
What does a red check mean?
Red means the check failed, e.g. no analytics tag found, Consent Mode V2 missing, pre-consent cookies set. A red check isn't a compliance violation yet, but a concrete item for setup review.
Why is the tool free?
Because an honest quick check tells you whether it's worth looking deeper. If three or more checks come back red, a proper audit is the next conversation. If everything's clean, you don't need us, and we say so.
What does this tool not see?
From the HTML, cookies, and network requests of a public page we can't detect:
- The inside of server containers: which tags the sGTM holds and where it forwards them. The endpoint itself is visible to the scan.
- Conversion APIs (Meta CAPI, Google Enhanced Conversions, TikTok Events API): server-to-server, invisible in the browser
- Anything behind the browser. BigQuery export, dbt models, CDPs, data warehouses
- Cookieless tools without detectable DOM selectors (Fathom, Pirsch, certain Plausible setups)
Are the scanned URLs stored?
To keep the result shareable (permalink, social preview image, embed badge), we store every result in the EU for 7 days automatically: the scanned domain, the score, and the findings, nothing else. No identity, no email, no IP. After that it deletes itself. Separately, we keep an anonymous count of how often an individual check fires, without the domain and without any link to a single scan. That counter holds nothing but whole numbers per quarter and feeds our public DACH benchmark. If you also request the report by email, your address goes into our EU-hosted lead list (Listmonk, data-minimised).
What are pre-consent cookies and why are they a problem?
Pre-consent cookies are set before the user agrees to the cookie banner. Under GDPR and ePrivacy they're only permitted if strictly necessary, analytics, marketing, or personalisation cookies don't qualify. They're the most common cause of CMP complaints to supervisory authorities.
Can the tool replace a proper audit?
No. 39 checks vs. 60+ in a real audit. The tool is an early-warning system, not a compliance certificate. If multiple checks come back red or amber, a proper audit is the next conversation.
What does an Audit Sprint cost?
Audit Sprint: €1,490 net, report in 3 working days. One website, one GA4 property, one web GTM container, one CMP, one ads account and up to three conversion paths. Evidence, action plan and a 45-minute review. From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning. Implementation is separate, with no follow-up obligation.
Last updated:
Templates you keep: CMP and GTM consent QA · Consent mapping worksheet · Consent Mode audit checklist · GTM form tracking template
Next step
You have checked. Now we rank the fixes.
The Audit Sprint turns findings into a sequence with effort and price attached. 3 working days, from €1,490 net.
From the agreed start with complete access and documents. Scope and delivery date are agreed before commissioning.