FreeNo signup for the free scan.
TagAudit visits your site in a real browser, watches every tag fire, tests clicks and forms, and checks whether your cookie banner actually blocks anything. You get a scored report with a fix list — most scans finish in under two minutes.
Free scan only while we finish beta
No signup for the free scan.
Three things no source-code scanner can tell you.
One URL in, one work order out.
A clean headless browser visits your site — fresh profile, no cookies, and your consent banner left unanswered or declined.
Network beacons, cookies, dataLayer, consent state — at load and while interacting with your page.
Health score, stack inventory, consent behaviour, interaction gap map, and a prioritized fix list your developer can start today.
Most tools need a script on your site or a configured journey before they can tell you anything. We start at none — and only ask for more when it buys you something.
Most public websites. Nothing to install, nothing to configure, and it works on sites you don't own — prospect research, competitor teardowns, a client who hasn't onboarded yet. Bot protection in front of the site can block it, and a page with too little on it to audit is turned away.
Works on the same public sites as the free scan. If bot protection blocks us, allowlist one address and the scanner reaches your real site instead of a bot challenge. It's the only change we ask for, it's scoped to your hostname, and it's reversible in the same click that made it. How to allowlist us →
Logged-in journeys, checkout and purchase confirmation can't be reached from outside at all. Covering them means collecting inside your own session — so we do it only when you ask. Never the default, never switched on quietly.
Start free. One-off — nothing recurring, nothing to cancel.
Prices are loading. If this persists, the pricing service is unavailable — nothing here is out of date, it just isn't showing yet.
The free scan loads publicly accessible pages exactly like a normal browser visit and analyzes only what any visitor's browser receives — the same category of analysis as BuiltWith or Wappalyzer. Interaction testing goes further and we are specific about it: on every scan we scroll, click in-page links, and fill in form fields to see what tracking fires — every value we enter says, in the field itself, that it is a test. Submitting them is switched off in our current configuration, on every site.
Add a DNS TXT record or a meta tag we give you. Takes two minutes and proves you control the site. No scan needs it.
Sometimes not — bot protection can't distinguish our scanner from any other automated client, so it may serve a challenge page instead of your site. When that happens the scan says so and withholds the score rather than reporting a near-empty stack as if it were real. On a domain you've verified, one allowlist rule fixes it permanently: how to allowlist us.
We never enter payment details and never pay for anything. Actions that would send something to your site — submitting a form, adding to a cart, walking into checkout — are switched off in our current configuration, on every site. Forms are filled and abandoned so we can watch which tracking fires, and every value we put in a field says so in the field itself — a form reads "THIS IS A TEST - PLEASE IGNORE", so whoever sees it knows immediately.
Server-to-server integrations — Meta CAPI, offline conversion uploads, warehouse syncs — aren't externally observable. The report flags where these likely exist and tells you exactly what to verify in your own accounts.
Often not. The most common finding across audits is a properly installed banner that only gates half the stack. Having a CMP is not the same as enforcing it — that's precisely what we test.