Tracking audit
See what your tracking setup is actually doing. Enter a URL, we scan it live — ad and analytics tags, server-side vs. client-side, cookie consent — free, no signup.
What's scored
Four categories, all from one fetch.
No AI narration, no invented numbers — every point traces to a signal this scan can actually observe.
Advertising & Analytics
Whether ad pixels and GA4/GTM are detected running client-side only, with no first-party infrastructure behind them.
Technical
First-party tag-loader infrastructure, and tracking scripts loading without async/defer.
Privacy
Whether a cookie consent tool is present, and whether cookies are set before consent is collected.
FAQ
The questions that come up every time.
What does the Tracking Audit check?
Whether GA4, Google Ads, Meta Pixel and similar tags are installed, whether they run client-side or through first-party server-side infrastructure, whether a cookie consent tool is present, and how many tracking scripts block page render. Everything is read from one fetch of your homepage — nothing is installed and nothing changes on your site.
Is this really free?
Yes, no signup. We fetch your homepage once, score what we find, and show you the report.
Why does client-side-only tracking lose data?
Ad blockers and Safari's Intelligent Tracking Prevention (ITP) both target client-side pixels and JavaScript-set cookies. Data collected server-side, first-party, isn't subject to either.
What can't this audit see?
It reads one server-side fetch of your homepage — it cannot execute JavaScript, so it cannot see what tags a detected Google Tag Manager container fires internally, and it cannot observe cookies your tracking scripts set via document.cookie (only literal Set-Cookie response headers count). Every claim on the report is scoped to what a single fetch can honestly show.
Who can see my report?
Anyone with the report's link can view it — we don't index reports for search or list them publicly, but treat the link like you would any shareable document.
An audit tells you what's broken. It doesn't fix it.
SourceTrack's first-party, server-side tracking is the fix for what this scan flags — one script tag, 28 days free.