Free tool
See what's inside any GTM container.
Paste a GTM container ID. In seconds, see every tracking platform, pixel, and tag embedded inside — no login, no account access required.
Enter GTM Container ID
Accepts GTM-XXXXXXX or just the alphanumeric ID. We fetch the public container JS — no account access needed.
Platform Detection
Identifies GA4, Google Ads, Meta Pixel, TikTok, LinkedIn, Pinterest, Twitter/X, Snapchat, Bing UET, Hotjar, Clarity, and more.
Consent Mode Audit
Checks whether Google Consent Mode v2 is configured — a requirement for EU Google Ads since March 2024.
Server-Side Detection
Looks for first-party server endpoints and server-side GTM configurations that improve data quality.
Custom HTML Scan
Counts custom HTML tags injected through GTM — a common source of performance drag and security risk.
Data Layer Inspection
Detects dataLayer variable references to understand what structured data the container relies on.
Actionable Findings
Generates warnings and recommendations based on what's present — and what's missing — in your container.
Every container tells a story
A GTM container is the single point through which most marketing and analytics tags enter a website. Over time, containers accumulate — old pixels from campaigns that ended, duplicate tags from agency handoffs, custom HTML injections that nobody remembers adding. This tool reads the publicly available container JavaScript and surfaces what's actually running.
What the public JS reveals
When Google Tag Manager loads on a page, it fetches a JavaScript file that contains the container's configuration — tag definitions, trigger conditions, variable references, and third-party platform IDs. While it's minified and obfuscated, patterns for major platforms (GA4 measurement IDs, Meta Pixel IDs, consent mode configuration) are identifiable through string matching. This is the same file every visitor's browser downloads.
Common problems we find
Missing consent mode configuration — required for EU Google Ads since March 2024. Custom HTML tags that inject arbitrary JavaScript with no security review. Orphaned pixels for platforms no longer in use, adding page weight and sending data to vendors you've stopped paying. No server-side tracking, meaning iOS Safari and Firefox users are partially invisible. Legacy Universal Analytics tags still firing into a deprecated endpoint.
Limitations of a public scan
This tool analyses the publicly served JavaScript — the same file any browser downloads. It cannot see trigger conditions, firing rules, variable configurations, or workspace-level settings. Some tags are loaded conditionally and may not appear in the default container JS. For a full audit with GTM admin access, event validation, and data layer review, you need a hands-on assessment.
[ ⌖ ] Next step
Need the full container audit?
Trigger conditions, data layer validation, tag firing order, consent enforcement — available as a paid engagement.