A step-by-step method for auditing every tracker on your site: inventory pages, scan for beacons, triage tag sprawl, verify consent, and re-audit.
Websites accumulate tracking scripts the way attics accumulate boxes: a Meta Pixel from a 2021 campaign, a duplicate analytics property, a chat widget nobody remembers installing. Each one slows pages, leaks visitor data to vendors you may no longer use, and widens your consent-compliance surface. A tracker audit is the inventory that lets you clean it up — here is the method, step by step.
You cannot audit pages you do not know exist. Start from the site's own inventory: read robots.txt, follow it to the sitemap.xml files, and recursively expand sitemap indexes into the full URL list. For pages missing from the sitemap (orphans, staging leaks), add a breadth-first crawl of internal links. How sitemap enumeration works. Include subdomains — blog., shop., docs. each carry their own tracker stacks. How subdomain discovery works.
Fetch each page and pattern-match the HTML against known tracker signatures, extracting identifiers (GTM container IDs, GA4 measurement IDs, Meta Pixel IDs). The default static scan misses trackers injected at runtime by JavaScript — most commonly tags deployed through tag managers — so run a browser-render pass for those. Why static scans miss JavaScript-injected trackers. Record results per URL: one beacon row per tracker per page, not a site-wide summary.
Sort the beacon inventory into buckets:
An inventory of embedded trackers is only half the compliance question; the other half is when they fire. Render a page as a first-time visitor with no consent given — trackers firing in that state are firing pre-consent, a concrete, reportable finding. GDPR & CCPA tracker consent basics. What the audit can and can't verify about consent banners.
Remove dead and duplicate pixels (pause first in the tag manager, watch a full reporting cycle, then delete), migrate hardcoded tags into the tag manager, then re-run the audit to confirm the beacon table is clean. How to find and remove unused tracking pixels.
The audit tool automates steps 1 and 2 for any public domain: enter a domain, choose a discovery mode, and get the pages table and per-URL beacon inventory with CSV export. The triage, consent review, and cleanup are yours — the report is the evidence you work from. Run it as a repeatable checklist.