tagora
container audit

GTM-N8MWMP7H

4 tags, no hand-written scripts, 1 third-party host — smaller than 85% of the 46,522 containers we have measured, and carrying none of the hand-written JavaScript most of them do.

Tags4
Custom scripts0
Third parties1
Delivered373 KB
Versions3

What we observed

A real browser loaded wbbjtv.com a month ago and recorded every request it made. This is what happened, as distinct from what the container is configured to do. It is one page load — anything that fires only deeper in the site did not fire here.

Container loaded from www.wbbjtv.com — the site's own host, at /pf/resources/dist/__global/js/analytics/gtm.js rather than the default path, and googletagmanager.com
Measurement sent to google-analytics.com — Google

The container is self-hosted; the measurement still goes to Google. The first-party path that a tagging server provides is not being used for the data itself.

Consent Quantcast answered its own API. 1 measurement hit left the page before it was granted, carrying a client id (whether that is permitted depends on jurisdiction, and this was not a European visit). no new hosts appeared after granting — either the tags are ungated, or they fire regardless and record the decision. Google recorded gcs=G1 (no consent signal). 10 advertising hosts were contacted before anything was granted.
Third parties contacted 25 hosts — gray-wbbj-prod.gtv-cdn.com, polyfill-fastly.io, cdnjs.cloudflare.com, c.amazon-adsystem.com, cdn.taboola.com, s.go-mpulse.net, static.chartbeat.com, www.queryly.com, and 17 more

Where the data goes

Not observed — on the page we loaded, measurement went to Google and nowhere else. observed on wbbjtv.com More info »

Findings

Ordered by consequence. review has a concrete cost when it bites; info is real but depends on your setup. Seen is how common it is across the containers we have measured — reported separately on purpose, because common and harmless are different claims.

reviewNo consent signal in the container (1)
Nothing in this container sets, reads, or gates on a consent state.

WhyThe container itself neither sets a Consent Mode default, holds any tag back for consent, nor references a known consent platform. Either enforcement lives entirely outside GTM — where it cannot be audited from here — or tags fire regardless of what a visitor chose.

CheckIf a consent platform blocks scripts before GTM loads, this is fine — confirm that is actually the case. If not, tags are firing on a choice nobody recorded.

Seenseen in 52.1% of 46,522 containers measured

Third parties it can reach

Each host is a party that can execute code or receive data in a visitor's browser. Follow one to see who else loads it. More info »

www.google-analytics.com ×4

Detected on

Sites observed loading this container. A container used across many hosts is a shared template; one on a single host is a bespoke build. Follow a site to see every container it loads.

wbbjtv.com

What this audit describes

Containers change. These findings describe one specific artifact, and you can re-fetch it to check this reading.

ContainerGTM-N8MWMP7H
Published version3 — the identity of this configuration. It changes only when someone publishes.
Read at2026-08-23 17:52:34 UTC (a month ago)
Sourcehttps://www.googletagmanager.com/gtm.js?id=GTM-N8MWMP7H
Body checksum6196d25efeb6e0f7ae5a10109d22e762ce29d2dea54aaaf91810b0c3e0a677a9
Evidence of the exact bytes we read, not an identity: Google varies the response per request, so re-fetching an unchanged container yields a different checksum. Compare the published version instead.

Re-audit

This reading is from a month ago. A container can be republished at any time, and nothing here updates on its own — a fresh read is the only way to know whether it still says this. Running it again replaces this page in place, so the link keeps working.

Re-audit GTM-N8MWMP7H

Check another container

Put this container under version control. Tagora exports it to a repository you own, so every change arrives as a pull request. How it works »