tagora
container audit

GTM-W3C4FSC

6 tags, 5 custom scripts, 4 third-party hosts — an ordinary container, near the middle of what we measure (median: 39 tags, 4 custom scripts).

Tags6
Custom scripts5
Third parties4
Delivered338 KB
Versions23

What we observed

A real browser loaded farmerama.com a month ago and recorded every request it made. This is what happened, as distinct from what the container is configured to do. It is one page load — anything that fires only deeper in the site did not fire here.

Container loaded from googletagmanager.com — Google
Measurement sent to google-analytics.com — Google
Consent Quantcast answered its own API. Nothing measured until it was granted — no analytics or advertising hit left the page beforehand, and 2 fired afterwards. That is the outcome consent is meant to produce. 10 hosts appeared only after consent was granted. Google recorded gcs=G111 (all granted).
Third parties contacted 25 hosts — sharedservices.bpsecure.com, js.hcaptcha.com, code.jquery.com, www.youtube.com, pit-835.bpsecure.com, www.facebook.com, www.googletagmanager.com, 760db2495c41.w.hcaptcha.com, and 17 more
dataLayer events seen gtm.js, consent_default, gtm.dom, gtm.load, gtm.click, consent_cookie_update, consent_loaded, gtm.triggerGroup

Where the data goes

Not observed — on the page we loaded, measurement went to Google and nowhere else. observed on farmerama.com More info »

Findings

Ordered by consequence. review has a concrete cost when it bites; info is real but depends on your setup. Seen is how common it is across the containers we have measured — reported separately on purpose, because common and harmless are different claims.

reviewNo consent signal in the container (1)
Nothing in this container sets, reads, or gates on a consent state.

WhyThe container itself neither sets a Consent Mode default, holds any tag back for consent, nor references a known consent platform. Either enforcement lives entirely outside GTM — where it cannot be audited from here — or tags fire regardless of what a visitor chose.

CheckIf a consent platform blocks scripts before GTM loads, this is fine — confirm that is actually the case. If not, tags are firing on a choice nobody recorded.

Seenseen in 52.1% of 46,522 containers measured

Third parties it can reach

Each host is a party that can execute code or receive data in a visitor's browser. Follow one to see who else loads it. More info »

pixel.wp.pl ×3cdnjs.cloudflare.com ×1tracking.womplay.io ×1trc.taboola.com ×1

What the custom templates can do

Custom templates are third-party code shipped inside the container. Injecting scripts and running page globals is ordinary for them — most tag templates need it to work — so this is an inventory, not a warning. It lists the capability each template declares so you can match it against templates you meant to install.

__cvt_7198575_38 private injects code from cdn.taboola.com

Detected on

Sites observed loading this container. A container used across many hosts is a shared template; one on a single host is a bespoke build. Follow a site to see every container it loads.

farmerama.com

What this audit describes

Containers change. These findings describe one specific artifact, and you can re-fetch it to check this reading.

ContainerGTM-W3C4FSC
Published version23 — the identity of this configuration. It changes only when someone publishes.
Read at2026-08-22 10:47:22 UTC (a month ago)
Sourcehttps://www.googletagmanager.com/gtm.js?id=GTM-W3C4FSC
Body checksuma5a4e8c3b21739f39ff9ef5faa0afffbb60d492f6a19b9fec31a96579ce336f6
Evidence of the exact bytes we read, not an identity: Google varies the response per request, so re-fetching an unchanged container yields a different checksum. Compare the published version instead.

Re-audit

This reading is from a month ago. A container can be republished at any time, and nothing here updates on its own — a fresh read is the only way to know whether it still says this. Running it again replaces this page in place, so the link keeps working.

Re-audit GTM-W3C4FSC

Check another container

Put this container under version control. Tagora exports it to a repository you own, so every change arrives as a pull request. How it works »