tagora
container audit

GTM-W7PTHKCJ

69 tags, 1 custom scripts, 4 third-party hosts — an ordinary container, near the middle of what we measure (median: 39 tags, 4 custom scripts).

Tags69
Custom scripts1
Third parties4
Delivered545 KB
Versions95

What we observed

A real browser loaded jdsports.co.uk a month ago and recorded every request it made. This is what happened, as distinct from what the container is configured to do. It is one page load — anything that fires only deeper in the site did not fire here.

Container loaded from googletagmanager.com — Google
Measurement sent to www.jdsports.co.uk — not Google, at /1qpj/ga/g/c

Measurement is first-party; the container still loads from Google. These are separate decisions, and this is the more common of the two.

Forwarded to GA4 ×4 — read from the measurement id, not the hostname
Consent OneTrust answered its own API. Measurement fired beforehand but carried no identifier — analytics_storage was denied, which is Consent Mode working as designed rather than a gap. 10 hosts appeared only after consent was granted. Google recorded gcs=G100 (all denied).
Third parties contacted 25 hosts — proxy.csidetm.com, cdn.media.amplience.net, www.googletagmanager.com, jdsportsproduction.cdn.content.amplience.net, js-agent.newrelic.com, cdn.cookielaw.org, bam.nr-data.net, geolocation.onetrust.com, and 17 more
dataLayer events seen csideLoaded, gtm.dom, gtm.js, session_start, gtm.load, OneTrustLoaded, OptanonLoaded, gtm.triggerGroup

Where the data goes

Confirmed — a browser watched this site send measurement data to www.jdsports.co.uk, not to Google. observed on jdsports.co.uk More info »

Findings

Ordered by consequence. review has a concrete cost when it bites; info is real but depends on your setup. Seen is how common it is across the containers we have measured — reported separately on purpose, because common and harmless are different claims.

reviewdocument.write (1)
1 piece of custom code call document.write.

Whydocument.write blocks the HTML parser while it runs, and browsers ignore it entirely once the page has finished parsing — so an async-loaded tag using it can silently do nothing.

CheckIf these tags fire on page load they are costing render time; if they fire later they may not be working at all. Worth confirming the tag still does what it was added to do.

Seenseen in 18.4% of 46,522 containers measured

infoConsent configuration detected (2)
The container declares one or more consent signals.

WhyConsent handling is present in the container. This describes what the artifact declares; what actually happened on the page is measured separately, above.

CheckConfirm these settings match the consent policy you intend to enforce, and compare them with the before-and-after observation.

Seenseen in 44.6% of 46,522 containers measured

Third parties it can reach

Each host is a party that can execute code or receive data in a visitor's browser. Follow one to see who else loads it. More info »

www.google-analytics.com ×37googleads.g.doubleclick.net ×6www.googleadservices.com ×3fls.doubleclick.net ×2

What the custom templates can do

Custom templates are third-party code shipped inside the container. Injecting scripts and running page globals is ordinary for them — most tag templates need it to work — so this is an inventory, not a warning. It lists the capability each template declares so you can match it against templates you meant to install.

__cvt_WP4D8 gallery injects code from cookie-cdn.1trust.app, cdn.cookielaw.org, cdn-ukwest.onetrust.com, cookie-cdn.cookiepro.com, cdn-au.onetrust.com, cdn-apac.onetrust.com · runs page-level globals
__cvt_191729894_1146 private runs page-level globals
__cvt_5DG2W gallery runs page-level globals
__cvt_T9BM6 gallery injects code from t.contentsquare.net · runs page-level globals

Detected on

Sites observed loading this container. A container used across many hosts is a shared template; one on a single host is a bespoke build. Follow a site to see every container it loads.

jdsports.iejdsports.itjdsports.co.uk

What this audit describes

Containers change. These findings describe one specific artifact, and you can re-fetch it to check this reading.

ContainerGTM-W7PTHKCJ
Published version95 — the identity of this configuration. It changes only when someone publishes.
Read at2026-08-12 22:55:43 UTC (a month ago)
Sourcehttps://www.googletagmanager.com/gtm.js?id=GTM-W7PTHKCJ
Body checksum34a566ef998fa3f14a928e1646719d05d1414567720aa13ac299801ea8c4bc62
Evidence of the exact bytes we read, not an identity: Google varies the response per request, so re-fetching an unchanged container yields a different checksum. Compare the published version instead.

Re-audit

This reading is from a month ago. A container can be republished at any time, and nothing here updates on its own — a fresh read is the only way to know whether it still says this. Running it again replaces this page in place, so the link keeps working.

Re-audit GTM-W7PTHKCJ

Check another container

Put this container under version control. Tagora exports it to a repository you own, so every change arrives as a pull request. How it works »