tagora
container audit

GTM-WV2H

10 tags, 1 custom scripts, 3 third-party hosts — an ordinary container, near the middle of what we measure (median: 39 tags, 4 custom scripts).

Tags10
Custom scripts1
Third parties3
Delivered350 KB
Versions37

What we observed

A real browser loaded juznevesti.com a month ago and recorded every request it made. This is what happened, as distinct from what the container is configured to do. It is one page load — anything that fires only deeper in the site did not fire here.

Container loaded from googletagmanager.com — Google
Measurement sent to google-analytics.com — Google
Consent Quantcast answered its own API. 3 measurement hits left the page before it was granted, carrying a client id (whether that is permitted depends on jurisdiction, and this was not a European visit). no new hosts appeared after granting — either the tags are ungated, or they fire regardless and record the decision. Google recorded gcs=G111 (all granted). 5 advertising hosts were contacted before anything was granted.
Third parties contacted 18 hosts — maxcdn.bootstrapcdn.com, cdn.onesignal.com, securepubads.g.doubleclick.net, www.googletagmanager.com, static.cloudflareinsights.com, fundingchoicesmessages.google.com, analytics.google.com, stats.g.doubleclick.net, and 10 more
dataLayer events seen gtm.js, gtm.dom, gtm.load

Where the data goes

Not observed — on the page we loaded, measurement went to Google and nowhere else. observed on juznevesti.com More info »

Findings

Ordered by consequence. review has a concrete cost when it bites; info is real but depends on your setup. Seen is how common it is across the containers we have measured — reported separately on purpose, because common and harmless are different claims.

reviewHardcoded http:// URL (1)
1 piece of custom code reference a plain http:// address.

WhyOn an https:// page the browser blocks or upgrades these. Blocked means the tag quietly stops working; upgraded only works if that host also serves https.

CheckCheck whether the hosts below still respond over https, and update the URLs.

Seenseen in 12.8% of 46,522 containers measured

infoConsent configuration detected (2)
The container declares one or more consent signals.

WhyConsent handling is present in the container. This describes what the artifact declares; what actually happened on the page is measured separately, above.

CheckConfirm these settings match the consent policy you intend to enforce, and compare them with the before-and-after observation.

Seenseen in 44.6% of 46,522 containers measured

Third parties it can reach

Each host is a party that can execute code or receive data in a visitor's browser. Follow one to see who else loads it. More info »

www.google-analytics.com ×2d7d3cf2e81d293050033-3dfc0615b0fd7b49143049256703bfce.ssl.cf1.rackcdn.com ×1t.contentinsights.com ×1

Detected on

Sites observed loading this container. A container used across many hosts is a shared template; one on a single host is a bespoke build. Follow a site to see every container it loads.

juznevesti.com

What this audit describes

Containers change. These findings describe one specific artifact, and you can re-fetch it to check this reading.

ContainerGTM-WV2H
Published version37 — the identity of this configuration. It changes only when someone publishes.
Read at2026-08-23 18:22:04 UTC (a month ago)
Sourcehttps://www.googletagmanager.com/gtm.js?id=GTM-WV2H
Body checksum9cd1b6b97859cdff8b1941d8ce3a87f42a53024086d20dffdc512d662c9f9fa0
Evidence of the exact bytes we read, not an identity: Google varies the response per request, so re-fetching an unchanged container yields a different checksum. Compare the published version instead.

Re-audit

This reading is from a month ago. A container can be republished at any time, and nothing here updates on its own — a fresh read is the only way to know whether it still says this. Running it again replaces this page in place, so the link keeps working.

Re-audit GTM-WV2H

Check another container

Put this container under version control. Tagora exports it to a repository you own, so every change arrives as a pull request. How it works »