datascale

Search services, integrations and blog posts.

Tool

Measurement Health Check: your tracking audited in seconds

One URL, one click. In seconds you see whether your tracking runs cleanly and where it opens GDPR risk. 20+ checks across GA4, consent, and security. Free, no account.

Advanced optionsSetup type and deep scan. Most people don't need these.
What's your setup?

Optional, helps us filter out irrelevant findings. Leave on Standard if you're not sure.

  • free
  • no account
  • cookieless
  • EU-hosted
  • result in seconds
Try one

In three steps

How the tool works.

No login, no install. All you need is your web address.

  1. 01

    Enter your domain

    Your web address in the field, one click on "Start check". No login, no code on your site.

  2. 02

    We scan in the EU

    20+ checks run on our servers in Falkenstein. In under 20 seconds, with nothing for you to do.

  3. 03

    Read the verdict

    A Health Score from 0 to 100. Every finding in plain words: what it means and what to do next.

The result

An honest verdict, in plain words.

This is what your result looks like. A score, plus every finding with its meaning and next step.

82/100
SolidHealth Score
  • T-04No server-side tracking detectedcritical

    Ad blockers can cut off your measurement. Server-side makes it more robust.

  • C-04Cookies set before consentto review

    Your site sets cookies before visitors agree. A typical GDPR finding.

  • C-01Consent Mode V2 activeOK

    Google gets all the signals it needs. Cleanly done.

Example verdict. Your real scan looks just like this.

What we check

20+ checks across four areas.

We read only what is visible from the outside: HTML, cookies, and network requests.

  • 015 checks

    Is your tracking working at all?

    Tracking core

    GA4, GTM, dataLayer, server-side tracking, conversion APIs

  • 026 checks

    Is your consent GDPR-compliant?

    Consent & privacy

    Consent Mode V2, TCF v2.2, cookie banner, cookies before consent

  • 033 checks

    Are scripts slowing your site down?

    Performance & UX

    Tracking payload, third-party scripts, Privacy Sandbox

  • 047 checks

    Are the basics secured?

    Security & bots

    HTTPS, security headers, robots.txt, AI bot policy, llms.txt

Honest & data-minimal

Why the tool is free.

  • Free, no catch

    No newsletter wall, no tracking pixel on your site. One URL in, one verdict out.

  • EU-hosted, cookieless

    The scan runs in Falkenstein. This site itself uses no cookie and no consent banner.

  • Built by the senior team

    The same people who run the Audit Sprint. No juniors sold as seniors.

Who is behind it
  • Q01
    What does the tool check?

    20+ technical checks across four categories, all derived from the HTML, cookies, and network requests of a publicly reachable URL. It samples up to three representative pages (the entry page plus one content and one form page, when discoverable), not the whole site. With the deep scan enabled it also drives the cookie banner automatically and compares the accept state with the reject state. No login, no tracking code on your site.

    • Tracking core: analytics tag, dataLayer, tag manager, server-side tracking, server-side event APIs (Meta CAPI, TikTok, LinkedIn, Enhanced Conversions)
    • Consent & privacy: Consent Mode V2, IAB TCF v2.2, cookie banner detection, pre-consent cookies & scripts, 3rd-party cookies
    • Performance & UX: tracking payload, third-party scripts, Privacy Sandbox (Core Web Vitals + Lighthouse audit are part of the Audit Sprint, not the free scan)
    • Security & bots: HTTPS, security headers (HSTS, CSP, XFO), meta tags, JSON-LD, robots.txt, AI bot policy, llms.txt
  • Q02
    What is the deep scan?

    An optional mode (a checkbox before the scan, about 15 seconds). We open the page in a real browser, drive the cookie banner automatically, and compare two states: after 'Accept all' and after 'Reject all'. That yields three findings: whether 'Reject' is actually respected (the most common GDPR finding at supervisory authorities), whether 'Accept' activates measurement, and whether a gtag consent update fires after opt-in. It needs an interactable cookie banner, otherwise the tool reports 'Consent simulation not possible'.

  • Q03
    Can I share the result?

    Yes. 'Copy link' creates a stable permalink with a social preview image that stays available for 7 days, then deletes itself automatically. 'Save as PDF' produces a printout in the inspection-report layout, 'Copy as ticket' a Markdown block per finding for Jira, Linear, or GitHub, and 'Embed' gives you a Health Score badge.

  • Q04
    Which analytics tools are checked?

    GA4, GTM, Plausible (detected but not deep-checked), Matomo / Piwik PRO (detected). Server-side tracking (sGTM, stape.io, custom endpoints) is only visible indirectly, see the "What this tool can't see" note in the result.

  • Q05
    What does a red check mean?

    Red means the check failed, e.g. no analytics tag found, Consent Mode V2 missing, pre-consent cookies set. A red check isn't a compliance violation yet, but a concrete item for setup review.

  • Q06
    Why is the tool free?

    Because an honest quick check tells you whether it's worth looking deeper. If three or more checks come back red, a proper audit is the next conversation. If everything's clean, you don't need us, and we say so.

  • Q07
    What does this tool not see?

    From the HTML, cookies, and network requests of a public page we can't detect:

    • Server-side tracking (sGTM, Stape, custom endpoints)
    • Conversion APIs (Meta CAPI, Google Enhanced Conversions, TikTok Events API)
    • Anything behind the browser. BigQuery export, dbt models, CDPs, data warehouses
    • Cookieless tools without detectable DOM selectors (Fathom, Pirsch, certain Plausible setups)
  • Q08
    Are the scanned URLs stored?

    To keep the result shareable (permalink, social preview image, embed badge), we store every result in the EU for 7 days automatically: the scanned domain, the score, and the findings, nothing else. No identity, no email, no IP. After that it deletes itself. If you also request the report by email, your address goes into our EU-hosted lead list (Listmonk, data-minimised).

  • Q09
    What are pre-consent cookies and why are they a problem?

    Pre-consent cookies are set before the user agrees to the cookie banner. Under GDPR and ePrivacy they're only permitted if strictly necessary, analytics, marketing, or personalisation cookies don't qualify. They're the most common cause of CMP complaints to supervisory authorities.

  • Q10
    Can the tool replace a proper audit?

    No. 20+ checks vs. 60+ in a real audit. The tool is an early-warning system, not a compliance certificate. If multiple checks come back red or amber, a proper audit is the next conversation.

  • Q11
    What does an Audit Sprint cost?

    €2,400 net fixed price, 2 weeks, prioritised action plan including server-side, data pipelines, and data quality. More under Request an Audit Sprint.