The library
Did the browser request the vendor's own JavaScript, and did it return successfully? Nearly every other tool stops here, which is why nearly every other tool says a broken tag is fine.
Including what it cannot see. An instrument you cannot inspect is not evidence.
Four page types per store, in a real Chromium browser with JavaScript running, from Frankfurt unless you tell us otherwise.
| Page type | How we find it on Shopify | How we find it on WooCommerce |
|---|---|---|
| Home | The address you gave us, after redirects | The address you gave us, after redirects |
| Collection | /collections.json | /wp-json/wc/store/v1/products/categories |
| Product | /products.json | /wp-json/wc/store/v1/products |
| Cart | /cart | /cart/ |
We never add anything to a cart and never submit a form. One request per second per store, and we identify ourselves as TagnovoScanner/1.0 so you can allow orblock us.
Two separate observations per vendor, never one.
Did the browser request the vendor's own JavaScript, and did it return successfully? Nearly every other tool stops here, which is why nearly every other tool says a broken tag is fine.
Did a request actually reach the vendor's collection endpoint? For GA4 that is/g/collect; for Meta it is facebook.com/trcarrying an event name. Library without event is the finding.
Every store runs a first-party beacon of its own. We use it as a control.
If your store's own beacon fired on a page and GA4 did not, the page rendered and GA4 is at fault. If nothing fired at all, we suspect our own reading, not your store — and we report the page as one we could not observe. No finding is ever raised on a page where the control was also silent.
On Shopify the control is strong. On WooCommerce there is no guaranteed beacon, so we fall back to any first-party request the site makes, and below that to proving JavaScript executed at all. Every report says which control was used, because a finding backed by a weak control is weaker evidence and you should be able to see that.
| Blind spot | Why |
|---|---|
| Shopify's checkout | It runs on Shopify's own domain. Add the tag if you need it watched. |
| Anything behind a login | We only load pages a customer could load without an account. |
| Server-side tagging | If events leave from your server rather than the browser, there is nothing for us to observe. |
| Stores that challenge us | Some firewalls serve a challenge page. We report that plainly rather than guessing. |
| Whether a tag is configured correctly | We can see an event was sent. We cannot see whether it carried the right value. |
Every scan records which version of our detection rules produced it. When we change a rule we publish a new version rather than editing the old one, so a report from March still means what it meant in March and the published dataset stays reproducible.See the rule changelog.