Title: ScriptSpy &#8211; Third-Party Script Intelligence
Author: Avo Avetisyan
Published: <strong>ছেপ্টেম্বৰ 3, 2026</strong>
Last modified: ছেপ্টেম্বৰ 3, 2026

---

প্লাগিনৰ সন্ধান কৰক

![](https://ps.w.org/scriptspy/assets/banner-772x250.png?rev=3680357)

![](https://ps.w.org/scriptspy/assets/icon-256x256.png?rev=3680357)

# ScriptSpy – Third-Party Script Intelligence

 [Avo Avetisyan](https://profiles.wordpress.org/loyaltyoverroyalty/)-ৰ দ্বাৰা

[ডাউনল’ড কৰক](https://downloads.wordpress.org/plugin/scriptspy.1.0.2.zip)

 * [বিশদ বিৱৰণ](https://as.wordpress.org/plugins/scriptspy/#description)
 * [পৰ্য্যালোচনা](https://as.wordpress.org/plugins/scriptspy/#reviews)
 *  [ইনষ্টলেশ্যন](https://as.wordpress.org/plugins/scriptspy/#installation)
 * [বিকাশ](https://as.wordpress.org/plugins/scriptspy/#developers)

 [সাহায্য](https://wordpress.org/support/plugin/scriptspy/)

## বৰ্ণনা

ScriptSpy is a focused script intelligence dashboard. It is **not** a cookie banner
and **not** a consent wizard — those tools already exist. ScriptSpy answers one 
question:

**“What is loading on my site, who owns it, what data does it collect, and give 
me a PDF I can show my lawyer.”**

#### Two-layer detection

 * **Server-side scan** — fetches your own pages with `wp_remote_get` and parses
   HTML with `DOMDocument` to extract every external script, iframe, preconnect 
   hint, and tracking pixel. Catches statically loaded scripts.
 * **Browser beacon** — a JavaScript beacon you can run in a real browser (logged-
   in admin or anonymous via signed token URL). Uses `PerformanceObserver`, `MutationObserver`,
   and intercepts `fetch`, `XMLHttpRequest`, and `navigator.sendBeacon` to capture
   every dynamically loaded resource — including pixels that Google Tag Manager 
   loads after page render.

#### What you get

 * Live dashboard with summary cards: total scripts, known/identified, require consent,
   unrecognized
 * Per-script detail modal: owner, country, data collected, legal basis, GDPR relevance,
   data transfer destination, Schrems II notes, links to privacy policy and DPA
 * PDF audit report (cover, executive summary, full inventory, unknown scripts list)
 * CSV export
 * Cookie + localStorage detection
 * Scan history with diff between scans (added/removed scripts)
 * Optional weekly/monthly automated scans with email reports
 * Knowledge base of 70+ third-party services (Google Analytics, Meta Pixel, TikTok,
   Hotjar, Stripe, Intercom, etc.)

#### Anonymous beacon mode

GTM rules often suppress pixels for logged-in WordPress administrators. ScriptSpy
generates a tokenized scan URL you can open in incognito to capture those pixels—
without exposing the beacon to your real visitors.

#### Privacy

ScriptSpy makes no external HTTP requests except scanning your own site. No telemetry,
no phone-home, no third-party API calls. The bundled knowledge base is a static 
JSON file shipped with the plugin.

## স্ক্ৰীনশ্বট

[⌊Main dashboard: summary cards, filters, and the results table with owner, category,
data collected and GDPR level for every script.⌉⌊Main dashboard: summary cards, 
filters, and the results table with owner, category, data collected and GDPR level
for every script.⌉[

Main dashboard: summary cards, filters, and the results table with owner, category,
data collected and GDPR level for every script.

[⌊Script detail: owner, country, data collected, legal basis, data transfer destination,
Schrems II note, and every page the script was found on.⌉⌊Script detail: owner, 
country, data collected, legal basis, data transfer destination, Schrems II note,
and every page the script was found on.⌉[

Script detail: owner, country, data collected, legal basis, data transfer destination,
Schrems II note, and every page the script was found on.

[⌊Scan in progress: server scan percentage, live browser-beacon status, and the 
anonymous scan URL.⌉⌊Scan in progress: server scan percentage, live browser-beacon
status, and the anonymous scan URL.⌉[

Scan in progress: server scan percentage, live browser-beacon status, and the anonymous
scan URL.

[⌊Diff between two scans - scripts added and removed.⌉⌊Diff between two scans - 
scripts added and removed.⌉[

Diff between two scans – scripts added and removed.

[⌊PDF audit report: executive summary and full script inventory.⌉⌊PDF audit report:
executive summary and full script inventory.⌉[

PDF audit report: executive summary and full script inventory.

[⌊Scan history with per-scan PDF and CSV export, plus diff against the previous 
scan.⌉⌊Scan history with per-scan PDF and CSV export, plus diff against the previous
scan.⌉[

Scan history with per-scan PDF and CSV export, plus diff against the previous scan.

[⌊Settings: scan depth, scheduled scans, email reports and excluded domains.⌉⌊Settings:
scan depth, scheduled scans, email reports and excluded domains.⌉[

Settings: scan depth, scheduled scans, email reports and excluded domains.

## ইনষ্টলেশ্যন

 1. Upload the `scriptspy` folder to `/wp-content/plugins/`.
 2. Activate via Plugins menu in WordPress.
 3. Go to Tools  ScriptSpy.
 4. Click **Start new scan**.
 5. Open the anonymous scan URL in an incognito window and browse a few pages so the
    beacon can capture dynamically loaded scripts.
 6. Return to the dashboard, review results, download PDF or CSV.

## সঘনাই উত্থাপিত প্ৰশ্ন

### Does this replace a cookie consent banner?

No. ScriptSpy detects and reports — it does not block scripts or show banners to
visitors. Use it alongside a consent platform.

### Will it slow down my site?

The server scan runs in batches via WP-Cron, not on visitor requests. The browser
beacon is injected only for logged-in admins or visitors carrying a valid scan token—
never for normal traffic.

### Can it detect server-side conversion APIs (e.g., Meta Conversions API)?

No. Server-to-server calls are invisible to client-side detection by design. ScriptSpy
lists known server-side endpoints in its knowledge base for awareness but cannot
confirm whether they fire.

### Why are some pixels missing from the report?

Many GTM containers exclude logged-in WordPress administrators from firing pixels.
Use the **anonymous scan URL** in an incognito browser to capture those pixels.

### Does the PDF require any external libraries?

The plugin bundles TCPDF 7 (via Composer) and the Helvetica core font definitions
it needs. If TCPDF is unavailable for any reason, ScriptSpy falls back to a styled
HTML report download.

## পৰ্য্যালোচনা

এই প্লাগিনৰ বাবে কোনো পৰ্য্যালোচনা নাই।

## অৱদানকাৰী আৰু বিকাশকাৰীসকল

“ScriptSpy – Third-Party Script Intelligence” হৈছে মুক্ত উৎসৰ ছফ্টৱেৰ। এইসকল লোকে
এই প্লাগিনত অৱদান আগবঢ়াইছে।

অৱদানকাৰীসকল

 *   [ Avo Avetisyan ](https://profiles.wordpress.org/loyaltyoverroyalty/)

[আপোনাৰ ভাষাত “ScriptSpy – Third-Party Script Intelligence” অনুবাদ কৰক।](https://translate.wordpress.org/projects/wp-plugins/scriptspy)

### বিকাশৰ প্ৰতি আগ্ৰহী?

[ক’ড ব্ৰাউজ কৰক](https://plugins.trac.wordpress.org/browser/scriptspy/), [SVN ৰিপজিটৰী](https://plugins.svn.wordpress.org/scriptspy/)
চাওক নাইবা [RSS](https://plugins.trac.wordpress.org/log/scriptspy/?limit=100&mode=stop_on_copy&format=rss)-
দ্বাৰা [বিকাশৰ পঞ্জী](https://plugins.trac.wordpress.org/log/scriptspy/) ছাবস্ক্ৰাইব
কৰক।

## সলনি-পঞ্জী

#### 1.0.2

 * Fixed: inline-detected scripts (Google Analytics, Meta Pixel, Intercom and others
   recognised from inline snippets) showed a knowledge base id where the domain 
   belongs. They are now labelled “inline script”.
 * Fixed: the Google Analytics 4 measurement endpoint (`/g/collect`) was not in 
   the knowledge base, so GA4 traffic captured by the browser beacon was counted
   as unrecognized.
 * Fixed: long privacy policy and page URLs overlapped the following line in the
   PDF script inventory.
 * Knowledge base updated to v1.0.1.

#### 1.0.1

 * Upgraded bundled TCPDF to 7.0.7 (now requires PHP 8.2+).
 * Generic CDN hosts are now classified through the bundled knowledge base instead
   of a hard-coded list.
 * Browser beacon is enqueued through `wp_enqueue_scripts`.
 * Hardened scan-token validation, CSV export and settings sanitization.

#### 1.0.0

 * Initial release.
 * Two-layer detection: server-side DOMDocument scan + browser beacon.
 * Anonymous tokenized beacon mode for capturing pixels GTM hides from admins.
 * PDF and CSV export.
 * Cookie and localStorage detection.
 * Scan history and diff.
 * Bundled knowledge base of 70+ third-party services.

## মেটা

 *  **1.0.2** সংস্কৰণ
 *  **2 সপ্তাহ আগত** শেষবাৰ আপডে’ট হৈছিল
 *  সক্ৰিয় ইনষ্টলেশ্যন **10টাতকৈ কম**
 *  WordPress-ৰ সংস্কৰণ ** 6.0 বা তাতকৈ ওপৰৰ **
 *  ইমানলৈকে পৰীক্ষা কৰা হৈছে **7.1**
 *  PHP-ৰ সংস্কৰণ ** 8.2 বা তাতকৈ ওপৰৰ **
 *  ভাষা
 * [English (US)](https://wordpress.org/plugins/scriptspy/)
 * [audit](https://as.wordpress.org/plugins/tags/audit/)[compliance](https://as.wordpress.org/plugins/tags/compliance/)
   [GDPR](https://as.wordpress.org/plugins/tags/gdpr/)[privacy](https://as.wordpress.org/plugins/tags/privacy/)
   [scripts](https://as.wordpress.org/plugins/tags/scripts/)
 *  টেগবোৰ
 *  [উচ্চখাপৰ ভিউ](https://as.wordpress.org/plugins/scriptspy/advanced/)

## ৰে’টিংবোৰ

এতিয়ালৈ কোনো পৰ্য্যালোচনা দাখিল কৰা হোৱা নাই।

[Your review](https://wordpress.org/support/plugin/scriptspy/reviews/#new-post)

[সকলো পৰ্য্যালোচনা চাওক](https://wordpress.org/support/plugin/scriptspy/reviews/)

## অৱদানকাৰীসকল

 *   [ Avo Avetisyan ](https://profiles.wordpress.org/loyaltyoverroyalty/)

## সাহায্য

কিবা ক’বলগীয়া আছে? সহায় লাগে?

 [সাহায্যৰ ফ’ৰাম চাওক](https://wordpress.org/support/plugin/scriptspy/)