{"id":309338,"date":"2026-09-03T20:20:18","date_gmt":"2026-09-03T20:20:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/scriptspy-third-party-script-intelligence\/"},"modified":"2026-09-03T20:32:06","modified_gmt":"2026-09-03T20:32:06","slug":"scriptspy","status":"publish","type":"plugin","link":"https:\/\/fr.wordpress.org\/plugins\/scriptspy\/","author":18252589,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.1","requires":"6.0","requires_php":"8.2","requires_plugins":null,"header_name":"ScriptSpy - Third-Party Script Intelligence","header_author":"Avo Avetisyan","header_description":"Detects every third-party script loading on your site, identifies owners and data collected, exports PDF audit report.","assets_banners_color":"26282f","last_updated":"2026-09-03 20:32:06","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/loyaltyoverroyalty\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":63,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"loyaltyoverroyalty","date":"2026-09-03 20:20:02","revision":3680361},"1.0.2":{"tag":"1.0.2","author":"loyaltyoverroyalty","date":"2026-09-03 20:32:06","revision":3680376}},"upgrade_notice":{"1.0.2":"<p>Bug fixes only: correct labelling for inline-detected scripts, GA4 measurement endpoint recognised, PDF layout fix.<\/p>","1.0.1":"<p>Requires PHP 8.2 or newer because of the TCPDF 7 upgrade.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3680357,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3680357,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3680357,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3680357,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3680358,"resolution":"1","location":"assets","locale":"","width":2480,"height":1622},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3680358,"resolution":"2","location":"assets","locale":"","width":2400,"height":1800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3680358,"resolution":"3","location":"assets","locale":"","width":2400,"height":1800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3680359,"resolution":"4","location":"assets","locale":"","width":2400,"height":1800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3680359,"resolution":"5","location":"assets","locale":"","width":2400,"height":1800},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3680360,"resolution":"6","location":"assets","locale":"","width":2500,"height":1622},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3680360,"resolution":"7","location":"assets","locale":"","width":2498,"height":1624}},"screenshots":{"1":"Main dashboard: summary cards, filters, and the results table with owner, category, data collected and GDPR level for every script.","2":"Script detail: owner, country, data collected, legal basis, data transfer destination, Schrems II note, and every page the script was found on.","3":"Scan in progress: server scan percentage, live browser-beacon status, and the anonymous scan URL.","4":"Diff between two scans - scripts added and removed.","5":"PDF audit report: executive summary and full script inventory.","6":"Scan history with per-scan PDF and CSV export, plus diff against the previous scan.","7":"Settings: scan depth, scheduled scans, email reports and excluded domains."}},"plugin_section":[],"plugin_tags":[8533,14361,131785,396,2864],"plugin_category":[54],"plugin_contributors":[279072],"plugin_business_model":[],"class_list":["post-309338","plugin","type-plugin","status-publish","hentry","plugin_tags-audit","plugin_tags-compliance","plugin_tags-gdpr","plugin_tags-privacy","plugin_tags-scripts","plugin_category-security-and-spam-protection","plugin_contributors-loyaltyoverroyalty","plugin_committers-loyaltyoverroyalty"],"banners":{"banner":"https:\/\/ps.w.org\/scriptspy\/assets\/banner-772x250.png?rev=3680357","banner_2x":"https:\/\/ps.w.org\/scriptspy\/assets\/banner-1544x500.png?rev=3680357","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/scriptspy\/assets\/icon-128x128.png?rev=3680357","icon_2x":"https:\/\/ps.w.org\/scriptspy\/assets\/icon-256x256.png?rev=3680357","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-1.png?rev=3680358","caption":"Main dashboard: summary cards, filters, and the results table with owner, category, data collected and GDPR level for every script."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-2.png?rev=3680358","caption":"Script detail: owner, country, data collected, legal basis, data transfer destination, Schrems II note, and every page the script was found on."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-3.png?rev=3680358","caption":"Scan in progress: server scan percentage, live browser-beacon status, and the anonymous scan URL."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-4.png?rev=3680359","caption":"Diff between two scans - scripts added and removed."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-5.png?rev=3680359","caption":"PDF audit report: executive summary and full script inventory."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-6.png?rev=3680360","caption":"Scan history with per-scan PDF and CSV export, plus diff against the previous scan."},{"src":"https:\/\/ps.w.org\/scriptspy\/assets\/screenshot-7.png?rev=3680360","caption":"Settings: scan depth, scheduled scans, email reports and excluded domains."}],"raw_content":"<!--section=description-->\n<p>ScriptSpy is a focused script intelligence dashboard. It is <strong>not<\/strong> a cookie banner and <strong>not<\/strong> a consent wizard \u2014 those tools already exist. ScriptSpy answers one question:<\/p>\n\n<p><strong>\"What is loading on my site, who owns it, what data does it collect, and give me a PDF I can show my lawyer.\"<\/strong><\/p>\n\n<h4>Two-layer detection<\/h4>\n\n<ul>\n<li><strong>Server-side scan<\/strong> \u2014 fetches your own pages with <code>wp_remote_get<\/code> and parses HTML with <code>DOMDocument<\/code> to extract every external script, iframe, preconnect hint, and tracking pixel. Catches statically loaded scripts.<\/li>\n<li><strong>Browser beacon<\/strong> \u2014 a JavaScript beacon you can run in a real browser (logged-in admin or anonymous via signed token URL). Uses <code>PerformanceObserver<\/code>, <code>MutationObserver<\/code>, and intercepts <code>fetch<\/code>, <code>XMLHttpRequest<\/code>, and <code>navigator.sendBeacon<\/code> to capture every dynamically loaded resource \u2014 including pixels that Google Tag Manager loads after page render.<\/li>\n<\/ul>\n\n<h4>What you get<\/h4>\n\n<ul>\n<li>Live dashboard with summary cards: total scripts, known\/identified, require consent, unrecognized<\/li>\n<li>Per-script detail modal: owner, country, data collected, legal basis, GDPR relevance, data transfer destination, Schrems II notes, links to privacy policy and DPA<\/li>\n<li>PDF audit report (cover, executive summary, full inventory, unknown scripts list)<\/li>\n<li>CSV export<\/li>\n<li>Cookie + localStorage detection<\/li>\n<li>Scan history with diff between scans (added\/removed scripts)<\/li>\n<li>Optional weekly\/monthly automated scans with email reports<\/li>\n<li>Knowledge base of 70+ third-party services (Google Analytics, Meta Pixel, TikTok, Hotjar, Stripe, Intercom, etc.)<\/li>\n<\/ul>\n\n<h4>Anonymous beacon mode<\/h4>\n\n<p>GTM rules often suppress pixels for logged-in WordPress administrators. ScriptSpy generates a tokenized scan URL you can open in incognito to capture those pixels \u2014 without exposing the beacon to your real visitors.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>ScriptSpy makes no external HTTP requests except scanning your own site. No telemetry, no phone-home, no third-party API calls. The bundled knowledge base is a static JSON file shipped with the plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>scriptspy<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate via Plugins menu in WordPress.<\/li>\n<li>Go to Tools \u2192 ScriptSpy.<\/li>\n<li>Click <strong>Start new scan<\/strong>.<\/li>\n<li>Open the anonymous scan URL in an incognito window and browse a few pages so the beacon can capture dynamically loaded scripts.<\/li>\n<li>Return to the dashboard, review results, download PDF or CSV.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20replace%20a%20cookie%20consent%20banner%3F\"><h3>Does this replace a cookie consent banner?<\/h3><\/dt>\n<dd><p>No. ScriptSpy detects and reports \u2014 it does not block scripts or show banners to visitors. Use it alongside a consent platform.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>The server scan runs in batches via WP-Cron, not on visitor requests. The browser beacon is injected only for logged-in admins or visitors carrying a valid scan token \u2014 never for normal traffic.<\/p><\/dd>\n<dt id=\"can%20it%20detect%20server-side%20conversion%20apis%20%28e.g.%2C%20meta%20conversions%20api%29%3F\"><h3>Can it detect server-side conversion APIs (e.g., Meta Conversions API)?<\/h3><\/dt>\n<dd><p>No. Server-to-server calls are invisible to client-side detection by design. ScriptSpy lists known server-side endpoints in its knowledge base for awareness but cannot confirm whether they fire.<\/p><\/dd>\n<dt id=\"why%20are%20some%20pixels%20missing%20from%20the%20report%3F\"><h3>Why are some pixels missing from the report?<\/h3><\/dt>\n<dd><p>Many GTM containers exclude logged-in WordPress administrators from firing pixels. Use the <strong>anonymous scan URL<\/strong> in an incognito browser to capture those pixels.<\/p><\/dd>\n<dt id=\"does%20the%20pdf%20require%20any%20external%20libraries%3F\"><h3>Does the PDF require any external libraries?<\/h3><\/dt>\n<dd><p>The plugin bundles TCPDF 7 (via Composer) and the Helvetica core font definitions it needs. If TCPDF is unavailable for any reason, ScriptSpy falls back to a styled HTML report download.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fixed: inline-detected scripts (Google Analytics, Meta Pixel, Intercom and others recognised from inline snippets) showed a knowledge base id where the domain belongs. They are now labelled \"inline script\".<\/li>\n<li>Fixed: the Google Analytics 4 measurement endpoint (<code>\/g\/collect<\/code>) was not in the knowledge base, so GA4 traffic captured by the browser beacon was counted as unrecognized.<\/li>\n<li>Fixed: long privacy policy and page URLs overlapped the following line in the PDF script inventory.<\/li>\n<li>Knowledge base updated to v1.0.1.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Upgraded bundled TCPDF to 7.0.7 (now requires PHP 8.2+).<\/li>\n<li>Generic CDN hosts are now classified through the bundled knowledge base instead of a hard-coded list.<\/li>\n<li>Browser beacon is enqueued through <code>wp_enqueue_scripts<\/code>.<\/li>\n<li>Hardened scan-token validation, CSV export and settings sanitization.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Two-layer detection: server-side DOMDocument scan + browser beacon.<\/li>\n<li>Anonymous tokenized beacon mode for capturing pixels GTM hides from admins.<\/li>\n<li>PDF and CSV export.<\/li>\n<li>Cookie and localStorage detection.<\/li>\n<li>Scan history and diff.<\/li>\n<li>Bundled knowledge base of 70+ third-party services.<\/li>\n<\/ul>","raw_excerpt":"Detect every third-party script loading on your site, identify owners, data collected, and export a GDPR audit report your lawyer can use.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/309338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=309338"}],"author":[{"embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/loyaltyoverroyalty"}],"wp:attachment":[{"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=309338"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=309338"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=309338"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=309338"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=309338"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=309338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}