How to use it
- 1
Enter a public page URL.
- 2
Run the bounded script inventory.
- 3
Review cross-host scripts, blocking candidates, duplicates, and host groups.
What the tool can do
- Separates inline, external, same-host, and cross-host candidates.
- Shows async, defer, module, nomodule, integrity, and crossorigin.
- Groups known hostname patterns for analytics, tag managers, ads, social platforms, and CDNs.
Common use cases
- Review the script surface after adding analytics or a tag manager.
- Find parser-blocking candidates and duplicate src values.
- Prepare an inventory for performance and privacy review.
How it works inside
The tool makes one SafeHttpFetcher request and does not download JavaScript resources.
Hostname groups are a transparent heuristic, not a verdict about script purpose.
Questions and answers
Does the tool find every tracker?
No. It shows static script sources and selected known hostname patterns without runtime execution.
Why can a same-host script still be third-party?
A reverse proxy or first-party collection endpoint can hide the actual provider; ownership requires manual review.
