PerformanceChecked through WebDiag API

Third-party Script Analyzer

Enter a URL to inspect script elements in source HTML without executing JavaScript, building a runtime waterfall, or making fake tracker claims.

  • static HTML
  • async / defer / module
  • hostname classification
Online tool

Try the tool

Enter a URL: WebDiag will run a safe network check and show the result.

Page URL

Network check through backend

For HTTP/SEO tools, the URL is sent to the WebDiag API, where SSRF protection, DNS/IP policy, and redirect limits are applied.

Reviewed: 2026-07-17
01

How to use it

  1. 1

    Enter a public page URL.

  2. 2

    Run the bounded script inventory.

  3. 3

    Review cross-host scripts, blocking candidates, duplicates, and host groups.

02

What the tool can do

  • Separates inline, external, same-host, and cross-host candidates.
  • Shows async, defer, module, nomodule, integrity, and crossorigin.
  • Groups known hostname patterns for analytics, tag managers, ads, social platforms, and CDNs.
03

Common use cases

  • Review the script surface after adding analytics or a tag manager.
  • Find parser-blocking candidates and duplicate src values.
  • Prepare an inventory for performance and privacy review.
04

How it works inside

The tool makes one SafeHttpFetcher request and does not download JavaScript resources.

Hostname groups are a transparent heuristic, not a verdict about script purpose.

05

Questions and answers

Does the tool find every tracker?

No. It shows static script sources and selected known hostname patterns without runtime execution.

Why can a same-host script still be third-party?

A reverse proxy or first-party collection endpoint can hide the actual provider; ownership requires manual review.