Meta Pixel & CAPI
Detect Facebook / Meta Pixel and Conversions API scripts that fire before consent.
New apps, pixels, and theme updates can bypass your cookie banner. Automatically audit your store in a real browser and catch tracking leaks.
By running this scan, you confirm you are authorized to audit this domain and agree to our Terms of Service and Privacy Policy.
Keep your CMP. SecureSpells is your runtime safety net — works alongside Cookiebot, OneTrust, CookieYes, and custom CMPs.
Cookiebot (or another CMP) is set up and the store looks compliant.
A Shopify app install or Klaviyo / Meta pixel update lands in Google Tag Manager.
Scripts execute before consent — customers never see the banner first.
Shoppers complain or auditors warn. The CMP banner still looks fine.
| Capability | Your CMP | SecureSpells Watchtower |
|---|---|---|
| Primary job | Collects & records visitor consent | Verifies actual browser network egress & tracking |
| Execution reality | Controls the banner interface | Tests what scripts actually execute in a real browser |
| Change detection | Assumes site code remains static | Detects unexpected trackers from apps or deploys |
| Role in stack | Consent collection | Independent runtime verification |
High-intent shops run Meta, TikTok, Klaviyo, and GTM together. SecureSpells catches when those layers drift past consent.
Detect Facebook / Meta Pixel and Conversions API scripts that fire before consent.
Catch ad tags injected by apps or GTM that bypass the banner.
Surface email and retention scripts that load on every storefront visit.
Verify Tag Manager containers and Analytics tags against consent timing.
Spot trackers introduced by plugins and marketplace apps after launch.
Monitor this store with Professional Workbench (€129.00/mo). Running multiple storefronts? See Agency Workspace from €329.00/mo.
Multi-store teams: Agency Workspace for reusable client slots.
Including the ones where the honest answer is not the flattering one.