Account setup, automated container audits, version diffing, AI living documentation, team workflows, and scheduled monitoring. Use the sidebar to jump straight to what you need.
GTMalyzer is an automated intelligence and documentation suite built for digital marketers, analytics engineers, SEO specialists, and agencies managing Google Tag Manager at scale.
New to GTMalyzer? Jump into a quick audit to see your container health score in under 60 seconds.
Modern Google Tag Manager containers are complex codebases that accumulate technical debt over years: broken triggers, orphaned variables, unvetted external scripts, and GDPR consent violations. GTMalyzer replaces manual spreadsheet audits and risky releases with instant AI-powered scans, automated living documentation, version diffing, and deployment approvals.
Key platform pillars
Everything in GTMalyzer is structured around six core capabilities:
•Automated Multi-Domain Auditing: Deterministic configuration checks paired with Gemini AI evaluation across Cleanliness, Performance, Security, and GDPR Privacy.
•Container Version Diffing: Item-level and line-by-line character comparisons between any two container exports or live versions.
•AI Living Documentation: Natural-language summaries of every tag, trigger, and variable, with one-click note syncing back into Google Tag Manager.
•Deployments & Approval Gates: Safe multi-stage deployment workflows with approval requirements for production containers.
•Container Monitoring & Alerts: Scheduled container health checks delivering immediate notifications via Slack and custom webhooks.
•Team Workspaces & Access Control: Centralized multi-client management with granular role permissions (Owner, Admin, Member).
GETTING STARTED
Sign in & Authentication
Connect securely with your Google account via OAuth 2.0 to access live GTM accounts, or use the instant JSON export upload fallback if you don't have direct API access.
Google OAuth Access
When you connect via Google OAuth, GTMalyzer requests read-only and container editing permissions (https://www.googleapis.com/auth/tagmanager.readonly and https://www.googleapis.com/auth/tagmanager.edit.containers). The edit scope allows GTMalyzer to push AI documentation notes directly to your GTM workspace and create staged draft workspaces for deployments. Your OAuth tokens are encrypted at rest using industry-standard AES-256.
JSON Upload Fallback
If your organization restricts third-party OAuth access or you are auditing a client container before gaining Google account permissions, you can export your container directly from Google Tag Manager (Admin → Export Container) and drop the .json file into our uploader. Both workflows run the exact same deterministic rules and AI-powered multi-domain analysis.
Session Management
GTMalyzer sessions are secured with JWT and NextAuth. If your token expires during an active session, the app silently re-authenticates or presents a non-intrusive re-login modal preserving your current form state and unsaved inputs.
GTMalyzer only reads container configuration schemas. We never inspect your website visitors' personal data, live traffic payloads, or analytics hits.
GETTING STARTED
Workspaces & Team Roles
Organize clients, brands, and team members into isolated workspaces. Share audit reports, living documentation, and deployment templates seamlessly.
Inviting team members to a workspace
1
Open Team Settings
Navigate to the Team tab from the main sidebar navigation.
2
Teammate Sign-in
Ensure your team member has signed in to GTMalyzer with their email address.
3
Add Member
Click 'Invite Member', enter their email address, and select their role (Admin or Member) to grant workspace access instantly.
Workspace Roles & Permissions
Each workspace maintains strict role-based access control (RBAC):
•Owner: Primary billing contact. Can delete the workspace, transfer ownership, manage subscriptions, and invite/remove any user.
•Admin: Can invite members, configure workspace webhooks, manage Slack integrations, and approve container deployment requests.
•Member: Can run container audits, view comparison diffs, generate living documentation, and submit deployment proposals.
GETTING STARTEDFree
Plans & Credit System
GTMalyzer operates on a predictable credit model. Every account receives free credits upon registration, with scalable monthly tiers and one-off top-up packs.
Monthly balances reset on your billing anniversary
What consumes a credit?
A single credit covers a complete container audit (Cleanliness, Security, Performance, GDPR compliance), an AI living documentation generation, or a deep version comparison diff. Viewing existing reports, re-opening audit history, and downloading PDFs do not consume any credits.
On-demand Credit Top-ups
If you run out of monthly credits during an intensive client onboarding or audit sprint, you can purchase credit top-up packs directly from the Billing page without upgrading your subscription plan.
CONTAINER AUDITINGCore
Running an Audit
Execute deterministic configuration checks and AI-powered contextual evaluation on any GTM container in under 60 seconds.
How to run your first container audit
1
Navigate to New Audit
Click 'Audits' in the sidebar, then select 'New Audit'.
2
Select Container Source
Choose either 'Live GTM Account' (via OAuth) or 'Upload GTM JSON Export'.
3
Multi-Domain Evaluation
GTMalyzer automatically analyzes Cleanliness, Performance, Security, and GDPR compliance.
4
Run & Inspect
Click 'Run Audit'. Full deterministic checks and AI findings are generated in seconds.
Audits are permanently cached in your audit history. You can return to them, generate updated remediations, or re-download PDF exports at any time without consuming credits.
CONTAINER AUDITING
Cleanliness & Hygiene Audit
Detect abandoned tags, broken trigger linkages, orphaned variables, and inconsistent naming conventions that clutter your container and confuse team members.
Key Checks Performed
Our static engine analyzes every element for hygiene anomalies:
•Orphaned Variables: Identifies User-Defined Variables that are never referenced by any tag, trigger, or child variable.
•Unlinked Triggers: Flags triggers that have no firing tags assigned to them.
•Paused Tags: Highlights legacy tags left paused that contribute to container payload bloat.
•Duplicate Firing Rules: Catches multiple tags listening to the exact same event on the same page with duplicate payloads.
•Naming Convention Deviations: Flags tags and triggers violating standard naming formats (e.g. '[Vendor] - [Event] - [Destination]').
CONTAINER AUDITING
Performance & Payload Audit
Identify heavy third-party scripts, oversized Custom HTML blocks, and runaway triggers that harm Core Web Vitals and degrade user experience.
What we monitor
Performance checks target the main causes of frontend latency:
•Container Payload Size: Analyzes overall tag, trigger, and variable count for payload bloat.
•Custom HTML Complexity: Flags inline JavaScript tags containing resource-intensive loops, heavy DOM queries, or blocking code.
•Micro-Interaction & Runaway Triggers: Evaluates scroll and visibility triggers that fire excessively without debouncing.
•Duplicate Firing Tags: Highlights tags executing concurrently on the same trigger event.
CONTAINER AUDITINGCore
Security & Vulnerability Audit
Protect your users and website integrity by detecting unverified third-party script injections, risky DOM manipulations, and accidental credential leaks.
Security scan criteria
The security analysis inspects Custom HTML and variables for high-risk patterns:
•Unverified External Endpoints: Flags network requests to unknown third-party endpoints or unauthorized CDNs.
•High-Risk DOM Manipulations: Scans Custom HTML tags for unsafe element insertions, outerHTML rewrites, and innerHTML injections vulnerable to Cross-Site Scripting (XSS).
•Secret & API Key Leakage: Searches variable values and tag parameters for exposed private tokens, authorization bearer headers, or unhashed passwords.
•Form Field Harvesting: Identifies scripts attempting to read inputs with sensitive password or payment card patterns.
Never place private API secret keys or payment processor private tokens inside GTM variables. GTM configurations are entirely public in the visitor's browser.
CONTAINER AUDITINGCore
GDPR & Consent Mode v2 Audit
Ensure complete compliance with European privacy regulations (GDPR/ePrivacy) and verify Google Consent Mode v2 configuration before facing regulatory penalties.
Consent evaluation rules
Our AI engine inspects the sequence and configuration of consent logic:
•Consent Mode v2 Signals: Verifies default states for ad_storage, analytics_storage, ad_user_data, and ad_personalization.
•Premature Tag Firing: Flags marketing and tracking tags that fire on generic 'All Pages' or 'DOM Ready' before user consent has been explicitly granted.
•Manual CMP Bypass: Scans custom scripts for code that modifies cookies (like CookieConsent or OptanonAlertBoxClosed) to trick the consent management platform.
•Automated Opt-In Violations: Flags default configuration parameters that set opt-in flags to 'granted' without an active user gesture.
CONTAINER AUDITING
Health Scores & Remediations
Every audit calculates a deterministic 0-100 container health score and provides actionable, step-by-step remediation recipes for every identified issue.
Health Score Calculation
The overall Container Health Score (0-100) is deterministically calculated from configuration checks: each failed check deducts 18 points, and each warning deducts 7 points. Informational checks and AI findings do not lower the score, providing clear and predictable benchmarking. Containers with scores above 85 are considered healthy.
Actionable Remediation Plans
Every check and AI issue includes an actionable remediation recommendation and associated configuration evidence. Teams can also manage remediation progress directly on the report by setting issue statuses to Open, In Progress, or Resolved.
CONTAINER AUDITING
Tokenized Sharing & PDF Export
Deliver professional audit reports to clients, stakeholders, and developers via cryptographically secure public links or branded PDF downloads.
Shareable Tokenized Links
Generate a unique read-only link for any audit. Anyone with the link can explore the full interactive audit findings and health scores without requiring a GTMalyzer login or account.
Print & PDF Optimization
Click the 'Download PDF' or 'Print' button on any audit report. GTMalyzer applies a clean, print-optimized stylesheet with page breaks, high-contrast charts, and formatted issue tables ideal for client presentations.
CONTAINER DIFFCore
Container Diff Overview
Compare any two versions of a GTM container or upload two separate JSON exports to visually inspect every addition, deletion, and code change.
How to compare two container versions
1
Open Compare Tool
Navigate to 'Compare' in the sidebar navigation.
2
Select Version A (Base)
Select the baseline container version or upload the older JSON export.
3
Select Version B (Target)
Select the comparison version or upload the newer JSON export.
4
Generate Diff
Click 'Compare Containers' to render the interactive structural and code diffs.
CONTAINER DIFF
Item-Level Structural Diff
Review added, modified, and removed tags, triggers, and variables grouped cleanly with status indicators.
What is tracked
Structural comparisons identify:
•Added Elements: Newly created tags, triggers, or variables highlighted in green.
•Modified Elements: Existing elements whose parameters, firing conditions, or consent settings changed, highlighted in amber.
•Removed Elements: Deleted tags, triggers, or variables highlighted in red.
•Firing Trigger Alterations: Shows exactly which triggers were attached or detached from existing tags.
CONTAINER DIFF
Code-Level Line Diffing
Inspect line-by-line syntax changes inside Custom HTML tags and Custom JavaScript variables with side-by-side and unified code views.
Detailed Code Analysis
Whenever a Custom HTML tag or Custom JavaScript variable is modified between versions, GTMalyzer runs a character-level unified diff. Green rows denote inserted lines, red rows denote deleted code, and changed variables within lines are highlighted for rapid code review.
LIVING DOCSCore
Component Documentation
Generate plain-English, technical specifications for every asset in your GTM container automatically using Google Gemini AI.
Automated Plain-English Summaries
Rather than decoding cryptic regex variables or nested trigger conditions manually, GTMalyzer translates each component into clear documentation explaining: what the tag does, when it fires, what data it collects, and where it sends the payload.
Target Audience
Perfect for onboarding new analytics engineers, preparing compliance records for legal teams, or handing off client projects with complete documentation.
LIVING DOCSCore
Push Notes to Google Tag Manager
Write AI-generated documentation notes directly into your live Google Tag Manager container with a single click.
One-Click GTM Workspace Synchronization
Rather than keeping documentation trapped in an external tool, GTMalyzer connects directly to the Google Tag Manager API. You can push AI summaries straight into the native 'Notes' field of any tag, trigger, or variable in your chosen GTM workspace.
Preserve Container Knowledge
When team members or external consultants open your container inside Google Tag Manager, they see exact explanations of what each tag does and why it was created, eliminating guesswork and preventing accidental deletions.
DEPLOY & TEMPLATESPro
GTM Deployments
Deploy verified tag templates and audit fixes directly to your Google Tag Manager containers with version staging and safety checks.
Staged Deployment Process
All deployment operations create a draft workspace in the target GTM container. Nothing is published directly to live production without explicit user review in the GTM interface, preventing accidental tracking outages.
DEPLOY & TEMPLATES
Template Library
Save, organize, and reuse battle-tested tracking recipes, Consent Mode v2 configurations, and custom JavaScript variables across all your containers.
Standardizing Tracking Standards
Create custom templates for ecommerce events (GA4 Purchase, Add to Cart, View Item), server-side tagging setups, or privacy consent banners and push them to any client container with one click.
DEPLOY & TEMPLATESAgency
Team Approvals Workflow
Enforce four-eyes review policies before changes are deployed to client containers, ensuring strict quality assurance and audit trails.
How Approvals Work
When an analytics specialist creates a deployment request, team Admins or Owners receive an alert. They can inspect the associated container diff, verify health score impact, and approve or reject the release with feedback notes.
MONITORING & ALERTSPro
Scheduled Monitoring
Automate periodic health checks on your production containers to catch unauthorized edits, broken triggers, or sudden security vulnerabilities immediately.
Setting up a container monitor
1
Open Monitoring Panel
Navigate to 'Monitoring' in the sidebar.
2
Select Container
Choose the live GTM container to monitor.
3
Define Schedule
Select an hourly, daily, or weekly monitoring frequency.
4
Connect Webhooks
Connect workspace webhooks (Slack or custom HTTP endpoints) to receive notifications when check runs complete.
MONITORING & ALERTS
Slack & Custom Webhooks
Deliver instantaneous alerts to your team's Slack channels or any custom HTTP endpoint when an audit fails or a container regression is detected.
Connecting Slack
Create an Incoming Webhook in your Slack Workspace (api.slack.com/apps), paste the webhook URL into your GTMalyzer workspace settings, and send a test notification to verify delivery.
Custom HTTPS Webhooks
Stream structured JSON payloads for monitor runs, audit completions, and deployment approvals to endpoints like Zapier, Make, n8n, or internal incident response pipelines.
FAQ
Common Questions & Support
Find fast answers to common questions regarding security, billing, container privacy, and support response times.
Does GTMalyzer store my website visitors' tracking data?
No. GTMalyzer exclusively analyzes container configuration architecture (JSON schemas consisting of tags, triggers, and variables). We never place tracking scripts on your website and never collect or store your website visitors' personal data or browsing hits.
Do I need Google OAuth verification to audit my container?
No. While Google OAuth offers convenient direct access to live GTM accounts, you can always export your container as a .json file directly from Google Tag Manager and upload it instantly to GTMalyzer with zero Google authorization steps.
Can I share audit reports with clients without giving them an account?
Yes. Every audit report includes a 'Share' button that generates a secure tokenized public URL. Anyone with this link can view the complete interactive audit, health score, and remediation steps without logging in.
What happens when my monthly credits run out?
Existing audit reports, diff comparisons, and living docs remain accessible forever. To run new audits or documentation generations, you can purchase one-off top-up credit packs or upgrade your monthly subscription.
How do I report an issue or request a feature?
Our engineering team responds to all inquiries within one business day. Reach out via the Contact page or email us directly at [email protected].
Still have questions?
We answer all support and technical questions directly within one business day. Contact our engineering team for help with custom GTM integrations or enterprise requirements.