ScriptSpy – Third-Party Script Intelligence Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
ScriptSpy is a focused script intelligence dashboard. It is not a cookie banner and not a consent wizard — those tools already exist. ScriptSpy answers one question:
“What is loading on my site, who owns it, what data does it collect, and give me a PDF I can show my lawyer.”
Two-layer detection
- Server-side scan — fetches your own pages with
wp_remote_getand parses HTML withDOMDocumentto extract every external script, iframe, preconnect hint, and tracking pixel. Catches statically loaded scripts. - Browser beacon — a JavaScript beacon you can run in a real browser (logged-in admin or anonymous via signed token URL). Uses
PerformanceObserver,MutationObserver, and interceptsfetch,XMLHttpRequest, andnavigator.sendBeaconto capture every dynamically loaded resource — including pixels that Google Tag Manager loads after page render.
What you get
- Live dashboard with summary cards: total scripts, known/identified, require consent, unrecognized
- Per-script detail modal: owner, country, data collected, legal basis, GDPR relevance, data transfer destination, Schrems II notes, links to privacy policy and DPA
- PDF audit report (cover, executive summary, full inventory, unknown scripts list)
- CSV export
- Cookie + localStorage detection
- Scan history with diff between scans (added/removed scripts)
- Optional weekly/monthly automated scans with email reports
- Knowledge base of 70+ third-party services (Google Analytics, Meta Pixel, TikTok, Hotjar, Stripe, Intercom, etc.)
Anonymous beacon mode
GTM rules often suppress pixels for logged-in WordPress administrators. ScriptSpy generates a tokenized scan URL you can open in incognito to capture those pixels — without exposing the beacon to your real visitors.
Privacy
ScriptSpy makes no external HTTP requests except scanning your own site. No telemetry, no phone-home, no third-party API calls. The bundled knowledge base is a static JSON file shipped with the plugin.
Screenshots
Main dashboard: summary cards, filters, and the results table with owner, category, data collected and GDPR level for every script.
Script detail: owner, country, data collected, legal basis, data transfer destination, Schrems II note, and every page the script was found on.
Scan in progress: server scan percentage, live browser-beacon status, and the anonymous scan URL.
Diff between two scans – scripts added and removed.
PDF audit report: executive summary and full script inventory.
Scan history with per-scan PDF and CSV export, plus diff against the previous scan.
Settings: scan depth, scheduled scans, email reports and excluded domains.

