GET /trackers returns every third-party tracker a page loads: analytics, advertising pixels, session replay, chat widgets, marketing automation, A/B testing and monitoring. It loads the page in a real browser, so it also finds the pixels a tag manager injects, which you will never see by reading the page source.
Why the page source isn't enough
Most sites don't paste the Meta Pixel into their HTML any more. They install Google Tag Manager once, and marketing adds pixels inside it. The source shows one script. The browser then loads ten more.
We ran the endpoint on a well-known retail site as a test. Its HTML referenced three tools. The browser loaded thirteen, and ten of those were injected: seven advertising pixels, two session-replay tools and an analytics tag, none of them visible in the source.
That gap is why a website privacy audit done by viewing source undercounts.
What the response contains
curl "https://seoscoreapi.com/trackers?url=https://example.com" \
-H "X-API-Key: YOUR_KEY"
{
"summary": {
"trackers": 13,
"by_category": {"advertising": 7, "session_replay": 2, "analytics": 1,
"tag_manager": 1, "marketing_automation": 1, "ab_testing": 1},
"tracker_requests": 94,
"tracker_bytes": 1828826,
"third_party_requests": 269,
"consent_manager": "OneTrust"
},
"trackers": [
{
"vendor": "TikTok Pixel",
"category": "advertising",
"found_in": ["network"],
"injected": true,
"requests": 15,
"transfer_bytes": 168683,
"evidence": ["https://analytics.tiktok.com/i18n/pixel/events.js"]
}
]
}
For each tracker you get the vendor, its category, whether it was in the source or only on the network, how many requests it made, and how many bytes they transferred. injected: true means something else loaded it, usually a tag manager. Google Analytics, Tag Manager and Google Ads entries also carry the account id when the page exposes one.
summary.consent_manager names the consent tool on the page, if there is one. The endpoint recognises 59 tracker vendors and 10 consent managers.
What it does not tell you
It reports what loaded during one visit with no clicks. It does not tell you whether a tracker waited for consent, because a single automated visit can't establish that, and it is not legal advice. Use it as an inventory: the list of what is on the page, to check against what you thought was there.
Three uses
Privacy reviews. Before a privacy policy is written or updated, someone has to list what the site actually sends to third parties. This is that list, with evidence URLs.
Client onboarding for agencies. Sites collect pixels from campaigns that ended years ago. The inventory shows what is still loading and what it weighs, which is an easy first cleanup to propose.
Performance. tracker_bytes and the per-vendor totals show how much of a page's weight is third-party tracking. One retail homepage in our test loaded 1.8 MB of it.
Running it across a site
The endpoint takes one URL. To cover a site, loop over the pages that matter, since a checkout or a booking page often carries different pixels from the homepage:
import requests
pages = ["https://example.com/", "https://example.com/pricing", "https://example.com/contact"]
for page in pages:
r = requests.get("https://seoscoreapi.com/trackers",
params={"url": page}, headers={"X-API-Key": "YOUR_KEY"})
data = r.json()
names = sorted(t["vendor"] for t in data["trackers"])
print(page, len(names), names)
Each call counts as one audit against your plan. A page that can't be loaded returns a 422 with a reason and isn't counted.
Frequently asked questions
Which plans include the tracker inventory?
All of them, including the free tier's two audits a day.
Does it detect self-hosted analytics?
It recognises Matomo by its script name wherever it is hosted. A custom first-party analytics script with no known signature won't be listed.
Does it check for a cookie banner?
It reports the consent manager it finds, by name. It doesn't test what the banner does.