Third-party scripts can add analytics, chat, maps, video, booking, personalization, advertising, or support features. Each script also adds provider dependency, performance, privacy, security, failure, and maintenance work that should be visible.
Inventory every script
Collect scripts from templates, tag managers, components, embeds, plugins, consent tools, and browser requests. Record provider, purpose, page, owner, loading method, data, cookies, destination, and date reviewed.
Confirm business purpose
Ask what decision or customer task the script supports and whether that purpose still exists. Remove a script that only remains because nobody knows whether the business needs it.
Check consent and data flow
Document what loads before or after a visitor choice, what data leaves the site, which provider receives it, and how opt-out or deletion works. Keep the page and privacy explanation aligned with the real behavior.
The cookie audit checklist and privacy page guide cover data and choice.
Measure performance impact
Test blocking time, requests, transfer size, main-thread work, layout shift, interaction delay, and mobile behavior with the script active. Consider whether a tag can load later, only on relevant pages, or through a lighter provider.
Test failure behavior
Block the provider, delay it, return an error, and disable the network. Confirm that content, forms, booking, navigation, accessibility, and support do not become unusable when an optional script fails.
Review access and supply chain
Limit who can add or edit tags, record provider changes, review permissions, and keep a removal path. Treat an external script as a dependency that can change outside the website release.
Assign an owner and cadence
Give every script an owner, review date, purpose, performance threshold, privacy note, and removal decision. Recheck after provider, campaign, analytics, booking, or consent changes.
Third-party scripts keep appearing without an owner? Ask Vertinus to inventory, test, and prioritize the dependencies.