Google Tag Manager
Google Tag Manager is a container. Instead of a developer adding each analytics, advertising or support script to the page by hand, the site loads one Google script that decides at runtime which other scripts to fetch, and a marketing team edits that list without touching the codebase. The indirection is why the name shows up in so many devtools panels and privacy reports: it is usually not the thing collecting anything, it is the thing that fetched whatever is. This index detected it on 4,007 of the 5,294 sites measured, 75.7% of them, more sites than any other technology tracked here.
The reach is the finding; the rest is the web's own middle
No other technology in this index appears on more sites. That single fact changes how the rest of the numbers should be read.
When a group holds three out of every four measured sites, its medians stop being a property of the tool. The median site here contacted 6 companies over 33 requests with 1 of them classified as tracking, and among the thirteen technologies in this index that is sixth by company count, eighth by request count and fifth by tracker count — mid-table on every measure. A tag manager does not make a page heavy or light. It is present on the heavy ones and the light ones because it is present on nearly everything.
One container, wildly different contents
What a container loads is decided site by site, and the examples show how far apart those decisions land. doubleclick.net contacted 1 company. cloudflare.com and wordpress.org contacted 2 each. mail.ru contacted 14, with 9 of them reached before the consent point.
The same spread shows in the middle of the range: netflix.com and spotify.com each reached 6 companies, fastly.net 7, tiktok.com 4, gandi.net 3. A detection tells you the mechanism is installed. It says nothing about the size of the list inside it, which is why counting containers is a poor proxy for counting exposure.
Timing, from 54 ms to well past two seconds
Across the group the median first third-party contact came at 659 ms, and the earliest recorded anywhere in it was 54 ms. Ranked against the other twelve technologies from latest median to earliest, this group sits ninth — towards the early end.
The examples straddle that median by a wide margin. mail.ru made first contact at 338 ms, cloudflare.net at 343 ms, wordpress.org at 495 ms. At the other end digicert.com waited 2,408 ms and ntp.org 2,085 ms, and on both of those the crawl recorded no company at all reached before the consent point. gandi.net at 1,686 ms sits between the two behaviours with 2 of its 3 companies inside the window.
Consent tooling on the sites that carry it
A consent tool was detected on 1,908 of the 4,007 sites — a little under half. Seen alongside the container were OneTrust on 845 sites, an IAB TCF consent tool on 740, Cookiebot on 104, Osano on 70, Usercentrics on 60 and CookieYes on 57. Those figures are not slices of the 1,908: a site can carry more than one banner product, so they overlap and are counted separately.
In the examples the banner and the container coexist without a fixed pattern. cloudflare.com, netflix.com, spotify.com, fastly.net and cloudflare.net were all recorded with OneTrust; mail.ru, tiktok.com, doubleclick.net, wordpress.org, digicert.com, gandi.net and ntp.org with no detected consent tool at all.
Early contact on 3,693 sites
On 3,693 of the 4,007 sites, 92.2%, at least one company was contacted before the banner could have been answered, and the median site had 4 companies arrive inside that window. After the window, the median site added none: the median count of companies appearing afterwards is 0.
That is a statement about those pages, not an attribution to the container, which is why the two ends of the example set are worth putting side by side. netflix.com reached 6 companies with all 6 inside the window; digicert.com reached 5 with none inside it. Same technology, opposite sequencing.
| Site | Companies | Before consent | First contact |
|---|---|---|---|
| cloudflare.com | 2 | 2 | 1242 ms |
| mail.ru | 14 | 9 | 338 ms |
| fastly.net | 7 | 3 | 670 ms |
| doubleclick.net | 1 | 1 | 955 ms |
| netflix.com | 6 | 6 | 1003 ms |
| wordpress.org | 2 | 2 | 495 ms |
| digicert.com | 5 | 0 | 2408 ms |
| gandi.net | 3 | 2 | 1686 ms |
| tiktok.com | 4 | 4 | 530 ms |
| cloudflare.net | 4 | 2 | 343 ms |
| spotify.com | 6 | 6 | 550 ms |
| ntp.org | 4 | 0 | 2085 ms |
| Tool | Sites |
|---|---|
| OneTrust | 845 |
| IAB TCF consent tool | 740 |
| Cookiebot | 104 |
| Osano | 70 |
| Usercentrics | 60 |
| CookieYes | 57 |
The six most common are listed. The remaining 32 of 1908 sites with a banner carry something outside that six. One tool is recorded per site, so these counts never overlap.
Questions
What does Google Tag Manager actually load?
Whatever the site put in its container — analytics, advertising pixels, chat widgets, A/B testing, sometimes nothing beyond a single measurement tag. The list is site-specific, which is why the per-site counts in this index range from 1 company to 14 among the examples alone.
Is it the same thing as Google Analytics?
No. The tag manager is the loader; an analytics product is one of the things a container can be configured to load. A page can carry the container without carrying analytics, and can carry analytics with no container at all.
Why does it appear on sites that contact almost nobody?
Because it is installed as infrastructure rather than as a decision about tracking. doubleclick.net was recorded contacting 1 company and wordpress.org 2, both with the container present.
How many of the Google Tag Manager sites showed a consent banner?
1,908 of the 4,007. The most common one seen alongside was OneTrust, on 845 sites, with an IAB TCF consent tool on 740.
Why does first contact sometimes take two seconds?
Because the container itself has to be fetched and evaluated before anything it holds runs, and a site can defer that further. digicert.com made first contact at 2,408 ms and ntp.org at 2,085 ms, against a group median of 659 ms.