The stack is a list of decisions someone paid for
A competitor’s revenue is behind their login and can only be guessed at. Their app stack is served to anyone who loads the page. It is public, checkable, and it says more about how the business actually works than a modelled monthly figure ever will.
317 domains. 243 companies. 106 of them tracking. That is the maintained fingerprint set — and the gap between the first two numbers is the point: Google Analytics and Google Ads are two domains and one company, and counting them separately inflates the only figure that matters.
What the categories look like
The largest groups in the catalogue, by number of distinct services:
| Category | Services | What it signals |
|---|---|---|
| Advertising | 21 | Paid acquisition, and how many channels at once |
| Upsell & cross-sell | 18 | Working the basket rather than the funnel |
| Analytics | 13 | Measurement — and often several overlapping tools |
| Payments | 12 | Which markets and methods they are set up for |
| Reviews | 12 | Social proof as a deliberate investment |
| Popups & email capture | 11 | Owned-audience building |
| Consent management | 9 | Someone thought about compliance |
| Session replay | 8 | Watching individual sessions back |
| Social proof & urgency | 7 | Pressure tactics, sometimes fabricated |
How to read a stack
The individual names matter less than the shape:
- Reviews + loyalty + subscriptions — a business built on repeat purchase. They expect a customer to come back, and are paying monthly for it.
- Urgency widgets + one pixel + nothing else — buying traffic and converting it once. Often a store that will not exist in six months, which is worth knowing before you copy its product selection.
- Three analytics tools — either sophisticated attribution or nobody ever removed the last two. Both are informative.
- No consent platform, EU traffic — a compliance decision, made or not made.
- Session replay — someone is watching recordings of individual visitors. Legal, common, and something most shoppers assume is not happening.
Why a third of the catalogue is marked tracking
106 of 317 vendors are flagged as existing wholly or partly to identify or profile visitors — and that flag is applied conservatively, so it is a floor rather than a ceiling. The density is not uniform: advertising and analytics are almost entirely tracking, while payments, CDNs and fonts largely are not.
That distinction matters when you look at a page and see “fourteen third parties”. Fourteen CDNs and font hosts is a different fact about a site than fourteen ad networks, and a count that does not separate them is not telling you much.
The part that is genuinely surprising
How much of it fires before anyone consents to anything. That is a separate measurement and we made it: the Consent Gap Index counts the companies a page contacts before the banner is answered. A cookie banner is a question, and on a great many sites the answer arrives after the data has already left.
What this cannot tell you
- What each app costs them. Pricing is per-plan and mostly private.
- Whether any of it works. A stack is evidence of intent, not of results.
- Server-side tools. Anything that runs in their backend never reaches your browser, so no detector can see it. What you get is the client-side stack, which is most of it but never all.
MurmStack names every third party a page contacts, groups them by company rather than domain, and shows the evidence for each match — so the count is checkable rather than asserted.
How MurmStack works →→Questions
How do I see what apps a Shopify store uses?
The apps announce themselves by loading scripts from their own domains. A detector matches those domains against a catalogue.
Domains or companies — which number matters?
Companies. Two Google domains are one company, and conflating them inflates the figure.
What does the stack reveal?
Where the money and attention go: repeat purchase, or one-time conversion.
Is checking this legal?
You are reading what a public page sent to your own browser.