Capabilities

What Safeliant checks

Every check below is implemented and running today. Where a capability carries a limit a reader needs to know about, it is marked LIMITED and the limit is stated with it — not in a footnote.

Measurement

GA4, Google Ads, Meta and GTM behaviour, and the integrity of the ecommerce events themselves. Beacons are decoded into event name, value and currency rather than counted.

  • No web analytics detected on the storefront

    LIVE
  • GA4 absent while other analytics is present

    LIVE
  • Deprecated Universal Analytics tag still installed

    LIVE
  • Multiple GA4 measurement IDs on one page

    LIVE
  • Multiple GTM containers loaded

    LIVE
  • Meta Pixel loaded without a resolvable pixel ID

    LIVE
  • GTM present but no dataLayer activity

    LIVE
  • Google Ads traffic with no conversion tag on the pages sampled

    LIMITED

    Only fires when the landing URL carries paid-click parameters such as gclid, and only for the pages actually sampled.

  • Ecommerce events sent without value or currency

    LIVE
  • No view_item event on the product page

    LIVE
  • No add_to_cart event when a product was added

    LIVE
  • No begin_checkout event at checkout entry

    LIVE
  • Duplicate ecommerce events inflating reported performance

    LIVE
  • Meta Pixel missing funnel events GA4 did record

    LIVE

Funnel and checkout

The revenue journey as a shopper experiences it — product discovery, add to cart verified by cart state, the cart, and checkout entry — plus the storefront errors that break it.

  • No product page reachable from the storefront

    LIVE
  • Add-to-cart control not found or not clickable

    LIVE
  • Cart empty after a successful add — silent revenue failure

    LIVE
  • Checkout entry could not be reached

    LIVE
  • JavaScript errors on the storefront and inside the funnel

    LIVE
  • Failed or 4xx/5xx script and XHR requests

    LIVE
  • Slow storefront load and slow funnel steps

    LIVE
  • No cart route found

    LIVE
  • Journey steps the scanner could not measure, reported as coverage gaps

    LIVE

Consent, as it affects measurement

Whether tags fire before a visitor chooses, and whether tracking actually resumes once they accept. Revenue Guard checks consent state and tag timing; it does not assess legal compliance.

  • Tracking fired before any consent interaction

    LIVE
  • Advertising pixels present with no consent manager detected

    LIVE
  • Consent accepted but tracking still did not fire

    LIMITED

    Scanned from a single country, so a geo-gated consent banner shown only in other regions would not be observed.

Evidence and change tracking

What is captured with each finding, and how findings are tracked from one run to the next.

  • Per-step screenshots and network evidence captured for every finding

    LIVE
  • Every finding states what was tested, observed and expected

    LIVE
  • Portfolio scanning — many clients, one ranked report

    LIVE
  • Cross-client patterns — issues shared by several clients

    LIVE
  • Change-only alerting between runs

    LIVE
  • First-seen, resolved and regression tracking across scans

    LIVE
  • Suppress a finding you have judged out of scope

    LIVE
  • Scheduled scans you run in your own CI or cron

    LIMITED

    Safeliant generates the cron, GitHub Actions or systemd schedule; the schedule runs on infrastructure you control. There is no hosted scheduler yet.

  • Alert delivery to Slack/Teams-compatible webhooks, a digest file, or stdout

    LIMITED

    Webhook, file and stdout only. Safeliant does not send email.

  • Platform detection — Shopify, WooCommerce, Magento and others

    LIVE
  • Product structured-data completeness for AI and search discovery

    LIVE

Current coverage

Shopify revenue journeys are validated through checkout entry. Safeliant does not place customer orders. WooCommerce journey coverage is more limited today, and some storefronts may also restrict automated access; those checks are reported as unassessed rather than passed or failed.

Recurring checks run from the schedule Safeliant generates for your existing CI, cron or server environment.