Anonymized scan report: duplicate GA4 pageviews

[ site withheld ]

Run 29 July 2026 · external scan, one observed page load · address and identifiers withheld

Anonymized, based on an actual report — the one behind the anonymized duplicate-pageview study. The site’s address and every vendor identifier are withheld. The substantive findings, inventory, consent evidence, and coverage gaps are unchanged — both findings, all four beacons and every inventory row are what the report actually carries. A live report also has a share link and a watch opt-in, which a static copy cannot.

Summary

Result GA4 pageview counted more than once. The observed page load sent 2 GA4 page_view beacons for G-•••••••• — a single install sends one per pageview. 1 more finding is detailed below.
Verified No legacy Universal Analytics, retired Adobe DTM, or orphaned GA4/Meta loaders.
Observed 9 vendor-and-ID rows across 7 vendor families, including a OneTrust banner and recognized tracking after acceptance.
Scope External scan of one observed page load documenting browser-fired tracking, not GTM container or server-side configuration details.

This page’s tracking has a problem that can distort the numbers built on it. On a live report, this is where you would opt in to a watch so a later scan reports the next change.

What we found

Each finding carries a severity — how much it can distort the numbers you rely on (info = minor or hygiene, warning = likely skews a metric, critical = corrupts a core number) — and a confidence in the claim as stated (high = the claim is directly shown without material ambiguity or corroborated beyond the minimum, medium = the evidence supports the claim but only at the minimum needed or with an important alternative still open).

This duplicate is medium: two beacons directly show that the pageview was sent twice, but that is the minimum evidence for the claim. Three or more beacons, or a repeated loader request, would corroborate it further; neither identifies the underlying configuration cause.

critical · medium confidence

GA4 pageview counted more than once

The observed page load sent 2 GA4 page_view beacons for G-•••••••• — a single install sends one per pageview.

Pageview counts for affected loads are inflated by the double-counting. Engagement rate and bounce rate may also be distorted; whether sessions and conversions are affected depends on how the duplicate is wired.

Main (no-interaction) load

+5.161s   POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

+10.166s  POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

Times are offset from page-load start.

Install context observed

gtag.js loader   googletagmanager.com/gtag/js?id=G-••••••••
GTM container    googletagmanager.com/gtm.js?id=GTM-••••••••

Accept-interaction load

+4.722s   POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

+9.723s   POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

The duplicate reproduced on the consent-accepted pass as well as the first pass.

Accept-interaction install context

gtag.js loader   googletagmanager.com/gtag/js?id=G-••••••••
GTM container    googletagmanager.com/gtm.js?id=GTM-••••••••

Whether this is a duplicate install (for example a hardcoded gtag.js alongside a GTM-managed tag) and which reports it inflates — that needs read-only access to the GA4/GTM configuration.

warning · high confidence

Tags fired before any consent interaction was possible

In a fresh browser profile with no prior consent and no interaction, 2 measurement requests fired during the same page load in which the OneTrust consent banner was shown and left unanswered.

Measurement requests were sent before the visitor made a choice. That can make browser-side measurement behavior inconsistent with the consent flow presented to the visitor and complicate interpretation of the resulting data.

Consent state

OneTrust banner visible when probed after page settle, unanswered
(fresh browser profile, no interaction at any point,
 observation window 8004ms, scanned from our US scan region)

GA4 fired before interaction

+5.161s   POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

+10.166s  POST 204  google-analytics.com/g/collect
          ?v=2&tid=G-••••••••&gcs=G100&gcd=13u3u3u3u5l1&dma_cps=-&dma=0&en=page_view

Times are offset from page-load start.

Whether this behavior was intended by the CMP or Consent Mode configuration, what the destinations retained or reported, and which legal framework applies cannot be determined from this scan.

What we verified

What we observed loading

The analytics and ad tools we recognized loading on this page.

VendorIDBehaviorRequests
FloodlightDC-••••••••2 pixel fires2
GA4G-••••••••loads and fires5
GTMGTM-••••••••loads1
Google AdsAW-••••••••loads and fires2
Google AdsAW-••••••••loads and fires4
Heap3 collect hits3
Heap••••••••loads1
Metaloads and fires2
OneTrustconsent platform — banner shown1

Two Google Ads rows are two distinct conversion accounts, both masked here. The unlabelled Heap and Meta rows carried no ID we could attribute.

Consent signals on the wire

Scanned from our US region, so this records what was visible and what was on the wire for consent mechanics on this page. It is not a legal compliance verdict.

What this scan could not see

The study this report backs: duplicate GA4 pageviews on an e-commerce homepage.
The failure mode in general: duplicate GA4 pageviews.

See what a report says about a site you manage: run a free scan.

Report run: July 29, 2026