Release Notes
Track the latest features and improvements to AnalyticsProof.
- Change The “conditional step” switch on journey steps is gone. A step whose element is not on the page is now simply a step that did not run: the baseline stays in warm-up and the break notice asks you to re-record the journey. Nothing is clicked blindly, as before
- Change The “Environment reachability” button has left the compliance scan page. Reachability of a protected test environment is checked where it belongs — in the GitHub connection dialog. The scan country is chosen when a test is created
- Feature New accounts get a 14-day Starter trial after e-mail verification, no card needed. When it ends, the trial results stay visible but locked until an upgrade; a short feedback form extends the trial by 7 days once
- Feature The verification e-mail is now sent right after sign-up, with a page to resend it
- Change Compliance scans now give the same result for the same site on every run: the scanner starts on the page where the cookie banner was recorded, waits for the site’s own signals instead of fixed delays, and reads consent state at the moment the decision is made
- Change The accept and reject flows run one after the other with a fixed observation window after every page reload, so lazily loaded trackers are counted the same way every time. Compliance scans take a bit longer than before
- Change A compliance scan that could not finish one of its flows in time is reported as “no data” instead of a lower score
- Feature A tracking cookie written before consent is reported as a finding with the moment it appeared, instead of silently lowering the score
- Change A vendor whose cookie appeared before consent is marked non-compliant even when the vendor itself only showed up after the consent click
- Change Saved cookie-banner instructions that stopped working are retired after two failed attempts, so the scanner looks for the banner afresh instead of repeating a dead click
- Change Banner discovery uses one fixed AI region per site — no more differing selectors between runs
- Feature A journey step whose element is not on the page today — a cookie banner that no longer appears, a promotion that is gone — is skipped and reported as “target absent” instead of being clicked blindly. You can mark such a step as conditional so the journey keeps measuring
- Feature A click covered by another layer is reported as “blocked by overlay”, with the covering element named, instead of landing on the wrong thing
- Change Web journey clicks are delivered through the browser’s own click pipeline at the recorded spot; the recorded position is now a measurement, not a reason to move the click
- Change Fewer false findings: values that are empty in both the baseline and the scan, Google Analytics internal parameters, and “page did not change” after typing are no longer reported
- Change Baseline warm-up messages say what is actually missing — including which step is waiting for your approval — and long TV journeys made of remote-control presses can now establish a baseline
- Change A broken journey is announced once per cause and marked resolved after two clean scans, instead of a new alert on every scan
- Feature Gemius is detected, Google Tag Manager is recognised on custom domains, and TV scans list the hosts they contacted but could not attribute
- Change Every compliance scan runs alone on its scanner instance, and a scan that could not observe the reject flow is reported as “no data” instead of a lower grade
- Feature Preview environments protected by HTTP Basic authentication can now be tested — store the preview login with the repository connection and every pull-request check signs in before it replays your journeys. Enterprise
- Feature “Otestovat a uložit” — AnalyticsProof resolves the preview URL from what you typed and opens it with your login before anything is stored, so a repository connection is only saved once it is proven to work
- Change Connecting a repository is one screen — the installation steps and the preview-URL placeholders moved behind a hint you can hover or focus, instead of pushing the form out of the dialog
- Change A repository with no preview deployment yet can still be connected and checked later
- Change Viewers now see the GitHub button on a test, greyed with an explanation, instead of no button at all — changing the connection stays with editors and above
- Change Scans started from GitHub or the public API are shown in a test’s run history from the journey’s “…” menu, the choice is remembered between visits, and each such run is labelled GitHub or API in the Initiator column
- Change A protected preview whose stored login is refused is now reported as “login rejected” rather than “login required”, so a wrong password is distinguishable from a missing one
- Feature AnalyticsProof now measures how the product itself is used — which screens, scans and journeys people reach and where they stop — recorded per environment and reported only in aggregate
- Change Screenshots and recordings left in cloud storage by a deleted scan are now cleaned up daily, so removing a test, a journey or a project no longer leaves its artefacts behind
- Feature Connect a GitHub repository to a test yourself — install the AnalyticsProof App, pick the repository, choose how preview URLs are found (GitHub Deployments or a URL template), run a dry check, done. Enterprise
- Feature Every pull request gets an AnalyticsProof check that replays your journeys against the PR’s preview deployment, with a comment and SARIF alerts in the repository
- Feature Findings are split into “New in this PR” and “Already on production”, so a problem that is already live never blocks someone else’s pull request
- Change Only new critical dataLayer changes block a pull request; warnings stay advisory, and a journey that cannot be judged is reported as neutral rather than green
- Change The result link in a pull request opens for every member of the project, and the test history can show GitHub and API runs on request
- Change Scans started from GitHub never send e-mail, Slack or digest notifications and never touch a journey’s saved baseline
- Feature The scanner’s exit IP for your country is shown on the test, and a protected preview environment can be checked for reachability before a scan runs
- Change The whole product moves onto the brand’s two surfaces — Paper for the site, articles, reports and e-mails, Ink for the dashboard
- Change A journey’s verdict is always a full row with one collapsible “Technical detail” block, and screenshots are one size everywhere
- Feature The public API adds identity, API-key administration, dataLayer decisions, explanations, SARIF and vendor state — all additive, version 1.2 unchanged
- Feature Step recovery — when a typed field’s selector no longer resolves, replay re-anchors the step from its label or types at the recorded point behind a focus check, never into an unverified element, so the scan completes instead of stopping at a moved form field
- Feature Selector fixes you approve — a verified recovery proposes a new selector in the review dialog; the old one is kept as a fallback and the baseline is not reset. Nothing in a journey is rewritten without your approval
- Change Monitoring can now start from a journey whose step resolves through a recorded fallback selector — ending the “steps recovered” loop that kept some journeys from ever getting a baseline
- Change The “monitoring not running” banner states the actual reason, including a selector fix waiting for your approval, and the digest e-mail lists pending fixes
- Change The recorder no longer accepts auto-generated, enumerated element IDs as selectors — they are not stable between page loads and had already broken a recorded journey
- Change One digest e-mail per test per run — a run that finishes after a newer one has already reported can no longer trigger a second digest, and a 10-minute per-test cooldown caps any repeat
- Change Compliance verdicts the scan didn’t earn are no longer published (web and TV) — a scan that saw no vendors and no banner reports “no data” instead of 100/A, and “we couldn’t find the banner” is no data rather than “there is none”
- Change Compliance points are earned, not assumed — banner points require a verified accept click, Consent Mode counts as “implemented correctly” only when a default was observed, and consent persistence is claimed only for flows that actually ran
- Change Sites that use GA4 alone now receive their Consent Mode checks — a vendor-name mismatch had silently skipped them
- Change Session-replay tools (Clarity, Hotjar) recording before consent are a new low-severity finding, and tracking-cookie recognition now covers Bing, Piwik, Hotjar and Clarity
- Change Mobile verdicts derive from timestamps and observations, not phase labels — no “tracking after reject” for a reject that never happened; “before consent” means after app launch and before your accept tap, with emulator and system traffic excluded; a CMP without a reject option gets its own finding; “personal identifiers detected” is claimed only when the payload was actually decoded
- Change Mobile scans distinguish your app crashing from the test device dropping it, so a broken step is attributed to the right side
- Change The mobile compliance score scale changed with the rules above — mobile scores from before this release are not comparable with new ones, so expect a visible step in mobile trends
- Change The dataLayer diff reports only what it measured — empty values are no longer flagged as type changes (the most common false positive), approving an intermittent event or parameter marks it optional instead of producing the opposite finding forever, nested e-commerce payloads such as the items array are now diffed, and baselines refuse to freeze from a broken, skipped or eventless run
- Change A scan with no data says so — the score cell, the scan detail and the public results page show an explicit “no data” state with the scanner’s reason instead of a blank score next to “Completed”
- Feature Multiple named journeys per test — up to 5 on Professional and 20 on Enterprise (Starter keeps 1). Journeys replay one after another in a single run; each has its own Scan again, Edit and Remove, and reorder arrows set the run order. One digest e-mail per run lists every journey, the green ones included
- Feature Rename and duplicate journeys from the card menu — a duplicate copies the name, steps and recording settings, not the frozen expected schema, findings, schedules or history
- Feature Continue recording from saved steps — the remote browser replays the journey’s saved steps first and then hands you control; if a saved step can’t be located it stops and offers to discard the unreached steps
- Feature Per-journey scan history — each journey’s runs live in its own expandable row, the collapsed row shows how the last run went, and test-level metrics aggregate across journeys. Scan-history filters and page numbers are replaced by a “Load more” list
- Change A scan that finished successfully can no longer be relabelled failed (and send both notifications) after a hiccup following completion. Manual runs started while a cycle is running now wait behind it as “Queued” instead of being refused
- Change Re-recording a mobile journey keeps its mobile viewport and always replaces the previous recording (the Android “recording mode” choice is gone), and Meta Pixel advanced-matching identity parameters no longer produce diff findings. Typing the name to confirm a deletion is now asked only when deleting a project
- Change The dataLayer interceptor no longer trips an infinite recursion inside GTM on some sites — previously it could break the site’s own analytics during a scan and make a login page fail mid-navigation, which showed up as a false broken step. Pushes that bypass the hook are still captured and attributed to the right step
- Change A scan that measured nothing is not a completed scan — a blank page, a dead site or an app that never came up is reported as “no data” instead of being graded, and it never auto-resolves your open findings or counts as a successful run
- Change dataLayer diff correctness — consent parameters are now actually compared, approving a drifted event keeps the approved expectation, steps the replay never reached produce one “could not be verified” row instead of a critical per expected event, and findings from skipped or failed steps are no longer blamed on your tags
- Change Public results page — a scan with no data no longer renders as a graded result with a PDF, failed scans say “failed” rather than “not found”, and consent-change findings can be approved, ignored or marked as an error
- Feature Editor role — editors run scans, manage tests, journeys, targets and schedules, approve dataLayer changes, upload APKs and manage API keys; team, billing and project deletion stay with owners and admins. Owners and admins assign the role from Team
- Change Recording equals replay — the recorder no longer clicks cookie banners for you either. Click the banner yourself while recording and exactly that click is replayed, with identical browser settings, locale and timezone on both sides, so the scan’s exit country can’t diverge from the recording
- Change Long journey replays (over five minutes, typical for HbbTV) are no longer cut off seconds before finishing and reported as timed out
- Change The public OpenAPI description now loads in Swagger UI, Redoc and client generators (OpenAPI 3.0.3 with operationIds)
- Change Journey replay reports a broken step after three consecutive unresolvable steps instead of running to a timeout, failed and broken scans open from history with the error shown inline, and journey replays get a 10-minute budget
- Feature Consent-state diff — the dataLayer diff decodes the effective consent state carried in each event and raises a critical finding when consent flips between scans; approving it folds the new state into the baseline
- Change The volatile dma_cps parameter no longer triggers “parameter removed” alerts
- Change Mobile scans detect an app that never actually loaded (stuck spinner, offline or error screen), relaunch it, and no longer count background pings from a dead screen as content reached
- Change The dashboard “Result” cell for dataLayer tests shows an amber count whenever anything awaits your review, not only critical findings — so a green “OK” means clean
- Change The tests overview is now the dashboard landing page, and disabling a schedule clears its next-run time
- Feature Programmatic API 1.1 for CI/CD (Enterprise) — gate results can include exactly which events and parameters regressed, a saved journey can be replayed against a preview URL without touching its baseline, and new gate rules fail a build on a broken step or a newly appeared vendor. A gate with no baseline yet reports a warning instead of passing green. Reference at /developers
- Feature Dashboard overhaul — journey scans show a dataLayer-integrity state (ok, drift, broken) instead of a misleading “0” score, and every run shows who or what started it (schedule, manual, API)
- Change Web compliance reject flows — a “Reject” button inside a second-layer settings dialog is now pressed inside that dialog instead of clicking through to the page behind it, so reject-flow verdicts are earned and repeat scans return the same score. Manual banner corrections remember which dialog a button lives in
- Change Journey replay is strictly what you recorded — replay no longer dismisses cookie banners on its own, so a recorded consent click is never reported broken because the banner had already vanished; a step whose layout shifted but whose click verifiably landed on the right element is no longer flagged as broken
- Change Vendor IDs are recognised for far more vendors (Google Ads, Criteo, Adobe, Matomo, HubSpot, Pinterest, TikTok, Meta, Sklik, server-side GTM, Nielsen, JHMT), long ID lists wrap as chips, and a false Hotjar ID no longer appears
- Feature Record and scan mobile journeys in landscape — for video, gaming and media apps that run sideways, so their analytics are captured the way real users actually see them
- Change Replace an app build in place — upload a new APK to an existing mobile test without recreating it, and every uploaded version is kept for a clean audit trail
- Change Consistent web compliance scores — repeat scans of the same site now return the same score instead of drifting run to run, so your trends are trustworthy
- Change Far fewer false DataLayer alerts — values that naturally change on every visit (cache-busters, session IDs, ad-tech flags) no longer trigger “something changed” notifications
- Change Silence expected UI changes — accept a step’s visual drift once (rotating banners, dynamic content) and it stops being flagged on future scans
- Feature LinkedIn Insight Tag events are now decoded into readable parameters
- Feature Self-healing journeys — when a website or app layout shifts, replay re-finds the right element and flags the change for one-click review, so scans keep running instead of breaking
- Feature Per-vendor tabs for mobile analytics — Firebase, GA4 and other SDKs each get their own view, now including analytics from non-Google mobile SDKs
- Change More accurate DataLayer change detection across multi-step journeys, with cleaner alerts and fewer duplicates
- Change Mobile scans now match the recording’s country and timezone end-to-end for consistent geo-accurate results
- Feature Programmatic API and CI/CD gate (Enterprise) — trigger scans straight from your build pipeline and automatically fail a release when compliance drops or new tracking regressions appear
- Feature Choose exactly which analytics vendors each test watches for changes, so you only get alerted about the tools you care about
- Feature Enterprise invoice billing — group multiple projects under one company and receive a single consolidated invoice, with correct EU VAT handling
- Change DataLayer tests now show the number of journey steps instead of raw request counts
- Feature Approve the expected analytics for each journey step, then get alerted the moment a later scan drifts from it — with per-step approve and ignore decisions
- Feature Upload your own APK/XAPK for mobile tests — scan apps that aren’t on the store yet, including pre-release builds
- Feature Pick the target country when creating a test
- Feature Delete your account and data yourself, directly from the dashboard
- Change Mobile scans now send notifications and flag when analytics capture was degraded
- Feature Test analytics behind login walls — record a username and password once and have them re-entered deterministically on every scheduled scan
- Feature Scan DRM-protected video flows — Widevine playback lets VOD services play protected content so the video analytics that depend on it actually fire and get checked
- Feature Report an issue without leaving the dashboard — one click captures the current screen and page context and sends it to our team
- Change Analytics inside login-gated streaming apps is now captured end-to-end — sign-in holds through replay instead of dropping after login
- Change Web compliance scans on large, ad-heavy sites (e.g. major news portals) now complete reliably instead of timing out
- Change More reliable Android scans — network routing and device-clock fixes mean recorded mobile journeys replay consistently and capture analytics accurately
- Feature Self-healing Android journeys — when an app’s layout shifts, replay re-matches elements across multiple attributes and flags the drift for one-click review
- Feature Full device controls in the Android recorder — Back, Home, and Recents so you can navigate any flow while recording
- Change Visual journey replay — every step now shows a screenshot with tap crosshairs and swipe arrows, so you can see exactly what was automated
- Change Scan country is set automatically from your browser timezone for consistent geo-accurate results
- Feature Record and replay Smart TV (HbbTV) journeys in your browser, then run them as scheduled analytics scans
- Feature Mobile Analytics journeys for Android — record a tap-by-tap flow on a cloud phone and replay it to capture and diff per-step events
- Feature Far richer DataLayer capture — each push now shows its source file and line, a live consent snapshot, and events from Adobe Launch, Adobe Web SDK, Tealium, and server-side GTM
- Feature New Nielsen and JHMT detectors plus server-side GTM recognition, surfacing analytics on broadcaster HbbTV applications that were previously invisible
- Change More accurate per-step attribution on multi-page journeys — events land on the right step instead of bleeding into the next page, and a final settled step captures the page you ended on
- Feature Record Android app journeys remotely via live device streaming — interact with a cloud phone in your browser
- Feature Interactive journey recorder with remote browser — record a flow once, replay it on every scan for repeatable DataLayer QA
- Feature Revamped notifications — per-project defaults with per-user overrides for email and upcoming channels
- Change Smarter AI navigation — vision-based element recognition for more reliable multi-step scans
- Change Reworked network capture with clearer pre/post-consent phase markers and unpacked GA4 batch requests
- Change More accurate banner detection — filters out false positives from overly generic selectors and detects late-loading consent scripts
- Change Fewer false positives in Google Consent Mode compliance checks and detection of vendors blocked by Content-Security-Policy
- Feature DataLayer scan viewer with per-vendor tabs and decoded GA4 parameters
- Feature AI-driven step-based DataLayer scan workflow — automatically walks through user flows to validate tracking
- Feature Facebook SDK analytics captured on Android — full event payloads visible via HTTPS interception
- Feature AppsFlyer structured analytics decoding on Android with two-step launch for better event coverage
- Feature Interactive Mobile Events flow visualization with portrait nodes and resizable panels
- Change Dashboard is now fully usable on phones with a swipeable sidebar and smooth transitions
- Change Unified website test creation — single flow for compliance and DataLayer scans with improved scheduling
- Feature Geo-accurate scans — simulate users from multiple countries for localized consent banners and analytics
- Feature Country-matched SIM, GPS, and carrier spoofing for Android scans — apps see a native local device
- Feature Android scans now run on ephemeral cloud VMs — faster, isolated, and production-ready
- Feature Unified mobile compliance results using the same viewer as web scans
- Change More reliable Android analytics detection — fixed logcat timing, consent signals, and nested event parsing
- Change AppsFlyer events now captured on Android with unfiltered logcat streaming
- Feature HbbTV app scanning — detect analytics and consent compliance on HbbTV applications, with Samsung and LG TV browser profiles
- Feature Full Firebase GA4 payload decoding on Android — extract consent mode, session IDs, and event parameters via SSL pinning bypass
- Feature Firebase Consent Mode v2 compliance evaluation with per-SDK scoring for mobile apps
- Feature Blog with first compliance study — "69% of Top Websites Fire Trackers Before You Consent"
- Feature 4 new mobile analytics detections — AppsFlyer, Adjust, Facebook SDK, Bloomreach
- Change Improved mobile app scanning — multi-step onboarding bypass and more accurate pre-consent traffic counting
- Change Hidden consent banners now detected — finds CMPs that load invisible and appear after navigation
- Change Fixed consent button detection when accept and reject have identical selectors
- Feature AI-powered login flow handling for apps requiring authentication
- Feature Community Q&A platform with Apache Answer SSO integration
- Change Optimized AI token usage for mobile app scanning
- Feature Android app compliance scanning with AI-powered navigation
- Feature Mobile analytics detection for Firebase, Google Analytics, and more
- Feature Detection of analytics SDKs in apps using certificate pinning (SNI-based)
- Feature Automated APK provisioning for reproducible scans
- Feature Cookie wall detection with compliance scoring penalties
- Feature Missing reject option detection in consent banners
- Change Distributed AI inference across 9 EU regions for faster scans
- Change Improved shadow DOM traversal and iframe replay handling
- Feature Banner detection override — manually correct and rescan misdetected banners
- Feature PDF report export styled to match the dashboard
- Change Better handling of websites with anti-bot protection
- Change Improved banner detection in deeply nested shadow DOM structures
- Feature Stripe subscription management with Free, Starter, and Professional tiers
- Feature Team invitations with owner, admin, and viewer roles
- Feature Test scheduling with automatic email notifications
- Feature Compliance leaderboard showing top-scoring websites by country
- Feature Real-time scan progress updates
- Feature Invoice generation with EU VAT logic (domestic, reverse charge, non-EU)
- Feature Error monitoring for improved reliability
- Change Improved cookie banner detection with multilingual support and nested iframe handling
- Change Password reset flow with OAuth-aware error messages
- Feature Web dashboard with multilingual support (Czech, English, German)
- Feature User registration, login, and OAuth sign-in (Google, GitHub)
- Feature Public scan results with shareable URLs (cached 30 days)
- Feature Homepage quick compliance scan — check any website instantly
- Change IP-based rate limiting for public scans
- Feature 9 new vendor detections — Matomo, Plausible, Exponea (Bloomreach), Adobe Analytics, Adobe Launch, Heureka, Fathom Analytics, Pinterest Tag, HubSpot
- Feature Consent-gated vendor detection — identifies vendors that load only after consent
- Change Parallel accept/reject scanning — ~40% faster scan times
- Change Scan performance optimized (reduced from ~54s to ~22s)
- Feature Website compliance scanner with AI-powered cookie banner detection
- Feature 19 analytics vendor detections including GA4, Meta Pixel, Google Ads, LinkedIn, TikTok, and more
- Feature Google Consent Mode validation
- Feature Compliance grading system (A–F) with 9 scoring criteria
- Feature Support for complex two-step cookie rejection flows (Settings → Save)