Website Script Extractor
Find out what JavaScript a page loads. The extractor lists every external script with its address and loading attributes – async, defer, module, integrity – flags scripts in the head that block rendering, counts third-party domains and recognises common services such as Google Tag Manager, Google Analytics, Meta Pixel, Hotjar, Clarity, Stripe, reCAPTCHA and consent tools. Inline scripts are listed with their size and first characters.
- Encrypted connection
- No sign-up
- Free to use
How to use Website Script Extractor
- Enter a page address (or paste HTML).
- Click “Find scripts”.
- Review render-blocking and third-party scripts.
- Check the recognised services.
Website Script Extractor features
Loading attributes
async, defer, module, SRI.
Render-blocking
Scripts that delay painting.
Third parties
Domains and services.
Inline scripts
Size and preview.
Paste mode
Analyse HTML you paste, e.g. from a staging site.
Safe fetching
Public addresses only, with size and time limits.
When to use Website Script Extractor
- Privacy and cookie audits.
- Performance reviews.
- Checking tag manager set-ups.
- Competitor technology research.
Website Script Extractor FAQ
What is a render-blocking script?
A script in the head without async or defer: the browser stops building the page until it has downloaded and run it.
What is Subresource Integrity?
An integrity attribute with a hash that makes the browser refuse a file that was changed on its server.
Does it see scripts loaded by a tag manager?
No – those load later. Use the browser’s network panel to see them.
Is the detection complete?
It recognises common services by address patterns; unknown scripts are listed without a name.
Scripts, speed and privacy
Every third-party script adds download time and may collect data about visitors. Knowing which scripts run is the first step to deciding which are worth it.
Moving scripts to defer or async is often the quickest speed improvement.
How it works: our server downloads the page once through a guarded fetcher that only connects to public addresses, follows a limited number of redirects and stops after a size and time limit. The HTML is then analysed in your browser as inert text – scripts on the page never run and nothing is stored.
What it cannot see: content and resources that a page adds with JavaScript after it loads, pages behind a login, and servers that block automated requests. For those, open the page in your browser, use its developer tools, or paste the page source where the tool offers a paste option.
Use the results as a starting point: fix the items marked red first, review the yellow warnings in context, and run the check again after a change. Requests are rate-limited to keep the service fair; if you check many pages in a row, wait a few minutes.
Related checks on this site cover the rest of a technical review – speed and Core Web Vitals, security headers, structured data, accessibility and SEO signals – so you can work through a whole site audit one topic at a time.
Who it is for: site owners checking their own pages, developers debugging a release, SEO and marketing teams auditing clients or competitors, and students learning how the web works. No account or installation is needed, and the results are plain text and tables you can copy into a report or ticket.