GA4 mini audit report · Sample
Summary.
The basics of this GA4 setup are sound: page views fire once, settings are mostly right and Google Ads is linked. But three problems change the numbers the business relies on.
- Consent: analytics cookies are set before visitors choose, which the banner says doesn't happen.
- Attribution: customers who pay by PayPal lose their campaign, so marketing looks weaker than it is.
- Revenue: some purchases are counted twice, so GA4 revenue runs about 8% ahead of the order system.
All three can be fixed in under a day of work. The fixes, in order, are at the end.
Scorecard.
| Area | Result | In short |
|---|---|---|
| Property settings | Minor issues | Timezone and currency are right. Data retention is at 2 months and office traffic isn't filtered. |
| Core tracking | Sound | Page views and events fire once per page, on every template checked. |
| Key events | Problem | Add to basket is a key event and is imported into Google Ads as a conversion. |
| Ecommerce | Problem | Some purchases are sent without a transaction ID, so they can be counted twice. |
| Consent | Serious | The GA4 tag fires before the consent default is set, so cookies are set before anyone chooses. |
| Attribution | Problem | Visitors who pay by PayPal come back as referrals, and their campaign is lost. |
| Google Ads | Sound | GA4 and Google Ads are linked, and key events import. |
Findings, ranked by business impact.
Analytics cookies are set before the visitor chooses
What was found
The consent default is set by a tag on the page view trigger, but the GA4 tag fires earlier, on Initialisation. On a first visit, GA4 sets its _ga cookies while the banner is still open.
Why it matters
The banner says analytics waits for consent, and it doesn't. This is exactly what the ICO's cookie checks look for. It also means Consent Mode never applies to the first page of each visit.
The fix
Move the consent default to the Consent Initialisation trigger, so it's set before any other tag fires, then test with the banner untouched.
Purchases paid by PayPal lose their campaign
What was found
paypal.com isn't on the list of unwanted referrals. Customers who pay by PayPal return to the confirmation page as a new referral from paypal.com.
Why it matters
Around a fifth of online orders are credited to Referral instead of the campaign that brought the customer. Paid search and email look weaker than they are, and Google Ads gets fewer conversions to learn from.
The fix
Add paypal.com and the card provider's domain to unwanted referrals in the GA4 data stream settings. No code is needed. Past data can't be corrected.
Some purchases can be counted twice
What was found
On orders paid by PayPal, the purchase event is sent with an empty transaction_id. When the customer reloads the confirmation page, or comes back to it from an email, a second purchase is recorded.
Why it matters
GA4 revenue runs ahead of the order system, by about 8% in the month checked. Any report or bid strategy using GA4 revenue overstates it.
The fix
Have the developer fill transaction_id from the order number on every payment route. GA4 then drops repeat purchases with the same ID. Test with an order on each payment method.
Add to basket is treated as a conversion
What was found
add_to_cart is marked as a key event and imported into Google Ads, alongside purchase.
Why it matters
Google Ads bidding counts a basket addition as a success, so it finds people who add to basket rather than people who buy. Conversion rates in reports look about six times higher than the sales behind them.
The fix
Unmark add_to_cart as a key event, remove it from Google Ads conversion goals, and keep it as a normal event for funnel reports. Tell whoever runs Google Ads first, as bidding will adjust.
Office traffic is counted as customers
What was found
No internal traffic rule is set up, so staff visits from the office and warehouse are included in every report.
Why it matters
A small but steady inflation of sessions and engagement, which is largest on product pages the team checks every day.
The fix
Define internal traffic by the office IP addresses in the data stream settings, then switch the internal traffic filter to active.
Data is kept for 2 months
What was found
Event data retention is set to 2 months, the default.
Why it matters
Explorations can only look back two months, so year-on-year comparisons of journeys and funnels aren't possible. Standard reports aren't affected.
The fix
Change data retention to 14 months in the property settings. It only applies from now on.
What to do, in order.
- Fix the consent order in Tag Manager (finding 1). It's the compliance risk, and it's quick.
- Add the payment domains to unwanted referrals (finding 2). It protects attribution from today.
- Ask the developer to send transaction_id on every payment route (finding 3), and test each one.
- Agree with whoever runs Google Ads, then remove add to basket as a conversion (finding 4).
- Tidy the two settings (findings 5 and 6).
What was checked.
GA4 property settings, the Google Tag Manager container and the live website: page views and events on each main template, key events, the purchase journey on each payment method, consent behaviour with the banner untouched, accepted and refused, channel grouping and UTMs, and the Google Ads link. Access was read-only, and nothing in the account was changed.