Version Notes
Dated changes to SiteTrust Consent, Consent Mode v2, Site Audit, and the docs. Check here first if something changed after an update.
September 2026
Consent Mode v2 in the widget
consent-widget.js fires gtag('consent', 'default', …) as soon as it loads: ad_storage, analytics_storage, ad_user_data, and ad_personalization denied, with wait_for_update: 500, url_passthrough: true, and ads_data_redaction: true. Accept and Decline fire gtag('consent', 'update', …) mapped from the banner categories.
Geo defaults
The widget looks up country via ipapi.co. EEA member states plus the United Kingdom and Switzerland stay on the strict default. Other regions may grant analytics_storage only. Ads signals stay denied. Lookup failure keeps the strict default. Geo is recorded on the consent receipt (geo, country). Verify and Audit remain the plans we position for regional consent defaults.
Google Tag Manager path
Supported install is now two Custom HTML tags on Consent Initialization — All Pages: Consent Default, then Consent Widget sequenced after it. Do not load consent-widget.js in the site head and in GTM at the same time. Guide: Install via Google Tag Manager. GTM is also a platform option in onboarding.
Configuration ID in the dashboard
Banner Setup → Installation shows the Configuration ID in its own Copy field above the Header snippet, so GTM and other integrations do not have to scrape the script tag.
Basic mode blocking
Default remains basic mode: known tracker scripts are held until the matching category is granted. Advanced mode (cookieless Google pings before consent) stays available on request, not as the default.
Site Audit Run A and Run B
Dashboard Run A also runs a source pre-scan. If trackers exist in HTML but the banner blocked them, the audit can report “trackers detected but blocked” instead of a misleading zero. Run B is no longer marked N/A only because zero tags fired after a blocking banner.
Documentation
This documentation hub now includes Getting Started, platform install guides, Consent Mode v2, testing, Trust Badge, and Trusted Site Scan articles. Support remains wecare@sitetrust.com.
What did not change
- The Trust Badge is still
widget.js. Consent is stillconsent-widget.js. - The badge still hides until tracker evidence, AI disclosure, and required legal pages pass.
- Images and Accessibility remain advisory. They never block the Trusted Site badge.
- Free scans still email a 10-check PDF and still lock deeper rows until a plan runs B, C, and receipts.
If something broke after a deploy
Confirm you still have a single install path (head or GTM), a real Configuration ID, and Consent Initialization if you use GTM. Then walk Troubleshooting.
Need help?
Email wecare@sitetrust.com with your site URL and platform. One business day response, Monday through Friday.