Method, version 1.0
The eight revenue leaks
Sports publishers lose money in the same eight places. Each one below gives what it is, which signals measure it, the thresholds that trigger a finding, where judgment enters, and what would change the answer.
Everything is measured from public data. Where the data comes from
Compliance is tracked separately. Privacy signals and betting-content rules are recorded as risk flags, not leaks, because they cost money indirectly and carry consequences money doesn't measure. They appear in every map under their own heading.
How a finding is built
- A capture reads one live article page, the domain's ads.txt, and Google's public performance data.
- Rules compare what was captured against the thresholds on this page.
- Each finding gets a severity, a confidence label, its evidence, and an owner: the publisher, or the parent company when ads.txt names one.
- Anything labeled verify first is re-captured in an ordinary browser before it reaches a client.
Leak 1 of 8
The yield leak
Money lost on impressions the publisher already serves. The audience shows up, the ad loads, and it clears below what it should, usually because too few buyers compete or the auction is configured badly. Separate from the inventory leak, where attention exists and nothing is sold against it at all.
What we measure
- Header bidding presentPrebid.js or a managed wrapper on the page. Without it one demand source sets the price, unchallenged.
- Prebid versionThe library reports its own. Old versions miss adapters, identity and privacy updates.
- Bidder timeoutPrebid config. How long the page waits for bids.
- Timeout rateAuction events during the capture. Bidders that miss the window add latency without winning.
- Price floorsPrebid floors module. Floors set a minimum clearing price, tunable by page type and season.
- Identity modulesPrebid user ID config. Covered in full under the identity leak.
- Ad server presentGoogle Ad Manager tag. Without one, direct-sold sponsorship can't run beside programmatic.
Thresholds, and why
No header bidding at all: High. Every impression clears through a single path with no competing bids. The largest single yield gap available, and the only finding here that routinely justifies changing platforms.
Prebid major version below 9: Medium. Current majors are in the 10 range. Two or more behind usually means missing adapters and unpatched privacy handling. An upgrade conversation, not an emergency.
Bidder timeout of 2,000ms or more: Medium. Common configurations sit between 1,000 and 1,500ms. Past 2,000ms the wait hurts viewability and page experience, and the extra bids rarely pay for the delay. The recommendation is always a split test, because the right number depends on the bidder mix and the audience's devices.
Bidder timeout under 700ms: Low. Short enough that slower bidders may be cut off. Check the timeout rate by bidder.
More than 20% of bid requests timing out: Medium. Measured from the capture's own auction events, minimum 10 requests before the rule fires.
No price floors: Low. Not every publisher needs dynamic floors. They matter at scale and around seasonal demand peaks, which for sports means the fall.
Where judgment enters
- The timeout thresholds are conventions from common industry configuration, not a study of this publisher. That is why the output is a test, not a change.
- Severity reflects typical revenue impact, not certainty. High severity means the gap is usually large when confirmed, not that the dollars were measured.
- We don't score whether the bidder mix itself is good. That depends on audience and direct relationships, which public data doesn't show.
What would change a finding
- A capture where auctions didn't run (bot protection, lazy loading) invalidates every auction-based number here. Those are labeled verify first and re-captured in an ordinary browser.
- A managed ad network running the stack moves the owner to the network, and the useful question becomes benchmarking the revenue share rather than re-plumbing.
- A parent company named in ads.txt OWNERDOMAIN moves ownership of the finding to the parent.
Rules HB-001, HB-002, HB-003, HB-003b, HB-005, HB-006, AS-001.
Leak 2 of 8
The supply-path leak
Buyers reach the same impression through several routes, and they increasingly pick the shortest, cleanest one. When a publisher's authorization file is messy, stale or reseller-heavy, bids get discounted or skipped entirely. The impression still sells. It sells for less, to fewer bidders.
What we measure
- ads.txt present and parseableThe domain's public file. Many buyers will not bid without it.
- DIRECT vs RESELLER mixThe file's own records. Long reseller chains are what supply-path optimization prunes.
- Number of exchange domainsParsed records. Duplication across dozens of exchanges rarely adds incremental demand.
- Syntax errorsSpec validation. Malformed lines are skipped by crawlers, silently.
- sellers.json matchEach exchange's public file. A DIRECT line the exchange doesn't confirm reads as resold inventory.
- OWNERDOMAINads.txt variable. Names who actually controls the stack.
Thresholds, and why
No valid ads.txt: High. The file is the entry condition for most programmatic demand.
Reseller share above 60%, with more than 30 records: Medium. Not wrong by itself: resellers exist for a reason. But a reseller-heavy file with many exchanges is the profile buyers prune first, and it's usually accumulated rather than chosen.
Any malformed lines: Low. Cheap to fix, and a crawler that chokes on a line drops the authorization it carries.
DIRECT lines that sellers.json does not confirm: Medium. Either the record is stale or the relationship isn't what the file claims. Both make buyers treat direct inventory as resold.
OWNERDOMAIN pointing elsewhere: recorded as context, not a finding. It tells us the parent controls the stack, so stack findings are routed there.
Where judgment enters
The right number of exchanges depends on a publisher's direct sales and geography. We flag the shape of the file, not a target count. Pruning should be tested against revenue by path, which requires the publisher's own reporting.
What would change a finding
- A publisher on a managed network inherits the network's ads.txt entries, so the file reflects the network's choices, not theirs.
- Recent platform migrations leave stale lines that look worse than the current setup. A date on the last file change resolves it.
Rules AT-001 through AT-004, OW-001.
Leak 3 of 8
The inventory leak
Attention nobody is selling against. A page gets read, a video gets watched, a newsletter gets opened, and no advertiser is buying that moment, either because the format doesn't exist or because nothing packages it into something a sales team can sell twice.
What we measure
- Video player presentRendered page. Video usually earns several times display rates.
- Video ad SDK presentRendered page. A player without ad support is content cost with no revenue.
- Ad slots per articleAd server tag. Too few leaves money unsold, too many hurts experience.
- Sponsorable surfacesPage composition. Newsletter, podcast, live and preview pages that carry no sponsor slot.
- Affiliate and betting linksPage links. Shows whether commerce revenue is already in play.
Thresholds, and why
No video player and no video ad SDK on article pages: Medium, inferred. Inferred rather than verified because a publisher may run video only on section fronts or a separate property. It is flagged as an opportunity to check, not a fault.
A newsletter or podcast with no visible sponsor placement: Medium. Direct-sold newsletter sponsorship typically clears well above programmatic display for the same audience, and it is inventory a small team can sell without ad-tech work.
Ad slots far below or above category norms: Low. Reported as an observation with the count, not a prescription. Density trades against page experience, covered in leak 7.
Where judgment enters
Whether an unsold surface is worth selling depends on audience size and the sales capacity the publisher has. A sponsor product that nobody has time to sell is not revenue. Every inventory finding names who would have to sell it.
What would change a finding
- A publisher with a direct sales team may already sell these surfaces off-platform. Public data cannot see a signed sponsorship.
- Seasonal formats (a preview hub, a playoff package) may be dark at capture time.
Rule VD-001, plus inventory observations reported without a rule ID.
Leak 4 of 8
The context leak
Sports content is unusually rich in context: team, league, player, game state, fantasy and betting intent. When none of that reaches the buyer, a page about Sunday's NFL slate is sold as an anonymous impression. Context is also the targeting that still works when cookies don't.
What we measure
- Targeting keys on the pageGoogle Ad Manager tag. Shows what the publisher tells buyers about the page.
- Content-descriptive keysSame, filtered. Keys naming sport, team, league, section, topic or content category.
- Contextual classification vendorsLoaded scripts. Indicates a third-party classifier is already in place.
Thresholds, and why
Targeting keys present but none describe the content: Medium. The stack is capable of passing context and isn't. This is usually the cheapest meaningful yield improvement available, because it needs no new vendor: the CMS already knows the team and the league.
No ad server targeting at all: recorded under the yield leak instead.
Where judgment enters
We can see that keys exist and whether they look content-descriptive by name. We cannot see whether buyers actually use them, or whether the values are populated correctly on every template. Confirming that takes one report from the publisher's ad server.
What would change a finding
- Some publishers pass context through a first-party data platform rather than ad server keys. If a classifier vendor is detected, the finding is downgraded and noted.
- Managed networks often control targeting, which moves the owner.
Rule CT-001.
Leak 5 of 8
The identity leak
A large share of a publisher's traffic arrives without a third-party cookie: Safari and Firefox block them by default, and many users opt out elsewhere. Without an alternative signal, those impressions are sold with less information and clear lower. This is about what buyers can know, not about collecting more personal data.
What we measure
- Identity modules in PrebidPrebid user ID configuration. Shared IDs let buyers value cookieless inventory.
- Identity and data vendors loadedPage scripts. Shows which graphs and platforms are in play.
- Logged-in state signalsPage composition. A registered audience is the strongest first-party signal a publisher can own.
Thresholds, and why
Header bidding present with no identity modules: Medium. The stack supports them and none are configured, so the cookieless share of inventory is sold blind.
Three or more overlapping audience-data platforms: Low, inferred. Reported under vendor cost as well. More graphs is not more signal; it is usually more contracts.
Where judgment enters
We do not rank identity providers. Which ones matter depends on the publisher's buyers and geography, and the landscape changes faster than a method page should pretend to. We report presence and absence.
What would change a finding
- Publishers with meaningful logged-in traffic may deliberately rely on their own first-party IDs. That is a stronger position, not a gap, and it changes the finding to a note.
- A capture from a consent-restricted region may suppress identity modules.
Rules ID-001, VN-002.
Leak 6 of 8
The owned-audience leak
Search and social send a reader to one article, and the publisher gets nothing durable from the visit. No email, no registration, no reason to come back on purpose. Every other leak on this list is about monetizing attention the publisher already has. This one is about whether that attention can be reached again, which is the only inventory a publisher fully owns.
What we measure
- Email capture on article pagesRendered page. Where readers actually land from search and social.
- Newsletter prompts in the bodyPage text. Footer fields convert far worse than contextual in-article prompts.
- Subscribe and sign-up controlsPage controls. Shows whether any registration path exists.
- Sponsorable newsletterCross-checked with the inventory leak. An owned list with no sponsor slot is two leaks at once.
Thresholds, and why
No email field and no newsletter mention on an article: High. The highest-severity finding in the set that requires no ad-tech work to fix, which is why it ranks above several larger-dollar items: a publisher can act on it this week.
Email capture present but nothing in the article body: Medium, inferred. A footer field technically exists. Contextual prompts ("get our NFL picks every Thursday") typically convert several times better, but the multiple depends on the publisher, so this is inferred rather than measured.
Where judgment enters
List size and revenue per subscriber are the publisher's numbers, not ours. We flag the missing mechanism, not the money. Sizing happens in the working session, from their analytics.
What would change a finding
- Some publishers run their newsletter entirely off-site and link to it from navigation rather than in-article. That is still a gap in capture, but a smaller one, and the finding says so.
- Registration walls and app installs can be the chosen path instead of email.
Rules OA-001, OA-002.
Leak 7 of 8
The page-experience leak
Advertising that costs more traffic than it earns. Slow pages lose search rankings and readers; ads that shift the layout hurt both the reader and the advertiser, since an ad nobody sees is an ad that clears low. This leak is where monetization and audience growth meet, and it is usually where they are in conflict.
What we measure
- Mobile performance scoreGoogle PageSpeed Insights. A composite of load and responsiveness.
- Largest contentful paintPageSpeed lab data and Chrome UX field data. When the main content actually appears.
- Cumulative layout shiftSame, plus our own capture. Ads loading into unreserved space move the page.
- Requests and transfer sizeThe capture's own resource timing. How much weight the page carries.
- Third-party host countThe capture. Each vendor is another connection and another blocking risk.
Thresholds, and why
Mobile performance score below 50: Medium. Google treats this band as poor. It is a composite rather than a revenue number, so it is reported with the lab timings behind it.
Cumulative layout shift above 0.10: Medium. Google's own threshold for needs improvement. Reserving space for ad slots is the standard fix and does not reduce ad density.
Eighty or more third-party hosts: Medium, reported under vendor cost too. No single host is the problem. The count is a symptom of accumulated tags nobody removed.
Where judgment enters
Performance scores move with the test device and network, so single scores are noisy. We report field data from real Chrome users alongside lab results when it exists, and we never recommend cutting ad density without a revenue test attached, because the experience win can cost more than it returns.
What would change a finding
- Heavy interactive pages (live scoreboards, video hubs) carry weight for good reason. Article templates are the fair comparison.
- A consent banner shown in one region changes the measured load in that region only.
Rules PX-001, PX-002.
Leak 8 of 8
The vendor-cost leak
The only leak on this list where the fix puts money back immediately rather than earning more. Publisher stacks accumulate: an analytics tool from two redesigns ago, two audience platforms doing the same job, a verification vendor nobody reads reports from. Each one costs a fee, a revenue share, or page speed, and often all three.
What we measure
- Third-party hosts on one articleThe capture. The raw footprint.
- Vendor identificationHost-to-vendor catalog. Turns hostnames into named products and categories.
- Category overlapSame, grouped. Two or more vendors doing the same job.
- Audience-data platformsSame. The most commonly duplicated and most expensive category.
Thresholds, and why
Eighty or more third-party hosts: Medium. A count, not a verdict. It is the trigger for a real audit rather than a finding about a specific vendor.
Three or more audience-data platforms detected: Low, inferred. Inferred because a platform may be present for a client's campaign rather than the publisher's own contract. Still worth asking, because these are annual contracts with real numbers attached.
Parent-owned stacks: owner reassigned. When ads.txt names a parent, vendor contracts are almost always theirs, so the finding routes to the parent.
Where judgment enters
We can see what loads. We cannot see what it costs, whether it is bundled, or whether it is contributing revenue we can't observe. Every vendor finding is framed as a question for the publisher's contract list, not a recommendation to cut.
What would change a finding
- Tag managers can load vendors conditionally, so one capture may over- or under-count.
- A vendor may be present for a single advertiser's campaign and disappear next week.
Rules VN-001, VN-002.
Tracked separately from the eight leaks
Compliance flags
Privacy and betting-content issues are recorded as risk flags rather than leaks. They cost money indirectly, through withheld demand or worse, and they carry consequences money does not measure.
US privacy signals
What we look for. Whether the page exposes the standard US privacy signal (GPP or the older USP string), and whether Prebid reports its consent modules enabled.
Why it matters. Buyers who require a consent signal will withhold bids without one, and state privacy laws set obligations that vary by where the reader is.
Threshold. No signal detected and no consent module enabled: Medium, always labeled verify first.
The limit, stated plainly. Consent tools commonly load only for visitors in states with privacy laws. A capture from a state without one proves nothing. This finding is never shared with a publisher until it has been re-checked from a location covered by such a law. We do not give legal advice; where a flag holds up, the recommendation is to route it to the publisher's counsel or privacy vendor.
Betting content
What we look for. Sportsbook affiliate links, bonus-code pages, and betting modules.
Why it matters. Sportsbook demand pays well, and it comes with rules: availability by state, age-gating, and placement standards. Getting geo-gating wrong is a liability, not an optimization.
Threshold. Betting content present: recorded as a note, always, with a prompt to confirm state gating and age treatment.
The limit. We can see that betting content exists. We cannot verify from a single capture whether gating behaves correctly in every state, which takes testing from multiple locations.
Rules CP-001, BT-001.