Whats worse is some of them are fetched externally rather than bundled with the host code thus increasing latency and potential security risks
Some vendor SDKs can be built and bundled from NPM, but most of them explicitly require you fetch their minified/obfuscated bundle from their CDN with a script tag. This is so they don't have to support older versions like most other software in the world, and so they can push updates without requiring customers to update their code.
Try to use vendors that distribute open-source SDKs, if you have to use vendors.
it would be almost impossible to measure success without it, whether it's a conversion funnel or tracking usage of a new feature
The major players here are explicitly not anonymous, they are designed to keep track of people over time so that they can collate habits and preferences across different sites to better target advertising. Yes, your AB test script isn't doing the same thing, but is it really adding any value to be as a consumer, or is it just optimising an extra 0.01% revenue for you?
If it is put in by a developer, the budget for that is like an hour to copy paste the code snippet in the right spot. Few are going to pay the hours required for an in house data collection layer that then has to integrate with the third party if that's even an option.
At least that is my experience through agency work. Maybe a product owner company could do it.
Not to be rude to the industry either, but I don't see why the assumption would bet that an in house dev has the chops to not make the same mistakes a third party does.
earlier in the conversation someone talked about pasting a snippet. We're talking about the "chops" to not paste a snippet that is hundreds of thousands of lines long. A snippet so long it would crash many editors.
It is very common to get multiple departments and contracted companies sticking their misc JS in since every marketing SaaS tool they use has it's own snippet. Your SEO guy wants 3 trackers, your marketing has another 5, and you sell on XYZ online market and they have affilliate trackers etc.
No devs engaged at any point and the site performance isn't their responsibility. They can't do their job without their snippets so the incentives are very sticky, and the circus goes on.
It's kind of like an NPM dependency tree of martech SaaS vendors...
After those things it is the heavy libs that cause performance problems, like maps and charts, usually some clever lazy loading fixes that. Some things I personally ran into: - QR code scanning lib and Map lib being loaded at startup when it was actually just really small features on the application - ALL internationalisation strings being loaded at startup as a waterfall request before any other JS ran. Never managed to get this one fixed... - Zendesk just completely destroys your page performance, mandated through upper-management, all I could do was add a delay to load it
After that then it comes just badly designed code triggering too many DOM elements and/or rerenders and/or waterfall requests.
After that comes app-level code size, some lazy loading also fixes this, but it is usually not necessary until your application is massive.