Prebid.js 11 Is Here: An Upgrade Checklist for Publisher Ad Ops
Prebid.js 11.0 shipped March 12 with PAAPI and adpod removed, stricter mediaType checks and strict storage enforcement. Here is what to audit before you upgrade.
Prebid.js 11.0 was released on March 12, 2026, and the 11.x line has moved quickly since, with point releases landing every week or two. Major versions are where the project clears out old code and changes defaults, which makes them the moment a wrapper that has run quietly for a year can start dropping bids without an obvious error. If your team runs its own Prebid build, plan this move on purpose rather than letting a dependency bump do it for you.
Below is what changed for publishers, what is most likely to bite, and how we would sequence the upgrade.
What Prebid 11 removes
The Prebid 11 release notes list the headline changes for publishers:
- PAAPI support is gone. The paapi, paapiForGpt and topLevelPaapi modules have been removed. This follows Google's October 2025 announcement that it would retire Protected Audience, Topics and several other Privacy Sandbox technologies, citing low adoption.
- Adpod is no longer supported. The adpod module and its submodules (categoryTranslation, dfpAdpod, gamAdpod, freeWheelAdserverVideo) are removed. The old dfpAdServerVideo module is also out; gamAdServerVideo replaces it.
- Other modules are removed, including dmdIdSystem, express, intersectionRtdProvider, the Quantcast bid adapter and ID module, and a few other adapters.
- Three events are removed: addAdUnits, bidAccepted and seatNonBid. The notes point to auctionInit or beforeRequestBids, bidResponse, and pbsAnalytics as the replacements.
If your build includes a removed module, you find out right away because the module no longer exists. That is the easy case. The harder cases are behavior changes that fail quietly.
The changes that fail quietly
Stricter mediaType enforcement
Bids that declare a mediaType not present in the ad unit's mediaTypes are now rejected as invalid. A banner-only ad unit that has been accepting video or native responses from a loosely configured adapter will stop accepting them. That is arguably correct, but it can show up as a fill or revenue dip on specific bidders. You can turn the check off with auctionOptions.rejectInvalidMediaTypes set to false, and a new rejectUnknownMediaTypes option lets you go the other way and require every bid to declare its format. Bids with no mediaType are still treated as banner by default.
storageControl now enforces
If your build includes the storageControl module, it now defaults to strict enforcement: undisclosed storage use fails instead of logging a warning. Publishers who added the module to monitor disclosures and never read the warnings are the most exposed, because an ID module or adapter writing cookies or localStorage keys it has not disclosed will simply stop working. Check your console on the current version before upgrading. Any storageControl warning you see today is a failure after the upgrade. The release notes document an enforcement setting if you need to fall back to warnings while you fix disclosures.
GPT slot matching is consolidated
setTargetingForGPTAsync no longer accepts a customSlotMatching argument, and the bidViewability.customMatchFunction and gptPreAuction.customGptSlotMatching options are gone. A single new option, customGptSlotMatching, replaces all of them. Publishers whose ad unit codes do not match GPT slot element IDs or ad unit paths often depend on custom matching. If that function stops being called, targeting will not land on the right slots, and header bidding demand quietly stops competing in the ad server.
Viewability signaling is reworked
Prebid 11 overhauls how viewability is calculated and signaled. It adds an element property on ad units and a getAdUnitElement utility so adapters can connect a bid request to its location on the page. If you use lazy-loaded or dynamically injected slots, confirm those element references resolve once the container exists.
A sequenced upgrade plan
- Inventory your build. List every module in your current build and compare it with the removed-modules table. Anything on that list needs a replacement or a decision to drop it.
- Search your page code. Look for onEvent handlers on bidAccepted, addAdUnits and seatNonBid, calls to setTargetingForGPTAsync with a second argument, and any PAAPI configuration in ad units or setConfig. Analytics adapters and in-house dashboards are common hiding places for a bidAccepted listener.
- Read the warnings you already have. On your current version, load key templates with Prebid debug enabled and capture storageControl and mediaType warnings. That is your list of things that will break.
- Build 11 in staging and compare auctions. Run the same pages on both builds and compare, per bidder, bid requests, bid responses, rejected bids with reasons, and wins. Rejections are the key signal. A bidder whose rejections jump almost always has a mediaType or storage problem.
- Split traffic before you cut over. Serve Prebid 11 to a slice of traffic alongside the current build for at least a week, keyed so each user sees one version. Compare revenue per thousand sessions, not just CPM, and break it down by device and template. A full week covers both weekday and weekend patterns.
- Keep the rollback ready. Keep the previous build deployable until the new one has run at full traffic for a full week.
How to read the split test
A wrapper A/B test is only useful if the two arms differ in one thing. Do not change timeouts, bidder lists or floors at the same time you change versions, or you will not know what moved the numbers. Watch three things: header bidding revenue per session, bid rate by bidder, and page performance (Largest Contentful Paint and layout shift on ad-heavy templates). If revenue is flat but one bidder's bid rate fell, look at that adapter's rejected bids first.
Check your analytics pipeline too. If it keyed on a removed event, your reporting may show a drop that is not real. Validate against the ad server's own numbers before drawing conclusions.
What about video pods?
Publishers who used Prebid's adpod support for long-form or CTV-style pods need a different path, because that code is gone in 11. Single-ad instream video through gamAdServerVideo continues to work. If pod-based monetization matters to you, talk to your SSP and ad server partners about how pods will be handled before you upgrade, not after.
The takeaway
Prebid 11 is a cleanup release. Most of what it removes, especially the Privacy Sandbox code, was delivering little for most publishers. The risk is not the removals; it is the defaults that now enforce rules your setup may have been bending. Treat the upgrade like any other revenue change: inventory, stage, split test, then cut over. If your wrapper is managed, ask your provider when the move to 11 is planned and how it will be tested, because the same checklist applies whoever holds the keys.
Related Articles
Q4 Starts in 10 Days: A Yield Checklist for Lifestyle, Retail and Travel Sites
The fourth quarter is when ad budgets peak and mistakes cost the most. A practical checklist for code freezes, floors, supply chain hygiene, direct deals and monitoring before October 1.
Amazon DSP Can Now Buy Publisher-Hosted PG Deals in GAM. Get Your Setup Ready
Amazon DSP self-service buyers can now run Google Ad Manager programmatic guaranteed deals with creatives hosted by the publisher. Here is how to package and traffic those deals before Q4.
Google Now Uses IP Addresses for Ads in Europe. Check Your TCF Strings
Since August 3, Google uses IP addresses for ad measurement and personalization in the EEA, UK and Switzerland. Publishers need their consent setup to disclose it correctly.