Skip to content

Cookie scanner:Does your site track visitors before they click Accept?

See every cookie and tracker your page sets before a visitor answers the cookie banner, what changes after Accept, and whether the banner offers a reject option.

  • Free, no account
  • Results in under a minute
  • 25 trackers, 18 consent platforms
Example result

example-shop.hr

WordPress 6.8

Sample shop · homepage · mobile Chrome · the same check you get for your own site

Run it on your site
Best practices

3 passed · 0 failed · 0 warnings. Nothing to fix here.

Detected technology

  • WordPress 6.8
  • WooCommerce
  • Elementor
  • jQuery 1.12.4
  • LiteSpeed
no cookie banner found0 cookies before consent

Cookies

0 observed · 0 third-party

No cookies were set, before or after consent.

Trackers

0 before consent

No known analytics, advertising or session-replay requests.

What we found

0 failed0 warnings3 passed

Everything this tool checks passed.

Show 3 passed checks

What this tool checks

A first-time visit recorded before and after consent, with every cookie classified.

  • Trackers before consent

    Finds analytics and ad trackers that load before the visitor answers the cookie banner.

  • Cookies before consent

    Finds tracking cookies set before the visitor agrees, a common finding in data-protection audits.

  • Cookie banner reject option

    Checks the cookie banner lets visitors reject as easily as they accept, as EU regulators expect.

  • Cookie lifetime

    Finds cookies that last longer than 13 months, beyond what some EU guidance allows.

  • Cookie banner

    Detects which cookie consent banner runs on the page, if any.

  • Google Consent Mode

    Checks Google tags know what visitors agreed to, so analytics keep working after a reject.

  • Analytics and tag managers

    Lists the analytics and tag managers on the page, so you can spot old or unwanted trackers.

  • Privacy policy link

    Checks the page links to a privacy policy, which GDPR requires and visitors look for.

  • Secure flag on cookies

    Checks cookies are only sent over HTTPS, so nobody on the network can copy a session.

  • HttpOnly flag on cookies

    Checks cookies are hidden from page scripts, so an injected script can't steal a session.

  • SameSite attribute on cookies

    Checks cookies say when other sites may send them, which protects against forged requests.

Show 7 more checks
  • Cookie banner

    Detects which cookie consent banner runs on the page, if any.

  • Google Consent Mode

    Checks Google tags know what visitors agreed to, so analytics keep working after a reject.

  • Analytics and tag managers

    Lists the analytics and tag managers on the page, so you can spot old or unwanted trackers.

  • Privacy policy link

    Checks the page links to a privacy policy, which GDPR requires and visitors look for.

  • Secure flag on cookies

    Checks cookies are only sent over HTTPS, so nobody on the network can copy a session.

  • HttpOnly flag on cookies

    Checks cookies are hidden from page scripts, so an injected script can't steal a session.

  • SameSite attribute on cookies

    Checks cookies say when other sites may send them, which protects against forged requests.

How it works

  1. Visit as a first-timer

    The page loads in Chromium with no cookies and nothing accepted. Every cookie and request is recorded and matched against 25 well-known analytics, advertising and session-replay trackers.

  2. Click Accept

    The scanner finds the accept button, by the selectors of 18 consent platforms or a visible accept button in 20 languages, clicks it, waits and records what appeared.

  3. Classify and check

    Cookies are classified by name, lifetime and party, and the banner is checked for a reject control on its first layer.

Banners inside iframes, shown after a delay of more than a few seconds or with unusual button labels can be missed. You then get the pre-consent result only.

Questions

Is this really free?

Yes. getReport is funded by donations, not plans. This tool runs the full report and shows you the part it is about; the complete report with all seven modules is one click away, also free.

Does it accept the cookies on my site?

Only inside its own throwaway browser session, which is discarded after the scan. Nothing is stored about you or your visitors, and the click never reaches a real user.

My banner was not found or not clicked.

Banners rendered inside iframes, behind a delay longer than a few seconds, or with unusual button labels can be missed. The result then shows the pre-consent state only, which is still the important half; write to us with the URL and we add the pattern.

Do you store my results?

The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag; nothing about your visitors is collected.

Why scan before and after consent?

A cookie banner is not compliance. What matters is whether the analytics and ad tags actually wait for the click. Most sites we test have a banner and set _ga and _fbp before anyone touches it, because the tag manager fires on page load. The scan reproduces what a regulator or a privacy-conscious visitor sees, a fresh browser, the page, the banner. If a tracker request or tracking cookie exists at that moment, the banner is decorative. The result shows exactly which ones, so the fix is a configuration change, not a lawyer.

All 41 tools →

Free, funded by the people who use it

€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.

Chip in