What fires before anyone clicks accept.
A consent banner that is installed is not the same as a consent banner that works. The crawl loads the site as a stranger, then again after accepting, and this check reads only what happened before.
The problem
The banner is there. The tracker fired anyway.
Consent tooling gets configured once, on the day it was installed, and then a plugin update, a new tag or a theme change puts something back in front of it. Nobody notices, because noticing means opening dev tools on forty sites one at a time. ePrivacy Art. 5(3) is about what was stored on a visitor’s device before they agreed — not about whether a banner exists.
How it works
How cookies before consent works
- 1
Load the site as a stranger
No cookies, no consent, nothing accepted. Every cookie and every request the page makes in that state is tagged as pre-consent in the stored artifact.
- 2
Classify what was set
Cookies are matched against the Open Cookie Database. Third-party requests that look like tracking — a script, an XHR, a pixel, a beacon — are reported separately from cookies, because a pixel sets nothing and still phones home.
- 3
Report only the pre-consent half
A cookie set before consent, deduplicated per cookie and domain across the site. A tracking request fired before consent. Or no consent banner at all on a site that nonetheless sets non-essential cookies.
Why it matters
What you get
Classified, not guessed
A cookie we cannot classify from the public database is reported as unclassified at low severity, with the reason. You know what your own cookie is for and we do not, so we will not invent a purpose for it.
Necessary cookies are left alone
Session, CSRF, cart and the consent tool’s own cookies are never reported. A check that flagged a session cookie would be a check nobody reads twice.
No compliance score
The nearest comparable tool, CookieRisk, prints a 0–100 score. We do not, on purpose: there is no defensible way to turn "four trackers fired early" into a number, and the client will ask what the number means.
FAQ
Questions, answered
Is this a consent banner?
No. We do not install anything, do not change a page and do not sell a consent platform. This reports what the one already on the site did when a stranger arrived — which is the thing a consent platform cannot tell you about itself.
Can it tell me a site is GDPR compliant?
No. It tells you which cookies were set and which third parties were called before consent, on a date, with the rule each observation relates to. That is evidence someone can act on. Whether a site meets the GDPR is a judgement about a whole organisation, not about one crawl.
Features
More features
White-label client reports
One PDF per client per month, carrying your logo, your colours and their name. Nothing in it mentions us except the disclaimer.
Learn morePayment-page scripts
Every script on a page that really takes card details, inventoried and hashed, so a change in the set or in a body is something you hear about.
Learn moreAccessibility (WCAG 2.2 AA)
axe-core in a real browser against WCAG 2.2 AA, plus a draft accessibility statement that names the parts only your client can answer.
Learn moreStart with one page.
Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.