Skip to content
SitesProof
Cookies before consent

What fires before anyone clicks accept.

A consent banner that is installed is not the same as a consent banner that works. The crawl loads the site as a stranger, then again after accepting, and this check reads only what happened before.

The problem

The banner is there. The tracker fired anyway.

Consent tooling gets configured once, on the day it was installed, and then a plugin update, a new tag or a theme change puts something back in front of it. Nobody notices, because noticing means opening dev tools on forty sites one at a time. ePrivacy Art. 5(3) is about what was stored on a visitor’s device before they agreed — not about whether a banner exists.

How it works

How cookies before consent works

  1. 1

    Load the site as a stranger

    No cookies, no consent, nothing accepted. Every cookie and every request the page makes in that state is tagged as pre-consent in the stored artifact.

  2. 2

    Classify what was set

    Cookies are matched against the Open Cookie Database. Third-party requests that look like tracking — a script, an XHR, a pixel, a beacon — are reported separately from cookies, because a pixel sets nothing and still phones home.

  3. 3

    Report only the pre-consent half

    A cookie set before consent, deduplicated per cookie and domain across the site. A tracking request fired before consent. Or no consent banner at all on a site that nonetheless sets non-essential cookies.

Why it matters

What you get

Classified, not guessed

A cookie we cannot classify from the public database is reported as unclassified at low severity, with the reason. You know what your own cookie is for and we do not, so we will not invent a purpose for it.

Necessary cookies are left alone

Session, CSRF, cart and the consent tool’s own cookies are never reported. A check that flagged a session cookie would be a check nobody reads twice.

No compliance score

The nearest comparable tool, CookieRisk, prints a 0–100 score. We do not, on purpose: there is no defensible way to turn "four trackers fired early" into a number, and the client will ask what the number means.

FAQ

Questions, answered

Is this a consent banner?

No. We do not install anything, do not change a page and do not sell a consent platform. This reports what the one already on the site did when a stranger arrived — which is the thing a consent platform cannot tell you about itself.

Can it tell me a site is GDPR compliant?

No. It tells you which cookies were set and which third parties were called before consent, on a date, with the rule each observation relates to. That is evidence someone can act on. Whether a site meets the GDPR is a judgement about a whole organisation, not about one crawl.

Start with one page.

Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.

Scan a page free