The Best Cookie Compliance Scanners in 2026, Tested

Every scanner roundup ranks tools by their feature lists. We built a test page with known, documented consent violations instead, ran the scanners against it, and published what each one actually caught.

Tested comparison · 12 scanners
Reviewed by Ben Churchill · Last reviewed September 2026

Cookie scanners all promise the same outcome: point one at your site and learn whether you have a compliance problem. They do not all measure the same thing. Some request your homepage once and list the cookies they saw. Some run a real browser. Very few click the consent banner they find, and almost none compare what happens after a visitor rejects with what happened before.

Reviews of these tools repeat the vendors' own feature claims, so we did something different: we published a small website whose consent behavior is deliberately and precisely broken, and we run each scanner against it. The site fires one tracker before any consent choice, leaks another tracker only after the visitor rejects, gates a third correctly behind acceptance, and hides a fourth behind scrolling. It also plants items that are not trackers at all, to catch tools that cry wolf.

Disclosure: ConsentStack builds one of the scanners on this page. That is exactly why the methodology is public. The test rig at scannertest.consentstack.io documents its own ground truth, every result below is stamped with its run date, and you can rerun any scanner here against the rig and check our work.

The test: a site that is wrong on purpose

The rig uses the vendors' real tracking scripts with dummy IDs, so every network request a real deployment would make actually happens, but nothing is collected. The rig runs no consent management platform, not ConsentStack and not anyone else's: its banner is a few lines of plain JavaScript written for the test, because a real CMP exists to prevent exactly the violations the rig plants, and running one would bias the test toward whoever built it. Its complete behavior:

Google Analytics 4

Loads and fires on every page load, before any consent choice.

A correct scan reports: A pre-consent tracker fire.

TikTok pixel

Fires only after the visitor clicks Reject, and again on every later load while the stored choice is rejected.

A correct scan reports: A tracker firing after consent was rejected.

Meta pixel

Loads only after the visitor clicks Accept. This is correct gating.

A correct scan reports: A consent-gated tracker. A scanner that never accepts consent will wrongly report it absent.

LinkedIn Insight

Loads only after the visitor scrolls, regardless of consent.

A correct scan reports: An engagement-gated tracker fire.

dayjs (cdn.jsdelivr.net)

A functional date library on a third-party host. No tracking, no cookies.

A correct scan reports: Not a tracker. Flagging it is a false positive.

rig_session and rig_consent cookies

First-party session and consent-choice cookies.

A correct scan reports: Strictly necessary. Requiring consent for them is over-strict.

A perfect scanner catches the first two rows as violations, sees the third and fourth by exercising the page like a person would, and flags none of the last two rows. Scanning from more than one region earns a further distinction: the same behavior is judged under opt-in law for EU visitors and opt-out law for most US visitors, so a single verdict cannot be right for both. The full results are also available as a CSV download.

Snapshot

Twelve scanners besides ours were run against the rig on September 1, 2026. Eleven returned results the same day; Osano delivers reports only by email within 1 to 2 days, and nothing had arrived when this page was compiled. ConsentStack against the field of eleven, every number traceable to the matrix below:

ConsentStackvsThe 11 competitors
Caught the post-reject leak
Yesvs0 of 11
Caught the pre-consent fire
Yesvs4 of 11
Found all four planted trackers
4 of 4vs0 of 11(found all four)
Exercised the accept path
Yesvs0 of 11
Clicked the consent banner
Yesvs1 of 11
Regions scanned
2(EU + US)vs1(every competitor)

Two reports went beyond missing things and contradicted the rig's documented behavior: one scanner reported six storage items that do not exist on the rig, and another returned a green pass on post-opt-out tracking against a site built to keep tracking after rejection. Both are covered in the scanner-by-scanner sections.

Results

Each column is one scanner, run against the rig on the date shown. Every cell reports only what that scanner's own output showed; nothing in this table comes from a vendor's marketing pages. The per-scanner sections further down carry the evidence behind each mark, including screenshots of every report.

TestConsentStackCookiebot Website Cookie CheckerCookieYes Cookie CheckerTermly Cookie ScannerCookieScript Cookie ScannerCookie Scanner (cookie-scanner.com)CookieServe Cookie CheckerPiwik PRO Cookie ScannerOsano Compliance CheckUsercentrics Cookie Checkerconsentmanager Cookie ScannerCookieHub Cookie CheckerUniConsent Cookie Checker
Found the trackersYesNoPartialPartialNoPartialPartialPartialNo resultNoPartialPartialPartial
Caught the pre-consent fireYesNoNoNoNoPartialNoPartialNo resultYesYesYesYes
Caught the post-reject leakYesNoNoNoNoNoNoNoNo resultNoNoNoNo
Exercised the accept pathYesNoNoNoNoNoNoNoNo resultNoNoNoNo
Caught the scroll-gated trackerYesNoPartialNoNoNoNoNoNo resultNoNoNoNo
No false positivesYesPartialPartialPartialNoPartialPartialNoNo resultPartialPartialPartialPartial
Scanned from more than one regionYesNoNoNoNoNoNoNoNo resultNoNoNoNo
Run date2026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-012026-09-01

How they rank

Ranked by how many of the seven tests each scanner passed, with one further rule applied to every tool equally: a report containing statements the rig's documented behavior contradicts ranks below a report that merely found less, because a wrong answer costs a site owner more than a missing one.

  1. 1. Caught the full consent lifecycle

    ConsentStack Compliance Scanner

    Passed all seven tests: found the trackers, caught the pre-consent fire and the post-reject leak, exercised the accept path, caught the scroll-gated tag, flagged nothing benign, and returned different verdicts under EU and US law. We build this tool, which is why the rig and this methodology are public: this is the easiest row on the page to check.

  2. 2. Caught the pre-consent fire, nothing after it

    UniConsent Cookie Checker · consentmanager Cookie Scanner · CookieHub Cookie Checker · Usercentrics Cookie Checker

    Each of these correctly failed the rig for tracking before consent, the one planted violation visible from a cold page load. None of them rejects or accepts consent, so the post-reject leak and the accept-gated pixel are invisible to all four.

  3. 3. Inventory only: no violation caught

    CookieYes Cookie Checker · Termly Cookie Scanner · CookieServe Cookie Checker · Cookie Scanner (cookie-scanner.com) · Piwik PRO Cookie Scanner

    These returned lists of cookies or requests with no compliance verdict attached, so a site with three planted violations produced reports containing zero violations. cookie-scanner.com and Piwik PRO both have machinery pointing the right way (a banner click, before-and-after tabs) that produced no comparison on the rig.

  4. 4. Results contradicted by ground truth

    Cookiebot Website Cookie Checker · CookieScript Cookie Scanner

    Cookiebot's report returned a green pass stating the rig stops tracking users after they opt out, against a site whose planted tracker fires only after rejection (its check tests a GPC signal, not the banner). CookieScript reported six storage items that do not exist on the rig. Both reports contain statements the rig's documented behavior contradicts.

  5. 5. No result

    Osano Compliance Check

    Produced nothing gradeable: results are promised by email within 1 to 2 days, and no report had arrived when this page was compiled. This section will be updated if it arrives.

The platforms you cannot test at all

Several major consent platforms have no publicly runnable scanner: their scanning exists only inside the product, so a buyer cannot check its accuracy before purchasing, and neither can this page. Verified against each vendor's own site on September 1, 2026. If one of them ships a public tool, it joins the matrix.

  • OneTrust: Website scanning is a feature of the paid Cookie Consent product. The public path to a scan is a contact-sales form.
  • TrustArc: Cookie scanning ships inside the Cookie Consent Manager product. No public URL-entry tool.
  • Didomi: Scanning is part of the Advanced Compliance Monitoring product. No public URL-entry tool.
  • iubenda: The site scanner runs inside the product for your own configured site. No public URL-entry tool.

Scanner by scanner

ConsentStack Compliance Scanner

By ConsentStack (that is us; see the disclosure above). Run against the rig on 2026-09-01. Run this scanner

Caught every planted behavior: the pre-consent GA4 fire, the post-reject TikTok leak, the accept-gated Meta pixel, and the scroll-gated LinkedIn tag, with zero false positives on the non-tracker traps. It was also the only result to differ by region on purpose, reporting the same site as violating opt-in rules in the EU while noting the US visit was over-blocked relative to opt-out law. It also identified the rig's hand-rolled banner as a custom CMP and operated it.

TestResultWhat the scanner's output showed
Found the trackersYesAll four trackers identified by product name.
Caught the pre-consent fireYesGA4 flagged as a pre-consent violation in the EU scan, and correctly treated as permitted default-grant behavior in the US scan, where opt-out rules apply.
Caught the post-reject leakYesTikTok flagged as firing after rejection in both regions. The site verdict came back “leaky”.
Exercised the accept pathYesMeta pixel observed blocked before consent and firing after acceptance, so the accept path was actually exercised.
Caught the scroll-gated trackerYesThe scroll-gated LinkedIn Insight tag was caught in both regions.
No false positivesYesZero. The jsDelivr library and both first-party cookies were classified as exempt.
Scanned from more than one regionYesScanned concurrently from the EU and the US, with different verdicts where the law differs: the US scan flagged the rig's opt-in gating of Meta as stricter than the region requires.
Score 49 with separate EU and US verdicts, five issue counters, and the rig's banner identified as a custom CMP.
Per-tracker page load, reject, and accept results for both regions: TikTok fires on Reject, Meta on Accept.
Critical issues name the violation and its phase, including the TikTok fire after Reject in both regions.
Cookie outcomes per phase, with _ga persisting after Reject.
The tracker and cookie inventory with product and vendor names.
The scan running from EU and US servers in parallel.

Cookiebot Website Cookie Checker

By Usercentrics (Cookiebot). Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Cookiebot

Results are gated behind a mandatory email address. What comes back is a CCPA compliance checklist rather than a report on observed behavior: it found no CMP on a site with a visible consent banner, named no trackers, and its opt-out check returned a green pass against a site built to keep tracking after rejection (the check tests a GPC signal, not the banner). The to-do list ends in a signup button for Cookiebot's own CMP.

TestResultWhat the scanner's output showed
Found the trackersNoThe report shows a count of 3 detected services and no tracker or cookie inventory, so none of the four planted trackers is named.
Caught the pre-consent fireNoThe four checks returned are CCPA checks about CMP presence, a Do Not Sell link, and GPC. Nothing in the report addresses trackers firing before consent.
Caught the post-reject leakNoReturned a green pass reading 'Your website stops tracking users after they opt out' on a site whose planted tracker fires only after Reject. The check is scoped to a GPC opt-out signal rather than the banner's Reject button, so the leak is invisible to it, but the checkmark is still green.
Exercised the accept pathNoNo consent interaction occurs; the accept-gated Meta pixel appears nowhere in the report.
Caught the scroll-gated trackerNoThree services detected from a cold page load; the scroll-gated LinkedIn tag is not among them.
No false positivesPartialThe report contains no tracker or cookie inventory, so the false-positive traps could not be evaluated either way. It did report that no CMP was detected, although the rig shows a visible banner with Accept and Reject buttons.
Scanned from more than one regionNoThe report frames everything under CCPA and CPRA, with no EU verdict and no second region.
Results are locked behind a mandatory email address.
High risk header with four CCPA checks. Check 3 passes the rig for stopping tracking after opt-out.
The to-do list repeats the checks and ends in a Cookiebot CMP signup.

CookieYes Cookie Checker

By CookieYes. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs CookieYes

An ungated cookie inventory: seven cookies with domains, durations, and database-sourced descriptions, delivered quickly and with no email required. It has no concept of consent state, so the planted pre-consent fire, the post-reject leak, and the accept-gated pixel are invisible to it by design. It did reach the scroll-gated LinkedIn tag, which most tools here missed, but reported its cookies as ordinary rows.

TestResultWhat the scanner's output showed
Found the trackersPartialGoogle Analytics and three LinkedIn cookies appear in the seven-cookie inventory; TikTok and Meta do not.
Caught the pre-consent fireNoThe report is a cookie inventory with no consent state: GA is listed as a row, not as a tracker that fired before consent.
Caught the post-reject leakNoThe scanner never rejects consent, and no TikTok entry appears.
Exercised the accept pathNoThe scanner never accepts consent, and no Meta entry appears.
Caught the scroll-gated trackerPartialLinkedIn's bcookie, li_gc, and lidc cookies were captured, so the scan reached the scroll-gated tag, but they are presented as ordinary rows with no note that they loaded without consent.
No false positivesPartialNothing benign was flagged, but the report flags nothing at all; the rig's own session cookie is listed as type Other with an empty description rather than recognized as necessary.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Seven cookies with categories, durations, and database descriptions. No consent state anywhere in the report.

Termly Cookie Scanner

By Termly. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Termly

The highest raw cookie count of any free inventory tool on the rig (12, versus 7 for CookieYes), with category donuts and per-cookie tables behind a signup for the full report. It states the compliance principle at the top of its own results but does not test it: no consent phase exists in the scan, so whether any of those 12 cookies was set before consent, or survived a rejection, is left to the reader.

TestResultWhat the scanner's output showed
Found the trackersPartialTwelve cookies are counted across categories including advertising and social, but only the Google Analytics rows are identified by name in the visible tables. No TikTok or Meta entry appears.
Caught the pre-consent fireNoThe page prints the rule, 'non-essential trackers should never be set prior to user consent', but the scan does not test whether the rig broke it.
Caught the post-reject leakNoNo consent interaction occurs and no TikTok entry appears.
Exercised the accept pathNoNo consent interaction occurs and no Meta entry appears.
Caught the scroll-gated trackerNoA Social category count of 1 appears with no cookie identified and no consent state attached.
No false positivesPartialNothing was flagged as a violation because the report issues no verdicts; 5 of the 12 cookies found are Unclassified.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Twelve cookies counted, five of them Unclassified. No consent lifecycle.

CookieScript Cookie Scanner

By CookieScript. Run against the rig on 2026-09-01. Run this scanner

Found the least of any tool tested (3 cookies) and reported the most that is not there: six local and session storage keys belonging to WooCommerce and Google reCAPTCHA, neither of which the rig runs, all confidently categorized as Strictly Necessary. We record that as observed output; the cause is not determinable from the report. No consent phase exists in the scan.

TestResultWhat the scanner's output showed
Found the trackersNoThree cookies total, the lowest count of any scanner tested: both GA cookies and the rig's session cookie. No TikTok, Meta, or LinkedIn entry.
Caught the pre-consent fireNoNo consent state is reported anywhere.
Caught the post-reject leakNoNo consent interaction occurs and no TikTok entry appears.
Exercised the accept pathNoNo consent interaction occurs and no Meta entry appears.
Caught the scroll-gated trackerNoNo LinkedIn entry appears.
No false positivesNoThe Storages section reports six items that do not exist on the rig: WooCommerce cart keys and a Google reCAPTCHA token, on a static page running neither, all labeled Strictly Necessary. The rig's real first-party session cookie lands in Unclassified.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Three cookies total on the rig, the lowest count of any scanner tested.
Both GA cookies plus the rig's session cookie, which lands in Unclassified.
Six storage keys the rig does not set: WooCommerce and reCAPTCHA entries, all labeled Strictly Necessary.

Cookie Scanner (cookie-scanner.com)

By cookie-scanner.com. Run against the rig on 2026-09-01. Run this scanner

The only competitor tool that recognized the rig's banner exists and clicked it, correctly labeling an unknown provider rather than declaring no CMP present. Its initiator tracing is the best of any competitor report here: each cookie is attributed to the script and line that set it. But the click leads nowhere: the report never compares before with after, so the consent lifecycle findings the click could have produced are absent.

TestResultWhat the scanner's output showed
Found the trackersPartialFound the Google Tag Manager and Google Analytics hosts and the jsDelivr request. TikTok, Meta, and LinkedIn hosts do not appear.
Caught the pre-consent firePartialA red card flags 'Tags and 3rd Party requests found' and each cookie is traced to the exact script and line that set it, but the report never states what happened before versus after consent.
Caught the post-reject leakNoThe only competitor scanner that detected and clicked the rig's banner (reported as 'Banner clicked: Yes', provider 'unknownbanner'), but the report does not compare states, so the post-reject TikTok leak does not surface.
Exercised the accept pathNoNo accept path is reported; the Meta pixel is absent.
Caught the scroll-gated trackerNoNo LinkedIn entry appears.
No false positivesPartialThe functional jsDelivr library is listed under the same red warning card as the tracking hosts, and first-party storage earns an amber flag, with no distinction drawn between a date library and a tracker.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Each cookie traced to the exact script and line that set it, the best attribution of any competitor report.
Three third-party hosts from the pre-consent load. TikTok, Meta, and LinkedIn are absent.

CookieServe Cookie Checker

By CookieYes (CookieServe). Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs CookieYes

Effectively the CookieYes engine under another name, and the reports match: seven cookies, the same category split, no email required, and no consent lifecycle. It detected that some banner platform exists ('Platform Detected: Others') but did not identify or interact with it.

TestResultWhat the scanner's output showed
Found the trackersPartialSeven cookies with the same category composition as CookieYes's report (CookieServe is a CookieYes property). The visible rows identify GA and the rig's session cookie; no TikTok or Meta entry.
Caught the pre-consent fireNoA single homepage load with no consent state. The report states its own scope: 'Cookieserve scans only the homepage of the website.'
Caught the post-reject leakNoNo consent interaction occurs and no TikTok entry appears.
Exercised the accept pathNoNo consent interaction occurs and no Meta entry appears.
Caught the scroll-gated trackerNoNo LinkedIn row is visible in the captured report.
No false positivesPartialNothing benign was flagged, but the report issues no judgments at all; the rig's session cookie lands in Other.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Seven cookies with the same composition as CookieYes. Homepage-only by the report's own statement.

Piwik PRO Cookie Scanner

By Piwik PRO. Run against the rig on 2026-09-01. Run this scanner

Architecturally the closest competitor to the right shape: it is the only other tool with an explicit before-consent and after-consent structure, and it shows raw request URLs no one else shows. On the rig the structure produced nothing: the consent manager was reported Undefined, the banner was never operated, and the After Consent tab came back empty, so no comparison was actually made.

TestResultWhat the scanner's output showed
Found the trackersPartialThe GA cookies are identified and vendor-tagged, and the full GA collect request URL is shown, the most granular network evidence in any competitor report here. TikTok, Meta, and LinkedIn do not appear.
Caught the pre-consent firePartialA Before Consent tab correctly lists the GA cookies and the GA beacon request from the pre-consent load, but the report attaches no compliance verdict to them.
Caught the post-reject leakNoThere is no reject concept, only before and after consent, and the After Consent tab returned 'No data'.
Exercised the accept pathNoThe After Consent tab came back 'Cookies not found', so the before-and-after comparison, the tool's own headline feature, produced nothing on the rig. The likely cause is visible in the same report: Consent Manager 'Undefined', meaning the banner was never operated.
Caught the scroll-gated trackerNoNo LinkedIn entry appears.
No false positivesNoThe functional jsDelivr library is listed in 'Requests out of EU' as a flagged item, indistinguishable from the tracking requests around it.
Scanned from more than one regionNoRequests are geo-attributed, but the scan itself runs from one place and issues one report.
Consent Manager reported as Undefined on a site with a visible banner.
The Before Consent tab lists the GA cookies and shows the full GA collect request.
The After Consent tab returned no data, so no comparison was produced.

Osano Compliance Check

By Osano. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Osano

Osano's Compliance Check returned nothing to grade. Submission ends with a promise of a compliance report by email within 1 to 2 days; no results, cookie lists, or counts are shown in the browser at any point, and no emailed report had arrived when this page was compiled. A report that arrives days later is also not a live read of the site at the moment of scanning. If the emailed report arrives, this section will be updated from it, with its own date.

TestResultWhat the scanner's output showed
Found the trackersNo resultNo report was produced. The tool accepts a URL and an email address and answers: 'You can expect to receive your compliance report via email within the next 1-2 days.' Nothing was viewable on screen, and no emailed report had arrived when these results were compiled.
Caught the pre-consent fireNo result
Caught the post-reject leakNo result
Exercised the accept pathNo result
Caught the scroll-gated trackerNo result
No false positivesNo result
Scanned from more than one regionNo result
The only output on screen: a promise of an emailed compliance report within 1 to 2 days.

Usercentrics Cookie Checker

By Usercentrics. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Usercentrics

The heaviest gating in the test: results are released only after first name, last name, company name, email address, and an answer to a sales-qualifying question about monthly traffic volume. The report that follows does catch the rig's core violation, failing it for collecting without prior consent, which only three other competitor tools managed. Its inventory is weaker than its verdict: zero marketing trackers counted on a rig running three of them, and a boilerplate claim of 10 pages scanned on a one-page site.

TestResultWhat the scanner's output showed
Found the trackersNoFive trackers reported, with Marketing counted as zero on a rig running TikTok, Meta, and LinkedIn. GA is classified as Functional.
Caught the pre-consent fireYesRequirement 1 fails the rig with 'You do not collect consent for cookies and trackers other than strictly necessary ones', a true finding about the planted pre-consent GA fire.
Caught the post-reject leakNoNo rejection occurs; the post-reject TikTok leak is absent from the report.
Exercised the accept pathNoNo acceptance occurs; the Meta pixel is absent from the report.
Caught the scroll-gated trackerNoNo LinkedIn entry appears in the tracker table.
No false positivesPartialNo trap was flagged, but the requirement verdicts are site-level rather than per-item, the rig's session cookie is Unclassified, and the report states 10 pages were scanned on a one-page site.
Scanned from more than one regionNoGDPR and ePrivacy framing only; no US verdict and no second region.
A required traffic-volume question appears mid-scan, before any results.
First name, last name, company, and email are required to view the finished report.
High risk verdict, 5 trackers, and zero Marketing counted on a rig running three marketing pixels.
Requirement 1 correctly fails the rig for collecting without prior consent.

consentmanager Cookie Scanner

By consentmanager. Run against the rig on 2026-09-01. Run this scanner

Gated behind a business email address and delivered as a PDF. Within its single measured state it is the most explicit competitor: it says plainly that cookies and vendors loaded when no consent was given, quantifies them, and adds a data-transfer dimension (vendors sending data outside the EEA, non-EU datacenter owners) that no other tool in the test reports. Everything after the cold load, the reject and accept paths, does not exist in its model.

TestResultWhat the scanner's output showed
Found the trackersPartialSeven unique cookies and the vendors behind them are counted, with 3 non-essential and 1 unknown vendor reported as loaded without consent; the planted trackers are not individually named in the report.
Caught the pre-consent fireYesThe most explicit pre-consent finding of any competitor tested: '2 problematic cookies from 2 vendors when no consent is given', plus counts of vendors loaded without consent, feeding a HIGH RISK verdict.
Caught the post-reject leakNoEverything is measured at the no-consent state; no reject phase exists, so the post-reject TikTok leak is not represented.
Exercised the accept pathNoNo accept phase exists; the accept-gated Meta pixel is not represented.
Caught the scroll-gated trackerNoNo LinkedIn finding appears.
No false positivesPartialLocalStorage is correctly reported as zero and no planted trap is individually flagged, but whether the functional CDN is among the 4 vendors counted as transferring data outside the EEA cannot be determined from the report.
Scanned from more than one regionNoOne crawl, one verdict. The report maps where requests go, not where the scan ran from.
A business email address is required before the crawler delivers results.
The PDF report: high risk verdict with pre-consent cookie and vendor counts quantified.
Cookie and vendor charts from the crawler report PDF.

CookieHub Cookie Checker

By CookieHub. Run against the rig on 2026-09-01. Run this scanner

A pre-consent check that works and says so: it failed the rig for setting analytical and marketing cookies before consent, and was the only competitor to count marketing cookies on the rig. It is also unusually candid about scope, noting its result is based on a single page. The full cookie tables sit behind an email gate, and nothing in the scan touches the reject or accept paths.

TestResultWhat the scanner's output showed
Found the trackersPartialCategory counts only in the on-screen report: 3 analytical and 3 marketing cookies, the only competitor report to count marketing cookies on the rig at all. The per-cookie tables are blurred pending an email address.
Caught the pre-consent fireYesThe verdict names the mechanism: 'your website sets analytical and/or marketing cookies before consent', which is the planted GA fire, and fails the site for it.
Caught the post-reject leakNoThe verdict is derived from a pre-consent page load only; nothing addresses what happens after Reject.
Exercised the accept pathNoNo accept path exists in the scan.
Caught the scroll-gated trackerNoNo LinkedIn finding appears on screen.
No false positivesPartialNothing benign is flagged on screen, but the detailed tables are email-gated, so the traps cannot be fully checked.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Fails the rig for setting analytical and marketing cookies before consent. Detail tables sit behind an email.

UniConsent Cookie Checker

By UniConsent. Run against the rig on 2026-09-01. Run this scanner

No email required, and the best framing of any competitor report: results split into 'Cookies Set Without Consent' versus 'Cookies Managed by CMP', with the offending count and domain in a single sentence. It was also one of only two competitor tools to acknowledge the rig's CMP exists. Its model still ends at the cold page load: nothing after Reject or Accept is measured, and its cookie classifications contain errors.

TestResultWhat the scanner's output showed
Found the trackersPartialFour cookies; GA is identified, attributed to Google LLC, and linked to its privacy policy. TikTok, Meta, and LinkedIn are absent.
Caught the pre-consent fireYesThe clearest presentation tested: a section titled 'Cookies Set Without Consent (2)' names the offending domain (google-analytics.com) and both GA cookies, each individually flagged.
Caught the post-reject leakNo'Without consent' means the cold page load; no reject phase exists, so the post-reject TikTok leak is not represented.
Exercised the accept pathNoNo accept phase exists; the Meta pixel is not represented.
Caught the scroll-gated trackerNoNo LinkedIn finding appears.
No false positivesPartialThe planted traps are not flagged and the rig's own cookies are correctly attributed to the CMP, but a Cloudflare bot-management cookie is categorized as Advertisement and attributed to Google LLC, and the report counts zero Necessary cookies, filing the rig's session cookie under Other.
Scanned from more than one regionNoOne scan, one location, no regional verdict.
Cookies Set Without Consent named and counted, alongside the cookies managed by the CMP.

Frequently asked questions

What is the best cookie compliance scanner?

The honest answer depends on what you need checked. If you only want a list of cookies present on a page, most free checkers produce one. If you need to know whether your site honors a rejection, fires trackers before consent, or blocks more than the law requires, you need a scanner that interacts with the consent banner and observes behavior over the full lifecycle. In our published rig test of twelve scanners, the ConsentStack Compliance Scanner was the only tool that caught the pre-consent fire, the post-reject leak, the accept-gated tracker, and the engagement-gated tracker, with zero false positives. We build that scanner, so do not take our word for it: the test rig is public and you can run every tool on this page against it yourself.

What should a cookie scanner actually test?

Five things. Whether trackers fire before any consent choice. Whether trackers still fire after a visitor rejects. Whether consent-gated trackers correctly appear after acceptance, which a scanner only sees if it accepts and keeps watching. Whether necessary first-party cookies and functional third-party resources get wrongly flagged, which causes over-blocking. And whether behavior differs by region, because opt-in law in the EU and opt-out law in most US states make the same site correct in one place and non-compliant in the other.

Are free cookie checkers accurate?

For listing cookies on a cold page load, generally yes. The gap is everything that happens after the load: in our test, none of the eleven competitor scanners that returned results clicked Reject, so none could see whether the banner actually controls anything. A site can pass a cookie inventory check while ignoring every rejection its visitors make.

Why does scanning from two locations matter?

Because the law your visitor is under changes what compliant behavior looks like. The EU requires opt-in, so a tracker firing before consent is a violation there. Most US states require opt-out, so the same pre-consent fire is permitted, and a site that forces EU-style opt-in on US visitors is stricter than the law requires, which costs measurement without buying compliance. A single-location scan can only ever see one of those realities.

Can I verify these results myself?

Yes. The test rig at scannertest.consentstack.io is public and documents its exact behavior on the page. Open any scanner on this page, point it at the rig, and compare what it reports against the rig's published ground truth. Every result we publish carries the date it was run.

Scan your site with the tool that passed the test.

Free behavioral scan from the EU and the US: what fires before consent, what leaks after Reject, and what is blocked more than the law requires.