Cookie scanners all promise the same outcome: point one at your site and learn whether you have a compliance problem. They do not all measure the same thing. Some request your homepage once and list the cookies they saw. Some run a real browser. Very few click the consent banner they find, and almost none compare what happens after a visitor rejects with what happened before.
Reviews of these tools repeat the vendors' own feature claims, so we did something different: we published a small website whose consent behavior is deliberately and precisely broken, and we run each scanner against it. The site fires one tracker before any consent choice, leaks another tracker only after the visitor rejects, gates a third correctly behind acceptance, and hides a fourth behind scrolling. It also plants items that are not trackers at all, to catch tools that cry wolf.
Disclosure: ConsentStack builds one of the scanners on this page. That is exactly why the methodology is public. The test rig at scannertest.consentstack.io documents its own ground truth, every result below is stamped with its run date, and you can rerun any scanner here against the rig and check our work.
The test: a site that is wrong on purpose
The rig uses the vendors' real tracking scripts with dummy IDs, so every network request a real deployment would make actually happens, but nothing is collected. The rig runs no consent management platform, not ConsentStack and not anyone else's: its banner is a few lines of plain JavaScript written for the test, because a real CMP exists to prevent exactly the violations the rig plants, and running one would bias the test toward whoever built it. Its complete behavior:
Loads and fires on every page load, before any consent choice.
A correct scan reports: A pre-consent tracker fire.
Fires only after the visitor clicks Reject, and again on every later load while the stored choice is rejected.
A correct scan reports: A tracker firing after consent was rejected.
Loads only after the visitor clicks Accept. This is correct gating.
A correct scan reports: A consent-gated tracker. A scanner that never accepts consent will wrongly report it absent.
Loads only after the visitor scrolls, regardless of consent.
A correct scan reports: An engagement-gated tracker fire.
A functional date library on a third-party host. No tracking, no cookies.
A correct scan reports: Not a tracker. Flagging it is a false positive.
First-party session and consent-choice cookies.
A correct scan reports: Strictly necessary. Requiring consent for them is over-strict.
A perfect scanner catches the first two rows as violations, sees the third and fourth by exercising the page like a person would, and flags none of the last two rows. Scanning from more than one region earns a further distinction: the same behavior is judged under opt-in law for EU visitors and opt-out law for most US visitors, so a single verdict cannot be right for both. The full results are also available as a CSV download.
Snapshot
Twelve scanners besides ours were run against the rig on September 1, 2026. Eleven returned results the same day; Osano delivers reports only by email within 1 to 2 days, and nothing had arrived when this page was compiled. ConsentStack against the field of eleven, every number traceable to the matrix below:
Two reports went beyond missing things and contradicted the rig's documented behavior: one scanner reported six storage items that do not exist on the rig, and another returned a green pass on post-opt-out tracking against a site built to keep tracking after rejection. Both are covered in the scanner-by-scanner sections.
Results
Each column is one scanner, run against the rig on the date shown. Every cell reports only what that scanner's own output showed; nothing in this table comes from a vendor's marketing pages. The per-scanner sections further down carry the evidence behind each mark, including screenshots of every report.
| Test | ConsentStack | Cookiebot Website Cookie Checker | CookieYes Cookie Checker | Termly Cookie Scanner | CookieScript Cookie Scanner | Cookie Scanner (cookie-scanner.com) | CookieServe Cookie Checker | Piwik PRO Cookie Scanner | Osano Compliance Check | Usercentrics Cookie Checker | consentmanager Cookie Scanner | CookieHub Cookie Checker | UniConsent Cookie Checker |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Found the trackers | Yes | No | Partial | Partial | No | Partial | Partial | Partial | No result | No | Partial | Partial | Partial |
| Caught the pre-consent fire | Yes | No | No | No | No | Partial | No | Partial | No result | Yes | Yes | Yes | Yes |
| Caught the post-reject leak | Yes | No | No | No | No | No | No | No | No result | No | No | No | No |
| Exercised the accept path | Yes | No | No | No | No | No | No | No | No result | No | No | No | No |
| Caught the scroll-gated tracker | Yes | No | Partial | No | No | No | No | No | No result | No | No | No | No |
| No false positives | Yes | Partial | Partial | Partial | No | Partial | Partial | No | No result | Partial | Partial | Partial | Partial |
| Scanned from more than one region | Yes | No | No | No | No | No | No | No | No result | No | No | No | No |
| Run date | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 | 2026-09-01 |
How they rank
Ranked by how many of the seven tests each scanner passed, with one further rule applied to every tool equally: a report containing statements the rig's documented behavior contradicts ranks below a report that merely found less, because a wrong answer costs a site owner more than a missing one.
1. Caught the full consent lifecycle
ConsentStack Compliance Scanner
Passed all seven tests: found the trackers, caught the pre-consent fire and the post-reject leak, exercised the accept path, caught the scroll-gated tag, flagged nothing benign, and returned different verdicts under EU and US law. We build this tool, which is why the rig and this methodology are public: this is the easiest row on the page to check.
2. Caught the pre-consent fire, nothing after it
UniConsent Cookie Checker · consentmanager Cookie Scanner · CookieHub Cookie Checker · Usercentrics Cookie Checker
Each of these correctly failed the rig for tracking before consent, the one planted violation visible from a cold page load. None of them rejects or accepts consent, so the post-reject leak and the accept-gated pixel are invisible to all four.
3. Inventory only: no violation caught
CookieYes Cookie Checker · Termly Cookie Scanner · CookieServe Cookie Checker · Cookie Scanner (cookie-scanner.com) · Piwik PRO Cookie Scanner
These returned lists of cookies or requests with no compliance verdict attached, so a site with three planted violations produced reports containing zero violations. cookie-scanner.com and Piwik PRO both have machinery pointing the right way (a banner click, before-and-after tabs) that produced no comparison on the rig.
4. Results contradicted by ground truth
Cookiebot Website Cookie Checker · CookieScript Cookie Scanner
Cookiebot's report returned a green pass stating the rig stops tracking users after they opt out, against a site whose planted tracker fires only after rejection (its check tests a GPC signal, not the banner). CookieScript reported six storage items that do not exist on the rig. Both reports contain statements the rig's documented behavior contradicts.
5. No result
Osano Compliance Check
Produced nothing gradeable: results are promised by email within 1 to 2 days, and no report had arrived when this page was compiled. This section will be updated if it arrives.
The platforms you cannot test at all
Several major consent platforms have no publicly runnable scanner: their scanning exists only inside the product, so a buyer cannot check its accuracy before purchasing, and neither can this page. Verified against each vendor's own site on September 1, 2026. If one of them ships a public tool, it joins the matrix.
- OneTrust: Website scanning is a feature of the paid Cookie Consent product. The public path to a scan is a contact-sales form.
- TrustArc: Cookie scanning ships inside the Cookie Consent Manager product. No public URL-entry tool.
- Didomi: Scanning is part of the Advanced Compliance Monitoring product. No public URL-entry tool.
- iubenda: The site scanner runs inside the product for your own configured site. No public URL-entry tool.
Scanner by scanner
ConsentStack Compliance Scanner
By ConsentStack (that is us; see the disclosure above). Run against the rig on 2026-09-01. Run this scanner
Caught every planted behavior: the pre-consent GA4 fire, the post-reject TikTok leak, the accept-gated Meta pixel, and the scroll-gated LinkedIn tag, with zero false positives on the non-tracker traps. It was also the only result to differ by region on purpose, reporting the same site as violating opt-in rules in the EU while noting the US visit was over-blocked relative to opt-out law. It also identified the rig's hand-rolled banner as a custom CMP and operated it.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Yes | All four trackers identified by product name. |
| Caught the pre-consent fire | Yes | GA4 flagged as a pre-consent violation in the EU scan, and correctly treated as permitted default-grant behavior in the US scan, where opt-out rules apply. |
| Caught the post-reject leak | Yes | TikTok flagged as firing after rejection in both regions. The site verdict came back “leaky”. |
| Exercised the accept path | Yes | Meta pixel observed blocked before consent and firing after acceptance, so the accept path was actually exercised. |
| Caught the scroll-gated tracker | Yes | The scroll-gated LinkedIn Insight tag was caught in both regions. |
| No false positives | Yes | Zero. The jsDelivr library and both first-party cookies were classified as exempt. |
| Scanned from more than one region | Yes | Scanned concurrently from the EU and the US, with different verdicts where the law differs: the US scan flagged the rig's opt-in gating of Meta as stricter than the region requires. |
Cookiebot Website Cookie Checker
By Usercentrics (Cookiebot). Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Cookiebot
Results are gated behind a mandatory email address. What comes back is a CCPA compliance checklist rather than a report on observed behavior: it found no CMP on a site with a visible consent banner, named no trackers, and its opt-out check returned a green pass against a site built to keep tracking after rejection (the check tests a GPC signal, not the banner). The to-do list ends in a signup button for Cookiebot's own CMP.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | No | The report shows a count of 3 detected services and no tracker or cookie inventory, so none of the four planted trackers is named. |
| Caught the pre-consent fire | No | The four checks returned are CCPA checks about CMP presence, a Do Not Sell link, and GPC. Nothing in the report addresses trackers firing before consent. |
| Caught the post-reject leak | No | Returned a green pass reading 'Your website stops tracking users after they opt out' on a site whose planted tracker fires only after Reject. The check is scoped to a GPC opt-out signal rather than the banner's Reject button, so the leak is invisible to it, but the checkmark is still green. |
| Exercised the accept path | No | No consent interaction occurs; the accept-gated Meta pixel appears nowhere in the report. |
| Caught the scroll-gated tracker | No | Three services detected from a cold page load; the scroll-gated LinkedIn tag is not among them. |
| No false positives | Partial | The report contains no tracker or cookie inventory, so the false-positive traps could not be evaluated either way. It did report that no CMP was detected, although the rig shows a visible banner with Accept and Reject buttons. |
| Scanned from more than one region | No | The report frames everything under CCPA and CPRA, with no EU verdict and no second region. |
CookieYes Cookie Checker
By CookieYes. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs CookieYes
An ungated cookie inventory: seven cookies with domains, durations, and database-sourced descriptions, delivered quickly and with no email required. It has no concept of consent state, so the planted pre-consent fire, the post-reject leak, and the accept-gated pixel are invisible to it by design. It did reach the scroll-gated LinkedIn tag, which most tools here missed, but reported its cookies as ordinary rows.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Google Analytics and three LinkedIn cookies appear in the seven-cookie inventory; TikTok and Meta do not. |
| Caught the pre-consent fire | No | The report is a cookie inventory with no consent state: GA is listed as a row, not as a tracker that fired before consent. |
| Caught the post-reject leak | No | The scanner never rejects consent, and no TikTok entry appears. |
| Exercised the accept path | No | The scanner never accepts consent, and no Meta entry appears. |
| Caught the scroll-gated tracker | Partial | LinkedIn's bcookie, li_gc, and lidc cookies were captured, so the scan reached the scroll-gated tag, but they are presented as ordinary rows with no note that they loaded without consent. |
| No false positives | Partial | Nothing benign was flagged, but the report flags nothing at all; the rig's own session cookie is listed as type Other with an empty description rather than recognized as necessary. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
Termly Cookie Scanner
By Termly. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Termly
The highest raw cookie count of any free inventory tool on the rig (12, versus 7 for CookieYes), with category donuts and per-cookie tables behind a signup for the full report. It states the compliance principle at the top of its own results but does not test it: no consent phase exists in the scan, so whether any of those 12 cookies was set before consent, or survived a rejection, is left to the reader.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Twelve cookies are counted across categories including advertising and social, but only the Google Analytics rows are identified by name in the visible tables. No TikTok or Meta entry appears. |
| Caught the pre-consent fire | No | The page prints the rule, 'non-essential trackers should never be set prior to user consent', but the scan does not test whether the rig broke it. |
| Caught the post-reject leak | No | No consent interaction occurs and no TikTok entry appears. |
| Exercised the accept path | No | No consent interaction occurs and no Meta entry appears. |
| Caught the scroll-gated tracker | No | A Social category count of 1 appears with no cookie identified and no consent state attached. |
| No false positives | Partial | Nothing was flagged as a violation because the report issues no verdicts; 5 of the 12 cookies found are Unclassified. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
CookieScript Cookie Scanner
By CookieScript. Run against the rig on 2026-09-01. Run this scanner
Found the least of any tool tested (3 cookies) and reported the most that is not there: six local and session storage keys belonging to WooCommerce and Google reCAPTCHA, neither of which the rig runs, all confidently categorized as Strictly Necessary. We record that as observed output; the cause is not determinable from the report. No consent phase exists in the scan.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | No | Three cookies total, the lowest count of any scanner tested: both GA cookies and the rig's session cookie. No TikTok, Meta, or LinkedIn entry. |
| Caught the pre-consent fire | No | No consent state is reported anywhere. |
| Caught the post-reject leak | No | No consent interaction occurs and no TikTok entry appears. |
| Exercised the accept path | No | No consent interaction occurs and no Meta entry appears. |
| Caught the scroll-gated tracker | No | No LinkedIn entry appears. |
| No false positives | No | The Storages section reports six items that do not exist on the rig: WooCommerce cart keys and a Google reCAPTCHA token, on a static page running neither, all labeled Strictly Necessary. The rig's real first-party session cookie lands in Unclassified. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
Cookie Scanner (cookie-scanner.com)
By cookie-scanner.com. Run against the rig on 2026-09-01. Run this scanner
The only competitor tool that recognized the rig's banner exists and clicked it, correctly labeling an unknown provider rather than declaring no CMP present. Its initiator tracing is the best of any competitor report here: each cookie is attributed to the script and line that set it. But the click leads nowhere: the report never compares before with after, so the consent lifecycle findings the click could have produced are absent.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Found the Google Tag Manager and Google Analytics hosts and the jsDelivr request. TikTok, Meta, and LinkedIn hosts do not appear. |
| Caught the pre-consent fire | Partial | A red card flags 'Tags and 3rd Party requests found' and each cookie is traced to the exact script and line that set it, but the report never states what happened before versus after consent. |
| Caught the post-reject leak | No | The only competitor scanner that detected and clicked the rig's banner (reported as 'Banner clicked: Yes', provider 'unknownbanner'), but the report does not compare states, so the post-reject TikTok leak does not surface. |
| Exercised the accept path | No | No accept path is reported; the Meta pixel is absent. |
| Caught the scroll-gated tracker | No | No LinkedIn entry appears. |
| No false positives | Partial | The functional jsDelivr library is listed under the same red warning card as the tracking hosts, and first-party storage earns an amber flag, with no distinction drawn between a date library and a tracker. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
CookieServe Cookie Checker
By CookieYes (CookieServe). Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs CookieYes
Effectively the CookieYes engine under another name, and the reports match: seven cookies, the same category split, no email required, and no consent lifecycle. It detected that some banner platform exists ('Platform Detected: Others') but did not identify or interact with it.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Seven cookies with the same category composition as CookieYes's report (CookieServe is a CookieYes property). The visible rows identify GA and the rig's session cookie; no TikTok or Meta entry. |
| Caught the pre-consent fire | No | A single homepage load with no consent state. The report states its own scope: 'Cookieserve scans only the homepage of the website.' |
| Caught the post-reject leak | No | No consent interaction occurs and no TikTok entry appears. |
| Exercised the accept path | No | No consent interaction occurs and no Meta entry appears. |
| Caught the scroll-gated tracker | No | No LinkedIn row is visible in the captured report. |
| No false positives | Partial | Nothing benign was flagged, but the report issues no judgments at all; the rig's session cookie lands in Other. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
Piwik PRO Cookie Scanner
By Piwik PRO. Run against the rig on 2026-09-01. Run this scanner
Architecturally the closest competitor to the right shape: it is the only other tool with an explicit before-consent and after-consent structure, and it shows raw request URLs no one else shows. On the rig the structure produced nothing: the consent manager was reported Undefined, the banner was never operated, and the After Consent tab came back empty, so no comparison was actually made.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | The GA cookies are identified and vendor-tagged, and the full GA collect request URL is shown, the most granular network evidence in any competitor report here. TikTok, Meta, and LinkedIn do not appear. |
| Caught the pre-consent fire | Partial | A Before Consent tab correctly lists the GA cookies and the GA beacon request from the pre-consent load, but the report attaches no compliance verdict to them. |
| Caught the post-reject leak | No | There is no reject concept, only before and after consent, and the After Consent tab returned 'No data'. |
| Exercised the accept path | No | The After Consent tab came back 'Cookies not found', so the before-and-after comparison, the tool's own headline feature, produced nothing on the rig. The likely cause is visible in the same report: Consent Manager 'Undefined', meaning the banner was never operated. |
| Caught the scroll-gated tracker | No | No LinkedIn entry appears. |
| No false positives | No | The functional jsDelivr library is listed in 'Requests out of EU' as a flagged item, indistinguishable from the tracking requests around it. |
| Scanned from more than one region | No | Requests are geo-attributed, but the scan itself runs from one place and issues one report. |
Osano Compliance Check
By Osano. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Osano
Osano's Compliance Check returned nothing to grade. Submission ends with a promise of a compliance report by email within 1 to 2 days; no results, cookie lists, or counts are shown in the browser at any point, and no emailed report had arrived when this page was compiled. A report that arrives days later is also not a live read of the site at the moment of scanning. If the emailed report arrives, this section will be updated from it, with its own date.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | No result | No report was produced. The tool accepts a URL and an email address and answers: 'You can expect to receive your compliance report via email within the next 1-2 days.' Nothing was viewable on screen, and no emailed report had arrived when these results were compiled. |
| Caught the pre-consent fire | No result | |
| Caught the post-reject leak | No result | |
| Exercised the accept path | No result | |
| Caught the scroll-gated tracker | No result | |
| No false positives | No result | |
| Scanned from more than one region | No result |
Usercentrics Cookie Checker
By Usercentrics. Run against the rig on 2026-09-01. Run this scanner · ConsentStack vs Usercentrics
The heaviest gating in the test: results are released only after first name, last name, company name, email address, and an answer to a sales-qualifying question about monthly traffic volume. The report that follows does catch the rig's core violation, failing it for collecting without prior consent, which only three other competitor tools managed. Its inventory is weaker than its verdict: zero marketing trackers counted on a rig running three of them, and a boilerplate claim of 10 pages scanned on a one-page site.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | No | Five trackers reported, with Marketing counted as zero on a rig running TikTok, Meta, and LinkedIn. GA is classified as Functional. |
| Caught the pre-consent fire | Yes | Requirement 1 fails the rig with 'You do not collect consent for cookies and trackers other than strictly necessary ones', a true finding about the planted pre-consent GA fire. |
| Caught the post-reject leak | No | No rejection occurs; the post-reject TikTok leak is absent from the report. |
| Exercised the accept path | No | No acceptance occurs; the Meta pixel is absent from the report. |
| Caught the scroll-gated tracker | No | No LinkedIn entry appears in the tracker table. |
| No false positives | Partial | No trap was flagged, but the requirement verdicts are site-level rather than per-item, the rig's session cookie is Unclassified, and the report states 10 pages were scanned on a one-page site. |
| Scanned from more than one region | No | GDPR and ePrivacy framing only; no US verdict and no second region. |
consentmanager Cookie Scanner
By consentmanager. Run against the rig on 2026-09-01. Run this scanner
Gated behind a business email address and delivered as a PDF. Within its single measured state it is the most explicit competitor: it says plainly that cookies and vendors loaded when no consent was given, quantifies them, and adds a data-transfer dimension (vendors sending data outside the EEA, non-EU datacenter owners) that no other tool in the test reports. Everything after the cold load, the reject and accept paths, does not exist in its model.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Seven unique cookies and the vendors behind them are counted, with 3 non-essential and 1 unknown vendor reported as loaded without consent; the planted trackers are not individually named in the report. |
| Caught the pre-consent fire | Yes | The most explicit pre-consent finding of any competitor tested: '2 problematic cookies from 2 vendors when no consent is given', plus counts of vendors loaded without consent, feeding a HIGH RISK verdict. |
| Caught the post-reject leak | No | Everything is measured at the no-consent state; no reject phase exists, so the post-reject TikTok leak is not represented. |
| Exercised the accept path | No | No accept phase exists; the accept-gated Meta pixel is not represented. |
| Caught the scroll-gated tracker | No | No LinkedIn finding appears. |
| No false positives | Partial | LocalStorage is correctly reported as zero and no planted trap is individually flagged, but whether the functional CDN is among the 4 vendors counted as transferring data outside the EEA cannot be determined from the report. |
| Scanned from more than one region | No | One crawl, one verdict. The report maps where requests go, not where the scan ran from. |
CookieHub Cookie Checker
By CookieHub. Run against the rig on 2026-09-01. Run this scanner
A pre-consent check that works and says so: it failed the rig for setting analytical and marketing cookies before consent, and was the only competitor to count marketing cookies on the rig. It is also unusually candid about scope, noting its result is based on a single page. The full cookie tables sit behind an email gate, and nothing in the scan touches the reject or accept paths.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Category counts only in the on-screen report: 3 analytical and 3 marketing cookies, the only competitor report to count marketing cookies on the rig at all. The per-cookie tables are blurred pending an email address. |
| Caught the pre-consent fire | Yes | The verdict names the mechanism: 'your website sets analytical and/or marketing cookies before consent', which is the planted GA fire, and fails the site for it. |
| Caught the post-reject leak | No | The verdict is derived from a pre-consent page load only; nothing addresses what happens after Reject. |
| Exercised the accept path | No | No accept path exists in the scan. |
| Caught the scroll-gated tracker | No | No LinkedIn finding appears on screen. |
| No false positives | Partial | Nothing benign is flagged on screen, but the detailed tables are email-gated, so the traps cannot be fully checked. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
UniConsent Cookie Checker
By UniConsent. Run against the rig on 2026-09-01. Run this scanner
No email required, and the best framing of any competitor report: results split into 'Cookies Set Without Consent' versus 'Cookies Managed by CMP', with the offending count and domain in a single sentence. It was also one of only two competitor tools to acknowledge the rig's CMP exists. Its model still ends at the cold page load: nothing after Reject or Accept is measured, and its cookie classifications contain errors.
| Test | Result | What the scanner's output showed |
|---|---|---|
| Found the trackers | Partial | Four cookies; GA is identified, attributed to Google LLC, and linked to its privacy policy. TikTok, Meta, and LinkedIn are absent. |
| Caught the pre-consent fire | Yes | The clearest presentation tested: a section titled 'Cookies Set Without Consent (2)' names the offending domain (google-analytics.com) and both GA cookies, each individually flagged. |
| Caught the post-reject leak | No | 'Without consent' means the cold page load; no reject phase exists, so the post-reject TikTok leak is not represented. |
| Exercised the accept path | No | No accept phase exists; the Meta pixel is not represented. |
| Caught the scroll-gated tracker | No | No LinkedIn finding appears. |
| No false positives | Partial | The planted traps are not flagged and the rig's own cookies are correctly attributed to the CMP, but a Cloudflare bot-management cookie is categorized as Advertisement and attributed to Google LLC, and the report counts zero Necessary cookies, filing the rig's session cookie under Other. |
| Scanned from more than one region | No | One scan, one location, no regional verdict. |
Frequently asked questions
What is the best cookie compliance scanner?
The honest answer depends on what you need checked. If you only want a list of cookies present on a page, most free checkers produce one. If you need to know whether your site honors a rejection, fires trackers before consent, or blocks more than the law requires, you need a scanner that interacts with the consent banner and observes behavior over the full lifecycle. In our published rig test of twelve scanners, the ConsentStack Compliance Scanner was the only tool that caught the pre-consent fire, the post-reject leak, the accept-gated tracker, and the engagement-gated tracker, with zero false positives. We build that scanner, so do not take our word for it: the test rig is public and you can run every tool on this page against it yourself.
What should a cookie scanner actually test?
Five things. Whether trackers fire before any consent choice. Whether trackers still fire after a visitor rejects. Whether consent-gated trackers correctly appear after acceptance, which a scanner only sees if it accepts and keeps watching. Whether necessary first-party cookies and functional third-party resources get wrongly flagged, which causes over-blocking. And whether behavior differs by region, because opt-in law in the EU and opt-out law in most US states make the same site correct in one place and non-compliant in the other.
Are free cookie checkers accurate?
For listing cookies on a cold page load, generally yes. The gap is everything that happens after the load: in our test, none of the eleven competitor scanners that returned results clicked Reject, so none could see whether the banner actually controls anything. A site can pass a cookie inventory check while ignoring every rejection its visitors make.
Why does scanning from two locations matter?
Because the law your visitor is under changes what compliant behavior looks like. The EU requires opt-in, so a tracker firing before consent is a violation there. Most US states require opt-out, so the same pre-consent fire is permitted, and a site that forces EU-style opt-in on US visitors is stricter than the law requires, which costs measurement without buying compliance. A single-location scan can only ever see one of those realities.
Can I verify these results myself?
Yes. The test rig at scannertest.consentstack.io is public and documents its exact behavior on the page. Open any scanner on this page, point it at the rig, and compare what it reports against the rig's published ground truth. Every result we publish carries the date it was run.
Scan your site with the tool that passed the test.
Free behavioral scan from the EU and the US: what fires before consent, what leaks after Reject, and what is blocked more than the law requires.