Research

ConsentStack Research

Can You Trust a Free Cookie Scanner?

We ran 11 free cookie scanners against a test site built to leak, then against our own site, twice each, and logged where every one scans from. And we turned our own scanner on all 12 vendors' websites.

By Ben Churchill · Published September 2026 · Behavioral research, not legal advice · We compete with every vendor named on this page

11 of 12

CMP vendors' own websites fired something before consent in our EU test

the 12th runs nothing that needs consent

3 of 11

scanners gave a different answer when run twice within the hour

one flipped its whole verdict in 16 seconds

0 of 11

caught the tracker that kept firing after Reject on our public test site

only 1 of 11 clicked the banner at all

0 of 11

disclose where in the world they scan from

so we measured it ourselves

Every consent vendor offers a free scanner, ours included. Paste a URL, get a verdict, usually next to a signup button. This study asks one question about those verdicts: are they measurements you can act on, or marketing with a number attached? On September 1, 2026 we put 11 of them through four tests and wrote down everything, with a scan id or screenshot behind every claim.

One thing before any table: we sell a consent management platform, which means we compete with every vendor named below and we have an interest in the conclusion. That is exactly why every row here is a dated observation you can re-run yourself, why our own site's results are printed alongside everyone else's, and why the one mistake our own instrument made during this study is documented on this page rather than quietly fixed.

What we tested, in one page

Four experiments, all run on the same day. First, every scanner against a public test site we built with planted violations, to see who catches what. Second, we collected what the vendors' own scanners say about the vendors' own websites. Third, we pointed all 11 tools at consentstack.io, a site we can verify is clean, and read what they flagged; we also ran our own two-region scanner across all 12 vendors' sites. Fourth, we ran every tool a second time within the hour to test repeatability, and separately fed each one a tagged URL on a logging endpoint we control to measure where it scans from and whether it executes JavaScript.

The test they failed

We built a public test site that breaks consent law on purpose: Google Analytics fires before any consent choice, and a TikTok pixel deliberately keeps firing after the visitor clicks Reject. Catching those two behaviors is the entire job of a compliance scanner. 4 of 11 caught the pre-consent fire. 1 of 11 clicked the banner at all. 0 of 11 caught the tracker that kept firing after Reject. That last miss is the costly one: in our census of 229 live sites, nearly half of the banner sites where Reject could be clicked kept a tracker firing afterward. A scanner that never clicks Reject is blind to the most common real-world violation.

ToolCaught the pre-consent fireCaught the post-reject leakTested more than one region
Cookiebot Website Cookie CheckerFailFailFail
CookieYes Cookie CheckerFailFailFail
Termly Cookie ScannerFailFailFail
CookieScript Cookie ScannerFailFailFail
Cookie Scanner (cookie-scanner.com)PartialFailFail
CookieServe Cookie CheckerFailFailFail
Piwik PRO Cookie ScannerPartialFailFail
Usercentrics Cookie CheckerPassFailFail
consentmanager Cookie ScannerPassFailFail
CookieHub Cookie CheckerPassFailFail
UniConsent Cookie CheckerPassFailFail

Graded from each tool's own output, September 1, 2026. Osano is not in this table because its email-gated report never arrived. Our own scanner ran against the same rig and is graded on the same seven tests, alongside the grading rules and per-tool screenshots, in the full results matrix.

What their scanners say about their own websites

The rig, at least, is our creation. This next table needs no instrument of ours at all: it is each vendor's own tool, pointed at the vendor's own site, in the vendor's own words.

Their toolTheir siteTheir verdict
consentmanager Cookie Crawlerconsentmanager.net“HIGH RISK ... not GDPR-compliant” against its own site (32 cookies, 1 flagged as problematic before consent)
Usercentrics checkerits own cookie-checker pageHigh risk, 132 trackers found, failing its own prior-consent requirement
Piwik PRO scannerpiwik.pro“Consent Manager: Undefined” on a page running a consent manager, with its own analytics cookies set before consent
UniConsent checkeruniconsent.comRejected its own homepage as an invalid URL
cookie-scanner.comits own homepageFlagged its own (bannerless) homepage red
CookieServecookieserve.com0 cookies found. Our scan of the same domain recorded 17 trackers
CookieHub checkercookiehub.comPassed itself. The one clean self-scan in the set

Collected September 1, 2026 with screenshots on file. The remaining vendors either offer no self-scannable tool or, in Cookiebot's case, no self-scan appeared in our capture set, so no claim is made about them here.

Then we pointed all 11 at our own site

Fairness cuts both ways, so we ran every tool against consentstack.io and published what came back. The short version: no tool, from any location, found a third-party tracker firing before consent on our site. Every flag raised was one of our consent system's own first-party cookies, a display preference, or a parser artifact. The largest number on the table, Termly's 49 cookies, is not a flag at all: Termly's scanner is an inventory that lists and categorizes what it finds without judging any of it.

ToolWhat it reportedWhat the flagged items are
CookiebotHigh risk. 4 trackers, 3 unclassifiedAll flagged rows are our consent system's own first-party cookies and a theme preference
UsercentricsHigh risk. 6 trackers, 3 unclassifiedSame rows, same engine as Cookiebot, which counted 4 in the same hour
CookieHub4 of 4 cookies set before visitor consentOne of the four “cookies” is setItem, the name of a JavaScript method, not a cookie
UniConsent4 cookies set without consentFlags include our storage-availability test key and a preference cookie; separately credits 3 cookies as CMP-managed
Termly49 cookies: 5 advertising, 17 analyticsNot flags: Termly's scanner is an inventory. It lists the cookies it finds and categorizes them, and made no compliance claim about any of the 49
CookieYes2 cookies, both “other”A theme preference and our visitor-count identifier
CookieServe2 cookies, both “other”Same two rows
CookieScript0 cookies across 10 pagesFound nothing at all on a site that demonstrably sets cookies
Piwik PROConsent Manager: Undefined. 0 cookies, but 83 “requests out of EU”The flagged requests are our own fonts and stylesheets loading from our own domain
cookie-scanner.com“No banner found” and “Banner clicked: Yes”Both claims in the same report, above its own screenshot showing our banner
OsanoNo resultReport is email-gated with a 1 to 2 day promise. Nothing arrived

Since several tools flagged them, here is exactly what our pre-consent first-party cookies do. The consent system's own state (the cookies that remember whether and how you consented, plus a storage-availability test key) must exist before consent, the same way every consent tool's does, or the choice could not be remembered. The theme cookie stores a light-or-dark display preference and contains no identifier. And consentstack_anon_id is a first-party pseudonymous identifier we use to count unique visitors for plan billing; it is hashed server-side and never sent to any third party. All three are disclosed in our privacy policy, and none of them is a third-party tracker.

Our scanner on the 12 vendors' own sites

The scanning went both directions: we ran our two-region scanner across the websites of all 12 consent vendors. 11 of the 12 fired something before consent in the EU test. The twelfth, cookie-scanner.com, passes trivially: its homepage runs nothing that needs consent. Findings are reported per phase, the way the law reads, rather than as a single score.

Vendor siteDetected CMPFired before consent (EU)Tracking continued after the choice
cookiebot.comscan ec0a34e9CookiebotYesNoBlocks 64 items in the US that US opt-out law lets run
usercentrics.comscan f19a6154UsercentricsYesNoBlocks 63 items in the US
osano.comscan 834e0adfOsanoYesNoBlocks 14 items in the US
cookieyes.comscan 7d156db2CookieYesYesYes (US)
cookieserve.comscan f9dfd950CookieYesYesYes (EU + US)
termly.ioscan 2f4d4999TermlyYesYes (EU + US)
piwik.proscan e3d1751eCookie InformationYesYes (EU + US)Runs a competitor's consent tool on its own site
cookiehub.comscan c00dacfbCookieHubYesYes (US)Blocks 18 items in the US
cookie-script.comscan 753ac77dCookieScriptYesYes (EU + US)
uniconsent.comscan 66342774UniConsentYesYes (EU + US)The banner offers no reject option in either region
consentmanager.netscan 60aa48ebconsentmanagerYesPartial scanThe site limited our crawl, so we withhold the full verdict. One pre-consent finding was recorded before the limit
cookie-scanner.comscan cf79cd96None detectedNothing to testNoThe homepage runs nothing that needs consent, so there was nothing to test

All scans September 1, 2026, each traceable by the scan id shown. "Fired before consent" means at least one request or cookie that needs consent was recorded before the banner was answered in the EU test. "Tracking continued after the choice" means at least one tracker or tracking cookie was still active after the visitor's consent decision in the region shown. consentmanager.net limited our crawl, so its full verdict is withheld rather than guessed. The "blocks N items in the US" notes are the opposite failure mode, stricter than US law requires; we report them but do not count them as violations, and the same rule is applied to every site our scanner tests.

Two rows deserve a sentence each. UniConsent's own banner offered no reject option in either region, on the website of a company whose product is consent. And piwik.pro runs Cookie Information, a competitor's consent tool, on its own site. We note both without speculating about why.

This table is 12 sites on one day. How each consent tool behaves across its wider installed base is a separate question, answered at scale in Cookie Compliance by Consent Tool.

Run it twice

A measurement you cannot repeat is an anecdote. So we ran every tool against consentstack.io a second time within the same hour, changing nothing. Three of the eleven gave a different answer. One of them, consentmanager's crawler, produced a high-risk verdict and a passing verdict sixteen seconds apart, and the run that found 48 cookies passed while the run that found 6 failed.

ToolFirst runSecond runSame answer?
consentmanagerHigh risk, 6 cookiesPass, 48 cookies (16 seconds later)Changed
CookiebotHigh risk, 4 trackersHigh risk, 6 trackersChanged
Termly49 cookies46 cookies, 4 of 6 categories changedChanged
Piwik PROReport generated 21:56Identical report, identical 21:56 timestampServed a cache
CookieYes2 cookies2 cookiesSame
CookieServe2 cookies2 cookiesSame
CookieScript0 cookies0 cookiesSame
CookieHub4 set early, including setItem4 set early, including setItemSame
UsercentricsHigh risk, 6 trackersHigh risk, 6 trackersSame
UniConsent4 flagged of 74 flagged of 7Same
cookie-scanner.com“No banner” + “banner clicked”Same contradictionSame

One caution the other way: consistency is not correctness. CookieScript was perfectly repeatable at zero cookies on a site that sets cookies. CookieHub reproducibly reported setItem, the name of a JavaScript method, as a cookie. cookie-scanner.com reproducibly printed "No banner found" and "Banner clicked: Yes" in the same report. Stable and right are separate tests, and a tool needs to pass both.

Two runs is a floor, not a distribution, so we say "in our two runs" and no more. Piwik PRO's rescan returned a byte-identical report with an identical generation timestamp, so its repeatability is untested rather than proven.

Where does a scanner scan from? None of them say

Scan location is not a detail. EU law is opt-in and most US law is opt-out, so a correctly configured site behaves differently for the two visitors: it must hold everything until consent in the EU, and it may lawfully run analytics until the visitor opts out in most of the US. A verdict from an undisclosed location is therefore uninterpretable, and none of the 11 tools disclose where they scan from.

So we measured it. We stood up a logging endpoint on a domain we control, gave each tool a tagged URL, and recorded the origin of every request. Four tools could be tagged cleanly:

ToolScans fromNetworkExecutes JavaScript
CookieYesDublin, IrelandAWSYes
CookieScriptAmsterdam, NetherlandsDigitalOceanYes
cookie-scanner.comBerlin, GermanyIONOSYes
CookieHubDublin, IrelandAWSYes

Credit where due: the four we could tag do scan from Europe, even if they never say so. The rest resisted measurement in instructive ways. Cookiebot and Usercentrics appear to normalize the URL and strip our tag before crawling, so URL tagging cannot attribute them. And consentmanager needed no probe at all: its own report prints a map of crawl origins, showing Canada and the United States. A crawler that grades sites against EU law, operating from North America, by its own disclosure.

For contrast, our scanner's vantage is part of the result: every scan runs once from Frankfurt, Germany and once from a California IP address, and the two regions get separate verdicts.

How to tell an instrument from a marketing asset

Every free scanner report we collected, including the ones that contradicted themselves, ended at the same place: that vendor's signup button. We will not guess at anyone's motives. We will give you the six questions this study asked, so you can grade any scanner yourself, ours included.

  1. Does it agree with itself? Run it twice. Three of eleven tools here could not pass this.
  2. Does it separate regions? EU and US law demand different behavior from the same site. One verdict for both is not a verdict about either.
  3. Does it click the banner, including Reject? One of eleven clicked at all; none caught the planted post-reject leak.
  4. Does it say where it scans from? Zero of eleven do, and location decides which law applies.
  5. Does it show its work? Per-phase findings you can verify beat a single score you must take on faith.
  6. Does it admit mistakes? Every instrument has failure modes. The question is whether the vendor documents them or hides them.

And here are our own answers, stated so you can check them rather than trust them:

Does it agree with itself?

Repeated scans of the same site return the same verdict. Our determinism rebuild derives every verdict from a recorded event log, and each result carries a scan id and date you can quote back to us.

Does it separate regions?

Every scan tests the site twice, as an EU visitor and as a US visitor, and publishes two verdicts, because the two laws demand different behavior from the same site.

Does it interact with the banner?

The scanner finds the banner, clicks Accept, clicks Reject, and records what fires after each. Reject behavior is where most real violations live.

Does it say where it scans from?

Yes: an EU vantage in Frankfurt, Germany and a US vantage with a California IP address. Both are printed here, not hidden.

Does it show its work?

Findings are reported per phase (before consent, after Accept, after Reject) rather than as a single score, and this study names the scan id behind every table row.

Does it admit mistakes?

During this study our own scanner misread four vendor sites as having no banner because it lacked their consent tools' fingerprints. We caught it with a manual browser check, shipped the fingerprints the same day, re-scanned, and published the corrected numbers plus this note.

How we tested

All runs happened on September 1, 2026. The 11 tools are the free, publicly accessible scanners of Cookiebot, CookieYes, CookieServe, CookieScript, cookie-scanner.com, CookieHub, consentmanager, Usercentrics, Piwik PRO, UniConsent, and Termly. Osano's scanner is email-gated and its report never arrived, so it appears only as a no-result. Each tool was run by a human in a browser, the way a site owner would use it, and every report was captured as a screenshot at the time of the run.

The rig test and its planted violations are documented in full, with per-tool screenshots, in the scanner comparison. The 12 vendor-site scans ran on our production scanner, one scan id per row above; the scanner loads each site from Frankfurt and from a California IP, clicks Accept and Reject, and records findings per phase. The repeatability pass re-ran every tool against consentstack.io within the same hour. The vantage measurement served each tool a tagged URL on a logging endpoint we control and recorded the country, network, and JavaScript execution of every request; untagged requests from unrelated crawlers were discarded, and tools that strip URL parameters are reported as unmeasurable rather than guessed at. Every observation table on this page is also available as a CSV download; the rig-test matrix has its own.

One correction from during the study, published rather than buried: our scanner initially reported "no banner found" on four of the twelve vendor sites. A manual browser check showed two of them displaying real banners, and the other two loading their consent tools but suppressing the banner for non-EU visitors. The cause was on our side: our detector lacked fingerprint signatures for those four vendors' consent tools. We shipped the signatures the same day, re-scanned all four, and every number on this page comes from the corrected scans.

Grade our scanner with the same six checks

Run it against your site, or against ours. Two regions, the banner actually clicked, findings per phase, vantage disclosed, and a scan id on the result. No signup, no email.

Questions and answers

Limitations

  • We are a competitor. Every vendor named here competes with us. That is why each claim carries a date, a scan id, or a screenshot, and why the checklist is designed to be run against us too.
  • One day, two runs. This is a snapshot from a single day, and repeatability was tested with two runs per tool, which is a floor. Any vendor may fix any of this tomorrow, and we would welcome that.
  • Free tiers only. We tested the public free scanners, not the paid platforms behind them. A vendor's paid product may behave differently from its free lead-generation tool; this study makes no claim about the paid products.
  • One partial verdict withheld. consentmanager.net limited our crawl, so we report only what was recorded before the limit and withhold its full verdict.
  • Our instrument has failure modes too. The fingerprint gap described in the methodology is proof. We found it, fixed it, and disclosed it, which is the standard this page argues every scanner should be held to.

This is a behavioral research study, not legal advice, and not a statement that any named company breaks any law. It reports what the named tools and websites did on September 1, 2026 under the described tests. For your own obligations, talk to qualified counsel.

See where your site leaks consent

Run a free compliance scan against EU and US rules. No signup required.

2,978 sites scanned and counting

Just want the cookie list? Run the free cookie checker to see every cookie and tracker a site sets, and which ones fire before consent.

100+ happy customers

AN
ML
LP
DM
JT

See what a real scan looks like

Two regions, the banner actually clicked, findings per phase, vantage disclosed. Run it on your site in a minute or two, with no signup.

Get started free