ConsentStack Research
Can You Trust a Free Cookie Scanner?
We ran 11 free cookie scanners against a test site built to leak, then against our own site, twice each, and logged where every one scans from. And we turned our own scanner on all 12 vendors' websites.
By Ben Churchill · Published September 2026 · Behavioral research, not legal advice · We compete with every vendor named on this page
CMP vendors' own websites fired something before consent in our EU test
the 12th runs nothing that needs consent
scanners gave a different answer when run twice within the hour
one flipped its whole verdict in 16 seconds
caught the tracker that kept firing after Reject on our public test site
only 1 of 11 clicked the banner at all
disclose where in the world they scan from
so we measured it ourselves
Every consent vendor offers a free scanner, ours included. Paste a URL, get a verdict, usually next to a signup button. This study asks one question about those verdicts: are they measurements you can act on, or marketing with a number attached? On September 1, 2026 we put 11 of them through four tests and wrote down everything, with a scan id or screenshot behind every claim.
One thing before any table: we sell a consent management platform, which means we compete with every vendor named below and we have an interest in the conclusion. That is exactly why every row here is a dated observation you can re-run yourself, why our own site's results are printed alongside everyone else's, and why the one mistake our own instrument made during this study is documented on this page rather than quietly fixed.
On this page
What we tested, in one page
Four experiments, all run on the same day. First, every scanner against a public test site we built with planted violations, to see who catches what. Second, we collected what the vendors' own scanners say about the vendors' own websites. Third, we pointed all 11 tools at consentstack.io, a site we can verify is clean, and read what they flagged; we also ran our own two-region scanner across all 12 vendors' sites. Fourth, we ran every tool a second time within the hour to test repeatability, and separately fed each one a tagged URL on a logging endpoint we control to measure where it scans from and whether it executes JavaScript.
The test they failed
We built a public test site that breaks consent law on purpose: Google Analytics fires before any consent choice, and a TikTok pixel deliberately keeps firing after the visitor clicks Reject. Catching those two behaviors is the entire job of a compliance scanner. 4 of 11 caught the pre-consent fire. 1 of 11 clicked the banner at all. 0 of 11 caught the tracker that kept firing after Reject. That last miss is the costly one: in our census of 229 live sites, nearly half of the banner sites where Reject could be clicked kept a tracker firing afterward. A scanner that never clicks Reject is blind to the most common real-world violation.
| Tool | Caught the pre-consent fire | Caught the post-reject leak | Tested more than one region |
|---|---|---|---|
| Cookiebot Website Cookie Checker | Fail | Fail | Fail |
| CookieYes Cookie Checker | Fail | Fail | Fail |
| Termly Cookie Scanner | Fail | Fail | Fail |
| CookieScript Cookie Scanner | Fail | Fail | Fail |
| Cookie Scanner (cookie-scanner.com) | Partial | Fail | Fail |
| CookieServe Cookie Checker | Fail | Fail | Fail |
| Piwik PRO Cookie Scanner | Partial | Fail | Fail |
| Usercentrics Cookie Checker | Pass | Fail | Fail |
| consentmanager Cookie Scanner | Pass | Fail | Fail |
| CookieHub Cookie Checker | Pass | Fail | Fail |
| UniConsent Cookie Checker | Pass | Fail | Fail |
Graded from each tool's own output, September 1, 2026. Osano is not in this table because its email-gated report never arrived. Our own scanner ran against the same rig and is graded on the same seven tests, alongside the grading rules and per-tool screenshots, in the full results matrix.
What their scanners say about their own websites
The rig, at least, is our creation. This next table needs no instrument of ours at all: it is each vendor's own tool, pointed at the vendor's own site, in the vendor's own words.
| Their tool | Their site | Their verdict |
|---|---|---|
| consentmanager Cookie Crawler | consentmanager.net | “HIGH RISK ... not GDPR-compliant” against its own site (32 cookies, 1 flagged as problematic before consent) |
| Usercentrics checker | its own cookie-checker page | High risk, 132 trackers found, failing its own prior-consent requirement |
| Piwik PRO scanner | piwik.pro | “Consent Manager: Undefined” on a page running a consent manager, with its own analytics cookies set before consent |
| UniConsent checker | uniconsent.com | Rejected its own homepage as an invalid URL |
| cookie-scanner.com | its own homepage | Flagged its own (bannerless) homepage red |
| CookieServe | cookieserve.com | 0 cookies found. Our scan of the same domain recorded 17 trackers |
| CookieHub checker | cookiehub.com | Passed itself. The one clean self-scan in the set |
Collected September 1, 2026 with screenshots on file. The remaining vendors either offer no self-scannable tool or, in Cookiebot's case, no self-scan appeared in our capture set, so no claim is made about them here.
Then we pointed all 11 at our own site
Fairness cuts both ways, so we ran every tool against consentstack.io and published what came back. The short version: no tool, from any location, found a third-party tracker firing before consent on our site. Every flag raised was one of our consent system's own first-party cookies, a display preference, or a parser artifact. The largest number on the table, Termly's 49 cookies, is not a flag at all: Termly's scanner is an inventory that lists and categorizes what it finds without judging any of it.
| Tool | What it reported | What the flagged items are |
|---|---|---|
| Cookiebot | High risk. 4 trackers, 3 unclassified | All flagged rows are our consent system's own first-party cookies and a theme preference |
| Usercentrics | High risk. 6 trackers, 3 unclassified | Same rows, same engine as Cookiebot, which counted 4 in the same hour |
| CookieHub | 4 of 4 cookies set before visitor consent | One of the four “cookies” is setItem, the name of a JavaScript method, not a cookie |
| UniConsent | 4 cookies set without consent | Flags include our storage-availability test key and a preference cookie; separately credits 3 cookies as CMP-managed |
| Termly | 49 cookies: 5 advertising, 17 analytics | Not flags: Termly's scanner is an inventory. It lists the cookies it finds and categorizes them, and made no compliance claim about any of the 49 |
| CookieYes | 2 cookies, both “other” | A theme preference and our visitor-count identifier |
| CookieServe | 2 cookies, both “other” | Same two rows |
| CookieScript | 0 cookies across 10 pages | Found nothing at all on a site that demonstrably sets cookies |
| Piwik PRO | Consent Manager: Undefined. 0 cookies, but 83 “requests out of EU” | The flagged requests are our own fonts and stylesheets loading from our own domain |
| cookie-scanner.com | “No banner found” and “Banner clicked: Yes” | Both claims in the same report, above its own screenshot showing our banner |
| Osano | No result | Report is email-gated with a 1 to 2 day promise. Nothing arrived |
Since several tools flagged them, here is exactly what our pre-consent first-party cookies do. The consent system's own state (the cookies that remember whether and how you consented, plus a storage-availability test key) must exist before consent, the same way every consent tool's does, or the choice could not be remembered. The theme cookie stores a light-or-dark display preference and contains no identifier. And consentstack_anon_id is a first-party pseudonymous identifier we use to count unique visitors for plan billing; it is hashed server-side and never sent to any third party. All three are disclosed in our privacy policy, and none of them is a third-party tracker.
Our scanner on the 12 vendors' own sites
The scanning went both directions: we ran our two-region scanner across the websites of all 12 consent vendors. 11 of the 12 fired something before consent in the EU test. The twelfth, cookie-scanner.com, passes trivially: its homepage runs nothing that needs consent. Findings are reported per phase, the way the law reads, rather than as a single score.
| Vendor site | Detected CMP | Fired before consent (EU) | Tracking continued after the choice |
|---|---|---|---|
| cookiebot.comscan ec0a34e9 | Cookiebot | Yes | NoBlocks 64 items in the US that US opt-out law lets run |
| usercentrics.comscan f19a6154 | Usercentrics | Yes | NoBlocks 63 items in the US |
| osano.comscan 834e0adf | Osano | Yes | NoBlocks 14 items in the US |
| cookieyes.comscan 7d156db2 | CookieYes | Yes | Yes (US) |
| cookieserve.comscan f9dfd950 | CookieYes | Yes | Yes (EU + US) |
| termly.ioscan 2f4d4999 | Termly | Yes | Yes (EU + US) |
| piwik.proscan e3d1751e | Cookie Information | Yes | Yes (EU + US)Runs a competitor's consent tool on its own site |
| cookiehub.comscan c00dacfb | CookieHub | Yes | Yes (US)Blocks 18 items in the US |
| cookie-script.comscan 753ac77d | CookieScript | Yes | Yes (EU + US) |
| uniconsent.comscan 66342774 | UniConsent | Yes | Yes (EU + US)The banner offers no reject option in either region |
| consentmanager.netscan 60aa48eb | consentmanager | Yes | Partial scanThe site limited our crawl, so we withhold the full verdict. One pre-consent finding was recorded before the limit |
| cookie-scanner.comscan cf79cd96 | None detected | Nothing to test | NoThe homepage runs nothing that needs consent, so there was nothing to test |
All scans September 1, 2026, each traceable by the scan id shown. "Fired before consent" means at least one request or cookie that needs consent was recorded before the banner was answered in the EU test. "Tracking continued after the choice" means at least one tracker or tracking cookie was still active after the visitor's consent decision in the region shown. consentmanager.net limited our crawl, so its full verdict is withheld rather than guessed. The "blocks N items in the US" notes are the opposite failure mode, stricter than US law requires; we report them but do not count them as violations, and the same rule is applied to every site our scanner tests.
Two rows deserve a sentence each. UniConsent's own banner offered no reject option in either region, on the website of a company whose product is consent. And piwik.pro runs Cookie Information, a competitor's consent tool, on its own site. We note both without speculating about why.
This table is 12 sites on one day. How each consent tool behaves across its wider installed base is a separate question, answered at scale in Cookie Compliance by Consent Tool.
Run it twice
A measurement you cannot repeat is an anecdote. So we ran every tool against consentstack.io a second time within the same hour, changing nothing. Three of the eleven gave a different answer. One of them, consentmanager's crawler, produced a high-risk verdict and a passing verdict sixteen seconds apart, and the run that found 48 cookies passed while the run that found 6 failed.
| Tool | First run | Second run | Same answer? |
|---|---|---|---|
| consentmanager | High risk, 6 cookies | Pass, 48 cookies (16 seconds later) | Changed |
| Cookiebot | High risk, 4 trackers | High risk, 6 trackers | Changed |
| Termly | 49 cookies | 46 cookies, 4 of 6 categories changed | Changed |
| Piwik PRO | Report generated 21:56 | Identical report, identical 21:56 timestamp | Served a cache |
| CookieYes | 2 cookies | 2 cookies | Same |
| CookieServe | 2 cookies | 2 cookies | Same |
| CookieScript | 0 cookies | 0 cookies | Same |
| CookieHub | 4 set early, including setItem | 4 set early, including setItem | Same |
| Usercentrics | High risk, 6 trackers | High risk, 6 trackers | Same |
| UniConsent | 4 flagged of 7 | 4 flagged of 7 | Same |
| cookie-scanner.com | “No banner” + “banner clicked” | Same contradiction | Same |
One caution the other way: consistency is not correctness. CookieScript was perfectly repeatable at zero cookies on a site that sets cookies. CookieHub reproducibly reported setItem, the name of a JavaScript method, as a cookie. cookie-scanner.com reproducibly printed "No banner found" and "Banner clicked: Yes" in the same report. Stable and right are separate tests, and a tool needs to pass both.
Two runs is a floor, not a distribution, so we say "in our two runs" and no more. Piwik PRO's rescan returned a byte-identical report with an identical generation timestamp, so its repeatability is untested rather than proven.
Where does a scanner scan from? None of them say
Scan location is not a detail. EU law is opt-in and most US law is opt-out, so a correctly configured site behaves differently for the two visitors: it must hold everything until consent in the EU, and it may lawfully run analytics until the visitor opts out in most of the US. A verdict from an undisclosed location is therefore uninterpretable, and none of the 11 tools disclose where they scan from.
So we measured it. We stood up a logging endpoint on a domain we control, gave each tool a tagged URL, and recorded the origin of every request. Four tools could be tagged cleanly:
| Tool | Scans from | Network | Executes JavaScript |
|---|---|---|---|
| CookieYes | Dublin, Ireland | AWS | Yes |
| CookieScript | Amsterdam, Netherlands | DigitalOcean | Yes |
| cookie-scanner.com | Berlin, Germany | IONOS | Yes |
| CookieHub | Dublin, Ireland | AWS | Yes |
Credit where due: the four we could tag do scan from Europe, even if they never say so. The rest resisted measurement in instructive ways. Cookiebot and Usercentrics appear to normalize the URL and strip our tag before crawling, so URL tagging cannot attribute them. And consentmanager needed no probe at all: its own report prints a map of crawl origins, showing Canada and the United States. A crawler that grades sites against EU law, operating from North America, by its own disclosure.
For contrast, our scanner's vantage is part of the result: every scan runs once from Frankfurt, Germany and once from a California IP address, and the two regions get separate verdicts.
How to tell an instrument from a marketing asset
Every free scanner report we collected, including the ones that contradicted themselves, ended at the same place: that vendor's signup button. We will not guess at anyone's motives. We will give you the six questions this study asked, so you can grade any scanner yourself, ours included.
- Does it agree with itself? Run it twice. Three of eleven tools here could not pass this.
- Does it separate regions? EU and US law demand different behavior from the same site. One verdict for both is not a verdict about either.
- Does it click the banner, including Reject? One of eleven clicked at all; none caught the planted post-reject leak.
- Does it say where it scans from? Zero of eleven do, and location decides which law applies.
- Does it show its work? Per-phase findings you can verify beat a single score you must take on faith.
- Does it admit mistakes? Every instrument has failure modes. The question is whether the vendor documents them or hides them.
And here are our own answers, stated so you can check them rather than trust them:
Does it agree with itself?
Repeated scans of the same site return the same verdict. Our determinism rebuild derives every verdict from a recorded event log, and each result carries a scan id and date you can quote back to us.
Does it separate regions?
Every scan tests the site twice, as an EU visitor and as a US visitor, and publishes two verdicts, because the two laws demand different behavior from the same site.
Does it interact with the banner?
The scanner finds the banner, clicks Accept, clicks Reject, and records what fires after each. Reject behavior is where most real violations live.
Does it say where it scans from?
Yes: an EU vantage in Frankfurt, Germany and a US vantage with a California IP address. Both are printed here, not hidden.
Does it show its work?
Findings are reported per phase (before consent, after Accept, after Reject) rather than as a single score, and this study names the scan id behind every table row.
Does it admit mistakes?
During this study our own scanner misread four vendor sites as having no banner because it lacked their consent tools' fingerprints. We caught it with a manual browser check, shipped the fingerprints the same day, re-scanned, and published the corrected numbers plus this note.
How we tested
All runs happened on September 1, 2026. The 11 tools are the free, publicly accessible scanners of Cookiebot, CookieYes, CookieServe, CookieScript, cookie-scanner.com, CookieHub, consentmanager, Usercentrics, Piwik PRO, UniConsent, and Termly. Osano's scanner is email-gated and its report never arrived, so it appears only as a no-result. Each tool was run by a human in a browser, the way a site owner would use it, and every report was captured as a screenshot at the time of the run.
The rig test and its planted violations are documented in full, with per-tool screenshots, in the scanner comparison. The 12 vendor-site scans ran on our production scanner, one scan id per row above; the scanner loads each site from Frankfurt and from a California IP, clicks Accept and Reject, and records findings per phase. The repeatability pass re-ran every tool against consentstack.io within the same hour. The vantage measurement served each tool a tagged URL on a logging endpoint we control and recorded the country, network, and JavaScript execution of every request; untagged requests from unrelated crawlers were discarded, and tools that strip URL parameters are reported as unmeasurable rather than guessed at. Every observation table on this page is also available as a CSV download; the rig-test matrix has its own.
One correction from during the study, published rather than buried: our scanner initially reported "no banner found" on four of the twelve vendor sites. A manual browser check showed two of them displaying real banners, and the other two loading their consent tools but suppressing the banner for non-EU visitors. The cause was on our side: our detector lacked fingerprint signatures for those four vendors' consent tools. We shipped the signatures the same day, re-scanned all four, and every number on this page comes from the corrected scans.
Grade our scanner with the same six checks
Run it against your site, or against ours. Two regions, the banner actually clicked, findings per phase, vantage disclosed, and a scan id on the result. No signup, no email.
Questions and answers
Limitations
- We are a competitor. Every vendor named here competes with us. That is why each claim carries a date, a scan id, or a screenshot, and why the checklist is designed to be run against us too.
- One day, two runs. This is a snapshot from a single day, and repeatability was tested with two runs per tool, which is a floor. Any vendor may fix any of this tomorrow, and we would welcome that.
- Free tiers only. We tested the public free scanners, not the paid platforms behind them. A vendor's paid product may behave differently from its free lead-generation tool; this study makes no claim about the paid products.
- One partial verdict withheld. consentmanager.net limited our crawl, so we report only what was recorded before the limit and withhold its full verdict.
- Our instrument has failure modes too. The fingerprint gap described in the methodology is proof. We found it, fixed it, and disclosed it, which is the standard this page argues every scanner should be held to.
This is a behavioral research study, not legal advice, and not a statement that any named company breaks any law. It reports what the named tools and websites did on September 1, 2026 under the described tests. For your own obligations, talk to qualified counsel.
See where your site leaks consent
Run a free compliance scan against EU and US rules. No signup required.
Just want the cookie list? Run the free cookie checker to see every cookie and tracker a site sets, and which ones fire before consent.
100+ happy customers
See what a real scan looks like
Two regions, the banner actually clicked, findings per phase, vantage disclosed. Run it on your site in a minute or two, with no signup.