Free Basic Report — no credit cardNew

Is your website exposing you to GDPR fines?

Scan your site in 30 seconds. CookieInspector detects hidden trackers, pre-consent cookie drops, and consent banner failures — before your legal team or a regulator does.

https://
+150K sites scannedGDPR & CCPA alignedNo credit card requiredUS & EU scan locationsBeta

Free first scan · See your scan results instantly · Enjoy a special discount after pre-scanning your site

Pre-consent tracking, explained

What your cookie banner isn't telling you

A real scan, start to finish: what loads before anyone clicks accept, and why regulators look there first.

New · Free forever

Run a privacy audit and get the Basic Report — free

No credit card, no hidden tier. Create a free account, submit a URL and you get the same plain-language read-out our paying customers use to brief legal and product teams.

  • Banner detection, vendor & blocking behaviour
  • Cookies, trackers & third-party domains breakdown
  • Pre-consent vs. after-consent — the only split that matters
  • Severity-coded compliance issues with affected resources
  • Your overall risk score and an AI-free, jargon-free summary
30-second scan · no credit card required
cookieinspector.com / report / basic

Domain scanned

example.com

Non-compliant

78 /100

Pre-consent trackers

7

3P cookies

24

3P domains

18

3P fonts

3

Issues

  • Pre-consent tracking detected (7)
  • Cookie banner not blocking
  • Privacy policy missing footer link
How it works

Transparent steps aligned with compliance

Every scan is aligned with GDPR, ePrivacy and CCPA expectations — including the California “Do Not Sell or Share” opt-out link, checked on every scan.

01

Instant start

Enter your domain

Type your URL and the scan is queued in seconds.

02

Banner, cookies, California opt-out

Deep scan

We detect consent behavior, trackers, cookie drops pre/post banner, and whether your “Do Not Sell or Share” link is there.

03

Audience-tailored

Reports ready

Developer, Compliance, and Business story + export-ready files.

04

Insight engine

AI insights

AI summarizes risks, highlights what changed, and suggests next steps.

05

Realtime alerts

Alerts & action

Get notified when scans detect new risks or regressions.

06

Continuous monitoring

Monitor

Schedule scans + get alerted when changes are detected.

Continuous visibility

AI Insights + Continuous Compliance Monitoring

Have you updated your site? Do you have developers, designers, or marketing making changes? Keep your cookie and consent setup under continuous review, and get alerted the moment tracking changes.

AI Analysis

We run multiple analyzers (banner, cookies, trackers, scripts) and then add AI insights on top—summaries, risk explanation, and prioritized next steps.

  • Executive summary + technical breakdown
  • Explains risk in plain English
  • Prioritized action plan
  • Highlights what changed since last scan (if available)

Compliance Monitor

Schedule recurring scans (daily/weekly) and get alerts when cookies, trackers, or consent behavior changes.

  • Recurring scans on autopilot
  • Alerts when new cookies/trackers appear
  • Detects consent/banner behavior changes
  • Scan from US East, US West or Germany to see what local visitors see (beta)
  • Audit-friendly history

Cookie compliance is not a one-time project—monitor it continuously.

How the Compliance Monitor works

Your site changes. We keep watching—so you don’t have to.

  1. Scan startedRunning
  2. Scan completeOK
  3. + 1 week (scheduled scan)OK
  4. + 1 week (scheduled scan)OK
  5. Scan result: AT RISKAT RISKSending alerts to your team…

Alerts trigger when new cookies/trackers appear or consent behavior changes.

Alert sent

New risk detected — notifying your team

DevelopersMarketingCompliance

Includes evidence + what changed + recommended next steps.

Built for every team

Tailored reports for Developer, Legal, and Business

Choose the preset that fits your audience and unlock export-ready evidence.

Developer Report

Technical details your engineers can act on.

Cookies listTrackers & scriptsEvidence exportsFindings CSV

Compliance Report

Risk aware summary mapped to consent expectations.

Findings + evidenceConsent simulationsRecommended actions

Business Report

Executive scorecard with quick wins and priorities.

Scorecard & trendsTop issuesRoadmap suggestions

Export in one click

Send reports where your teams work

Export to NOTION

Generate narrative summaries plus structured CSVs ready for documentation.

Export to CONFLUENCE

Download the same artifacts to attach or paste into your CONFLUENCE pages.

See what you get

Clear findings, evidence, and next steps

Structure your work with a scorecard, cookies by category, and the evidence that proves compliance.

+150K

sites scanned

98%

compliance improvement

acme-store.com · Evidence
6 issues

Consent timeline

requests captured
Before banner143
After reject121
After accept312
Fired before consentVendorCookies
connect.facebook.net/en_US/fbevents.jsMeta Pixel3
googleads.g.doubleclick.net/pagead/viewthroughconversionGoogle Ads2
analytics.tiktok.com/i18n/pixel/events.jsTikTok1
cdn.segment.com/analytics.js/v1Segment1
Next step: gate Meta Pixel and Google Ads behind marketing consent — removes 7 pre-consent requests.
Verified

Get Verified. Earn Trust Instantly.

Publish a CookieInspector badge so every visitor knows your site is continuously scanned for cookies, trackers, and consent integrity.

Public verification helps demonstrate compliance to customers, partners, and auditors.

Show trust instantly

Display a verified badge so visitors immediately see that you are regularly monitored.

Link to proof

Every badge links back to a live verification view with the latest scan data.

Stay compliant

Verification is driven by recurring scans that detect regressions before they become risks.

Stand out

Earn trust with a modern trust marker that pairs well with your brand colors.

For agencies & multi-site teams

Agency Mode

Manage 10+ client sites in one dashboard with monitoring, white-label reporting, and verification workflows.

Now available in early access • Limited spots

  • Multi-domain monitoring
  • White-label reports for clients
  • Bulk scans & recurring alerts
  • Verification badges per domain
Explore Agency →

CMS detection

What CMS does CookieInspector think you're using?

Every quick scan caches the CMS signals we capture, so you can check what we detected without rerunning a full audit.

Run a scan to see exactly which CMS CookieInspector detects for your environment.

WordPressShopifySquarespaceWebflowWixGhostDrupal

Examples of CMS platforms we can detect today.

Plans & pricing

Choose how your team scans

Clear limits today with advanced scanning capabilities.

Free foreverFree Basic Report

Free

$0 / forever

The plain-language Basic Report — your full privacy posture in one screen. No credit card and no time limit on viewing the result.

  • Free Basic Report — plain-language, no jargonNEW
  • Banner detection + cookies, trackers & domains breakdown
  • Severity-coded compliance issues
  • 1 scan per domain (1 page · 45 s)

Built for product, marketing and legal teams who want a quick read — without learning the cookie spec.

Pro tier

Pro

Starting from

$9.99 / mo (billed annually)

Billed $119.99 / year — you save $23.89 (17%) vs paying monthly.

Multiple domains, AI insights, scheduled monitoring, exports, and evidence-based alerts.

  • AI Insights: summary, risk explanation, and prioritized action planNEW
  • Bulk scan enqueue (upload CSV or paste multiple targets)NEW
  • Choose the scan location: US East, US West or GermanyBETA
  • Compliance Monitor: scheduled recurring scans (daily/weekly)
  • Compliance Monitor: up to 5 monitored sites
  • Alerts when new cookies/trackers appear or consent behavior changes
  • Notion & Confluence exports + scan history
  • 100 scans/month
  • Unlimited domains & rescans

Need shared scans with a team? See the Agency plan.

For teams

Agency

Starting from

$33.33 / mo (billed annually)

Billed $399.99 / year — you save $79.89 (17%) vs paying monthly.

Pro capabilities shared across your team. Up to 5 seats — scans, reports, and monitors are visible to every member.

  • Up to 5 team seats (Owner invites by email)
  • Shared scans, reports & monitors across the agency
  • 500 scans/month (shared across team)
  • Up to 25 monitored sites (shared)
  • All Pro features included

Invite your teammates after checkout — they inherit your entitlements.

No credit card required for your first scan.

Compare plans and scan limitsLimits apply per scan; your account page always shows live entitlements.
Key featureFreeProAgency
Monthly scans1 / lifetime100 scans/mo500 scans/mo (shared)
AI insights-IncludedIncluded
Scheduled monitoring-IncludedIncluded
Compliance Monitor sites-Up to 5 sitesUp to 25 sites (shared)
Alerts on changes-IncludedIncluded
Exports (Notion / Confluence)-IncludedIncluded
Bulk scan enqueue-IncludedIncluded
Scan location (US East, US West, Germany) · betaUS EastYour choiceYour choice
Rescans-IncludedIncluded
Team seats11Up to 5
Shared scans & reports--Included
PlanPages crawled per scanIncludes the submitted URL plus internal pages discovered during crawling, up to your plan limit.Scan timeout
Free1 URL45 s
Pro5 URLs120 s
Agency5 URLs120 s

Unique internal URLs visited in one scan. Agency shares Pro's scan capabilities across up to 5 teammates — members see every other member's scans, reports and monitors.

Roadmap

We ship fast

Here’s what CookieInspector does today — and what we’re building next.

Now
  • Cookie & consent banner detection
  • AI insights
  • Cookie / tracker inventory with evidence
  • Shareable reports
  • PDF export
  • Billing + plan-based limits
  • Scheduled recurring scans + alerts
  • Expanded CMP coverage (15+ consent platforms)
  • Multi-page crawling (sitemaps)
  • Scan from different regions (US East, US West, Germany)
  • Zapier integration + public V1 API
Next
  • VPPA Detection: Automatic detection of VPPA-related data sharing risks in video and media integrations.
  • Slack / Jira integrations
  • Scan-to-scan diffs (what changed)
Later
  • Region/device simulation
  • Team workspaces + roles
  • Notion / Confluence export improvements

Roadmap items are goals and may change as we learn from users.

Ready?

Ready to scan your site? Generate your first report in seconds.

Cookie compliance explained

Cookie compliance is the assurance that your tracking, consent banner, and third-party scripts behave in accordance with privacy law. A cookie compliance checker like CookieInspector goes beyond simple audits by continuously scanning pages, cookies, and consent banner responses so you can document what changed and why. When regulators or customers ask, you have a modern cookie audit tool to demonstrate compliance confidence.

The cookie scanner monitors pre-consent and post-consent behaviors, records the cookie categories that load, and flags any unexpected trackers dropped before visitors choose an option. Every insight feeds into detailed reports and action plans, so your teams stay ahead of consent banner compliance and privacy expectations without manual research.

Get Verified with explicit proof of your cookie compliance checker

Pre-consent tracking is a signature risk that can jeopardize GDPR cookie compliance. CookieInspector loads your site in a controlled browser environment, waits for consent banners to activate, and captures every cookie, script, and network request that occurs before a visitor agrees. This gives your privacy team the evidence needed to fix misbehaving tags and prove the functionality of your cookie compliance checker.

Because the tool is a continuous cookie scanner, you get alerts the moment new pre-consent cookies appear or when consent banner compliance slips. That real-time context feeds dashboards, public verification, and the GDPR-ready documentation your auditors appreciate. Think of it as your Free Cookie Scanner plus a policy-grade audit layered on top of every scan.

Which Third-Party Requests Count as Tracking?

Not every request to another company is tracking. A payment form, a CAPTCHA, a web font or an accessibility widget such as UserWay or accessiBe has to load before consent for the page to work, and none of it profiles the visitor. CookieInspector classifies every third-party host it sees and only scores the ones that track: analytics, advertising, session recording, fingerprinting.

Functional services still appear in the report with their role spelled out, so you see the whole picture without a false alarm. Unknown third parties stay in the tracking column on purpose: telling you a site is clean when it is not is the expensive mistake for a compliance tool. How the line is drawn

Platforms in the EU and US expect statements around GDPR cookie compliance, CCPA cookie notices, and even Google Consent Mode. CookieInspector maps your tags against those expectations, shows which cookies fire on each page, and tracks consent banner compliance signals to help you defend decisions to regulators or leadership.

Combine the insights with the pricing plan that fits your cadence, and you gain a cookie audit tool that makes compliance repeatable. Explore our pricing → CookieInspector plans, or check whether your tags honour consent with the free Google Consent Mode checker. For anything else, Support resources covers the rest.

Need clarity?

Frequently Asked Questions

A calm clarification of what CookieInspector does and how it fits into your compliance toolkit.

Get Verified

What does it mean when a site is "Verified" by CookieInspector?

Verified means the site owner authorized CookieInspector to run automated compliance scans and display the latest scan status publicly via the badge and verification page.

What’s the difference between a scan and verification?

A scan is a point-in-time analysis. Verification is the public status shown via the badge, based on the most recent successful scan.

What happens when someone clicks the CookieInspector badge on my site?

They’re taken to a public verification page showing the latest scan status, risk score, and what areas were checked.

Is my verification status public?

The verification page is public by design so visitors can confirm the latest status. It only shows compliance results—never account or personal information.

Can I remove the verification badge at any time?

Yes. Removing the badge stops public verification display, but you can still run scans from your dashboard.

Compliance Monitor

What is Compliance Monitor and who is it for?

Compliance Monitor automatically re-scans your sites on a schedule and alerts you when something changes—ideal for teams shipping updates frequently.

How often does CookieInspector re-scan a verified site?

It depends on your monitoring settings and plan. You choose the scan frequency in Compliance Monitor.

Can a site move from compliant to at risk or non-compliant?

Yes. Site changes, third-party scripts, or tag updates can introduce new issues—monitoring helps catch regressions early.

What happens if Compliance Monitor detects a new compliance issue?

You’ll see the updated status in your dashboard and receive an alert based on your notification settings.

Can I monitor more than one website?

Yes. Plans support monitoring multiple sites, with limits depending on your subscription.

AI Analysis

How does CookieInspector use AI in compliance analysis?

AI adds explanatory insights on top of scan data to help you understand what changed and what to review next.

What additional insights does the AI analysis generate?

It summarizes key risks, highlights likely causes, and suggests what to check—based on the scan signals we detect.

Does CookieInspector’s AI replace legal advice or a lawyer?

No. CookieInspector provides technical compliance signals and insights, but it’s not legal advice.

Risk score

What is the CookieInspector risk score and how is it calculated?

The risk score is a 0–100 indicator derived from scan findings and signals like pre-consent tracking and consent behavior. Lower is better. Each signal carries a published weight, and cookies set by the consent platform itself or by strictly-necessary services are not counted.

See exactly how the score is calculated

California (CCPA/CPRA)

How do you check for the "Do Not Sell or Share My Personal Information" link?

We load your page the way a visitor's browser does and look for a real link—not a mention of the phrase in your privacy text, which is not the clear and conspicuous link California asks for. We match the wordings sites actually ship, including "Do Not Sell My Personal Information", "Do Not Sell or Share", "Your Privacy Choices" and "Limit the Use of My Sensitive Personal Information". If your link is the standard opt-out icon with no visible text, we still find it: we read the link's accessible label and its address, so an icon pointing at /do-not-sell or labelled "Your Privacy Choices" counts.

Why is a missing California link sometimes a high-priority issue and sometimes just informational?

Because California only requires the link from businesses that sell or share personal information. We raise it to high priority when the same scan actually observed third-party advertising or tracking activity on your site—CPRA counts passing data to third parties for cross-context advertising as sharing. With no such activity observed, we still tell you the link is absent, but as information rather than a finding against you. We would rather be quiet than accuse a brochure site of a breach it cannot commit.

We only show the opt-out link to visitors in California. Will your scan report it as missing?

It may, and we say so in the finding itself. Our scanner runs from a US IP address, not a California one, so a link served only to visitors detected as being in California is one we would not see. That is why the finding reports what we observed rather than asserting you are in breach. If this is your situation, tell us through the feedback box on the report and we will correct it.

CookieInspector overview

Is CookieInspector a Consent Management Platform (CMP)?

No. CookieInspector is not a Consent Management Platform. We scan, audit, and monitor your website to keep your existing consent setup compliant over time.

Does CookieInspector replace Cookiebot, OneTrust, CookieYes, or Termly?

No. CookieInspector works alongside your existing CMP. We help detect compliance issues, unexpected tracking changes, and consent regressions after site updates.

Which consent platforms (CMPs) does CookieInspector detect?

CookieInspector identifies the major consent platforms by name—including Cookiebot, OneTrust, Usercentrics, Didomi, TrustArc, Sourcepoint, Quantcast Choice, Iubenda, CookieYes, Osano, Termly, Complianz, Axeptio, Ketch and CookieScript, among others. It also recognizes generic IAB TCF and US Privacy signals, so even unlisted or custom banners are detected. We expand and refine CMP detection continuously as vendors update their implementations.

Who is CookieInspector for?

CookieInspector is built for developers, compliance teams, and businesses that need continuous visibility and evidence—not just a one-time cookie scan.