Support

WAF Blocked or Limited Scans

CookieInspector marks a scan as WAF Limited when a website's firewall, CDN, or bot-protection system blocks or challenges some of the scanner's requests. This page explains what happened, what it means for the report, and what to do next — whether the website is yours or someone else's.

Looking at a limited report right now? Support can help review the domain.

Contact support

What happened

The website you scanned is protected by a firewall, CDN, or bot-protection system, and that system blocked or challenged some of the requests the CookieInspector scanner made. Instead of the real page, the scanner received an access-denied page, a challenge, a rate-limit response, or nothing at all.

CookieInspector does not try to bypass these controls. It records what it could observe and marks the scan as limited.

The block can come from many places, not only a traditional Web Application Firewall: a CDN, bot protection, a managed challenge, IP reputation, rate limiting, firewall rules, or automated-traffic detection. The report uses the label WAF Limited Report for all of them.

What it means for the report

Some parts of the scan may be incomplete. The Partial findings section of the report lists which steps completed and which were interrupted, so you can see exactly what was and was not observed.

A limited report should not be read as a complete scan. If the cookie banner, third-party requests, or script checks were blocked, the absence of a finding there is not evidence that the site is compliant — it means the scanner could not look.

If you manage the website

You can configure your WAF, CDN, or bot-protection provider to allow CookieInspector scanner traffic and then run the scan again. Whitelisting is only necessary when a scan reports being blocked or limited; most websites do not require any configuration changes.

Once the exception is in place, re-run the scan from the report. If the website continues blocking the scanner, the report may remain incomplete — check that the rule matches the User-Agent below and that it covers the product that is doing the blocking (see the Cloudflare notes further down).

If you do not manage the website

There is nothing you need to change on your side. The restriction is controlled by the website owner or their security provider, and only they can allow automated scanning.

You can retry the scan later — some blocks are temporary or rate-based — or contact CookieInspector Support if you need help reviewing the domain. Include the domain and the scan ID from the report.

CookieInspector scanner User-Agent

CookieInspector identifies its scanner using this User-Agent token:

CookieInspectorBot/1.0

The scanner loads pages in a real browser. Its first request looks like a regular desktop Chrome browser; when a website blocks or challenges that request, the scanner retries with the token appended to the end of the same Chrome User-Agent string. Match on the token, not on the full string.

A User-Agent is not authentication. Any HTTP client can send this value, so an exception based on it allows any traffic that presents it. Keep the rule as narrow as your security configuration permits — for example, limited to the paths you actually want scanned — and avoid disabling WAF or bot protection globally.

CookieInspector does not currently publish scanner IP addresses.

General configuration

Configuration varies by provider. In most WAF, CDN, and bot-protection dashboards, your security or DevOps team can create an exception for requests where the User-Agent contains CookieInspectorBot/1.0.

  • Prefer an allow or skip rule over turning protection off.
  • Scope the exception to the User-Agent token and, if possible, to specific paths.
  • If the provider offers separate controls for WAF rules, bot management, and challenges, the exception may need to cover more than one of them.

If you need help configuring your provider, contact CookieInspector Support and include the domain you are trying to scan.

Cloudflare

Cloudflare is the provider CookieInspector runs into most often. Its dashboard lets an administrator create a rule that skips or allows traffic matching a condition, without disabling Cloudflare for the whole site.

Conceptually, the rule matches requests where the User-Agent contains CookieInspectorBot/1.0 and applies an allow or skip action. Which rule type you need depends on which Cloudflare product is doing the blocking: a WAF custom rule, Bot Fight Mode or Super Bot Fight Mode, a managed challenge, or rate limiting each have their own settings, and an exception in one does not automatically cover the others.

The report's WAF challenge panel shows the evidence CookieInspector captured — often a Cloudflare challenge page — which helps identify the product involved. A single rule may not resolve every kind of block; if the scan is still limited after adding one, check the remaining products or contact Support with the domain.

Cloudflare's dashboard changes over time, so this page describes the approach rather than exact clicks. Cloudflare's own documentation for custom rules and bot management has the current steps.

Related guides

More insights

Ready to prove your compliance?

Start with a scan so you can show regulators and stakeholders the evidence you followed cookie compliance checker best practices.

Contact support