Historical calibration notes

Session replay: historical benchmark notes

Historical CertScore.ai counts for session recording and sensitive-input signals, recorded in May 2026. Review the aggregate, source revision, and incomplete provenance.

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

Historical aggregate — provenance incomplete

These counts were recorded in the source on May 18, 2026. That is the aggregate’s source date, not a verified scan date range. The declared scope was Tranco top 1–2500 calibration set, with an approximate denominator of 2,505 scan records and possible rank-band overlap.

The complete deduplicated scan manifest, exact scan dates, regions, scanner versions, and exclusion accounting are not established by this published aggregate. Counts are preserved for transparency; we do not present them as current website prevalence, a representative study, or a reproducible research dataset.

Source recorded
May 18, 2026
Editorial review
September 20, 2026
Source revision
839fa60a347c4af7cb6a2bc473073ff7aae277cd
Recorded counts; findings can overlap within a scan
SignalRecorded count
Session recording service signal228
Possible session replay near sensitive inputs7

Download the labeled historical aggregate (JSON)

What the signal categories mean

Pre-consent request activity and third-party cookie storage are related but distinct observations. A broad fingerprinting-related signal is not interchangeable with probable fingerprinting. Session recording presence does not prove that sensitive input was captured.

These are historical classifications. Their counts do not establish legal violations or imply that current scanner rules would produce identical results.

What a reproducible benchmark needs

A defined sampling frame and retained scan manifest; exact collection dates; region and browser conditions; scanner and rule versions; successful, failed, and excluded counts; a deduplication method; and bounded evidence for the measured findings.

Any future study must report its own denominator and collection method. We will not silently carry these historical counts into a new study or treat repeated scans as unique sites.

Use individual evidence for decisions

For a website you maintain, review the actual target, date, consent state, requests, storage, and coverage. A historical frequency is not a severity score and cannot decide whether that website’s behavior is appropriate.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.