CertScore Pulse

CertScore Pulse for kbdlab.io

Automated scan surfaced consent timing, fingerprinting review signals.

CertScore provides automated public-web observations for review. Results may be incomplete or contain errors. CertScore does not provide legal advice nor certify compliance. Always review the underlying evidence and consult qualified experts where appropriate.

Score

72/100

Risk level

review recommended

Freshness

fresh

Coverage

partial

Top findings

Third-party tracking observed before recorded consent

high

Before any consent choice was observed, third-party tracking requests were initiated to Google Tag Manager and Microsoft Clarity.

Teams commonly review whether consent mode, CMP state, and tag-manager triggers prevent non-essential analytics, advertising, measurement, or replay requests from firing before the relevant consent state is available.

Review evidence

Third-party cookie or storage observed before consent

high

Observed before a clear user choice was made.

Teams commonly review whether third-party cookie or storage writes are gated until consent state is available, and manually confirm purpose, necessity, exemption status, and vendor configuration.

Review evidence

Long-lived cookie retention review

high

4 long-lived tracking cookies exceeded the 365-day review threshold.

Review cookie purposes and vendors, shorten unnecessary expiration periods, classify unknown cookies, and update cookie or privacy disclosures to explain retention periods or criteria.

Review evidence

Session replay service signal observed

high

This signal is worth reviewer attention.

Teams commonly review replay vendor configuration, consent gating, masking, sampling, and page-level exclusions to determine whether the retained runtime signal reflects intended behavior.

Review evidence

Visual contrast accessibility issue

medium

Automated issues were surfaced in this area.

Teams commonly review the affected selector, color pair, component state, and applicable contrast threshold before adjusting design tokens or component styles.

Review evidence

Consent preference reopen control not observed

medium

No obvious cookie preferences, privacy settings, or consent-preference reopen control was observed on the scanned public pages.

Confirm that an accessible cookie preferences, privacy settings, CMP widget, footer link, or privacy-choice page lets users revisit or withdraw cookie/privacy choices.

Review evidence

Review lenses

CCPA / CPRA / CIPA: clear - Third-party collection, privacy-choice, and disclosure posture drive this review context.

GDPR / ePrivacy: clear - Consent timing, consent surface, and tracker behavior drive this review context.

FTC: watch - Consumer-facing claims, tracking posture, and disclosure signals should be reviewed together.

DOJ / ADA accessibility: clear - Automated accessibility signals are the main review area for this lens.

Evidence highlights

2 third-party domains observed; 2 classified tracker vendors identified.

2 policy URLs covered.

No probable fingerprinting detected. Related indicators, if present, are retained for review.

session replay 3 | tag manager 2 | unknown 1

Coverage

Automated public-web scan completed with coverage limitations. Homepage findings are based on observable public-page evidence.

  • Automated public-web scan only.
  • Coverage may be affected by bot defenses, geography, consent flow branching, lazy loading, protected routes, authenticated-only areas, or other runtime conditions. Absence of findings should not be interpreted as absence of risk.

Share with an agent

Was this Pulse useful?

[email protected]

CertScore provides automated public-web observations for review. Results may be incomplete or contain errors. CertScore does not provide legal advice nor certify compliance. Always review the underlying evidence and consult qualified experts where appropriate.