Cookie consent scanner

Cookie consent scanner

CertScore establishes a pre-consent baseline and, where an eligible consent control can be actioned safely, observes Accept and Reject in separate browser sessions. Reports retain observable requests and storage activity after a completed click and separately state whether consent registration was verified. These observations remain useful when registration is unconfirmed.

By CertScore.ai · Updated

CertScore.ai scans public website behavior for review signals. Findings are automated observations backed by retained evidence, not legal advice, certification, or compliance determinations.

What the scan reviews

Cookie and storage timing
Third-party cookies before consent
CMP banner and choice signals
Accept and Reject Path observations
Vendor and purpose review context

Scan a public website

Loading scan form…

From a scan to a reviewable decision

  1. Check the context. Open the report and confirm the target, scan date, region, and coverage. A blocked or incomplete observation is a limitation, not evidence of an absent control.
  2. Inspect the observation. Follow a finding to its retained request, cookie, storage, or policy evidence. Keep pre-consent activity separate from activity after an Accept or Reject click.
  3. Verify the interpretation. A visible Reject button, a completed click, and confirmed refusal are different facts. A cookie remaining in storage does not by itself prove active tracking.
  4. Assign and retest. Give the responsible team the affected vendor, page, consent state, and evidence. After a configuration change, compare a new scan under the same conditions.

Use the sample report to explore the report format; it describes its own retained scan, not your website.

What this scan cannot establish

Public-page observation does not cover private account flows, every page, every region, or all future behavior. Bot defenses and unavailable controls can limit coverage. Accept and Reject observations are separate eligible sessions; an unverified decision stays unverified. A clean observation is not a compliance certificate.

What to give your implementation team

Share the report's target and date, the affected vendor or storage identity, the consent state, and the retained evidence reference. Ask the team to inspect the relevant tag trigger, consent category, or embedded service, then compare a fresh scan after the change.

Direct answer

A cookie consent scanner observes whether cookies, storage, and related tracking activity appear before or after a recorded consent state. CertScore.ai surfaces evidence for human and agentic review rather than declaring legal outcomes.

What CertScore.ai checks

CertScore.ai reviews cookie timing, third-party domains, storage writes, consent surface presence, available choices, and separate Accept and Reject observations. Accept is a score-neutral comparison baseline; Reject can support a finding after confirmed refusal with qualifying activity, or after a completed Reject click with independently verified tracking evidence under the Reject-click review policy.

When to run it

Run a cookie consent scan after CMP rule changes, tag-manager publishing, marketing campaign tags, consent template updates, site launches, and vendor onboarding.

What to review first

Start with cookies or requests observed before consent, vendors classified as advertising or analytics, and any activity that appears to continue after a reject-style choice.

Frequently asked questions

What is a cookie consent scanner?

A cookie consent scanner observes cookies, storage, requests, and consent-surface behavior so teams can review whether live website behavior appears aligned with intended consent rules.

Can a scanner prove cookie compliance?

No. A scanner can provide useful evidence, but compliance depends on legal context, purposes, exemptions, disclosures, consent records, and implementation details.

Does CertScore.ai test reject behavior?

On eligible sites, CertScore can observe Accept and Reject in separate sessions. Reports retain activity observed after a completed Reject click and separately report refusal registration. A finding requires qualifying retained evidence under the confirmed-refusal or Reject-click tracking policy. Missing or incomplete capture remains limited coverage. Findings remain automated review signals, not legal determinations.

Key takeaways

CertScore.ai provides cookie consent scanning for public websites by observing cookie, storage, request, CMP, and consent-timing behavior.

CertScore.ai helps teams review consent implementation drift after CMP, tag-manager, and vendor changes.