Tracking Technologies
What is Cookie Scanner?
A cookie scanner is a tool that automatically crawls a website to detect and inventory the cookies, pixels, and tracking scripts it sets — including which ones fire before consent — producing the evidence base for cookie policies and compliance audits.
You cannot manage what you have not measured, and few organizations actually know what trackers their own sites run. Tags accumulate through tag managers, third-party apps, embedded widgets, and scripts that load other scripts. A cookie scanner answers the factual question every cookie law starts from: what does this site set, from which domains, for what purpose, and when.
A serious scanner behaves like a real visitor: it loads pages in an instrumented browser, records every cookie written and every third-party request made, and — critically — does so both before and after interacting with the consent banner. The before/after comparison is the compliance heart of the exercise: anything that fires before consent in an opt-in jurisdiction, or after an opt-out, is a violation in progress. Scanners then classify findings by category (necessary, analytics, marketing) and vendor.
Scan results feed several obligations: the cookie table in your cookie policy, the purpose descriptions in your consent banner, GDPR records of processing, and vendor due-diligence lists. Because sites change constantly — a new app install or a tag-manager publish can add trackers overnight — scanning is a recurring control, not a one-time project. Regulators and plaintiff firms both use scanners; running one yourself first means you see what they would see.
The pre-consent view has become especially important in the US, where CIPA demand letters are typically built on exactly this evidence: a crawl showing named trackers collecting data before the banner was answered. Running the same scan on your own schedule means the first party to discover the gap is you.
Why it matters for eCommerce
eCommerce platforms make tracker sprawl easy — every Shopify app or plugin can inject scripts, and seasonal campaign tags linger for years. A scheduled scan of your storefront catches new pre-consent trackers before a plaintiff's expert does, and keeps your cookie policy's table synchronized with reality instead of with the site as it existed at launch.
Frequently asked questions
- Why do I need a cookie scanner if I installed a consent banner?
- Because banners frequently do not block what they claim to. A scanner verifies enforcement: it shows which cookies and pixels actually fire before consent and after rejection. The banner is the promise; the scan is the proof.
- How often should a website be scanned?
- After every significant site change and on a regular schedule — monthly is a common baseline for eCommerce sites, where apps and tags change frequently. Continuous or scheduled scanning catches regressions that one-off audits miss.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Run a free scan of your site now