Tracking health check

See what fires before your visitors consent

Paste a URL. We load the page three times — untouched, after accept, and after reject — and show which tags fire in each state.

No account. No card. Most scans finish in about a minute.

 

What it checks

Plain observations from the network traffic we actually captured — a risk score summarises them, it is not a legal opinion.

  • Tags before any consent choice

    Requests that leave on an untouched page load, including session-recording tools, before anyone has clicked the banner.

  • Tags that keep firing after a decline

    Whether collecting tags still fire after a reject control actually responded — we do not report this unless the refusal was verified.

  • Google Consent Mode on GA4

    Whether Google Analytics 4 requests carry the Consent Mode signals (gcs/gcd) that tell Google the visitor's choice.

  • Duplicates, extra containers, shifting accounts

    The same tag firing twice, more than one GTM container on the page, or a vendor reporting to different accounts depending on the consent choice.

  • Personal data in tracking requests

    Values that look like an email address or phone number in a tracking request. Captured values are redacted; parameter names stay in the evidence.

  • Advertising tags with no real choice

    Marketing pixels with no consent banner detected, or a banner that offered no way to decline.

  • Declared GTM tags that never fire

    Tags present in the container that do not produce a matching request after accept-all — Consent Mode mapping, a blocked script, or a trigger this scan did not meet.

  • Setup and weight

    Deprecated tags still loading, vendors on third-party cookies, client-side-only pixels where a server-side path exists, tracking-script weight, and whether a privacy-policy link was found.

What you get

The scan itself is free and starts from the URL alone. A short summary is on screen when it finishes; the full report and PDF unlock after you leave your details.

On screen, from the URL

A risk score, headline counts per check, and one or two findings in full — enough to see that the scan actually looked. You can run that with the URL alone.

Full report, after your details

Name, work email and company unlock every finding, the pass comparison, and a PDF. No account and no card — one form, then the report is yours in that same session.

How it works

Most free scanners load the page once. This one runs three consent-aware passes against the same URL, then compares what fired.

  1. Baseline

    Load the page and do nothing. Whatever fires here fired with no banner click and no consent choice.

  2. Accept

    Find the consent banner, choose accept-all, and record what fires afterwards.

  3. Reject

    On a separate load, choose decline — when a reject control actually responds. If it does not, we record that rather than inventing a refusal.

Who it is for

E-commerce and lead-gen sites running GA4, Google Ads, Meta, and a consent management platform (Didomi, OneTrust, Axeptio, Cookiebot, and others the scanner already knows how to operate).

If Consent Mode signals are missing, that is a setup job — see how we implement Consent Mode v2 without dropping attribution.

Questions people actually ask

Do I need an account to scan a website?

No. Paste a URL and run the scan. There is no account, no card, and no email field above the fold. After the scan you see a summary; the full report unlocks when you leave your details.

What does a consent tracking scan actually check?

Which tags fire before any consent choice, which keep firing after a verified decline, whether GA4 carries Consent Mode signals, duplicate or misconfigured tags, personal data in tracking requests, advertising tags with no real choice, declared GTM tags that never fire, and a handful of setup issues such as deprecated tags and tracking-script weight.

How is a three-pass scan different from a free cookie scanner?

A single page-load cannot tell you what happens after someone accepts or declines. We load the same URL three times: untouched, after accept-all, and after reject — and only treat a decline as real when the reject control actually responded.

Does this check Google Consent Mode?

Yes, for Google Analytics 4. The scan looks at whether GA4 requests carry the Consent Mode parameters that tell Google the visitor's choice, and whether tags declared in GTM stayed silent after accept because a Consent Mode signal was missing or still denied.

How long does a website tracking scan take?

Most scans finish in about a minute. Each of the three passes has a 30-second budget, and a slow site can take longer — up to the two-minute job limit. We do not promise a number the scanner cannot hit.

Can I scan a site I do not operate?

You can run the scan on any public URL. The report describes what this scanner observed on that load, not a verdict about the site or its operator. If a bot challenge, geo-block, or interstitial answers instead of the page, we say so and produce no findings from a page we never saw.

Will you ask for my email before showing the result?

The scan runs from the URL alone. When it finishes you see a score, headline counts, and one or two findings. The rest of the report and the PDF unlock after you leave your name, work email and company.

Scan a site now

Same form as above. URL in, scan out — still no account.

 

Need the tracking rebuilt, not just observed? GA4 audit, setup and migration.