Cookie & Tracker Audit: GDPR Consent Checker
Pricing
from $4.00 / 1,000 page auditeds
Cookie & Tracker Audit: GDPR Consent Checker
Bulk-check websites for cookies and tracking tags that load before consent (GDPR / ePrivacy). Get every cookie with category and vendor, 70+ tags such as Meta Pixel, Google Analytics and TikTok with evidence, the consent banner (CMP) found, and plain-English risk flags. Not legal advice.
Pricing
from $4.00 / 1,000 page auditeds
Rating
0.0
(0)
Developer
Offera Studio
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
9 hours ago
Last modified
Categories
Share
What does Cookie & Tracker Audit do?
Cookie & Tracker Audit checks any list of web pages, up to 1,000 URLs per run, for what happens before a visitor clicks anything on the cookie banner. For every page you get:
- 🍪 every cookie set before consent: name, domain, first- or third-party, expiry, and a category guessed from 280+ known cookie names (analytics, ads, functional, unknown), with the rule that matched (for example
_ga_*→ Google Analytics) - 🏷️ third-party tags present before consent: Google Analytics / GA4, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, Google Ads, Pinterest, Snap, Reddit, X, Criteo, YouTube embeds and 50+ more, each with the URL or code snippet that matched
- ✋ whether each tag loads immediately or waits for consent (scripts held back with
type="text/plain",data-cookieconsent, OneTrust category classes ordata-srcare recognised) - 🛡️ the consent management platform (CMP) found, if any: OneTrust, Cookiebot, Didomi, Usercentrics, iubenda, CookieYes, Complianz, Borlabs, Quantcast/InMobi Choice, TrustArc, Sourcepoint and 20+ others, plus Google Consent Mode defaults
- 🚩 a plain-English list of risk flags and a risk level (high, medium, low, none), for example "Meta Pixel loads before consent and no consent banner (CMP) was detected."
Paste your URLs, click Start, and download the results as JSON, CSV, Excel or HTML, or get them through the Apify API. You can schedule audits, call them from your own code, and send the results to Google Sheets, Slack, Zapier, Make and other tools.
Not legal advice. The Actor reports what it can observe and says "likely", never "illegal". Whether a cookie or tag needs consent depends on its purpose, your legal basis and the country. Ask a qualified advisor for legal questions.
Who is this cookie checker for?
- Web agencies and freelancers: screen a client's or prospect's sites in minutes and show exactly which tags fire before consent, with the evidence.
- Privacy and compliance teams: monitor all brand sites and landing pages on a schedule and catch a new pixel that a marketing team added without a consent block.
- Consent management (CMP) consultants and resellers: find sites with trackers but no consent banner.
- Marketing and analytics teams: check that Google Analytics, Meta Pixel and friends really wait for the banner after a site or tag manager change.
- Due diligence and audits: get a quick, repeatable inventory of cookies and third-party tags across a portfolio.
What does it check?
| Area | What you get |
|---|---|
| Cookies | Every cookie present before consent. Static mode: cookies in Set-Cookie headers of the page and every redirect before it. Browser mode: also cookies set by JavaScript and third-party cookies. Name, domain, first/third party, category, vendor, matched rule, expiry in days, Secure, HttpOnly, SameSite. Cookie values are never stored. |
| Cookie categories | analytics, ads (advertising, marketing and social media), functional (sessions, security, load balancing, carts, language, consent storage) or unknown. Guessed from 280+ known names, and for third-party cookies from 60 known advertising and analytics domains. |
| Tags | Google Analytics, Google Tag Manager, Google Ads, DoubleClick, AdSense, Meta Pixel, TikTok, LinkedIn Insight, Microsoft Clarity and UET, Hotjar, X, Pinterest, Snap, Reddit, Criteo, Taboola, Outbrain, Amazon Ads, HubSpot, Klaviyo, Mixpanel, Segment, Amplitude, Heap, FullStory, Yandex Metrica, Adobe, Matomo and more. Cookieless analytics (Plausible, Fathom, Simple Analytics, Cloudflare Web Analytics, Umami) are listed but never flagged. |
| Consent block | Whether each tag loads right away or is held back until consent, and how (blockedBy). |
| Consent banner | 30+ CMPs by script, configuration or element id, IAB TCF, and consent banner scripts whose file name says so. |
| Google Consent Mode | Whether gtag('consent', 'default', …) is set and its ad_storage, analytics_storage, ad_user_data, ad_personalization defaults. |
| Risk | Plain-English riskFlags, a riskLevel and a one-sentence summary. |
Static check or browser check?
| Static (default) | Browser (renderJavaScript: true) | |
|---|---|---|
| Speed | Fast, 1 GB memory | Slower, 4 GB memory |
| Cookies | Only cookies the server sets in its HTTP response (and redirects) | Also cookies set by JavaScript and third-party cookies |
| Tags | Tags written in the HTML | Also every tag a tag manager fires, seen as real network requests |
| Price | $0.004 per page | same price, $0.004 per page |
Static mode is a quick first screen. Most analytics and advertising cookies are set by JavaScript, so they only show up with "Render JavaScript" on. In static mode, the row says so in notes, and a tag manager without a consent banner is flagged so you know to look deeper. In browser mode, each page opens in a fresh headless Chromium with no cookies, the Actor waits until the network is idle plus two seconds, and never clicks anything.
How to run a cookie consent audit
- Click Try for free and sign in to Apify (the free plan is enough to start).
- Paste one or more URLs into Website URLs, or upload a text file with one URL per line.
- Optional: set Pages per website to audit up to 20 pages per site (the start page plus pages linked from it).
- Optional: turn on Render JavaScript to see cookies set by scripts and every tag fired before consent.
- Click Start. Open the Overview, Risk flags, Cookies or Tracking tags tab when the run finishes.
Input example
{"startUrls": [{ "url": "https://www.example.com" }, { "url": "shop.example.org" }],"maxPagesPerSite": 3,"renderJavaScript": true}
Output example
One item per page (shortened, made-up data):
{"url": "https://www.example.com/","riskLevel": "high","summary": "Likely issue: Meta Pixel, Google Analytics load before consent; 3 advertising/analytics cookie(s) set before consent (no consent banner detected).","riskFlags": ["Meta Pixel loads before consent and no consent banner (CMP) was detected.","Google Analytics loads before consent and no consent banner (CMP) was detected.","Advertising cookies are set before consent: _fbp (Meta Pixel), fr (Meta (Facebook), facebook.com).","Analytics cookies are set before consent: _ga (Google Analytics)."],"cmpDetected": false,"cmpNames": [],"googleConsentMode": { "detected": false, "adStorage": null, "analyticsStorage": null, "adUserData": null, "adPersonalization": null },"cookiesCount": 4,"adsCookiesCount": 2,"analyticsCookiesCount": 1,"thirdPartyCookiesCount": 1,"cookies": [{ "name": "_fbp", "domain": "example.com", "party": "first-party", "category": "ads", "vendor": "Meta Pixel", "matchedRule": "_fbp", "setBy": "browser", "expiresInDays": 90, "secure": false, "httpOnly": false, "sameSite": "Lax" },{ "name": "fr", "domain": "facebook.com", "party": "third-party", "category": "ads", "vendor": "Meta (Facebook)", "matchedRule": "fr on facebook.com", "setBy": "browser", "expiresInDays": 90, "secure": true, "httpOnly": true, "sameSite": "None" },{ "name": "_ga", "domain": "example.com", "party": "first-party", "category": "analytics", "vendor": "Google Analytics", "matchedRule": "_ga", "setBy": "browser", "expiresInDays": 400, "secure": false, "httpOnly": false, "sameSite": null },{ "name": "PHPSESSID", "domain": "www.example.com", "party": "first-party", "category": "functional", "vendor": "Session (server framework)", "matchedRule": "PHPSESSID", "setBy": "http-header", "expiresInDays": null, "secure": true, "httpOnly": true, "sameSite": null }],"trackersBeforeConsent": ["Meta Pixel", "Google Analytics"],"trackers": [{ "vendor": "Meta Pixel", "category": "ads", "loadsBeforeConsent": true, "blockedBy": null, "matchedBy": "network-request", "evidence": "https://connect.facebook.net/en_US/fbevents.js", "cookieless": false, "note": null },{ "vendor": "Google Analytics", "category": "analytics", "loadsBeforeConsent": true, "blockedBy": null, "matchedBy": "script-src", "evidence": "https://www.googletagmanager.com/gtag/js?id=G-XXXXXXX", "cookieless": false, "note": null },{ "vendor": "YouTube (embedded video)", "category": "ads", "loadsBeforeConsent": false, "blockedBy": "data-src instead of src (data-cookieconsent=\"marketing\")", "matchedBy": "iframe", "evidence": "https://www.youtube.com/embed/abc", "cookieless": false, "note": "Standard YouTube embeds can set YouTube/Google cookies. youtube-nocookie.com avoids this until the video plays." }],"notes": ["Checked in a headless browser without clicking anything: cookies and requests are those present before any consent choice.", "…"],"disclaimer": "Automated, heuristic check of what happens before a visitor makes a consent choice. Not legal advice.","error": null}
Pages that can't be audited get a row with an error code (invalid-url, blocked-by-robots-txt, http-404, http-403, not-html, request-failed, …) and cost nothing.
How is the risk level decided?
| Risk level | When |
|---|---|
| high | An advertising or analytics tag loads before consent and no consent banner was found, or advertising/analytics cookies are already set before consent. |
| medium | A tag loads without a consent block although a consent banner was found, or a tag manager loads with no banner (static mode can't see what it fires). |
| low | Only minor points: Google tags that load but default to "denied" in Google Consent Mode, or cookies whose purpose can't be guessed from the name. |
| none | No advertising or analytics tags or cookies found before consent. |
The wording is deliberately careful ("likely", "possible issue"). It is a way to find and prioritise pages to look at, not a legal verdict.
How much does a cookie audit cost?
This Actor uses pay per event. You pay only for pages that were actually audited:
| Event | Price |
|---|---|
| Page audited | $0.004 per page |
| Page that failed, was blocked by robots.txt or returned an error | free |
- 100 pages cost $0.40; 1,000 pages cost $4.
- The price is the same with or without browser rendering.
- Apify also charges a tiny standard start fee per run ($0.00005 per GB of memory, so $0.00005 for a normal run and $0.0002 with browser rendering).
- Apify's free plan includes $5 of monthly usage, enough for about 1,000 audited pages a month.
- Set Maximum cost per run in the run options and the Actor stops when it is reached.
Limitations
- Location matters. The Actor runs on Apify's servers in the United States and uses no proxy. Many consent banners only hold tags back for visitors from the EU or UK, so a site can look worse here than it does for European visitors. When a consent banner is found and tracking still loads, the row says so in
notes. With Render JavaScript on and OneTrust,cmpVisitorCountryshows the country the banner assigned (usuallyUS), and the risk level is capped at medium. - Static mode only sees server cookies and tags written in the HTML. Cookies set by JavaScript, third-party cookies and tags fired by a tag manager need Render JavaScript.
- Nothing is clicked. The check covers the state before any consent choice. It doesn't test whether "Reject all" works, or what happens after scrolling or a long delay.
- Categories are guessed from names and domains. Unknown cookies are listed as
unknownso you can check them yourself; a first-party cookie with a generic name can't be categorised reliably. - CMP detection is by known signatures. A self-built banner without a telling script name may not be recognised.
- The Actor respects robots.txt and waits at least one second between requests to the same site. Sites that block automated visitors return an error row (free). Login-protected pages are not supported.
- This is not legal advice and not a compliance certificate.
FAQ
Does this tell me if my site is GDPR compliant?
No. It shows what loads and which cookies exist before a visitor makes a choice, and flags what is likely to need consent under the GDPR and the ePrivacy rules (cookie laws). Some cookies are strictly necessary and need no consent; some tags may be fine under your legal basis or configuration. Use the results to find what to look at, and ask a qualified advisor for legal decisions.
Why is a cookie marked "unknown"?
Its name isn't in the list of known cookies, and its domain isn't a known advertising or analytics domain. Site-specific cookies are often like that. The row lists them in a separate flag so you can check what they do.
Why do I see trackers although the site has a consent banner?
Either the tags are not connected to the banner, or the banner only blocks tags for visitors from certain countries. The Actor runs from the United States, so a banner that only applies to EU visitors will look inactive here. See notes and, in browser mode with OneTrust, cmpVisitorCountry.
Are cookie values stored?
No. Cookie values often contain unique visitor IDs, so the Actor only keeps the name, domain and attributes. It collects no personal data.
Can I run it on a schedule or from my code?
Yes. Create a task with your URLs and add a schedule in Apify Console, or call the Actor through the Apify API, the JavaScript or Python client, or integrations such as Make, Zapier and n8n.
Why did a page return blocked-by-robots-txt or http-403?
The site's robots.txt disallows crawlers for that page, or the site blocks automated visitors. These rows are free.
More tools from the same developer
All pay-per-result, no proxy or login needed, built and maintained by the same developer:
Website audits
- Website Accessibility Checker: WCAG 2.2 & EAA: accessibility issues with fixes, SEO basics and security headers.
- AI Crawler Access Checker: robots.txt & llms.txt: which AI crawlers a site allows, plus llms.txt.
- Website Change Monitor: Diffs, Prices & Alerts: get a row only when a page changes, with a clean diff.
Company data and compliance
- Company Contact Finder: Emails, Phones & Socials: contact details published on company websites.
- UK New Companies Feed: Companies House Daily: newly incorporated UK companies with sector filters.
- EU VAT Number Validator: Bulk VIES Checker: bulk VAT checks with name, address and consultation number.
- LEI Corporate Tree: GLEIF Parents & Subsidiaries: LEI lookup with parents, subsidiaries and a KYC summary.
Market signals
- US WARN Layoff Notices: 12 States Daily Feed: layoff and plant closure notices from official state sources.
- US Product Recalls Monitor: FDA & CPSC Feed: FDA and CPSC recalls in one feed, with severity.
Feedback
Found a cookie or tag that should be recognised, or a false alarm? Open an issue on the Issues tab with the page URL. New vendors are added to the maintained lists quickly.
