Privacy

Free Cookie and Tracker Scanner

See every tracker, third-party script and cookie a page loads — and whether your consent banner and privacy policy actually match what is running.

Free · No signup · Runs a full siteIQ audit on your URL

Most site owners genuinely do not know what their website loads. Trackers arrive with a marketing campaign, a chat widget, an embedded video or a plugin, and nobody removes them afterwards — so the privacy policy written two years ago describes a site that no longer exists.

This scan loads the page the way a visitor's browser does and reports every tracker and third-party script it finds, how many cookies get set, and whether a consent banner and privacy policy are present at all.

What this tool checks

Trackers detected

Analytics, advertising and social trackers, each categorised by what it collects.

GDPR risk rating

Which detected trackers carry the highest regulatory risk under GDPR.

Cookie count

How many cookies the page sets, including ones set before any consent is given.

Consent banner

Whether a cookie consent mechanism is present on the page at all.

Privacy policy

Whether a linked privacy policy and cookie policy actually exist.

Third-party scripts

Every external domain the page loads code from — each one is a party with access.

Why it matters

Under GDPR, non-essential cookies require consent before they are set, not after. A site that fires analytics and advertising trackers on page load and shows the banner afterwards is not compliant, no matter how well-worded the banner is. That ordering is the single most common failure.

There is a performance and security dimension too. Every third-party script is a request, an execution cost, and a party that can change what runs on your site without telling you. Scripts nobody remembers adding are the ones nobody is monitoring.

How to read your results

  • Start with high-risk trackers — advertising and cross-site tracking carry the most regulatory exposure.
  • If cookies are set before consent, that is the finding to fix first regardless of how many there are.
  • Compare the detected trackers against what your privacy policy actually lists. A mismatch is the thing a regulator or an enterprise client will notice.
  • Any third-party script you cannot explain should be removed. Unexplained scripts are both a privacy and a security problem.
  • Re-scan after changes — tag managers make it easy to add trackers without a deploy, so this drifts.

Frequently asked questions

Does this make my site GDPR compliant?

No. It is a technical scan, not legal advice. It tells you what your site actually loads so you can compare that against your policies — which is the factual groundwork compliance rests on, but not a substitute for legal review.

Why does it find trackers I never added?

Trackers arrive indirectly — through tag managers, embedded video players, chat widgets, plugins and A/B testing tools. One embed can pull in several third parties of its own.

What counts as a high-risk tracker?

Broadly, anything performing cross-site tracking or advertising profiling rather than first-party analytics. These are the categories regulators focus on and the ones most likely to need explicit consent.

Can I scan a competitor's site?

Yes. The scan only loads publicly available pages the way any browser would, so it works on any public URL.

Do cookies affect my site speed?

Cookies themselves are small. The scripts that set them are not — third-party tags are frequently the largest single cause of a slow page.

Read next

Security Headers Explained: What Each One Does and How to Set It

More free tools

Want the full picture?

Run a complete siteIQ audit — security, performance, SEO, accessibility and infrastructure — 65+ checks across 8 categories, in one report.

Free · No signup · Runs a full siteIQ audit on your URL