Automatic cookie scanner
Find out what cookies your website uses
Don't know what Cookies your website creates? Our scanner will find out in 60 seconds. Automatic detection, categorisation and regular updates.
How the scanner works
Advanced technology for a complete overview of First-party cookies and Third-party cookies on your website.
Deep scanning
Browses your website like a real user and detects all cookies.
Automatic categorisation
Cookies are automatically placed into the correct categories by purpose.
Known cookie database
We recognise thousands of cookies from GA, FB, Hotjar, Clarity and more.
Regular updates
Automatic repeated scanning according to your plan.
Change notifications
You receive a notification when new cookies appear on your website.
Detailed report
Clear output with the name, purpose and lifetime of each cookie.
What the scanner detects
Automatic categorisation into 4 groups: Essential cookies, Analytics cookies, Marketing cookies a Functional cookies.
Necessary
Cookies essential for website operation (session, cart, login)
Analytical
Cookies for measuring traffic and user behaviour
Marketing
Cookies for advertising, remarketing and personalisation
Preference
Cookies for storing user preferences
How to get started
Run your first scan in less than a minute.
Add your website
Enter your website URL into the Consentio dashboard.
Run the scan
Click the Scan button. The scan runs in the background.
Review the results
Within seconds you will see a complete list of cookies.
Automatic updates
The scanner regularly checks for changes on your website.
Why regular scanning matters
Cookies on a website change much more often than people realise. Add a new WordPress plugin, install a chat widget, swap analytics providers or turn on a retargeting campaign: and suddenly trackers are running that visitors know nothing about and that your cookie policy fails to mention. GDPR Article 13(3) requires the controller to re-inform data subjects whenever such changes occur.
European supervisory authorities have made this a clear enforcement priority since 2022. The CNIL fined Google EUR 150 million and Meta EUR 60 million for cookie-refusal failures, while the ICO has issued multiple six-figure UK enforcement notices for cookie policies that no longer matched the cookies actually being set. The most common failure mode is a privacy policy written two years ago while the site has since picked up Hotjar, Microsoft Clarity or TikTok Pixel. Automated scanning prevents that drift by flagging changes within minutes and proposing a policy refresh.
Continuous scanning also has practical impact on Google Consent Mode v2. If Consentio detects that you are loading Google Ads or Google Analytics 4, it automatically recommends the correct consent signals and category mappings so that remarketing and conversion measurement keep working under EEA law. Without correctly wired cookies and consent signals, Google has restricted reports and audiences for European traffic since March 2024.
The scanner also documents the state of your site over time. If you ever face an ICO audit or a data subject access request under GDPR Article 15, you have a full scan history as evidence that you were actively tracking cookies and responding to changes. Full logs are retained for the period required by GDPR and can be exported to PDF or CSV at any time.
How Consentio scanner compares
Side-by-side feature comparison against the leading cookie consent platforms and a manual DevTools audit. Enforcement under GDPR Article 7 and the ePrivacy Directive applies to every site that uses non-essential cookies, regardless of which platform you choose.
| Capability | Consentio | CookieBot | CookieYes | OneTrust | Manual (DevTools) |
|---|---|---|---|---|---|
| Headless browser crawl | Yes (Puppeteer) | Yes | Yes | Yes | No |
| Third-party cookie detection | Yes | Yes | Yes | Yes | Limited |
| Auto-categorisation (4 groups) | Yes | Yes | Yes | Yes | No |
| Known-cookies database | Thousands | Large | Medium | Large | None |
| Scan frequency (Pro plan) | Daily | Monthly | Monthly | Configurable | None |
| New-cookie email alerts | Yes | Yes | Yes | Yes | No |
| Page-count limits | Unlimited | 100 / subdomain | 500 / site | Unlimited | 1 page at a time |
Frequently asked questions
How does the automatic cookie scanner work?
The scanner uses a headless browser (Puppeteer) to crawl your website. It simulates real user behaviour and records all cookies the website creates. The process is fully automatic and safe.
How often is scanning performed?
Frequency depends on your plan. The FREE plan offers scanning once every 30 days; the Pro plan offers daily automatic scanning.
How are cookies categorised?
The scanner automatically categorises cookies into 4 groups: Necessary (website functionality), Analytical (traffic measurement), Marketing (advertising and remarketing) and Preference (user settings).
Does the scanner detect third-party cookies too?
Yes, the scanner detects both first-party cookies (created by your website) and third-party cookies (from external services such as Google Analytics, Facebook Pixel, Hotjar etc.).
Is a scanner enough to be GDPR-compliant on its own?
No. The scanner solves cookie discovery, but GDPR requires more: a banner that captures freely-given, specific, informed and unambiguous consent (Article 7), a cookie policy describing the purpose of each cookie (Article 13) and an easy way to withdraw consent. The ICO has been explicit on this in its cookie guidance, and the EDPB Guidelines 05/2020 confirm consent must be as easy to refuse as to give. Consentio bundles scanner, banner and policy in one plan so the three stay in sync.
How does the scanner know what each cookie does?
We maintain a database of thousands of known cookies from Google Analytics, Google Ads, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn Insight Tag, TikTok Pixel and similar services. When a cookie matches a known signature, the scanner auto-fills purpose, lifetime, provider and category. For unknown cookies it flags them as "unknown" and asks for manual classification: both the ICO and CNIL recommend a conservative approach (treat unknown cookies as non-essential by default).
Does the scanner work on pages behind a login?
Public pages are scanned automatically. For authenticated pages (admin areas, client dashboards, member-only content) we accept stored credentials, encrypted at rest. The Pro plan supports up to 5 login contexts per site, which covers e-commerce sites with customer / B2B / admin roles. Many cookies are only set after authentication, so missing this step is one of the most common reasons sites fail an ICO audit.
Does it scan the mobile version of my site as well?
Yes. The scanner launches a headless browser with desktop, tablet and mobile emulation in turn. Cookies that only fire on the mobile breakpoint (AMP pages, responsive ad scripts, mobile-only chat widgets) are captured the same way. This matters because the EDPB Guidelines 03/2022 on dark patterns explicitly note that consent must reflect what is actually happening: if your mobile site loads more trackers than the desktop one, users must be informed.
Aligned with European data protection authorities
The Consentio cookie scanner is built to help meet the requirements of the following legal frameworks and supervisory authority guidance:
- GDPR (Regulation (EU) 2016/679)
- ePrivacy Directive (2002/58/EC), Article 5(3)
- ICO: UK Information Commissioner guidance on cookies
- CNIL: French data protection authority
- EDPB: Guidelines 05/2020 on consent
Last updated:
Solve cookies today.
Sleep peacefully tomorrow.
Try for free - No card required
- 5 minutes to implementation
- Made in EU