howsafeismyapp

Free tool

Website Cookie & Tracker Scanner

Enter a URL to scan a website for cookies and trackers that run before anyone has consented: analytics cookies, ad pixels and third-party tracking scripts. The result names each tracking cookie and the vendor behind it — the part a cookie banner is supposed to hold back under § 25 TDDDG and the ePrivacy rules.

passive · no signup · nothing stored

What this checks

How the check works

We load your page like a first-time visitor and record what happens before any consent: tracking cookies written by the first response (named by cookie and vendor, never by value) and requests to third-party analytics and ad domains. If it fires on load, it fired without consent. Passive, GET only, nothing stored.

What is a tracker cookie?

A tracker cookie (or tracking cookie) is a cookie whose job is to recognise the same visitor across page views, sessions or websites so their behaviour can be measured or profiled. Google Analytics' _ga, Meta's _fbp, Hotjar's _hjSession and TikTok's _ttp are typical examples. A functional cookie such as a login session is different: the site needs it to work, and it needs no consent.

Tracker cookies come in two kinds. First-party tracker cookies are set on your own domain by a tracking script — that is what _ga is — so “first-party” says nothing about whether consent is needed. Third-party tracker cookies are set by another domain, mostly ad networks, and browsers increasingly block them. Both need opt-in before they are written, under § 25 TDDDG and Art. 5(3) of the ePrivacy Directive.

What the cookie scan finds — and what it can't

The scanner reads the Set-Cookie headers of the first response and matches the cookie names against those of known analytics and advertising vendors. It also scans the delivered HTML and JavaScript bundles for the loader URLs of those vendors. What you get is a list of tracking cookies and trackers that are present before any banner could have been clicked.

Cookies written later by JavaScript, after the page renders, are not visible to a passive scan, so a full browser session may show more cookies than this page does. Treat the list as a floor, not a ceiling: every cookie named here was set without consent.

Common questions

How do I scan a website for cookies?

Paste the address into the field above and click Check. The scan takes a few seconds and lists the tracking cookies and third-party trackers it saw before consent, with the vendor behind each. It works on any public website, not only your own.

Is this cookie scanner free?

Yes. It runs online, needs no signup, and nothing is stored. It is one slice of our 15-point GDPR and security check, which is free as well.

Why does it matter if trackers load before consent?

§ 25 TDDDG (Germany's ePrivacy rule) requires consent before non-essential cookies or tracking run. A banner that appears after the scripts already fired protects nobody — the data already left.

What counts as a third-party tracker?

Any script or request to a domain other than yours whose purpose is analytics, advertising or profiling — Google Analytics, Meta Pixel, TikTok, Hotjar and the like. The result lists which vendors it saw.

Why does the scan show fewer cookies than my browser's developer tools?

Because it is passive: it reads what the server sends and what the page's code references, without executing JavaScript. Cookies set by scripts after the page renders are not visible to it. The cookies it does list arrive with the very first response, which is the clearest case of tracking before consent.

How do I fix trackers firing too early?

Route every tracking script through a consent tool in its blocking mode so nothing loads until opt-in — or remove the tracker. Then re-test in a private window: nothing third-party should load before you click accept.

All free tools · every check explained · run the full 15-point check