howsafeismyapp

Free tool

Cookie & Tracker Scanner

Under § 25 TDDDG, consent has to come first — yet most sites fire analytics, ad pixels and tracking cookies the moment the page loads. Paste your URL to see what runs before anyone could say yes.

passive · no signup · nothing stored

What this checks

How the check works

We load your page like a first-time visitor and record what happens before any consent: requests to third-party analytics and ad domains, and tracking cookies written to the browser. If it fires on load, it fired without consent. Passive, GET only, nothing stored.

Common questions

Why does it matter if trackers load before consent?

§ 25 TDDDG (Germany's ePrivacy rule) requires consent before non-essential cookies or tracking run. A banner that appears after the scripts already fired protects nobody — the data already left.

What counts as a third-party tracker?

Any script or request to a domain other than yours whose purpose is analytics, advertising or profiling — Google Analytics, Meta Pixel, TikTok, Hotjar and the like. The scan lists which domains it saw.

How do I fix trackers firing too early?

Route every tracking script through a consent tool in its blocking mode so nothing loads until opt-in — or remove the tracker. Then re-test in a private window: nothing third-party should load before you click accept.

All free tools · every check explained · run the full 15-point check