Live checkFree, no sign-up

Cookie and Tracker Audit

See the cookies, tracking scripts and consent tool trace in your site's first response, in one screen.

rabbitclip · Tool

This tool reads the first response your server returns, before a visitor has made any consent choice at all. From the Set-Cookie headers it pulls each cookie's name, duration (session or day based) and security flags such as Secure, HttpOnly and SameSite, it never reveals the cookie's actual value. It then scans the HTML for known tracking scripts, Google Analytics, Tag Manager, Meta Pixel, TikTok, LinkedIn, Hotjar, Clarity and Yandex Metrica among them, for traces of consent tools such as Cookiebot, OneTrust or CookieYes, and for a link to a cookie or privacy policy.

A finding is flagged for attention in two cases: a known tracking script appears with no trace of a consent tool, or a marketing cookie such as _fbp or _gcl_au arrives before the visitor has made any choice. Cookie names get classified as necessary, measurement, marketing or unknown based on well known patterns, this classification rests on the name itself and doesn't guarantee what the site actually does with it. In a well built setup, marketing and measurement cookies only arrive after consent is given, not the moment the page loads.

This audit only reads the page's first response, it cannot see cookies that JavaScript plants in the browser later, after a visitor clicks a button, or scripts that load with a delay. A known tracker not showing up doesn't mean it isn't used at all, it may be custom built or hidden through a locally hosted setup. Most importantly, this tool is not legal advice and does not substitute for a legal assessment, checking your cookie policy against GDPR or similar rules still needs a qualified lawyer.

FAQ

Can I see the actual cookie values?

No, the tool only shows a cookie's name, duration and security flags, never its value, since that value can hold sensitive session data.

No consent tool was found, does that mean I'm breaking GDPR?

No, the tool only looks for the HTML trace left by known consent tools such as Cookiebot or OneTrust; a custom or self hosted solution can stay invisible to it. This finding is not a legal assessment on its own.

What should I do when I see a tracking script listed?

First check whether it fires before or after consent, if a marketing or measurement script runs without consent you need to review your cookie policy and consent setup.

Is the address I enter stored anywhere?

The address is not stored permanently; if the same one is checked again shortly after, the result stays in server memory for about ten minutes to answer faster, then it is cleared.

Related articles

Other tools

If you don’t know where to start, that’s fine; you’re in the right place.

Your project might already be clear in your head, or still just an idea. Either works. On a short call we talk through where you are and where you could go, together.

Let’s set up a call
Let’s talk about your project