Free Tool
Check Your Website's Cookies in Seconds
Our free cookie scanner crawls your website, identifies every cookie and tracking script, and shows you exactly what needs fixing for GDPR compliance.
Scan Your Website Free →How it works
Three steps to a full cookie audit.
-
Enter your URL
Paste your website address into the scanner on our homepage. Any publicly accessible URL works — no account creation, no installation, and no verification required. Just type in your domain and hit scan. The cookie checker accepts any format: with or without
https://, with or withoutwww. We will normalize the URL and begin the audit immediately. -
We scan your site
Our headless browser loads your website exactly the way a real first-time visitor would. It does not use cached data, stored cookies, or previous consent choices. This is important because GDPR compliance is measured by what happens on the very first visit, before any consent is given. During the scan, we detect every cookie set by your domain and by third parties, identify all tracking scripts and pixels, check whether a consent banner is present, and evaluate how that banner behaves. The entire process takes approximately 30 seconds.
-
Get your report
Once the scan completes, you receive a detailed compliance report. Every cookie found on your site is listed and categorized. You get a compliance score from 0 to 100, calculated based on your consent mechanisms, cookie handling practices, privacy policy presence, and overall GDPR posture. Each issue is categorized by severity — critical, important, or advisory — and accompanied by specific fix instructions that tell you exactly what to change and how to change it. No vague recommendations. No generic advice. Just clear, actionable steps prioritized by what matters most.
Report details
What the cookie checker report includes.
Every scan produces a comprehensive breakdown of your website's cookie and tracking behavior, compliance posture, and specific remediation guidance.
Cookie inventory
Every cookie found on your website is identified, named, and sorted into one of four categories: strictly necessary, analytics, marketing, or preferences. For each cookie, the report shows the domain that set it, whether it is a first-party or third-party cookie, its expiration time, and whether it is flagged as HTTP-only or secure. This inventory gives you a complete picture of what data your site collects from the very first page load. Many website owners are surprised to discover cookies they did not know existed — set by embedded widgets, social media buttons, or third-party scripts loaded by their theme or CMS. The cookie inventory makes every one of them visible, so you can decide which are necessary and which need to be blocked until consent is granted.
Third-party scripts
Beyond cookies, our website cookie checker identifies every external script loaded on your page. This includes analytics services like Google Analytics, advertising pixels from Meta and TikTok, customer chat widgets, A/B testing tools, heatmap providers, and embedded video players. Each script is listed with its source domain, a description of its purpose, and its compliance status. Scripts that set cookies or transmit data before consent are flagged as violations. This is critical because many GDPR enforcement actions have targeted websites that load third-party tracking scripts without obtaining prior consent from visitors. Knowing which scripts are present — and which fire before consent — is the first step toward fixing the problem.
Compliance score
Your website receives a GDPR compliance score between 0 and 100. This score is not a simple cookie count — it is a weighted assessment based on multiple compliance dimensions: whether a consent mechanism is present and functional, how cookies are handled before and after consent, whether your privacy policy exists and covers the required GDPR sections, and whether third-party data transfers are disclosed. The score gives you a single, easy-to-understand number that represents your overall compliance posture. It is useful for tracking progress over time, comparing your site against industry benchmarks, and demonstrating due diligence to stakeholders or regulators.
Consent banner check
The cookie checker evaluates whether your website displays a consent banner, and if so, whether that banner meets GDPR requirements. We check for the presence of a clearly visible banner on first visit, whether it loads before any non-essential cookies are set, whether it provides separate accept and reject buttons with equal prominence, and whether it allows visitors to manage individual cookie categories. We also detect dark patterns — design choices that manipulate visitors into accepting all cookies, such as hiding the reject option, using confusing language, or pre-checking consent categories. A banner that merely exists is not enough under GDPR. It must provide genuine, informed choice, and our scanner verifies that it does.
Privacy policy audit
GDPR requires that every website processing personal data has a privacy policy that is accessible, comprehensive, and accurate. Our cookie scanner checks whether a privacy policy page exists on your site, whether it is linked from your homepage and consent banner, and whether it covers the key sections mandated by GDPR Articles 13 and 14. These sections include the identity and contact details of the data controller, the purposes and legal basis for processing, categories of personal data collected, data retention periods, third-party data sharing disclosures, information about international data transfers, and details about data subject rights including the right to access, rectify, erase, and port personal data. Missing sections are flagged in the report with specific guidance on what to add.
Fix instructions
Every issue identified by the cookie checker comes with step-by-step fix instructions. These are not generic suggestions like "review your cookie policy." They are specific, actionable remediation steps tailored to the issue found. If the scanner detects Google Analytics loading before consent, the fix instructions explain exactly how to configure deferred loading or implement consent-based activation. If your privacy policy is missing a data retention section, the instructions tell you what to write and where to add it. Issues are prioritized by severity so you know what to fix first. Critical issues — those that represent an immediate compliance risk such as tracking cookies firing without consent — appear at the top of the list. Advisory issues, like missing optional disclosures, appear at the bottom.
Understanding your score
What your compliance score means.
After scanning your website for cookies, trackers, and consent mechanisms, we calculate a GDPR compliance score from 0 to 100. Here is how to interpret the result and what each range means for your website's regulatory risk.
Excellent compliance
Your website demonstrates strong GDPR compliance. A consent mechanism is in place and working correctly, cookies are blocked until consent is granted, your privacy policy covers the required sections, and third-party scripts are properly managed. Sites in this range have minimal regulatory risk. You may have a few advisory-level suggestions to further strengthen your posture, but no critical or important issues were found. Keep monitoring with scheduled re-scans to maintain this score as your site evolves and new scripts or plugins are added.
Good, minor issues
Your site has the foundations of GDPR compliance in place, but there are some issues that need attention. Common findings in this range include a consent banner that is present but missing a clear reject option, a privacy policy that exists but is missing one or two required sections, or a small number of analytics cookies that load before consent is confirmed. These are fixable issues that typically take less than an hour to resolve. Addressing them will bring your score into the excellent range and significantly reduce your exposure to regulatory scrutiny.
Needs attention
Your website has notable compliance gaps that should be addressed promptly. Sites in this range often have a consent banner that is partially functional — perhaps it appears but does not actually block cookies when a visitor declines — or they are missing a privacy policy entirely. Third-party marketing and analytics scripts may be firing on page load without waiting for consent. These are the kinds of issues that data protection authorities actively look for during website audits. Fixing them is not optional if you want to operate within GDPR requirements. The good news is that the report includes prioritized fix instructions for every issue found.
Significant compliance gaps
A score below 50 indicates serious GDPR violations that require immediate action. Websites in this range typically have no consent mechanism at all, set multiple tracking cookies on every page load without any form of consent, lack a privacy policy, and may be sharing visitor data with third parties without disclosure. This level of non-compliance carries real regulatory risk. Under GDPR, fines can reach up to 4% of annual global turnover or 20 million euros, whichever is greater. We strongly recommend addressing critical issues immediately and creating a free FixGDPR account to access the consent banner, privacy policy generator, and continuous monitoring tools.
Frequently asked questions
Common questions about the cookie checker.
Is the cookie checker really free?
Yes, completely free with unlimited scans. You can check cookies on any website as many times as you want without creating an account or entering payment information. There are no trial periods, no scan limits, and no feature gates on the basic cookie scanning functionality. We built the free cookie checker so that every website owner can understand their compliance posture, regardless of budget. If you want additional features like a consent banner, privacy policy generator, scheduled monitoring, or AI-powered fix instructions, those are available through our paid plans — but the core website cookie checker will always be free.
What cookies does the scanner detect?
The cookie scanner detects every type of cookie that your website sets during a first-time visit. This includes first-party cookies set by your own domain, third-party cookies set by external services and advertising networks, session cookies that expire when the browser is closed, persistent cookies that remain on the visitor's device for days, weeks, or years, HTTP-only cookies that cannot be accessed by JavaScript, secure cookies restricted to HTTPS connections, and tracking pixels that function as cookie-like identifiers. We also detect local storage and session storage entries used by modern tracking scripts as alternatives to traditional cookies. The scanner identifies the full range of client-side data collection mechanisms that GDPR considers personal data processing.
How is this different from browser DevTools?
Browser developer tools show you the cookies currently stored in your browser, but they do not tell you the full compliance picture. When you open DevTools on your own site, you are likely seeing cookies influenced by your own browsing history, cached consent choices, and authenticated sessions. Our cookie checker is different in several important ways. First, we simulate a genuine first visit with no prior cookies, no cached consent, and no authentication — exactly the way a new visitor or a regulatory auditor would experience your site. Second, we do not just list cookies; we categorize them by purpose, identify which ones are set before consent, and flag specific GDPR violations. Third, we evaluate your consent banner's behavior, check your privacy policy for completeness, score your overall compliance, and provide actionable fix instructions. DevTools shows you raw data. Our cookie checker gives you a compliance audit.
Do you store my scan results?
If you run a scan without an account, the results are displayed once in your browser and are not permanently stored on our servers. Once you close or navigate away from the results page, they are gone. If you create a free FixGDPR account, your scan results are saved to your dashboard and stored for 12 months. This allows you to track your compliance score over time, compare results across multiple scans, and demonstrate a history of compliance improvement to auditors or regulators. Saved results include the full cookie inventory, compliance score, issue list, and fix instructions from each scan. You can delete your account and all associated scan data at any time from your account settings.
Can I scan any website?
Yes, you can scan any publicly accessible URL. The cookie checker works with any website that can be loaded in a standard web browser — WordPress sites, Shopify stores, custom-built applications, single-page apps, static sites, and everything in between. The only requirement is that the URL is publicly reachable. You cannot scan pages behind authentication walls, password-protected staging environments, or sites restricted to specific IP addresses. If you need to scan an internal or staging site, you can temporarily make it accessible during the scan or use our WordPress plugin which runs scans directly from your server.
Get started
Ready to check your website?
Run a free cookie scan in under 30 seconds. See exactly what cookies your site sets, which ones violate GDPR, and how to fix every issue.
Related Resources
Learn more about cookie compliance.
Everything you need to know about implementing cookie consent that meets GDPR requirements, including banner design, consent storage, and user choice management.
A detailed breakdown of what the law actually requires for cookie consent, covering ePrivacy Directive obligations, GDPR standards, and recent enforcement trends.
A practical, step-by-step checklist for making your website GDPR compliant, from cookies and consent to privacy policies and data subject rights.
How to build or choose a consent banner that meets GDPR and ePrivacy requirements without frustrating your visitors or harming your conversion rate.