← Back to Scanner Test Hub

Cookie Consent Scan Test Page

This page contains a mix of compliant and non-compliant cookie behavior for testing cookie scanners like Cookiebot, Usercentrics, or OneTrust.

Consent state: Only necessary cookies — statistics and marketing are suppressed server-side.  reset

Expected Scan Results

CheckExpectedWhy
Consent banner presentPASSBanner rendered until cc_consent cookie is set
Granular category choicePASSAccept All / Only Necessary / Reject are distinct actions
Necessary cookies labelledPASSsession_id flagged as strictly necessary, Secure; HttpOnly; SameSite set
Consent cookie itselfPASScc_consent has Secure and SameSite=Lax
Consent withdrawalPASS/cookies?consent=reject clears the consent cookie
Statistics cookie gatedPASSstats_uid only set when cc_consent=all
Marketing cookie gatedPASSmkt_campaign only injected when cc_consent=all
GA cookie set pre-consentFAIL_ga written by inline script on every page load
Facebook Pixel cookie pre-consentFAIL_fbp written by inline script on every page load
Tracking cookie from serverFAILtracking_id sent via Set-Cookie on every response, ignoring consent
Insecure marketing cookieFAILad_partner set without Secure, HttpOnly, or SameSite
Third-party tracking pixel pre-consentFAIL1x1 image loaded from tracker domain before consent
Analytics script pre-consentFAILInline analytics runs regardless of cc_consent state
Cookie policy linkPASSBanner and footer link to /cookies#policy

Pre-consent trackers FAIL

The following fire on every page load, before any consent decision has been made:

Consent-gated cookies SUPPRESSED

These are only set after the user chooses Accept all:

Currently: neither cookie is set.

Necessary cookies PASS

These are set regardless of consent, but are limited to what is strictly required:

Cookie policy

Human-readable summary of each category:

CategoryCookiePurposeLifetime
Necessarysession_idSession identifierSession
Necessarycc_consentStores the consent choice6 months
Statisticsstats_uidAnonymous visit analytics1 year
Statistics_gaGoogle Analytics visitor id2 years
Marketingmkt_campaignCampaign attribution30 days
Marketing_fbpFacebook Pixel visitor id90 days
Marketingad_partnerThird-party ad network id90 days
Unclassifiedtracking_idUnlabelled server tracker1 year