How a scan works

Short answer: untick opens your site in a real browser with no cookies, as a first-time visitor would, and records what happens before a choice, after clicking your banner’s “Reject”, after “Accept” and after withdrawing consent. It then visits your key pages. Findings come from what the browser saw, each with screenshots and the requests behind it.

MethodologyLast reviewed Automated checks and general information, not legal advice.

The browser

  • A real Chromium browser running on Cloudflare, with a fresh profile for every visitor: no cookies, no storage, no earlier choices.
  • A desktop window of 1280 × 800 pixels, British English, on Central European time.
  • Service workers are switched off and every address is checked before it loads, so a scan can never be pointed at a private network.

What happens, step by step

  1. Load the page as a stranger

    A fresh browser opens your page and waits for it to settle without touching anything. We record every request and cookie with its timing, and match them against more than 30 analytics, advertising and session-replay vendors.

  2. Find the consent banner

    We look for the banner on the page, inside frames and inside shadow DOM, and recognise the common consent tools by their markup. Rules read the buttons (accept, reject, settings) in many languages; AI helps only when the wording is unusual.

  3. Click “Reject” and reload

    We click the banner’s own reject button, reload the page and record what still fires. Requests already on their way when we clicked don’t count against you.

  4. Open the preferences as a new visitor

    A second fresh visitor opens the banner’s settings layer and reads every category before changing anything, to catch options that are switched on by default.

  5. Click “Accept”, then change our mind

    A third visitor accepts and reloads, so we can read what your Google tags report after consent and how long tracking cookies are set to last. Then it looks for your “Cookie settings” link or consent icon, withdraws through it and records anything that still fires.

  6. Visit with Global Privacy Control on

    When ad trackers load without a choice (no banner, or a US-style “Do not sell or share” link), another visitor comes with GPC switched on. Ad trackers that still load are reported.

  7. Re-read any countdown

    If a timer is counting down, another first-time visitor reads it again at least 20 seconds later. A deadline that moves later is a timer that restarts per visitor.

  8. Visit your key pages

    We pick the pages most likely to hold forms, prices and pressure: checkout, signup, pricing, newsletter, product and contact pages. On each we read checkboxes as they load, timers, stock and viewer claims, decline wording, the privacy policy link and, for EU shops, the withdrawal button.

  9. Keep the evidence

    Screenshots with the problem outlined, the exact requests and cookies, and the wording we read, so anyone can check our work.

How many pages

Free scans check your homepage. Pro checks up to 8 pages per scan, and Agency up to 15. When a free scan finds key pages it didn’t open, the report lists them.

From findings to a grade

Each kind of problem counts once, however many pages it appears on, and takes points off a score of 100 depending on how serious it is:

  • Critical−30 points
  • High−18 points
  • Medium−9 points
  • Low−3 points

90 or more is an A, 75 a B, 55 a C and 35 a D; anything lower is an F. The Google Consent Mode panel explains your ad signals but doesn’t change the grade.

How we avoid false alarms

  • Locked “necessary” toggles and “remember me” boxes are ignored.
  • Google tags that report consent as denied aren’t counted as tracking.
  • A countdown is only called fake with two readings from two different first-time visitors.
  • The withdrawal button is only checked on shops that sell to EU consumers.
  • Each scarcity claim is counted once and quoted in full.

What an automated scan can’t see

  • Pages behind a login, and flows that need a real order or payment.
  • Server-side tracking, which never shows up in the browser.
  • Banners shown only to visitors from certain countries or on mobile.
  • A/B tests: we see the version our browser was given.
  • Pages we didn’t visit, beyond the key pages your plan includes.
  • Pop-ups that need scrolling, time on page or an exit intent.
  • Whether your privacy policy says the right things, and whether stock or viewer numbers are true.
  • Prices on pages that only show them after JavaScript runs: the daily price check reads the page’s own product data.

untick shows risk with evidence. It isn’t legal advice, and a clean scan isn’t a certificate of compliance.

Questions people ask

Does the scan affect my analytics or my visitors?

It shows up like a few ordinary visits. Nothing is installed on your site, and our browser only loads public pages.

Why didn’t the scan find something I know is there?

Usually because it sits behind a login, only appears in some countries, or is on a page outside the key pages we picked. The report lists every page we checked; tell us at hello@untick.io and we’ll look.

What if a finding is wrong?

Every finding shows its evidence, so you can see exactly what we saw. If it’s wrong, email hello@untick.io: every change to the scanner is tested against a set of reference sites with known problems and known-clean ones before it ships.

See it on your own site.

Find out in about a minute. Free, no signup.

No signup · nothing installed · results in about a minute