Docs menu
Cookie scanner
The CookieHug cookie scanner: real-browser scans, nightly subpage rotation, the four consent-health scenarios and cookie classification.
What the scanner does
The CookieHug scanner visits your website with a real browser (not a plain HTTP crawler), so it sees what a visitor sees: cookies set by JavaScript, dynamically loaded scripts and third-party resources. Collected cookies and services are classified into consent categories based on the service catalog and cookie catalog we maintain (PL/EN descriptions).
Scan types
- Panel scan — started manually for your domain; results feed the banner's cookie declaration.
- Nightly subpage rotation — the scanner groups sitemap URLs by page type and language (product page, category, post, info page) and visits further groups each night, so even a shop with thousands of products is covered within a few nights — without your involvement.
- Rejected-consent audit — a control visit with consent rejected checks that no consent-requiring scripts load despite the refusal.
- Public scanner — a quick test available without an account at cookiehug.com/scan; full results and history require an account.
Consent health — four control scenarios
The Consent health card (Domain → Advanced → Diagnostics) aggregates four automatic scenarios, refreshed roughly every 7 days in the scanner's nightly cycle. You can also request each scenario manually from the panel — the result appears the next day.
The aggregate status (green/red) is shown above the scenario list; issues from individual scans also feed the Anomaly Radar.
- Consent Mode ordering — a full scan checks that Google Consent Mode defaults are set before any Google tags load.
- Silence before consent — a visit with no decision: until the visitor clicks the banner, no consent-requiring scripts should load.
- Rejection blocks trackers — the rejected-consent audit: after a refusal, marketing and analytics scripts stay blocked.
- Acceptance unblocks measurement — the inverse check: after consent the tags actually fire, so you also catch consent not reaching your measurement.
How we classify cookies
Each detected cookie and script is matched against a service catalog entry (vendor, purpose, consent category). Cookie descriptions come from a curated catalog — you can override them with your own in the panel, and manual changes are not replaced by subsequent scans.
Classification results feed the banner's cookie declaration.
Domain services & overrides
The Domain → Advanced → External services section lists the services detected on your website together with the category assigned in the catalog. For a single domain you can override the category of a service or disable it entirely — the override applies only to that domain, takes precedence over the catalog and affects both script blocking and the cookie declaration. You can revert an override to the catalog value at any time.
Unclassified scripts
Scripts the scanner could not match to any service catalog entry land in Domain → Advanced → Unclassified scripts. For each one you can: assign a consent category or an existing service (creating an override for this domain), create a new service entry, mark it Ignore (skipped in future scans) or Block. Your classifications feed the catalog's auto-learning — the same script detected again is recognised automatically.
Limitations
The scanner does not sign in to your website (it will not see content behind a login) and respects time limits — very large websites are covered by rotating through page types — the inventory is a representative sample of sitemap URLs (the panel shows how many made it into the sample), not every single product. If your website blocks bots, add an exception for the scanner or run a manual scan after temporarily lifting the block.