Docs menu

Cookie scanner

The CookieHug cookie scanner: real-browser scans, nightly subpage rotation, the four consent-health scenarios and cookie classification.

What the scanner does

The CookieHug scanner visits your website with a real browser (not a plain HTTP crawler), so it sees what a visitor sees: cookies set by JavaScript, dynamically loaded scripts and third-party resources. Collected cookies and services are classified into consent categories based on the service catalog and cookie catalog we maintain (PL/EN descriptions).

Scan types

  • Panel scan — started manually for your domain; results feed the banner's cookie declaration.
  • Nightly subpage rotation — the scanner groups sitemap URLs by page type and language (product page, category, post, info page) and visits further groups each night, so even a shop with thousands of products is covered within a few nights — without your involvement.
  • Rejected-consent audit — a control visit with consent rejected checks that no consent-requiring scripts load despite the refusal.
  • Public scanner — a quick test available without an account at cookiehug.com/scan; full results and history require an account.

How we classify cookies

Each detected cookie and script is matched against a service catalog entry (vendor, purpose, consent category). Cookie descriptions come from a curated catalog — you can override them with your own in the panel, and manual changes are not replaced by subsequent scans.

Classification results feed the banner's cookie declaration.

Domain services & overrides

The Domain → Advanced → External services section lists the services detected on your website together with the category assigned in the catalog. For a single domain you can override the category of a service or disable it entirely — the override applies only to that domain, takes precedence over the catalog and affects both script blocking and the cookie declaration. You can revert an override to the catalog value at any time.

Unclassified scripts

Scripts the scanner could not match to any service catalog entry land in Domain → Advanced → Unclassified scripts. For each one you can: assign a consent category or an existing service (creating an override for this domain), create a new service entry, mark it Ignore (skipped in future scans) or Block. Your classifications feed the catalog's auto-learning — the same script detected again is recognised automatically.

Limitations

The scanner does not sign in to your website (it will not see content behind a login) and respects time limits — very large websites are covered by rotating through page types — the inventory is a representative sample of sitemap URLs (the panel shows how many made it into the sample), not every single product. If your website blocks bots, add an exception for the scanner or run a manual scan after temporarily lifting the block.