FREE WEBSITE PRIVACY & CONSENT SCANNER
Most consent banners aren't blocking anything. Find out if yours is one of them. Free scan, no signup required.
Full Compliance report in under 60 seconds
βMeta Pixel and TikTok Pixel sending user data to ad networks before any consent interaction.β
Regulatory Compliance
Generate Remediation Document
Step-by-step remediation guide

region1.google-analytics.com, _ga_Q1FXP4&JAS

GA4 (Google) loaded before consent: Sends pageview and event data to Google Analytics

Google Analytics cookie "_ga_Q1FXP4&JAS" set before consent

www.facebook.com, _fbp

Meta Pixel loaded before consent: Meta Pixel tracking endpoint

Meta Pixel wrote "_fbp" to localStorage before consent

analytics.tiktok.com, _ttp

TikTok Pixel (TikTok) loaded before consent: Sends event data to TikTok for ad measurement

TikTok Pixel cookie "_ttp" set before consent

Google Tag Manager loaded before consent: Loads the GTM container which may trigger other tags
The compliance landscape
β¬4.5B+
in GDPR fines issued since 2018
3 in 4
websites fire tracking tags before user consent
$25K+/yr
is what enterprise audit tools charge
How It Works
No setup. No integration. Just a URL and we take it from there.
Behind the scenes, we analyze how your site behaves in real-world conditions, before and after consent.
Every tag, cookie, storage write, and third-party request classified by severity - across up to 100 pages. GCM v2 audit, IAB TCF v2.2 status, 6-regulation compliance scoring, security headers, and a Remediation Document with per-finding team ownership. Compliance score out of 100.
What's in every scan
Every scan covers your full privacy posture - not just what's in the cookie jar.
A stealth Chromium browser visits your site with zero cookies and no history. Every network request, cookie, and storage write that fires before consent is recorded and classified against 50,000+ known tracker signals - including Meta Pixel, TikTok, GA4, Google Ads, Adjust, Segment, and more.
Tag Leak intercepts GCM calls before any page script runs. All 7 consent parameters are checked - ad_storage, ad_user_data, ad_personalization, and more. Your implementation is scored 0β100 with specific issues called out. Required for compliant Google Ads measurement in the EU after January 2024.
Six headers checked on every scan. Missing headers are flagged with in a remediation document so developers know exactly what to add.
Your homepage might be clean. Your /checkout, /blog, and /contact might not be. Tag Leak automatically discovers pages from your sitemap and scans up to 25 pages (Starter) or 100 pages (Pro) - deduplicating findings across pages and showing a per-page score breakdown.
All IAB-registered consent platforms (Cookiebot, Didomi, Axeptio, OneTrust, and 200+ others) are required to implement TCF v2.2. Tag Leak calls __tcfapidirectly - the same way a regulator's tool would - checks your version (v2.2 vs outdated), validates event status, and audits all 11 IAB consent purposes. Scored 0β100 with specific issues called out.
After your scan, generate a Remediation Document: a prioritized fix guide that assigns each violation to the right team - [Developer], [GTM Manager], [Legal]. Executive summary for leadership. Compliance checklist for sign-off. Download as PDF in one click. This is what $400/hr privacy consultants produce. Tag Leak does it in 30 seconds.
Generate a GDPR-compliant cookie policy from your actual scan - not a generic template. TagLeak pre-populates every cookie name, vendor, duration, and category detected on your site.
Cookies We Use
Your Rights
πͺπΊ GDPR - Right to withdraw consent, access, erasure
πΊπΈ CCPA - Right to opt out of sale/sharing
π§π· LGPD - Right to correction and portability
Continuous monitoring
A GTM update, a new third-party script, a seasonal campaign pixel, a CMP version upgrade - any of these can re-introduce violations you already fixed. Tag Leak re-scans your site on a daily or weekly schedule and emails you the moment your compliance score drops or a new pre-consent leak appears.
Compliance timeline - example.com
Why Tag Leak
Banners donβt stop data leaks. Checklists donβt catch real behavior. Tag Leak is built to expose whatβs really happening on your site β across vendors, regions, and consent states.
| Capability | Tag Leak | CookieYes | Cookiebot | OneTrust |
|---|---|---|---|---|
| Pre vs post-consent two-pass scan | β | - | - | - |
| GCM v2 implementation audit (0β100 score) | β | - | - | - |
| TCF v2.2 implementation audit (third-party) | β | - | - | - |
| 6-regulation compliance scoring | β | - | - | β |
| Geo-scanning (EU, UK, US, BR, APAC) | β | - | - | - |
| Security headers audit | β | - | - | - |
| AI remediation document | β | - | - | - |
| Cookie policy generated from scan data | β | - | - | - |
| Scan any URL free - no account, no install | β | - | - | - |
| Consent banner product | - | β | β | β |
"Implementation audit" = verifying whether an existing GCM v2 or TCF v2.2 setup is correctly configured, scored 0β100. CookieYes and Cookiebot implement these standards in their own banners - they do not audit third-party implementations. Comparison as of April 2026.
Who it's for
Tag Leak works wherever compliance matters.
Move fast without breaking privacy laws. One scan before each deploy tells you if you're compliant - no legal consultation required.
You added the pixels. Now prove to legal they're not firing before consent - with a document that assigns every fix to the right owner.
Scan any client site in 60 seconds. Deliver a branded PDF compliance report. Look like the expert you are.
Pricing
No credit card required. Cancel anytime.
See what's leaking. No commitment.
Everything you need to stay compliant.
For teams managing multiple sites.
Prices in USD.
FAQ
One scan. 60 seconds. No signup.