What you get

Cookie scanner & compliance audit

Scan your website for cookies, trackers, and consent violations. Ten compliance checks, one report, 60 seconds.

Scan regulation:All RegulationsGDPRUK GDPRCCPA / CPRALGPDPOPIAPDPA
PremiumFree account

Google Consent Mode v2 audit

Not just whether GCM v2 is present β€” whether it is correctly implemented.

GCM v2 is required for compliant GA4 and Google Ads conversion measurement in EU markets. The most common mistake: adding the consent call but leaving parameters defaulted to granted instead of denied. Tag Leak verifies the full implementation β€” timing, parameter values, and call order β€” and scores it 0–100.

What it checks

  • Detects v1 vs v2 β€” flags missing ad_user_data and ad_personalization parameters
  • Checks default consent state: 'denied' required, 'not_set' fails, 'granted' is a violation
  • Verifies consent call fires before GTM container (ordering matters)
  • GTM container IDs identified automatically β€” no manual config
  • Scored 0–100 across setup completeness, parameter values, and call timing
  • A strong GCM v2 score automatically adjusts the severity of related GA4 and Google Ads findings
PremiumFree account

IAB TCF v2.3 detection

The consent standard your CMP must implement β€” verified at the API level.

IAB TCF v2.3 is the technical consent framework all IAB-registered CMPs β€” Cookiebot, Didomi, OneTrust, Axeptio, and 200+ others β€” are required to implement. Tag Leak verifies your CMP's TCF implementation at the API level, checking version, consent signal validity, and status across all 11 IAB consent purposes.

What it checks

  • TCF version detection β€” v2.0 implementations flagged as outdated
  • Consent event status verified β€” checks the signal is complete, not just present
  • TC string presence and basic validity check
  • Consent status for all 11 IAB purposes (P1–P11)
  • Vendor count and CMP identity confirmed
  • Scored 0–100 across version, consent signal completeness, and CMP identity
PremiumFree account

Security headers audit

Six headers. One scan. No extra tool required.

Security response headers are a GDPR Article 32 requirement and appear in DPA technical audits. Tag Leak checks all six in the same scan as the consent audit β€” no separate security scanner needed. Missing headers are reported as info findings with the specific value recommended.

What it checks

  • Strict-Transport-Security (HSTS) β€” prevents protocol downgrade attacks
  • Content-Security-Policy β€” controls which resources the browser can load
  • X-Frame-Options β€” prevents clickjacking attacks
  • X-Content-Type-Options β€” prevents MIME-type sniffing
  • Referrer-Policy β€” controls what referrer information is sent
  • Permissions-Policy β€” restricts browser feature access (camera, microphone, geolocation)
Core$19/mo

Multi-page scanning

Your checkout page and product pages need to be compliant too.

GDPR violations frequently occur on pages other than the homepage β€” particularly forms, checkout flows, and content pages that load additional tracking scripts. Tag Leak discovers pages from your sitemap.xml automatically (with link crawl fallback) and scans them in parallel, giving you a full-site compliance picture.

What it checks

  • Automatic page discovery from your sitemap β€” with link crawl fallback if none exists
  • Starter: up to 25 pages per scan | Pro: up to 100 pages per scan
  • Pages scanned in parallel for fast results, even on large sites
  • Per-page score, critical/warning count, and consent banner status in report
  • Findings deduplicated across pages β€” one entry per unique violation, not 100 copies
  • Each finding includes the exact page URL so you know precisely where to fix it
CoreFree account

6-regulation compliance audit

GDPR, UK GDPR, CCPA, LGPD, POPIA, and PDPA β€” scored in one scan.

Every Tag Leak scan automatically evaluates compliance against all six major privacy regulations without pre-selection. Each regulation gets its own score (0–100), a status (compliant / issues / critical), and a per-check pass/fail breakdown that maps to the specific technical requirements of that framework.

What it checks

  • GDPR πŸ‡ͺπŸ‡Ί β€” pre-consent trackers, consent banner, GCM v2, TCF v2.3, cookie lifetime
  • UK GDPR πŸ‡¬πŸ‡§ β€” ICO guidance, PECR, 13-month cookie threshold
  • CCPA πŸ‡ΊπŸ‡Έ β€” Do Not Sell link, opt-out mechanisms, and consent signal detection
  • LGPD πŸ‡§πŸ‡· β€” opt-in consent model, pre-consent tracker detection
  • POPIA πŸ‡ΏπŸ‡¦ β€” opt-in model, banner presence, tracker detection
  • PDPA πŸ‡ΉπŸ‡­ β€” opt-in model, banner presence, tracker detection
Pro$49/mo

Geo-scanning

Test from the jurisdiction that matters β€” not just your office location.

Many sites serve different consent experiences based on visitor location β€” a compliant Cookiebot setup for EU visitors, a banner-less experience for US visitors, or a geo-redirect to a different domain entirely. Geo-scanning detects all of this by running the scan from a real IP in the target jurisdiction.

What it checks

  • πŸ‡ͺπŸ‡Ί EU β€” Germany (GDPR) | πŸ‡¬πŸ‡§ UK β€” United Kingdom (UK GDPR / PECR)
  • πŸ‡ΊπŸ‡Έ US β€” United States (CCPA) | πŸ‡§πŸ‡· Brazil (LGPD) | 🌏 APAC β€” Singapore (PDPA)
  • Geo-redirect detection β€” flags when hostname changes after navigation
  • Locale-accurate simulation β€” each scan sets the correct language and region signals
  • Each geo scan produces a complete report with region noted in the header
  • Consistent IP geolocation per region β€” scans originate from real IPs in each jurisdiction
PremiumFree account

AI Remediation Document

Every finding has an owner. Every fix has a step.

Generated directly from your scan findings, the Remediation Document is a structured fix plan that assigns every violation to the team that owns it β€” Developer, GTM Manager, or Legal. It is not a generic template. Download as PDF for your evidence file or to hand to the dev team.

What it checks

  • Executive Summary β€” compliance posture in 2–3 sentences
  • Priority Actions β€” critical findings with [Developer] / [GTM Manager] / [Legal] tag and specific fix steps
  • Recommended Actions β€” warnings with implementation notes
  • Quick Wins β€” security headers and low-effort fixes that unblock audit sign-off
  • What Cannot Be Automated β€” items requiring legal review
  • Compliance Checklist β€” yes/no per finding for sign-off evidence
  • Up to 3 generations per day | PDF export included

Compare Tag Leak

Most compliance tools help you look compliant. We show if you actually are.

Banners don’t stop data leaks. Checklists don’t catch real behavior. Tag Leak is built to expose what’s really happening on your site across vendors, regions, and consent states.

CapabilityTag LeakCookieYesCookiebotOneTrust
Pre vs post-consent two-pass scanβœ“β€”β€”β€”
GCM v2 implementation audit (0–100 score)βœ“β€”β€”β€”
TCF v2.3 implementation audit (third-party)βœ“β€”β€”β€”
6-regulation compliance scoringβœ“β€”β€”βœ“
Geo-scanning (EU, UK, US, BR, APAC)βœ“β€”β€”β€”
Security headers auditβœ“β€”β€”β€”
AI remediation documentβœ“β€”β€”β€”
Cookie policy generated from scan dataβœ“β€”β€”β€”
Scan any URL free β€” no account, no installβœ“β€”β€”β€”
Consent banner productβ€”βœ“βœ“βœ“

"Implementation audit" = verifying whether an existing GCM v2 or TCF v2.3 setup is correctly configured, scored 0–100. CookieYes and Cookiebot implement these standards in their own banners β€” they do not audit third-party implementations. Comparison as of April 2026.

Pricing

Start free. Upgrade when you need more.

Free

$0

  • 1-page scan
  • Top 3 critical + 2 warning
  • No signup required

Starter

$19/mo

  • 25-page scanning
  • 3 monitored sites (weekly)
  • Full report + all sections
  • AI Remediation Document
  • Cookie policy generator

Pro

$49/mo

  • 100-page scanning
  • 20 monitored sites (daily)
  • Geo-scanning (5 regions)
  • White-label PDF export
  • Everything in Starter

Frequently asked questions

What is a cookie scanner?

A cookie scanner is a tool that audits your website to detect all cookies and tracking technologies in use. It identifies which cookies fire before user consent, categorizes them by purpose (analytics, advertising, functional), and flags compliance issues with privacy regulations like GDPR, CCPA, and ePrivacy.

How does Tag Leak's cookie scanning work?

Tag Leak runs a two-pass scan in a real browser. First, it loads your site without any consent interaction to detect pre-consent tracking. Then it interacts with your consent banner (accept/reject) and scans again. This before-and-after approach reveals whether your consent mechanism actually blocks tracking β€” not just whether a banner appears.

How is Tag Leak different from other cookie scanning tools?

Most cookie scanners only list what cookies exist on a page. Tag Leak goes further: it tests pre-consent vs. post-consent behavior, audits Google Consent Mode v2 implementation (all 7 parameters), checks IAB TCF compliance, verifies post-rejection behavior, and scores your site 0-100 across 6 privacy regulations simultaneously.

Is Tag Leak free to use?

Yes. Single-page scans are free with no signup required. Free scans show the top 3 critical and 2 warning findings. Paid plans (Starter $19/mo, Pro $49/mo) unlock multi-page scanning, full reports, site monitoring, AI remediation documents, and geo-scanning from multiple regions.

Can Tag Leak scan websites that use any CMP?

Yes. Tag Leak is CMP-agnostic β€” it works with Cookiebot, OneTrust, CookieYes, Didomi, Usercentrics, Quantcast, and any other consent management platform. It detects and interacts with your CMP's banner automatically, then verifies whether it actually blocks tracking before consent.

All ten checks. One scan. 60 seconds.

Free scan, no signup. Paid features unlock automatically when you create an account.