Bayer

bayer.com

Compare

https://bayer.com

Scanned Apr 15, 2026 · 33.5s

Your website score is

50/100
Needs Work

Grade

C50

Banner

Yes

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 4 user data leaks before consent on bayer.com, including Akamai (Analytics Tracker).

Security Headers

5/6 present

Strict-Transport-Security

max-age=63072000; includeSubDomains; preload

Content-Security-Policy

script-src 'self' 'unsafe-inline' 'unsafe-eval' addtocalendar.com cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://identitynet.bayer.com https://maps.googleapis.com https://polyfill.io https://rebilly.github.io https://unpkg.com https://video-streaming.bayer.com https://www.google.com unpkg.com www.gstatic.com cdn.cookielaw.org analytics.silktide.com www.googletagmanager.com js-agent.newrelic.com www.google-analytics.com snap.licdn.com *.hotjar.com www.youtube.com connect.facebook.net js.adsrvr.org ga-internaltraffic.weba.bbs.cnb s.go-mpulse.net embed.content-sync.io embed.cms-content-sync.io https://player.vimeo.com https://googleads.g.doubleclick.net blob: f.vimeocdn.com www.gstatic.com https://www.googleadservices.com alttext.ai plugin.handtalk.me; object-src none; report-uri /report-csp-violation

X-Frame-Options

ALLOW-FROM *.bayer.com

X-Content-Type-Options

nosniff

Referrer-Policy

no-referrer-when-downgrade

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

V2
65/100

Consent Parameters

ParameterDefaultUpdated
Ad Storagenot_setgranted
Ad User Datanot_setgranted
Ad Personalizationnot_setgranted
Analytics Storagenot_setgranted
Functionality Storagenot_setnot_set
Personalization Storagenot_setnot_set
Security Storagenot_setnot_set

Issues (2)

No default consent call detected — consent mode may not be initialised correctly

No GTM container detected — consent mode works best with Google Tag Manager

Post-Rejection Audit

Reject Button

Found

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

Not detected

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

✓ gtag('consent', 'update') call detected on rejection

No tracking vendors detected firing after rejection

Consent Record Audit

Pass

Consent record stored after interaction

GDPR Art. 7(1)

Found: OptanonConsent (OneTrust)

Record contains timestamp

Art. 7(1)

Timestamp field detected

Record contains consent state

Art. 7(1)

Accept/reject state detected

Record contains consent categories

Art. 7(1)

Consent categories (analytics, marketing, etc.) not found in record

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

Cookie settings link / floating button found

Consent record and withdrawal mechanism are both correctly implemented

Tracker categories detected

Analytics1 vendor
Security1
Functional1 vendor
Critical3
Akamai (Analytics Tracker)
Akamai (Analytics Tracker)3 findings

s.go-mpulse.net, c.go-mpulse.net, 684dd32f.akstat.io

Akamai (Analytics Tracker)
criticalNetworkAnalyticsAkamai (Analytics Tracker)

Akamai (analytics) loaded before consent

Host: s.go-mpulse.netFired: 649ms after load
Akamai (Analytics Tracker)
criticalNetworkAnalyticsAkamai (Analytics Tracker)

Akamai (analytics) loaded before consent

Host: c.go-mpulse.netFired: 781ms after load
Akamai (Analytics Tracker)
criticalNetworkAnalyticsAkamai (Analytics Tracker)

Akamai (analytics) loaded before consent

Host: 684dd32f.akstat.ioFired: 1195ms after load
Warnings1
warningStorage

localStorage key "_boomr_clss" written before consent

Key: _boomr_clssType: localStorageFired: 733ms after load
Info4
OneTrust
OneTrust2 findings

cdn.cookielaw.org, OptanonConsent

OneTrust
infoNetworkConsent MgmtOneTrust

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

Host: cdn.cookielaw.orgFired: 473ms after load
OneTrust
infoCookieConsent MgmtOneTrust

OneTrust cookie "OptanonConsent" set before consent

Cookie: OptanonConsentDomain: .www.bayer.com
Cloudflare (Cdn)
infoNetworkCloudflare (Cdn)

Cloudflare (cdn) loaded before consent

Host: cdnjs.cloudflare.comFired: 495ms after load
OneTrust CMP
infoNetworkConsent MgmtOneTrust CMP

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location

Host: geolocation.onetrust.comFired: 659ms after load
Compliant2
OneTrust
CompliantCookieConsent MgmtOneTrust

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Cookie: OptanonAlertBoxClosedDomain: .www.bayer.com
CompliantCookieFunctionalTripadvisor

Tripadvisor cookie "RT" set correctly after consent

Cookie: RTDomain: .www.bayer.comRetention: 399 days

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan bayer.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com