https://gamespot.com
Scanned Apr 15, 2026 · 38.8s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 20 user data leaks before consent on gamespot.com, including Experian (Advertising Tracker), WordPress VIP (Analytics Tracker), comScore (Analytics Tracker) and 2 more.
Security Headers
2/6 presentStrict-Transport-Security
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Add a Content-Security-Policy header to prevent XSS and code injection attacks
X-Frame-Options
Add X-Frame-Options header to prevent clickjacking attacks
X-Content-Type-Options
Set X-Content-Type-Options to 'nosniff' to prevent MIME type sniffing
Referrer-Policy
no-referrer-when-downgrade
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
V2Consent Parameters
Issues (1)
No default consent call detected — consent mode may not be initialised correctly
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
3 vendors
Consent Mode
Not Detected
GTM Load
3357ms pre-consent
Google Tag Manager(GTM-PWVTCD9)
Loaded 3357ms after page load — before the consent banner was detected (banner appeared at 7690ms). Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.
Consent Mode V2: Not Detected
Google Consent Mode was not detected on this site.
✓ gtag('consent', 'update') call detected on rejection
Vendors firing after rejection (3)
| Vendor | Category | Timing | URL |
|---|---|---|---|
| Sourcepoint — Sourcepoint CMP | consent_management | 18951ms | launchpad-wrapper.privacymanager.io |
| Google — Google Ads | advertising | 19569ms | pagead2.googlesyndication.com |
| Quantcast — Quantcast | advertising | 26922ms | cms.quantserve.com |
Consent Record Audit
Issues detectedConsent record stored after interaction
GDPR Art. 7(1)Found: OptanonConsent (OneTrust)
Record contains timestamp
Art. 7(1)Timestamp field detected
Record contains consent state
Art. 7(1)Accept/reject state detected
Record contains consent categories
Art. 7(1)Consent categories (analytics, marketing, etc.) not found in record
Consent withdrawal mechanism accessible
GDPR Art. 7(3)No way for users to withdraw consent found on page
No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.
Why this matters
Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.
Tracker categories detected
Critical10
Experian (advertising) loaded before consent
WordPress VIP (Analytics Tracker)2 findingscdn.parsely.com, p1.parsely.com
cdn.parsely.com, p1.parsely.com
WordPress VIP (analytics) loaded before consent
WordPress VIP (analytics) loaded before consent
comScore (analytics) loaded before consent
Impact (advertising) loaded before consent
Marfeel cookie "_scor_uid" set before consent — This cookie is used to store for temporary session
Sourcepoint — Sourcepoint CMP fires after user rejected consent

Google — Google Ads fires after user rejected consent

Quantcast — Quantcast fires after user rejected consent
No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)
Warnings14
Google Tag Manager2 findingsID trackedwww.googletagmanager.com

www.googletagmanager.com

Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-PWVTCD9)
Unknown third-party request to services.fandom.com before consent
Unknown third-party request to www.google.com before consent
Unknown third-party request to script.wikia.nocookie.net before consent
Unknown third-party request to static.wikia.nocookie.net before consent
localStorage key "modernizr" written before consent
localStorage key "lscache-__lscachetest__" written before consent
localStorage key "__test__" written before consent
localStorage key "__o1776289899767__" written before consent
localStorage key "__o1776289899770__" written before consent
localStorage key "instant-config-lock" written before consent
localStorage key "instant-config-gamespot" written before consent
localStorage key "ae3-provider-storage-test" written before consent
Info11
OneTrust3 findingscdn.cookielaw.org, OneTrustWPCCPAGoogleOptOut, OptanonConsent

cdn.cookielaw.org, OneTrustWPCCPAGoogleOptOut, OptanonConsent

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

OneTrust cookie "OneTrustWPCCPAGoogleOptOut" set before consent — This cookie is set by OneTrust. It is used to honor IAB CCPA laws for consent.

OneTrust cookie "OptanonConsent" set before consent

Cloudflare Web Analytics (Cloudflare) loaded before consent: Cloudflare Web Analytics beacon — privacy-focused, no cookies
Google (cdn) loaded before consent

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location
PrivacyPillar cookie "usprivacy" set before consent — This cookie stores the US privacy string.
Parse.ly2 findings_parsely_session, _parsely_visitor
_parsely_session, _parsely_visitor
Parse.ly cookie "_parsely_session" set before consent — JSON document storing information identifying a browsing session according to Parsely’s proprietary definition
Parse.ly cookie "_parsely_visitor" set before consent — JSON document uniquely identifying a browser and counting its sessions
Cloudflare bot management — necessary for site operation
Cloudflare challenge clearance — necessary for site access
Compliant21
Google Analytics4 findingsID trackedregion1.google-analytics.com, _ga_CTMGB962KH, _ga, _ga_HLJ6XDCTMV

region1.google-analytics.com, _ga_CTMGB962KH, _ga, _ga_HLJ6XDCTMV

GA4 (Google) loaded correctly after consent

Google Analytics cookie "_ga_CTMGB962KH" set correctly after consent

Google Analytics cookie "_ga" set correctly after consent

Google Analytics cookie "_ga_HLJ6XDCTMV" set correctly after consent
Google Ads3 findingsgoogleads.g.doubleclick.net, _gcl_au, _gcl_ls

googleads.g.doubleclick.net, _gcl_au, _gcl_ls

Google Ads (Google) loaded correctly after consent

Google Ads cookie "_gcl_au" set correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent
Sourcepoint CMP2 findingslaunchpad-wrapper.privacymanager.io, launchpad.privacymanager.io
launchpad-wrapper.privacymanager.io, launchpad.privacymanager.io
Sourcepoint CMP (Sourcepoint) loaded correctly after consent
Sourcepoint CMP (Sourcepoint) loaded correctly after consent

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Instagram cookie "sessionId" set correctly after consent
openx.net2 findingsi, pd
i, pd
openx.net cookie "i" set correctly after consent
openx.net cookie "pd" set correctly after consent
CreativeCDN cookie "g" set correctly after consent
PayPal cookie "ts" set correctly after consent

Quantcast cookie "mc" set correctly after consent
Snowplow cookie "sp" set correctly after consent

DoubleClick/Google Marketing cookie "IDE" set correctly after consent
Adform2 findingsC, uid

C, uid

Adform cookie "C" set correctly after consent

Adform cookie "uid" set correctly after consent
localStorage availability probe (null) wrote "__storage_test__" to localStorage correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan gamespot.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com