https://trendyol.com
Scanned Apr 15, 2026 · 36.6s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 89 user data leaks before consent on trendyol.com, including Adform (Advertising Tracker), Azerion (Advertising Tracker), VirtualMinds (Advertising Tracker) and 48 more.
Security Headers
4/6 presentStrict-Transport-Security
max-age=15768000;
Content-Security-Policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://trendyol.com https://*.trendyol.com https://www.googletagmanager.com https://www.google-analytics.com https://www.clarity.ms https://scripts.clarity.ms https://www.googleadservices.com https://static.criteo.net https://connect.facebook.net https://edge.fullstory.com https://www.fullstory.com https://cdn.cookielaw.org https://creativecdn.com https://static.hotjar.com https://trendyolde.api.useinsider.com https://ct.pinterest.com https://cdn.taboola.com https://trc.taboola.com https://analytics.twitter.com https://s2.adform.net https://track.adform.net https://platform.twitter.com https://static.ads-twitter.com https://googleads.g.doubleclick.net https://www.awin1.com https://cdn.dsmcdn.com/ https://static.dsmcdn.com https://js-agent.newrelic.com https://maps.googleapis.com https://static.cloudflareinsights.com https://bam-cell.nr-data.net https://widget.usersnap.com https://resources.usersnap.com https://sslwidget.criteo.com https://pay.google.com https://x.klarnacdn.net https://api.useinsider.com https://www.googleoptimize.com https://s.pinimg.com https://www.dwin1.com https://ln-rules.rewardstyle.com https://the.sciencebehindecommerce.com https://analytics.tiktok.com https://widgets.trustedshops.com https://bat.bing.com https://js.braintreegateway.com https://www.paypal.com https://www.mczbf.com https://c.paypal.com/ https://sc-static.net https://tags.creativecdn.com https://www.google.com https://www.gstatic.com https://checkout.tabby.ai https://dynamic.criteo.com https://challenges.cloudflare.com https://checkout.com https://risk.checkout.com https://fpjs.checkout.com https://fpjscache.checkout.com https://fpjsworker.checkout.com https://fpnpmcdn.net https://cdnjs.cloudflare.com/ajax/libs/Swiper/8.4.7/swiper-bundle.min.js media.flixcar.com media.flixfacts.com *.flix360.io *.flix360.com media.flixsyndication.net https://prod.flixgvid.flix360.io/ content.jwplatform.com assets-jpcust.jwpsrv.com ssl.p.jwpcdn.com *.flixcar.com http://d2m3ikv8mpgiy8.cloudfront.net d3np41mctoibfu.cloudfront.net media.pointandplace.com player.pointandplace.com t.pointandplace.com intent://arvr.google.com; frame-ancestors 'self' https://*.trendyol.com
X-Frame-Options
Add X-Frame-Options header to prevent clickjacking attacks
X-Content-Type-Options
nosniff
Referrer-Policy
same-origin
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
V2Consent Parameters
Issues (1)
No default consent call detected — consent mode may not be initialised correctly
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
0 vendors
Consent Mode
Not Detected
GTM Load
3440ms pre-consent
Google Tag Manager(GTM-W7RKTTC)
Loaded 3440ms after page load — before the consent banner was detected (banner appeared at 7368ms). Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.
Consent Mode V2: Not Detected
Google Consent Mode was not detected on this site.
✓ gtag('consent', 'update') call detected on rejection
Consent Record Audit
PassConsent record stored after interaction
GDPR Art. 7(1)Found: OptanonConsent (OneTrust)
Record contains timestamp
Art. 7(1)Timestamp field detected
Record contains consent state
Art. 7(1)Accept/reject state detected
Record contains consent categories
Art. 7(1)Consent categories (analytics, marketing, etc.) not found in record
Consent withdrawal mechanism accessible
GDPR Art. 7(3)Cookie settings link / floating button found
Tracker categories detected
Critical75
Adform (Advertising Tracker)5 findingss2.adform.net, track.adform.net, c1.adform.net, server.seadform.net, dmp.adform.net

s2.adform.net, track.adform.net, c1.adform.net, server.seadform.net, dmp.adform.net

Adform (advertising) loaded before consent

Adform (advertising) loaded before consent

Adform (advertising) loaded before consent

Adform (advertising) loaded before consent

Adform (advertising) loaded before consent
Azerion (advertising) loaded before consent
VirtualMinds (Advertising Tracker)2 findingsad.yieldlab.net, dsp.adfarm1.adition.com
ad.yieldlab.net, dsp.adfarm1.adition.com
VirtualMinds (advertising) loaded before consent
VirtualMinds (advertising) loaded before consent
Magnite (advertising) loaded before consent
Ströer Core (advertising) loaded before consent
Equativ (advertising) loaded before consent
Comcast (advertising) loaded before consent

Criteo (advertising) loaded before consent
IndexExchange (advertising) loaded before consent
SearchForce (Advertising Tracker)2 findingsuipglob.semasio.net, se.semasio.net
uipglob.semasio.net, se.semasio.net
SearchForce (advertising) loaded before consent
SearchForce (advertising) loaded before consent
Dun & Bradstreet (analytics) loaded before consent
Nielsen (Advertising Tracker)2 findingsloadm.exelator.com, load77.exelator.com
loadm.exelator.com, load77.exelator.com
Nielsen (advertising) loaded before consent
Nielsen (advertising) loaded before consent
LiveRamp (advertising) loaded before consent
PublicisGroupe (tracker) loaded before consent
OpenX (tracker) loaded before consent
OnlineSolution (advertising) loaded before consent
Google (tracker) loaded before consent
Microsoft (Advertising Tracker)2 findingssecure.adnxs.com, ib.adnxs.com

secure.adnxs.com, ib.adnxs.com

Microsoft (advertising) loaded before consent

Microsoft (advertising) loaded before consent
PubMatic (advertising) loaded before consent
AudienceProject (advertising) loaded before consent
Audiencerate (advertising) loaded before consent

Adobe (tracker) loaded before consent
TransUnion (advertising) loaded before consent
Roku (advertising) loaded before consent
The Trade Desk (tracker) loaded before consent
ID5 (advertising) loaded before consent
Weborama (advertising) loaded before consent
Teads (advertising) loaded before consent
VerveGroup (advertising) loaded before consent
ContentExchange (advertising) loaded before consent
mediarithmics (advertising) loaded before consent
OnAudience (advertising) loaded before consent
TripleLift (advertising) loaded before consent
OneTag (advertising) loaded before consent
Yahoo! (Analytics Tracker)2 findingscms.analytics.yahoo.com, ups.analytics.yahoo.com
cms.analytics.yahoo.com, ups.analytics.yahoo.com
Yahoo! (analytics) loaded before consent
Yahoo! (analytics) loaded before consent
Adform4 findingsC, CM, uid, CM14

C, CM, uid, CM14

Adform cookie "C" set before consent — Used to determine if browser of user accepts cookies or not

Adform cookie "CM" set before consent — Checks if a new partner cookie synchronization is required (cookie set by ad server)

Adform cookie "uid" set before consent — Contains a unique ID to identify a user

Adform cookie "CM14" set before consent — Checks if a new partner cookie synchronization is required (cookie set during cookie synchronization )
ComScore cookie "pid" set before consent — Collects a code that identifies the specific website or advertiser participating in the ScorecardResearch data collection program.
Smartadserver2 findingsTestIfCookieP, csync
TestIfCookieP, csync
Smartadserver cookie "TestIfCookieP" set before consent — Technical cookie used to test if persistent cookies are accepted
Smartadserver cookie "csync" set before consent — Optimises ad display based on the user's movement combined and various advertiser bids for displaying user ads.
Rapleaf2 findingsrlas3, pxrc
rlas3, pxrc
Rapleaf cookie "rlas3" set before consent — Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Rapleaf cookie "pxrc" set before consent — This cookie registers non-personal data on the visitor. The information is used to optimize advertisement relevance.
Casale Media3 findingsCMID, CMPS, CMPRO
CMID, CMPS, CMPRO
Casale Media cookie "CMID" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Casale Media cookie "CMPS" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads
Casale Media cookie "CMPRO" set before consent — Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that the visitor is shown the same advertisement.
semasio.net cookie "SEUNCY" set before consent — Registers a unique ID that identifies the user’s device for return visits.
openx.net cookie "i" set before consent — Registers user data, such as IP address, geographical location, websites visited and on which advertisements the user has clicked, with the aim of optimizing the display of advertisements based on user relocation on websites that use the same advertising network.
Nielsen3 findingsEE, udo, ud
EE, udo, ud
Nielsen cookie "EE" set before consent — Collects data related to the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Nielsen cookie "udo" set before consent — Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website.
Nielsen cookie "ud" set before consent — Collects data related to the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Audrte3 findingsarcki2, arcki2_adform, arcki2_ddp2
arcki2, arcki2_adform, arcki2_ddp2
Audrte cookie "arcki2" set before consent — Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
Audrte cookie "arcki2_adform" set before consent — Presents the user with relevant content and advertisement. The service is provided by third-party advertisement hubs, which facilitate real-time bidding for advertisers.
Audrte cookie "arcki2_ddp2" set before consent — Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
Adition cookie "UserID1" set before consent — Cookie sets a unique anonymous ID for a website visitor. This ID is used to recognize the user on different sessions and to track their activities on the website. The data collected is used for analysis purposes.

DoubleClick/Google Marketing cookie "IDE" set before consent — This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite
Weborama cookie "AFFICHE_W" set before consent — Used by the advertising platform Weborama to determine the visitor’s interests based on pages visits, content clicked and other actions on the website.
Roku2 findingswfivefivec, matchadform
wfivefivec, matchadform
Roku cookie "wfivefivec" set before consent — Collects data on the user's visits to the website, such as what pages have been loaded. The registered data is used for targeted ads.
Roku cookie "matchadform" set before consent — Presents the user with relevant content and advertisement. The service is provided by third-party advertisement hubs, which facilitate real-time bidding for advertisers.
OnAudience3 findingsdone_redirects297, done_redirects271, done_redirects252
done_redirects297, done_redirects271, done_redirects252
OnAudience cookie "done_redirects297" set before consent — Used to monitor website performance for statistical purposes.
OnAudience cookie "done_redirects271" set before consent — Used to monitor website performance for statistical purposes.
OnAudience cookie "done_redirects252" set before consent — Used to monitor website performance for statistical purposes.
Neustar cookie "ab" set before consent — This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.
Adobe Audience Manager2 findingsdemdex, dpm

demdex, dpm

Adobe Audience Manager cookie "demdex" set before consent — Unique value with which Audience Manager can identify a user. Used, among others, for identification, segmentation, modeling and reporting purposes.

Adobe Audience Manager cookie "dpm" set before consent — DPM is an abbreviation for Data Provider Match. It tells internal, Adobe systems that a call from Audience Manager or the Adobe Experience Cloud ID Service is passing in customer data for synchronization or requesting an ID.
Warnings14
Google Tag Manager2 findingsID trackedwww.googletagmanager.com

www.googletagmanager.com

Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-W7RKTTC)
Possible server-side tag proxy at en-collect.trendyol.com — analytics data may be forwarded to third parties before consent. Browser scanning cannot verify downstream recipients; audit your GTM Server-side or CNAME configuration.
Unknown third-party request to cdn.dsmcdn.com before consent
Unknown third-party request to target.digitalaudience.io before consent
sessionStorage key "stateHistory" written before consent
sessionStorage key "mergen_dice" written before consent
sessionStorage key "key" written before consent
localStorage key "tooltip-queue" written before consent
sessionStorage key "iahp" written before consent
localStorage key "__mergen_test__" written before consent
localStorage key "mergen-session" written before consent
localStorage key "basket_reminder" written before consent
localStorage key "breadcrumbs" written before consent
Info8

Cloudflare Web Analytics (Cloudflare) loaded before consent: Cloudflare Web Analytics beacon — privacy-focused, no cookies
OneTrust2 findingscdn.cookielaw.org, OptanonConsent

cdn.cookielaw.org, OptanonConsent

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

OneTrust cookie "OptanonConsent" set before consent
Cloudflare2 findings__cflb, _cfuvid

__cflb, _cfuvid

Cloudflare cookie "__cflb" set before consent — When enabling session affinity with Cloudflare Load Balancer, Cloudflare sets a __cflb cookie with a unique value on the first response to the requesting client. Cloudflare routes future requests to the same origin, optimizing network resource usage. In the event of a failover, Cloudflare sets a new __cflb cookie to direct future requests to the failover pool.

Cloudflare cookie "_cfuvid" set before consent — The _cfuvid cookie is only set when a site uses this option in a Rate Limiting Rule, and is only used to allow the Cloudflare WAF to distinguish individual users who share the same IP address.
Cloudflare bot management — necessary for site operation
Cross-site request forgery token — security mechanism
Load balancer server affinity — necessary for infrastructure
Compliant8

GA4 (Google) loaded correctly after consent

Meta Pixel (Meta) loaded correctly after consent
Google Ads3 findingswww.google.com, _gcl_au, _gcl_ls

www.google.com, _gcl_au, _gcl_ls

Google Ads (Google) loaded correctly after consent

Google Ads cookie "_gcl_au" set correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent
ComScore cookie "pid" set correctly after consent
Google cookie "sid" set correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan trendyol.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com