https://webmd.com
Scanned Apr 15, 2026 · 36.6s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 14 user data leaks before consent on webmd.com, including Google Ads, TrustARC (Tracker Tracker), Advertising Tracker and 2 more.
Security Headers
1/6 presentStrict-Transport-Security
Add HSTS header to enforce HTTPS connections and prevent downgrade attacks
Content-Security-Policy
upgrade-insecure-requests
X-Frame-Options
Add X-Frame-Options header to prevent clickjacking attacks
X-Content-Type-Options
Set X-Content-Type-Options to 'nosniff' to prevent MIME type sniffing
Referrer-Policy
Set a Referrer-Policy header to control how much referrer information is shared
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
V2Consent Parameters
Issues (2)
No default consent call detected — consent mode may not be initialised correctly
No GTM container detected — consent mode works best with Google Tag Manager
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
0 vendors
Consent Mode
Not Detected
GTM Load
Not detected
Consent Mode V2: Not Detected
Google Consent Mode was not detected on this site.
✓ gtag('consent', 'update') call detected on rejection
Consent Record Audit
PassConsent record stored after interaction
GDPR Art. 7(1)Found: OptanonConsent (OneTrust)
Record contains timestamp
Art. 7(1)Timestamp field detected
Record contains consent state
Art. 7(1)Accept/reject state detected
Record contains consent categories
Art. 7(1)Consent categories (analytics, marketing, etc.) not found in record
Consent withdrawal mechanism accessible
GDPR Art. 7(3)Cookie settings link / floating button found
Tracker categories detected
Critical5

Google Ads (Google) loaded before consent: Google Ads conversion tracking
TrustARC (tracker) loaded before consent
advertising tracker at privacy-policy.truste.com loaded before consent

GA4 (Google) loaded before consent: Google Analytics gtag.js library

Adobe Analytics cookie "AMCV_16AD4362526701720A490D45%40AdobeOrg" set before consent
Warnings9
Unknown third-party request to img.lb.wbmdstatic.com before consent
Unknown third-party request to www.google.com before consent
Unknown third-party request to assets.adobedtm.com before consent
Unknown third-party request to img.wbmdstatic.com before consent
Unknown third-party request to img-embody.lb.wbmdstatic.com before consent
Unknown third-party request to img.lb.staging.wbmdstatic.com before consent
sessionStorage key "iaf" written before consent
localStorage key "fipt" written before consent
sessionStorage key "desnityLogs" written before consent
Info8
OneTrust2 findingscdn.cookielaw.org, OptanonConsent

cdn.cookielaw.org, OptanonConsent

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

OneTrust cookie "OptanonConsent" set before consent

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location
Google (Cdn)2 findingswww.gstatic.com, fonts.gstatic.com
www.gstatic.com, fonts.gstatic.com
Google (cdn) loaded before consent
Google (cdn) loaded before consent
Amazon (cdn) loaded before consent
f5 BIG-IP cookie "BIGipServerredirects.ma1.webmd.com-443" set before consent — Used by the f5 BIG-IP load balancer to ensure one user's request is always handled by the same server to maintain a consistent user experience
Cloudflare bot management — necessary for site operation
Compliant119
Google Analytics3 findingsID trackedregion1.google-analytics.com, _ga_3ZVJC9H4TB, _ga

region1.google-analytics.com, _ga_3ZVJC9H4TB, _ga

GA4 (Google) loaded correctly after consent

Google Analytics cookie "_ga_3ZVJC9H4TB" set correctly after consent

Google Analytics cookie "_ga" set correctly after consent
Twitter/X Pixel2 findingsID trackedt.co, static.ads-twitter.com
t.co, static.ads-twitter.com
Twitter/X Pixel (X (Twitter)) loaded correctly after consent
Twitter/X Pixel (X (Twitter)) loaded correctly after consent
Pinterest Tag3 findingsID trackedct.pinterest.com, s.pinimg.com, _pin_unauth
ct.pinterest.com, s.pinimg.com, _pin_unauth
Pinterest Tag (Pinterest) loaded correctly after consent
Pinterest Tag (Pinterest) loaded correctly after consent
Pinterest Tag cookie "_pin_unauth" set correctly after consent

OneTrust CMP (OneTrust) loaded correctly after consent

Meta Pixel (Meta) loaded correctly after consent
Criteo2 findingsstatic.criteo.net, cto_bundle

static.criteo.net, cto_bundle

Criteo (Criteo) loaded correctly after consent

Criteo cookie "cto_bundle" set correctly after consent
Google Ads5 findings322dda659e1e3f95ecb55ba247b2d217.safeframe.googlesyndication.com, pagead2.googlesyndication.com, googleads.g.doubleclick.net, tpc.googlesyndication.com, _gcl_ls

322dda659e1e3f95ecb55ba247b2d217.safeframe.googlesyndication.com, pagead2.googlesyndication.com, googleads.g.doubleclick.net, tpc.googlesyndication.com, _gcl_ls

Google Ads (Google) loaded correctly after consent

Google Ads (Google) loaded correctly after consent

Google Ads (Google) loaded correctly after consent

Google Ads (Google) loaded correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent
Reddit Pixel2 findingsalb.reddit.com, _rdt_uuid
alb.reddit.com, _rdt_uuid
Reddit Pixel (Reddit) loaded correctly after consent
Reddit Pixel cookie "_rdt_uuid" set correctly after consent
OneTrust2 findingsOptanonAlertBoxClosed, OneTrustWPCCPAGoogleOptOut

OptanonAlertBoxClosed, OneTrustWPCCPAGoogleOptOut

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

OneTrust cookie "OneTrustWPCCPAGoogleOptOut" set correctly after consent
PrivacyPillar cookie "usprivacy" set correctly after consent
X cookie "personalization_id" set correctly after consent
Neustar cookie "ab" set correctly after consent
Marfeel2 findings_sharedID, _sharedID_cst
_sharedID, _sharedID_cst
Marfeel cookie "_sharedID" set correctly after consent
Marfeel cookie "_sharedID_cst" set correctly after consent
DoubleClick/Google Marketing3 findingsar_debug, IDE, __gads

ar_debug, IDE, __gads

DoubleClick/Google Marketing cookie "ar_debug" set correctly after consent

DoubleClick/Google Marketing cookie "IDE" set correctly after consent

DoubleClick/Google Marketing cookie "__gads" set correctly after consent
Media.net7 findingsvisitor-id, data-mts, data-r, data-pbs, data-ttd, data-g, data-co
visitor-id, data-mts, data-r, data-pbs, data-ttd, data-g, data-co
Media.net cookie "visitor-id" set correctly after consent
Media.net cookie "data-mts" set correctly after consent
Media.net cookie "data-r" set correctly after consent
Media.net cookie "data-pbs" set correctly after consent
Media.net cookie "data-ttd" set correctly after consent
Media.net cookie "data-g" set correctly after consent
Media.net cookie "data-co" set correctly after consent
Pinterest cookie "_pinterest_ct_ua" set correctly after consent
Adform2 findingsuid, C

uid, C

Adform cookie "uid" set correctly after consent

Adform cookie "C" set correctly after consent
openx.net2 findingsi, pd
i, pd
openx.net cookie "i" set correctly after consent
openx.net cookie "pd" set correctly after consent
NGINX Ingresss cookie "INGRESSCOOKIE" set correctly after consent
Yahoo2 findingsA3, IDSYNC
A3, IDSYNC
Yahoo cookie "A3" set correctly after consent
Yahoo cookie "IDSYNC" set correctly after consent
Google2 findingsreceive-cookie-deprecation, DSID
receive-cookie-deprecation, DSID
Google cookie "receive-cookie-deprecation" set correctly after consent
Google cookie "DSID" set correctly after consent
Xandr2 findingsXANDR_PANID, uuid2
XANDR_PANID, uuid2
Xandr cookie "XANDR_PANID" set correctly after consent
Xandr cookie "uuid2" set correctly after consent
Lotame4 findings_cc_dc, _cc_id, panoramaId, panoramaId_expiry
_cc_dc, _cc_id, panoramaId, panoramaId_expiry
Lotame cookie "_cc_dc" set correctly after consent
Lotame cookie "_cc_id" set correctly after consent
Lotame cookie "panoramaId" set correctly after consent
Lotame cookie "panoramaId_expiry" set correctly after consent
GumGum cookie "vst" set correctly after consent
TripleLift cookie "tluid" set correctly after consent
PubMatic21 findingsKADUSERCOOKIE, KRTBCOOKIE_391, KRTBCOOKIE_377, KRTBCOOKIE_80, DPSync4, KRTBCOOKIE_632, KRTBCOOKIE_452, KRTBCOOKIE_153, KRTBCOOKIE_945, KRTBCOOKIE_57, KRTBCOOKIE_32, KRTBCOOKIE_860, KRTBCOOKIE_1469, chk, KRTBCOOKIE_22, PugT, SyncRTB4, chkChromeAb67Sec, pi, pubsyncexp, SPugT
KADUSERCOOKIE, KRTBCOOKIE_391, KRTBCOOKIE_377, KRTBCOOKIE_80, DPSync4, KRTBCOOKIE_632, KRTBCOOKIE_452, KRTBCOOKIE_153, KRTBCOOKIE_945, KRTBCOOKIE_57, KRTBCOOKIE_32, KRTBCOOKIE_860, KRTBCOOKIE_1469, chk, KRTBCOOKIE_22, PugT, SyncRTB4, chkChromeAb67Sec, pi, pubsyncexp, SPugT
PubMatic cookie "KADUSERCOOKIE" set correctly after consent
PubMatic cookie "KRTBCOOKIE_391" set correctly after consent
PubMatic cookie "KRTBCOOKIE_377" set correctly after consent
PubMatic cookie "KRTBCOOKIE_80" set correctly after consent
PubMatic cookie "DPSync4" set correctly after consent
PubMatic cookie "KRTBCOOKIE_632" set correctly after consent
PubMatic cookie "KRTBCOOKIE_452" set correctly after consent
PubMatic cookie "KRTBCOOKIE_153" set correctly after consent
PubMatic cookie "KRTBCOOKIE_945" set correctly after consent
PubMatic cookie "KRTBCOOKIE_57" set correctly after consent
PubMatic cookie "KRTBCOOKIE_32" set correctly after consent
PubMatic cookie "KRTBCOOKIE_860" set correctly after consent
PubMatic cookie "KRTBCOOKIE_1469" set correctly after consent
PubMatic cookie "chk" set correctly after consent
PubMatic cookie "KRTBCOOKIE_22" set correctly after consent
PubMatic cookie "PugT" set correctly after consent
PubMatic cookie "SyncRTB4" set correctly after consent
PubMatic cookie "chkChromeAb67Sec" set correctly after consent
PubMatic cookie "pi" set correctly after consent
PubMatic cookie "pubsyncexp" set correctly after consent
PubMatic cookie "SPugT" set correctly after consent
The Tradedesk2 findingsTDID, TDCPM
TDID, TDCPM
The Tradedesk cookie "TDID" set correctly after consent
The Tradedesk cookie "TDCPM" set correctly after consent
CreativeCDN cookie "g" set correctly after consent
PayPal cookie "ts" set correctly after consent
Amazon2 findingsad-id, ad-privacy
ad-id, ad-privacy
Amazon cookie "ad-id" set correctly after consent
Amazon cookie "ad-privacy" set correctly after consent
Magnite4 findingskhaos, khaos_p, audit_p, audit
khaos, khaos_p, audit_p, audit
Magnite cookie "khaos" set correctly after consent
Magnite cookie "khaos_p" set correctly after consent
Magnite cookie "audit_p" set correctly after consent
Magnite cookie "audit" set correctly after consent
HAproxy cookie "SERVERID" set correctly after consent
ID53 findings3pi, gdpr, id5
3pi, gdpr, id5
ID5 cookie "3pi" set correctly after consent
ID5 cookie "gdpr" set correctly after consent
ID5 cookie "id5" set correctly after consent
Rapleaf2 findingsrlas3, pxrc
rlas3, pxrc
Rapleaf cookie "rlas3" set correctly after consent
Rapleaf cookie "pxrc" set correctly after consent
Casale Media3 findingsCMID, CMPS, CMPRO
CMID, CMPS, CMPRO
Casale Media cookie "CMID" set correctly after consent
Casale Media cookie "CMPS" set correctly after consent
Casale Media cookie "CMPRO" set correctly after consent
Tapad3 findingsTapAd_TS, TapAd_DID, TapAd_3WAY_SYNCS
TapAd_TS, TapAd_DID, TapAd_3WAY_SYNCS
Tapad cookie "TapAd_TS" set correctly after consent
Tapad cookie "TapAd_DID" set correctly after consent
Tapad cookie "TapAd_3WAY_SYNCS" set correctly after consent
LinkedIn3 findingsbcookie, li_gc, lidc
bcookie, li_gc, lidc
LinkedIn cookie "bcookie" set correctly after consent
LinkedIn cookie "li_gc" set correctly after consent
LinkedIn cookie "lidc" set correctly after consent
Smaato3 findingsSCM, SCMaps, SCMo
SCM, SCMaps, SCMo
Smaato cookie "SCM" set correctly after consent
Smaato cookie "SCMaps" set correctly after consent
Smaato cookie "SCMo" set correctly after consent
Outbrain cookie "obuid" set correctly after consent
Yieldmo cookie "yieldmo_id" set correctly after consent
SurveyMonkey cookie "re_sync" set correctly after consent

Quantcast cookie "mc" set correctly after consent
Sharethrough cookie "stx_user_id" set correctly after consent
Google AdSense2 findings__gpi, __eoi

__gpi, __eoi

Google AdSense cookie "__gpi" set correctly after consent

Google AdSense cookie "__eoi" set correctly after consent
1rx.io cookie "_rxuuid" set correctly after consent
Adobe Audience Manager2 findingsdemdex, dpm

demdex, dpm

Adobe Audience Manager cookie "demdex" set correctly after consent

Adobe Audience Manager cookie "dpm" set correctly after consent
Snowplow cookie "sp" set correctly after consent

Adobe Advertising cookie "everest_g_v2" set correctly after consent
Platform161 cookie "tuuid" set correctly after consent
bidswitch.net cookie "tuuid_lu" set correctly after consent
ComScore cookie "pid" set correctly after consent
localStorage availability probe (null) wrote "__storage_test__" to localStorage correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan webmd.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com