Best Cookie Scanners and Consent Auditing Tools

Every cookie inventory is wrong within a month. Not because it was done badly, but because someone installed a plugin, an embedded widget updated, or a marketing tool started setting something it did not set before. Scanning is a different product class from banners for exactly this reason: a banner describes what you believe your site does, and a scanner tells you what it actually does.
You cannot categorise a cookie you have not found, and a consent banner that omits half your trackers is a written statement that they do not exist. This article covers what scanning actually catches, how often to run it, and which tools do the job, including the free one already installed on your computer.
Verified August 2026. Prices confirmed against vendor pages.
Why manual inventories go stale immediately
A manual inventory is a photograph of a moving thing. Four common events invalidate it, and none of them announce themselves.
Plugin installation is the usual culprit. Marketing, ecommerce, and social plugins routinely inject tracking as part of their normal function, and nothing in the installation flow says so. Third-party updates change what an external service sets without touching your site at all; a chat widget or reviews platform can add a cookie in its own release cycle. Embedded content varies by page, so a scan of your homepage misses the video on one product page and the map on your contact page. And tag manager containers let anyone with access add a tag that your consent configuration has never heard of.
The practical implication is that scanning frequency matters more than scanning depth. A thorough annual audit is worth less than a shallow monthly one, because the risk is not that you failed to find something subtle. It is that something obvious appeared after you looked.
The 6 options compared
1. Browser developer tools
Free, already installed, and the only tool here that shows you the truth about a specific page rather than an aggregate. Every scanner in this comparison is ultimately automating what you can do by hand in ten minutes, and doing it by hand once teaches you what the automated reports mean.
Open a private window, load a page without touching the banner, and read two panels. The Network tab shows every third-party request, which is the more important view because a request to an advertising domain transmits data whether or not it sets a cookie. The Application tab lists cookies and local storage, including the things a cookie-focused scanner might classify oddly. Check a product page, a page with an embed, and your checkout, since those differ. The limitation is obvious: it does not scale, and it does not run itself while you are asleep.
- Price: Free
- Coverage: One page at a time, in complete detail
- Best for: Verifying anything a scanner tells you
- Watch out for: No scheduling, no history, no coverage of the whole site
2. Cookiebot by Usercentrics
The strongest dedicated scanner in the category and the product most worth buying for scanning alone. Its crawler works through your pages, builds an inventory, categorises what it finds, and repeats on a schedule so newly introduced trackers surface instead of accumulating quietly.
Pricing is by page count, roughly €12 a month under 500 pages, €28 under 5,000, and €49 above, which is the meter to check because it is driven by your archive rather than your audience. A shop with 8,000 SKUs or a publisher with a decade of posts lands on the top tier at €588 a year no matter how quiet the site is. Against that, a small business site with forty pages gets the best scanning available for €144 a year, which is straightforwardly good value.
- Price: ~€12, €28, or €49 a month by page count
- Coverage: Scheduled full-site crawl with categorisation
- Best for: Anyone who needs discovery to be automatic
- Watch out for: Large archives hit the top tier regardless of traffic
3. Complianz
Scanning is included in the free version, which is the single most useful fact in this article. Complianz runs a periodical cookie scan checking for changes in cookies, plugins, and third-party services, at no cost, on over a million installations.
Its approach differs from a pure crawler in a way that suits WordPress. Rather than only walking URLs, it inspects the installation, so a plugin that adds tracking is noticed as a plugin change rather than inferred from a page. That catches things earlier and is less dependent on the scanner happening to crawl the one page where a tracker appears. Premium at $59 a year, flat adds consent records, Consent Mode v2, geo-differentiated notices, and state-level US configuration, none of which is scanning. If discovery is all you want, the free version genuinely delivers it.
- Price: Free for scanning; Premium $59 a year, flat
- Coverage: Periodic scan of cookies, plugins, and services
- Best for: WordPress sites, at any budget including zero
- Watch out for: Consent records and Consent Mode v2 are premium
4. CookieYes
From $10 a month on a pageview meter, with scanning bundled into a platform that also handles banners, multiple jurisdictions, and policies. For a site that wants one subscription covering everything, that consolidation is the appeal.
Its scanning is competent rather than category-leading, which is the right expectation for a bundled feature. Where it differs usefully from Cookiebot is the meter: pageviews rather than page count, so a large archive with modest traffic is cheap here and expensive there, and a small high-traffic site is the reverse. Those two products are frequently shortlisted together, and the deciding factor is almost always which side of that meter your site sits on rather than any feature.
- Price: From $10 a month, scaling with pageviews
- Coverage: Bundled scanning within a full consent platform
- Best for: Large archives with modest traffic
- Watch out for: Traffic growth raises the bill
5. Free online scanners
Several vendors offer a free scan of a handful of pages as a lead generator, and used deliberately that is a genuine service rather than a trick. You get an independent inventory without installing anything or entering a card.
Their value is as a second opinion. Running one against a site that already has a consent tool configured is a cheap way to catch the gap between what your plugin believes and what an outsider sees, and the results are frequently uncomfortable in a useful way. Their limits are equally real: a small page allowance, no scheduling, no history, and a report engineered to make the paid product look necessary. Read the findings, ignore the urgency, and verify anything surprising in developer tools before acting on it.
- Price: Free, with page limits
- Coverage: A few pages, once
- Best for: An independent second opinion
- Watch out for: Reports designed to sell; verify before believing
6. Osano and enterprise platforms
Paid plans from around $199 a month, where scanning is one component of continuous monitoring across a portfolio rather than a feature you run against one site.
What the money buys is scope and accountability: monitoring across many properties, alerting when something changes, vendor and data-flow tracking beyond cookies, and reporting a compliance function can act on. For an organisation where a marketing team can deploy tags without telling anyone, continuous monitoring is genuinely the control that catches it. For a single WordPress site it is roughly forty times the cost of a plugin that scans adequately, and the honest recommendation is to start free and escalate only when a real gap appears.
- Price: Free tier; paid from around $199 a month
- Coverage: Continuous monitoring across a portfolio, with alerting
- Best for: Organisations where tags appear without warning
- Watch out for: Enterprise cost against single-site need
Comparison table
| Option | Price | Meter | Scheduled | Scope |
|---|---|---|---|---|
| Developer tools | Free | None | No | One page, full detail |
| Cookiebot | €12 to €49/mo | Page count | Yes | Full-site crawl |
| Complianz | Free; Premium $59/yr | None | Yes | Cookies, plugins, services |
| CookieYes | From $10/mo | Pageviews | Yes | Site scan plus consent platform |
| Free online scanners | Free | Page limits | No | A few pages, once |
| Osano and similar | From ~$199/mo | Platform tiers | Continuous | Portfolio monitoring with alerts |
The misclassifications scanners make
A scanner finds cookies; deciding what they are for is a judgement it makes with incomplete information. Four errors recur often enough to check by hand after any automated categorisation.
- Analytics filed as necessary. The most consequential error, and common because analytics feels essential to the site owner. It is not essential to the visitor, which is the test.
- Unknown cookies filed as necessary. When a scanner cannot identify something it often defaults to the safest-looking category, which is the least safe outcome. Anything unidentified should be investigated, not waved through.
- Marketing dressed as functional. Recently viewed products, personalised recommendations, and saved preferences that feed a profile are marketing wearing a functional label.
- Local storage ignored. Many scanners report cookies specifically. Storing an identifier in local storage instead of a cookie is the same act on the device and attracts the same rules.
Then there is the category nothing handles well: cookies set by embeds you do not control. A video, a map, or a social feed sets whatever its owner decides, and that can change without notice. You cannot maintain an accurate inventory of someone else’s choices, which is why the correct treatment is structural rather than clerical. Block the embed behind a placeholder until consent, and the question of what it sets stops being yours to track.
Related guides
Frequently asked questions
How often should I scan?
Monthly as a baseline, and after every plugin installation or marketing change. Frequency beats depth here, because the risk is a new tracker appearing rather than an old one hiding.
Do scanners find everything?
No. They see what a crawler encounters, so logged-in areas, checkout steps, and pages behind forms are frequently missed. Walk those manually in developer tools at least once.
Is a free scan good enough?
For most WordPress sites, yes. Complianz scans on its free version, and that plus a manual pass covers the majority of real cases. Pay when you need scheduling across many sites or alerting you cannot get otherwise.
What if the scanner finds something I cannot identify?
Search the cookie name, then work out which plugin sets it by deactivating candidates on staging. Do not categorise it as necessary because you cannot place it; that is exactly the wrong default.
Does scanning slow my site down?
A crawl adds load while it runs, which is worth scheduling for a quiet period on a large site. It has no effect on visitors outside the scan window.
Should the scan drive my banner automatically?
Let it populate the list, then review the categories yourself before publishing. Automatic categorisation is a good draft and a poor final answer, particularly for anything filed as strictly necessary.
The verdict
Start with the free version of Complianz. It runs periodic scans of cookies, plugins, and third-party services at no cost, on a WordPress site, which is what most people asking this question actually need.
If you want the best dedicated scanner: Cookiebot, budgeted by page count rather than traffic, and cheap at €144 a year for a small site.
If you have a large archive and modest traffic: CookieYes, whose pageview meter is the friendlier one for that shape of site.
And do one manual pass regardless. Open developer tools on a product page, a page with an embed, and your checkout, before touching the banner. Ten minutes there will tell you whether the automated inventory you are relying on is describing your site or a version of it that no longer exists.




