Reference

Which tools the scanner detects

Updated: September 22, 2026 For: analyst, head of analytics, developer, data protection officer

A website scan checks what a page sends to analytics and advertising tools before and after consent. To do that, it first has to recognise which tool it is looking at. This is the list of tools the scanner recognises, and how it recognises them.

This page covers website scans. Android apps have their own detection, which works on the app's traffic; this list does not apply to them.

How the scanner recognises a tool

The scanner opens the page in a browser and records what happens before the consent banner is clicked, after accepting and after rejecting. It recognises a tool by any of these traces:

  • a request to the tool's servers,
  • a cookie the tool writes,
  • an object the tool creates on the page, even when the site loads its script from its own domain,
  • the tool's code in the page's HTML, even while it is still waiting for consent.

As soon as the scanner finds any of them, the tool appears on the “Tools” tab. Entries in browser storage (localStorage, sessionStorage, IndexedDB) do not identify a tool on their own; for a tool already recognised, the scanner takes them into account in its rating. How the scanner rates it does not depend on its presence, though. What counts is what the tool did: whether it sent data or wrote an identifier before the visitor consented, and what it did after a rejection.

The list of tools

Category Tools
Analytics Adobe Analytics, Adobe Experience Platform, Exponea, Fathom Analytics, Gemius, Google Analytics 4, Google Universal Analytics, Hotjar, HubSpot, JHMT iCheck, Matomo, Microsoft Clarity, Nielsen, Plausible Analytics
Advertising Criteo, Google Ads, Heureka, LinkedIn Insight, Meta Pixel, Pinterest Tag, Seznam SEM, Seznam Sklik, TikTok Pixel
Functional Adobe Launch, Google Tag Manager

The category says what a tool is for, and with it what the scanner expects of it. Analytics, advertising and marketing tools count as tracking, and the scanner checks that they do not run ahead of consent. Functional tools, meaning tag managers, do not collect visitor data themselves. The scanner therefore does not count them as tracking and rates the tools the site launches through them instead.

The scanner looks for the consent banner by what is actually visible on the page, not by a list of vendors. It therefore also tests a banner from a platform it does not know, or a custom-built one.

Some platforms it also recognises by the object or element they create on the page: Borlabs, Complianz, Cookiebot, CookieFirst, CookieYes, CPEX, Didomi, OneTrust, Osano, Quantcast, Seznam CMP, SourcePoint, TrustArc, Usercentrics. It uses this only as further evidence that a consent platform has loaded; the scan result does not show the platform's name. The IAB TCF interface on its own does not identify a particular platform, so it is not on the list.

If your tool is missing

A tool the scanner does not know does not appear on the “Tools” tab and gets no rating of its own. The check for tracking cookies before consent, however, works from its own list of known cookie names, so it can still catch such a tool's identifier.

Does your site use a tool that is missing here? Tell us which one.



Found a mistake in this guide, or is something missing? Tell us

All guides