1 finding · 2 warnings · 6 checks passed
Vendors
5220968041507G-BJKL76S993GTM-3XTJ318029805739962934987862089090526421Violations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_010Affected: Hotjar
After a rejection the affected vendors must stop setting identifiers and sending measurement, or run only in a verified cookie-less mode.
GCM_009Affected: Google Analytics 4, Hotjar
The affected vendors set an identifier or sent measurement that is not verifiably cookie-less before the visitor chose. Load them only after consent, or configure a documented cookie-less mode that sends no identifiers.
GCM_012Affected: Google Ads
No identifier was observed, but the visitor's IP address and page context still reached a third party before consent. To be compliant under this check, load the vendor only after consent.
CSP_001Affected: Criteo, Google Analytics 4, Google Tag Manager, Hotjar, Meta Pixel
The site's script-src directive does not allow the listed vendors' script domains, so real visitors' browsers block them. Add the domains to script-src or remove the unused tags.