3 findings · 5 warnings · 1 checks passed
Vendors
ncbr2PL_gOqWzguTYUHcnadC7H_IXqxUPeeMyWQypOn.Z7zZeVVmOo5UDA9hJZoJVJELeO7zFY1VrDPPofrZw6cpv.c7G-3ZPM02HS52GTM-KJ3F4RCH35243201099680873230701hiq8meb07zh11ae9buxxdj4z849438Violations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_009Affected: Hotjar, Seznam Sklik
The affected vendors set an identifier or sent measurement that is not verifiably cookie-less before the visitor chose. Load them only after consent, or configure a documented cookie-less mode that sends no identifiers.
GCM_012Affected: Gemius
No identifier was observed, but the visitor's IP address and page context still reached a third party before consent. To be compliant under this check, load the vendor only after consent.
CSP_001Affected: Criteo
The site's script-src directive does not allow the listed vendors' script domains, so real visitors' browsers block them. Add the domains to script-src or remove the unused tags.