AUTOMATED AUDIT · SHADOW TRACKER DETECTION

Continuous Cookie & Tracker Scanner.

Automated production crawler identifying unclassified cookies, hidden tag manager drift, and unauthorized third-party scripts before regulators or users discover them.

Crawl Frequency
Continuous

Automated 24/7 DOM & network scanning

Vendor Taxonomy
3,800+ Vendors

Pre-categorized ad & analytics trackers

Tag Manager Drift
Zero Drift

Instant alerts on unapproved GTM triggers

DOM Interception
< 1ms Latency

Headless Chromium execution engine

DETECTION ENGINE

Comprehensive Client-Side Auditing

Modern web properties deploy hundreds of tags across dynamic SPAs and marketing experiments. ConsentPlix crawls every branch of your frontend.

++++
MODULE 01

Shadow Tracker Interception

Identifies third-party ad pixels, session replay beacons, and tracking scripts loaded outside your approved consent manager governance rules.

MECHANISMDeep DOM Mutation Observer
++++
MODULE 02

Tag Manager Drift Detection

Catches newly published Google Tag Manager (GTM) or Tealium containers that inject marketing scripts without updated statutory consent categories.

MECHANISMContainer Version Auditing
++++
MODULE 03

Cookie & Storage Categorization

Maps every HTTP cookie, LocalStorage token, and IndexedDB key to DPDP purposes: Strictly Necessary, Functional, Analytics, or Advertising.

MECHANISMAutomated Expiration & Scope Checks
++++
MODULE 04

Zero-Consent Pre-Leak Guard

Flags third-party network beacons and tracking pings that fire prior to visitor interaction, violating affirmative opt-in mandates under DPDP §6.

MECHANISMNetwork Waterfall Profiling
LIVE AUDIT REPORT SAMPLE

Tracker & Vendor Classification Matrix

Vendor Host / Script OriginPurpose CategoryObserved Storage KeysStatutory Governance StatusConfigured Lifespan
analytics.google.comAnalytics & Measurement_ga, _ga_*, _gidCompliant (Blocked Pre-Consent)2 Years (Configured to 13 Months)
connect.facebook.netAdvertising & Retargeting_fbp, frCompliant (Conditioned on Opt-in)90 Days
static.hotjar.comSession Recording & Heatmaps_hjSessionUser_*, _hjSession_*Requires Explicit DPDP Purpose Notice365 Days
api.segment.ioCustomer Data Platform (CDP)ajs_user_id, ajs_anonymous_idCompliant (Data Routing Verified)Session / LocalStorage
CRAWLER PIPELINE

How the Continuous Scanner Works

Headless browser instances render your pages exactly as real visitors experience them, verifying that no tracking scripts fire without explicit consent.

STAGE 01

Deep Page Crawling

Crawls your sitemap, landing pages, authentication gateways, and checkout funnels using headless Chromium to trigger all lazy-loaded scripts.

STAGE 02

Pre-Consent Network Sniffing

Monitors every outbound HTTP request, WebSocket handshake, and Beacon API call prior to clicking "Accept" on the consent banner.

STAGE 03

Instant Incident Alerts

Dispatches immediate Slack, Teams, or webhook alerts to engineering teams when an unauthorized tracking script leaks past the banner.

AUDIT YOUR SITE

Discover your domain's tracker compliance score.

Run an automated audit across your production domain and receive an instant report detailing all unclassified cookies and tag manager drift.