Continuous Cookie & Tracker Scanner.
Automated production crawler identifying unclassified cookies, hidden tag manager drift, and unauthorized third-party scripts before regulators or users discover them.
Automated 24/7 DOM & network scanning
Pre-categorized ad & analytics trackers
Instant alerts on unapproved GTM triggers
Headless Chromium execution engine
Comprehensive Client-Side Auditing
Modern web properties deploy hundreds of tags across dynamic SPAs and marketing experiments. ConsentPlix crawls every branch of your frontend.
Shadow Tracker Interception
Identifies third-party ad pixels, session replay beacons, and tracking scripts loaded outside your approved consent manager governance rules.
Tag Manager Drift Detection
Catches newly published Google Tag Manager (GTM) or Tealium containers that inject marketing scripts without updated statutory consent categories.
Cookie & Storage Categorization
Maps every HTTP cookie, LocalStorage token, and IndexedDB key to DPDP purposes: Strictly Necessary, Functional, Analytics, or Advertising.
Zero-Consent Pre-Leak Guard
Flags third-party network beacons and tracking pings that fire prior to visitor interaction, violating affirmative opt-in mandates under DPDP §6.
Tracker & Vendor Classification Matrix
| Vendor Host / Script Origin | Purpose Category | Observed Storage Keys | Statutory Governance Status | Configured Lifespan |
|---|---|---|---|---|
| analytics.google.com | Analytics & Measurement | _ga, _ga_*, _gid | Compliant (Blocked Pre-Consent) | 2 Years (Configured to 13 Months) |
| connect.facebook.net | Advertising & Retargeting | _fbp, fr | Compliant (Conditioned on Opt-in) | 90 Days |
| static.hotjar.com | Session Recording & Heatmaps | _hjSessionUser_*, _hjSession_* | Requires Explicit DPDP Purpose Notice | 365 Days |
| api.segment.io | Customer Data Platform (CDP) | ajs_user_id, ajs_anonymous_id | Compliant (Data Routing Verified) | Session / LocalStorage |
How the Continuous Scanner Works
Headless browser instances render your pages exactly as real visitors experience them, verifying that no tracking scripts fire without explicit consent.
Deep Page Crawling
Crawls your sitemap, landing pages, authentication gateways, and checkout funnels using headless Chromium to trigger all lazy-loaded scripts.
Pre-Consent Network Sniffing
Monitors every outbound HTTP request, WebSocket handshake, and Beacon API call prior to clicking "Accept" on the consent banner.
Instant Incident Alerts
Dispatches immediate Slack, Teams, or webhook alerts to engineering teams when an unauthorized tracking script leaks past the banner.
Discover your domain's tracker compliance score.
Run an automated audit across your production domain and receive an instant report detailing all unclassified cookies and tag manager drift.