Headless Chromium, watching every request the page actually makes. Free, no account, results in about a minute.
Free scan · no account · results in about a minute
The scan opens your pages in a real headless Chromium and records every network request they make, which is the only way to see a tracker that is injected by another script, added by a tag manager, or set from inside an embed. Parsing HTML finds the script tags somebody typed and misses everything loaded at runtime, which on a typical site is most of it. Each host found is matched against a table of 221 we classify by hand across 148 vendors; anything unrecognised is reported as unknown rather than guessed at, and stays blocked until you decide.
The policy is written from the scan rather than from a template, so it names the hosts actually on your site and the cookies they actually set.
A scanner that fetches your HTML and looks for known script tags will find Google Analytics and miss the four things Google Analytics loaded. It also cannot see cookies, because cookies are set at runtime and not written in the markup. The gap is not small: on most sites the majority of third-party requests come from other third parties rather than from anything in the page source.
No. Enter a domain and you get the result. An account is only needed to install the banner and keep the site scanned on a schedule.
Weekly by default, and you can set it to daily or monthly or run one on demand. A tracker found by a re-scan is blocked from the moment it appears, and you get an alert.
It is reported as unknown and held. Guessing a category would be worse than saying so: the safe outcome is that it stays blocked until somebody decides what it is.
It crawls a handful of pages once, politely, and identifies itself in its user agent. There is a page at https://getattesso.com/scanner explaining it, for whoever is reading your server logs.
Unlimited pages, unlimited visitors, 24 months of consent records in the EU. Less per site as you add more.
Start your free trial