Scanner

Run crawls, manage tracker inventory, fix classifications, and resolve compliance issues.

Scanner — Cookie compliance page ready to run a Quick or Full scan
Scanner — Cookie compliance page ready to run a Quick or Full scan

Overview

The Scanner visits your public website like a real browser. It finds cookies and third-party scripts, groups them into consent categories, and lists issues you should fix before (or after) you publish your banner.

You will use Scanner results in Consent Setup, Reports, and the AI Assistant. Most teams run a Quick Scan first, then a Full Scan once the site is ready.

When to use it

  • Setting up CookieShift for the first time
  • After you publish new tags in Google Tag Manager
  • After a theme, plugin, or app change
  • Before an audit or compliance review

Setup

  1. Select your website in the header.
  2. Open Scanner (also labeled Cookie compliance).
  3. Click Quick Scan for a faster sample, or Full Scan for a deeper crawl.
  4. Wait until the status shows Completed.
  5. Open Tracker Inventory and clear Unclassified items.
  6. Re-scan after major website or tag changes.

Examples

GoalWhere to start
First audit of a new propertyFull scan → Overview → Issues export
After GTM publishFull scan → compare new domains in Overview
Legal evidence packIssues tab → PDF export + Compliance
Ongoing monitoringMonitoring tab → schedule recurring scans

Troubleshooting

SymptomLikely causeFix
Scan stuck QueuedWorker or Redis unavailableCheck Settings → System Health; retry later
Scan FailedSite unreachable, auth wall, or timeoutConfirm URL is public HTTPS; reduce scope
Zero cookies foundBot blocked or SPA-only loadAllow crawler user-agent; test homepage
Counts differ from DevToolsCrawler visits more URLs than you manuallyExpected — use inventory as superset
Staging not scannedPassword-protectedAdd staging as its own property if publicly reachable

Best practices

  • Scan after every major release, tag-manager publish, or new marketing app — at least monthly.
  • Clear Unclassified items before exporting for legal review.
  • Keep one property per registrable domain unless using Cross-domain consent.
  • Pair scanner fixes with Consent Setup category copy updates.

Agency Shared Crawl Pool

On the Agency plan, scans do not burn pages from the shared pool each time they run. Instead:

  1. Your workspace has a Shared Monthly Crawl Pool (20,000 + optional +10,000 page packs).
  2. Each website receives a Monthly Crawl Allocation — reserved crawl capacity for that site.
  3. Every Quick / Full / Manual / Scheduled scan crawls up to that website’s allocation (and never more URLs than exist on the site).
  4. You may run scans unlimited times. Each run reuses the same allocation; it does not take another block of pages from the shared pool.
  5. When you add an Agency website, CookieShift first runs URL discovery with the same discovery engine the Scanner uses (no allocation required for discovery), then you can reserve pages from the shared pool (or configure later).

See Agency Shared Crawl Pool for allocation, coverage, and add-ons.


Detailed reference

What Scanner does

CapabilityOutcome
CrawlDiscovers cookies, scripts, and third-party requests on public pages
ClassifyAssigns Necessary / Preferences / Analytics / Marketing / Unclassified
Score riskLow, Moderate, Elevated based on gaps and unclassified share
Feed reportsPowers Compliance exports and dashboard KPIs

Header actions

ButtonWhen to use
View ReportOpen full persisted compliance report (needs report ID)
Run Scan / Run Full ScanStart standard crawl
Stop ScanCancel in-progress crawl
Export reportCSV export of current inventory
RefreshReload data without new crawl

Tabs

KPIs, charts, enterprise scan config, and scan history.

Overview tab

ElementMeaning
Scan progress barPages scanned vs target while running
Total cookiesCount from latest completed crawl
Active trackersScript-like resources tracked
Elevated riskAction-needed risk label
New domains / RemovedDelta vs previous scan
Insight bannersUnclassified %, risk narrative, last scan time
Category breakdownDonut + legend
Scan history chartTrend across crawls

Enterprise scan configuration (when shown):

SettingPurpose
Max pagesCap crawl size
DepthLink depth limit
Time limitStop after N seconds
WorkersParallelism
Auth modeCrawl behind login (advanced)
Multi-variant presetCrawl variants
Run enterprise scanExecute with these params

Scan history table: Date, pages, cookies, trackers, risk — View / per-row CSV.

Import last crawl: Appears when library empty but scan completed.

Categories tab

Pie chart + legend + total count—use for executive summaries.

Tracker Inventory tab

ControlBehavior
Open AI Review Queue/ai-review
Chart / Table / Group by domainLayout modes
Search + filtersCategory, domain, risk
Sortable columnsName, type, category, domain, risk, hits, source
Override categoryPer-row select; persists for property
Explain / Valid / False positiveScript review workflow
AI explanation panelModel reasoning when available
MetricSource
Config versionPublished banner generation
Decisions recordedLive consent count
Consent distribution donutVisitor choices
Script behavior chartTelemetry or heuristic
Summary cardsAccept / reject / customize %, quality, risk
LinkConsent logs for row-level export

Compliance Issues tab

ElementPurpose
Issues overview chartCounts by issue type (heuristic)
Export PDF / CSVAudit artifacts
Export historyRe-download past exports

Deep link: ?tab=compliance-issues or Reports hub ?focus=issues.


Risk labels

LabelMeaningTypical action
LowFew open gapsMonitor monthly
ModerateSome misclassified or missing copyFix inventory + Content
ElevatedMany unclassified or before-consent flagsUrgent review
In progressScan runningWait
AttentionLast scan failedRe-run scan

Scan modes compared

ModeBest forNotes
Standard Run ScanWeekly hygieneDefault limits
Run Full ScanDeep auditMore pages/time
Enterprise scanLarge sites, authConfigure caps first
Re-scan from WebsitesSame as Scanner entryPer-row shortcut

User journey: audit trackers

  1. Select property → Run Full Scan → wait for Completed.
  2. Overview — note Elevated risk and new domains.
  3. Inventory — filter Unclassified → override or AI classify.
  4. Issues — export PDF for legal.
  5. Consent Setup — align category copy.
  6. Re-scan → compare scores in Compliance.

FAQ

Why do counts differ from browser DevTools?

Crawler visits many URLs and may catch tags you never trigger manually.

Can I scan staging?

Add staging as its own property if it is publicly reachable; password-only staging may fail.

How often should I scan?

After every major release, tag manager publish, or new marketing app install—minimum monthly.