Your cookie banner says
“Reject all”. Does it?
Most consent banners record a refusal and then load the same trackers anyway. FixMyCookies clicks decline for you, reloads the page, and reports what was still watching.
- Nothing to install to look
- Real browser, not a HEAD request
- We never say “you're compliant”
1. A page tries to load two trackers
Below is the actual fixmycookies.js that ships to customers. A script on
this page is trying to inject a Meta Pixel and a Hotjar session recorder. Watch what
happens before you decide anything.
Blocked request log
Every attempt the SDK stopped, as it happened.
- nothing attempted yet
Findings, not a score out of 100
Every finding names the service, shows the evidence we saw, and says what to do about it. You can disagree with us with the data in front of you.
Trackers before consent
Analytics, ad pixels and session recorders that load on first paint, before anyone has been asked anything.
A refusal that does nothing
“Reject all” clicked, page reloaded, and the same trackers still fire. Our most serious finding, and the one almost nobody tests.
Cookies set too early
Named cookies with their vendor, purpose and lifetime — including the ones JavaScript can't see because they're HttpOnly.
Google Consent Mode
Whether consent default is declared at all, and whether any category is
granted before the visitor has chosen.
Global Privacy Control
We signal GPC the way a browser does and check whether advertising still loads. In California that signal is not decorative.
Policy that names nothing
“We use cookies to improve your experience” and not one cookie named. A regulator can check that in ten seconds.
Three scenarios in one real browser
Not a HEAD request. The interesting part of consent happens after the page loads, and you cannot see it from HTML.
First visit
A clean browser profile loads your page. Everything that fires before any choice is recorded, with timings.
Reject all, then reload
We find the refusal control, click it, reload, and diff the network activity. If the trackers come back, that is the headline.
Accept all
What consent actually unlocks — useful when someone asks you why the analytics dashboard went quiet.
Things we will not do
A compliance product that lies to you about compliance is worse than no product. So, in writing:
We will never tell you that you are compliant
No scan can establish that. It depends on your lawful basis, your contracts and your data flows — none of which are visible from outside your business.
We will never invent a statistic
No made-up percentages, no “average fine” figure, no customer counts we can't evidence. Where a number appears here, you can check it.
We will say when a result is unproven
Consent banners are usually shown only to visitors a site thinks are in the EU. When we cannot appear European, we say a missing banner is unproven — not that none exists.
We will show our working
Every report exposes the raw observations behind it, including the cookies and third parties, so a developer can verify each conclusion directly.
We will not sell with fear
GDPR Art. 83(5) allows up to €20 million or 4% of total worldwide annual turnover, whichever is higher. That is the ceiling, not the expectation, and we will not blur the two to sell you a subscription.
Free, and honest about why
FixMyCookies is in beta. The scanner works, the banner works, and both are free to use while we finish the hosted version. There is no card field anywhere on this site because there is nothing to charge you for yet.
What exists today
The scanner, the refusal test, the consent banner SDK, signed consent receipts, and the reports.
What does not
Hosted accounts, scheduled monitoring emails, and billing. We will say so on the day that changes.
What that means for you
Use it, keep the reports, and don't build a process that depends on us existing yet.
The banner, in two lines
Self-hosted, self-contained, and it makes no third-party requests of its own.
<!-- In <head>, WITHOUT defer: it must install its hooks
before your tag manager runs. -->
<script src="/fixmycookies.js"></script>
<script>
window.FixMyCookiesConfig = {
endpoint: '/api/consent', // where signed receipts are sent, optional
policyUrl: '/privacy'
};
</script>
<!-- Anything held back until consent: -->
<script type="text/plain" data-consent="analytics"
src="https://www.googletagmanager.com/gtm.js?id=GTM-XXXX"></script>
Worth asking
Why might you find no banner when there is one?
Because location decides. Many consent banners are only shown to visitors a site believes are in Europe. Our scanner presents itself as European, but it cannot change the IP address it connects from — so a site that geolocates by IP still shows us the non-European page.
When that happens the report marks the absence unproven rather than deciding it for you. We would rather say “we don't know” than be confidently wrong.
Is this free? What's the catch?
Free while in beta. The catch is that it is a beta: the hosted scanning service and scheduled monitoring are not finished, and this page tells you so rather than implying otherwise. See the terms.
I don't have EU visitors. Does this apply to me?
If you have EU or UK visitors, GDPR or UK GDPR applies — where your business is based doesn't change that. Other regimes differ in kind, not just in name: California's CCPA/CPRA is principally an opt-out and disclosure regime rather than a prior-consent one, so a GDPR-shaped banner may be the wrong shape for it.
Is this legal advice?
No, and it is not a substitute for it. We describe observed behaviour and cite the rule an observation relates to. Whether it creates exposure depends on facts we cannot see.
What are the known gaps in the beta?
Stated plainly, because you will find them eventually: single-page apps are observed on one load only; a banner hidden inside a cross-origin iframe will be missed; login-gated pages are not scanned by design; and consent receipts tell you what a browser reported, not that a particular person understood anything.