SiteAud!tLint Support

Consent checks and tracking before consent

Detect consent management platforms and Google Consent Mode, and find pixels and tracking cookies that fire before a visitor accepts cookies.

Consent rules such as GDPR, UK GDPR and ePrivacy expect analytics and ad tracking to wait until a visitor agrees. SiteAud!tLint checks whether a site has a consent tool and, with JavaScript rendering on, whether tracking starts before anyone clicks accept.

What is checked

  • Consent tool: 20 consent management platforms are recognised, including Cookiebot, CookieYes and OneTrust, plus Google Consent Mode defaults.
  • Tracking before consent: with rendering on, each page loads as a first-time visitor who has accepted nothing. Pixels that fire and tracking cookies that are set at that moment are reported as Tracking before consent, a critical issue.
  • GA4 hits sent with Consent Mode denied (gcs=G100) are allowed and not flagged, because they carry no cookies.

When analytics or pixels load and no consent tool or Consent Mode default is found at all, the audit reports Tracking without a consent tool.

  1. Load tags through the consent tool's GTM integration or Google Consent Mode.
  2. Set GTM tags to require ad_storage or analytics_storage consent.
  3. Remove hard-coded pixels from the theme; they bypass the consent tool.
  4. Run the audit again with rendering on and check Consent & cookies.

Personal data in URLs

Analytics tools record full page URLs. An email address, token or similar value in a URL ends up in GA4, which is against Google's terms, and leaks through referrers and server logs. SiteAud!tLint reports it as Personal data or tokens in URL.

Applies to SiteAud!tLint 0.7.0 and later. Current version 0.7.1.