Free Cookie Scanner: Check Your Website Compliance
Every website sets cookies. The question is: do you know which ones yours sets, who put them there, and whether your visitors have consented to them? Under privacy regulations like the Saudi PDPL, EU GDPR, and UAE PDPA, setting non-essential cookies without explicit consent is a legal violation. The first step toward compliance is knowing exactly what your website does — and that starts with a cookie scan.
Arqam360's free cookie scanner analyzes your website in seconds, detecting every cookie, tracker, and third-party script. It identifies compliance gaps, checks for Google Consent Mode v2 implementation, and gives you a clear A-F grade so you know exactly where you stand. No signup required — just enter your URL.
What Are Cookies and Why Do They Matter?
Cookies are small text files that websites store in visitors' browsers. They serve different purposes, and privacy law treats them differently based on their function:
- Essential cookies: Required for basic site functionality — login sessions, shopping carts, security tokens. These are always allowed.
- Analytics cookies: Track visitor behavior — page views, session duration, traffic sources. Google Analytics, Hotjar, and Clarity use these.
- Marketing cookies: Build audience profiles for advertising — Meta Pixel, TikTok Pixel, Snapchat Pixel, Google Ads. These require explicit consent under most privacy laws.
- Preference cookies: Store user preferences like language, theme, and region. Some regulations require consent for these.
Why Scanning Matters
Most website owners underestimate how many cookies their site sets. A typical e-commerce site loads 25-50 cookies from various sources — many added automatically by third-party scripts, plugins, and embedded widgets. You may have installed Google Analytics years ago and forgotten about the Facebook Pixel your marketing team added, the Hotjar session recording tool from a UX audit, or the LinkedIn Insight Tag from a B2B campaign.
Each of these scripts sets cookies that track your visitors. Under PDPL, GDPR, and other privacy laws, you are responsible for every cookie set on your domain — even those placed by third-party scripts you did not write. A cookie scan is the only way to get a complete, accurate picture of what your website actually does when a visitor arrives.
What the Arqam360 Scanner Checks
- First-party cookies: Cookies set by your domain, including session cookies, preferences, and analytics
- Third-party cookies: Cookies set by external domains — ad networks, social media platforms, analytics providers
- Tracker scripts: Detects GA4, Meta Pixel, TikTok Pixel, Snapchat Pixel, LinkedIn Tag, Bing UET, and more
- Google Consent Mode v2: Checks whether your site fires the four required consent signals (analytics_storage, ad_storage, ad_user_data, ad_personalization)
- Global Privacy Control (GPC): Tests whether your site respects the GPC browser signal
- Security headers: Checks HTTPS, Content-Security-Policy, and other security configurations
- Consent banner detection: Identifies if you have a consent management platform installed
How to Use the Free Scanner
Using the scanner takes less than a minute. Here is the process:
- Go to arqam360.com/tools/cookie-scanner
- Enter your full website URL (including https://)
- Wait 15-30 seconds while Arqam360 loads your site in a headless browser and catalogs every cookie and tracker
- Review your compliance score (0-100) and letter grade (A through F)
- See the list of detected cookies and trackers, categorized by type
- Identify the top compliance threats that need immediate attention
- Enter your email to receive the full detailed report (optional)
Understanding Your A-F Grade
Your scan results include a score from 0 to 100 and a corresponding letter grade. Here is what each grade means:
- A (90-100): Excellent compliance posture. Consent banner present, Google Consent Mode v2 active, minimal unconsented trackers.
- B (75-89): Good compliance with minor gaps. Usually missing one or two consent signals or has a few uncategorized cookies.
- C (50-74): Needs improvement. Consent banner may be present but not properly blocking trackers before consent. GCM v2 likely incomplete.
- D (25-49): Significant compliance risk. Multiple trackers firing without consent, no GCM v2 signals, missing privacy policy.
- F (0-24): Critical non-compliance. No consent mechanism, trackers loading freely, high risk of regulatory penalties.
Common Issues We Find
The most common issues detected across MENA websites are: Google Analytics firing before consent (found on 73% of scanned sites), Meta Pixel loading without a consent banner (61%), missing Google Consent Mode v2 signals (84%), no Arabic-language privacy policy (69% of Saudi sites), and third-party cookies from ad networks the site owner did not knowingly install (45%). Each of these represents a compliance violation under PDPL.
How to Fix Your Compliance Gaps
Once you have your scan results, the path forward is clear. Deploy a Consent Management Platform that blocks non-essential cookies until consent is granted, fires Google Consent Mode v2 signals, and stores consent records for audit purposes. Arqam360 does all of this automatically — install the widget, and your compliance gaps are resolved within minutes.
For Salla and Shopify stores, Arqam360 offers native integrations with zero-click setup. For any other website, add a single script tag and configure your banner from the dashboard. The scanner results page includes a direct link to start your free trial with Arqam360 pre-configured to address the specific issues found on your site.
Optimize your consent rates
Arqam360 helps MENA e-commerce sites achieve 70%+ opt-in rates with smart banner optimization.
Start Free TrialRelated Articles
Stay updated
Get privacy compliance tips and Arqam360 updates delivered to your inbox.