2
1 Comment

I built a GDPR cookie consent scanner after seeing small sites fail external cookie scans

I have been building GDPRChecker, a privacy readiness tool for website owners who need a practical way to inspect cookie consent behavior.

The pain point: many small businesses install a cookie banner, but Google Analytics, Meta Pixel, GTM, or other marketing scripts may still fire before consent. External scanners then report a bad score, and the team has no clear evidence of what happened or where to fix it.

GDPRChecker focuses on technical behavior:

  • scan a public URL

  • detect cookie banner and policy links

  • inspect pre-consent cookies and network requests

  • check Google Consent Mode v2 defaults

  • show remediation guidance

  • for managed sites, install a runtime banner and verify heartbeat/config behavior

I am intentionally avoiding legal guarantees. The product does not provide legal advice. It gives operators a clearer technical picture of consent, cookies, and tracker behavior.

Current focus:

  • improving SEO pages

  • building trust with transparent evidence reports

  • making scanner results easier for non-technical founders

Try it: https://www.gdprchecker.online/scanner?utm_source=indiehackers&utm_medium=post&utm_campaign=seo_outreach

Questions for other founders:

  1. Have customers ever asked you for cookie consent evidence?

  2. Do you use Cookiebot, CookieYes, OneTrust, or something lighter?

  3. Would you pay for ongoing runtime verification, or only one-off scanning?

posted toAvatar for product GDPRChecker
GDPRChecker
  1. 1

    The sharpest line in your whole product is in this post, not on your homepage: a small business installs a cookie banner, and Google Analytics, Meta Pixel and GTM still fire before consent anyway. That is a specific, visceral problem, "my banner is lying to me and I cannot see it," and it is far stronger than the homepage's "free GDPR checker and website scanner," which is a category anyone can claim. Lead with the broken banner, not the generic scan.

    It also sharpens your competitive position. Cookiebot, CookieYes and OneTrust sell the banner. You are the tool that proves the banner actually works, catching the scripts that fire before consent even when one of those is installed. That is a complementary wedge, not a head-on fight: "the evidence layer that checks whether your consent setup really blocks trackers." Sitting on top of the incumbents is a far easier sale than replacing them, and keeping legal claims out, as you already decided, makes it more credible, not less. You are the technical truth, not another lawyer.

    To your monetization question: the one-off scan is your free SEO magnet, not your product. The business is the ongoing runtime verification, because a banner passes today and a new marketing tag breaks it next Tuesday. "Continuous proof your trackers stay blocked" is a subscription; a one-time scan is a screenshot. Which do the people who reach out to you ask about first, the score, or being able to prove it later?