Scanner FAQ

Frequently asked questions

Everything you need to know about your cookie compliance scan, the regulations it measures against, and how to fix the issues it finds.

Why is my score so low when I have a consent tool installed?

The most common cause is the same late-loading issue described above: if your banner injects after the initial HTML, our scanner doesn't see it and scores your site as if it has no banner at all — a floor of 25/100 under our algorithm.

This isn't a quirk of our scanner. A real visitor's browser loads the page the same way we do; non-essential scripts fire before the banner asks for consent. That's what PECR Regulation 6 prohibits. The fix is to move the banner (or a blocking script) into the page <head> so it runs before any tracking.

Why are scripts I own showing as “Unknown”?

Our service database catalogues the most common third-party tools — Google Analytics, Meta Pixel, HubSpot, LinkedIn Insight, and so on. Scripts hosted on your own domain — your React/Next.js bundles, inline app logic, custom code — are tagged as first-party and won't match our database.

First-party unknown scripts don't affect your compliance score. If a third-party script shows as "Unknown", it means we haven't catalogued that service yet. Review it manually to confirm its category.

What regulations does this scan measure against?

The scan evaluates UK cookie law, which combines:

Equivalent rules apply across the EU under the ePrivacy Directive (2002/58/EC) and GDPR. SmartConsent covers 11 jurisdictions including UK, EU, California, Canada, Brazil, India and others.

Can I re-scan after fixing the issues?

Yes. Once you've installed SmartConsent or adjusted your banner, run the scanner again to verify. Pro subscribers get automatic monthly re-scans and compliance alerts if a regression is detected.

My cookies list is empty but I know my site sets cookies. Why?

The quick scan reads the initial HTTP response and only sees cookies set via Set-Cookie response headers. Cookies set by JavaScript after the page loads — which is very common — aren't visible to this type of scan. Our deep scan (headless browser) detects those; it's currently available to Pro subscribers only.

Does the scanner check pages other than my homepage?

The scan checks the exact URL you submitted. If you submitted your homepage, that's what we scan. Different pages on the same site can set different cookies (e.g. a checkout page with a payment processor), so if you want a fuller picture you can run additional scans on other URLs.

Does a low score mean I'll be fined?

No. A low score indicates compliance risk — not an automatic fine. The ICO typically engages organisations before taking enforcement action and will usually give time to remediate.

That said, the ICO has fined major UK sites for cookie non-compliance (see their enforcement register). Under UK GDPR, fines can reach 4% of annual worldwide turnover. More commonly, the reputational cost of an ICO investigation is what organisations want to avoid.

What's the difference between a quick scan and a deep scan?

Quick scan reads your site's HTML response — fast (2–5 seconds), sees anything present in the initial markup, and catches cookies set via HTTP headers. It's what we run on every free scan.

Deep scan loads your site in a real headless browser (Chromium), waits for JavaScript to execute, and captures cookies, scripts and network requests that only appear at runtime. It takes 15–30 seconds and is available to Pro subscribers.

Official sources

The scanner's findings and this FAQ are based on the following primary sources. We link out so you can verify everything directly.

Ready to scan your site?

Free, instant, no credit card. Get a compliance score in under 30 seconds.