Checklist
Free cookie scanners compared: after Reject All, who still sees the request?
On Store F, four free scanners returned no cookie list. After Reject All, a request log still showed which hosts kept sending. No HAR.
In brief
On Store F, four free cookie scanners finished empty or never left a progress screen. None showed who still received requests after Reject All. The request log, with no HAR, showed the hosts that kept requesting. After Reject All and one reload, GA, GTM, syndication, TVSquared, Attentive, Dynamic Yield, and Elevar still requested. Northbeam, Heap, Contentsquare, and a set of ad hosts stopped. Cookies already set stayed. One US session on October 7, 2026. This page is not legal advice.
Not legal advice
This page records one automated browser session on Store F, a bedding brand on Shopify with OneTrust, after Reject All. It is not legal advice and not a ruling on any store. The record is a request log plus the four free-scan screens. Observation is not counsel permission.
Last updated October 7, 2026. The capability table is doc-sourced, not verified by us. Check date: 2026-10-07 (Asia/Shanghai).
Short answer
The same Store F URL went through Cookiebot, CookieYes, CookieScript, and Termly on October 7, 2026. Cookiebot stayed on Preparing data for more than three minutes and asked for an email. No email was entered. CookieYes finished empty. CookieScript returned no report, twice. Termly stayed on Scanning your website for more than two minutes. None of those screens listed who still received requests after Reject All.
A separate pass logged request hosts. There is no HAR. Before any click, every host in the table below was already requesting. After Reject All and one homepage reload, google-analytics.com, googletagmanager.com, googlesyndication.com, the TVSquared collector, Attentive, Dynamic Yield, and the Elevar GTM suite were still requesting. northbeam.io, heap-api.com, contentsquare.net, and the stackadapt, tapad, impact, grin, pdscrb, and mgln hosts were not seen again in that window.
Cookies already on the profile stayed, including _ga, _fbp, and cookies for Attentive, Northbeam, Heap, Contentsquare, TVSquared, and Ometria. A free US-baseline visit is not an EU or California legal conclusion. ConsentProbe does not install a CMP.
What the October 7, 2026 session showed
The browser was an automated session. Requests were counted by host for about 10 to 12 seconds after network idle. There was no DevTools Network panel and no HAR export. The shell exit was Ashburn, Virginia, in the United States. The browser was assumed to use that same egress. It was not checked on its own.
The profile already held Store F cookies from earlier visits. OptanonAlertBoxClosed was absent, so the OneTrust banner still appeared. The first layer showed Reject All, Manage Preferences, and Accept Cookies. Fresh was the homepage with no banner click.
Reject All was clicked on that first layer. The session waited about 10 seconds, then reloaded the homepage once. The banner did not return. OptanonAlertBoxClosed was set, and the browser posted to privacyportal.onetrust.com. No product page was opened on this pass.
The table is the host set written down for this compare. Other hosts in the same log, including a fraud vendor and a wishlist relay, sit outside it. A host missing after the reload was not seen in that window. Absence in the window does not prove the tag never fires.
| Host | Fresh, no click | After Reject All and reload |
|---|---|---|
| google-analytics.com | yes | yes |
| googletagmanager.com | yes | yes |
| googlesyndication.com (pagead2 and ade) | yes | yes |
| us.tvsquared.com collector | yes | yes |
| attn.tv and attentivemobile.com | yes | yes |
| dynamicyield.com | yes | yes |
| getelevar.com (Elevar GTM suite) | yes | yes |
| northbeam.io | yes | no |
| heap-api.com | yes | no |
| contentsquare.net | yes | no |
| stackadapt, tapad, impact, grin, pdscrb, mgln | yes | no |
Cookies stayed, and parameters were not read
None of those cookies were cleared after Reject All. _ga, a _ga_* cookie, _fbp, and cookies for Attentive, Northbeam, Heap, Contentsquare, TVSquared, and Ometria were still present. This session did not check whether the values were rewritten. OneTrust did not delete the existing cookies on reject in this session.
Query parameters were not read. A google-analytics.com row in this log is not split into a cookieless Consent Mode ping and a hit that still carries a cookie. That split is the cookieless ping check.
What the four free scanners showed
The same homepage URL was submitted to each free public scanner. No email was entered. Empty and unfinished screens are the result. Nothing in this table is a filled cookie inventory.
Cookiebot's blurred overlay included placeholder lines, including "Low risk" and zero trackers. The scan had not finished, so those lines were not treated as a report. The visible copy talked about prior consent in general. It did not name Reject All, and it did not list hosts that still received requests after a reject.
CookieYes completed. The page said: Sorry! We couldn't find any cookies on this URL. CookieScript was tried with the www URL and again without www. Both times the page said: Oh... Sorry, no report found. Termly was still on Scanning your website after more than two minutes, with a sign-up prompt to be notified. The page says 30 to 60 seconds is normal.
None of the four clicked Reject All. None showed the after-Reject host list from the request log.
| Scanner | What the free page showed | After-Reject hosts shown? |
|---|---|---|
| Cookiebot | Stuck on Preparing data for more than 3 minutes. Email form for the report. No email entered. Blurred overlay not counted. | No |
| CookieYes | Finished. Sorry! We couldn't find any cookies on this URL. | No |
| CookieScript | Tried twice. Oh... Sorry, no report found. | No |
| Termly | Still on Scanning your website after more than 2 minutes. Sign-up prompt to be notified. | No |
What the vendor pages say they do
The next table is what the vendors' own pages say a free scanner can do. Every cell is doc-sourced, not verified by us. Check date: 2026-10-07 (Asia/Shanghai). The Store F run is the section above, not this table.
Cookiebot's scan-report article describes prior-consent flags, including cookies set before consent. CookieYes says its checker can include some cookies set while someone uses a banner. The CookieScript and Termly scanner pages do not describe a labeled before-Accept pass. Store F produced no finished Cookiebot report, so this session has no prior-consent flag.
Those pages name GDPR, ePrivacy, or US state laws. They do not publish the country of the crawl. This article does not assign a scan location to Cookiebot, CookieYes, CookieScript, or Termly.
Public comparison pages checked the same day mostly set price, page limits, and cookie categories next to each other. ConsentStack published its own scanner study on 2026-09-01. That study is their evidence.
| Scanner | Cookie inventory in the docs | Reject All recheck in the docs | Request-level evidence in the docs | Free public limit in the docs |
|---|---|---|---|---|
| Cookiebot | Yes. The report uses Necessary, Preferences, Statistics, Marketing, and Unclassified. The checker page also names necessary, functional, analytics, performance, and advertising. | Not claimed on the free checker page. | Claims first- and third-party cookies and third-party requests, with Source, Initiator, and Via. No downloadable HAR is claimed. | Free checker with an email report. A separate free CMP subscription is one domain under 50 pages, and automated monthly scanning is off. |
| CookieYes | Yes. Necessary, Functional, Analytics, Performance, and Advertisement, with cookie ID, domain, duration, and description. | Not claimed on the free checker page. | Detects HTTP, JavaScript, and HTML5 local storage cookies. The free checker page does not claim a full third-party request list. | Free plan: 5 scans a month, 100 pages a scan, 5,000 pageviews a month. No scheduled scan. |
| CookieScript | Yes. A cookie test organized by category, including pattern cookies for random names. | Not claimed on the scanner page. | The scanner page talks about cookies and running JavaScript. It does not claim a third-party request list. | Public scan without an account: 10 pages. |
| Termly | Yes. Six categories: Essential, Performance and Functionality, Analytics and Customization, Advertising, Social Networking, and Unclassified. | Not claimed. The scanner crawls, categorizes, and emails a cookie report. | Cookie report. The product page does not claim a HAR or a request waterfall. | Free to scan. Free plan: quarterly scans. |
How to read a free scan next to a Reject log
Read the file the scanner actually returned, then put it next to a labeled Reject host list.
- If the free page says it found no cookies, or the scan never finishes, write that sentence down. Do not copy numbers off a blurred preview.
- Check whether that product clicked Reject All. These four free pages did not.
- On the same URL, log request hosts before any banner click. Label that pass Fresh.
- Click the Reject control that is actually on the page, reload, and log which hosts still request. If the first layer has no Reject All, record the control you used and do not rename it.
- Put the scanner screen next to that host table. An empty scanner page on Store F sat beside hosts that were still requesting.
- Keep the exit labeled. A free US-baseline scan is not an EU or California legal conclusion.
Run Fresh and Reject
The free Reject All tracking check is a US-baseline look at hosts after Reject. The cookie audit stores the Fresh and Reject report. The testing hub is the page that picks the next pass.
FAQ
Do free cookie scanners show who still gets requests after Reject All?
On this Store F session, no. Cookiebot, CookieYes, CookieScript, and Termly did not show which hosts still received requests after Reject All. The request log did. There is no HAR.
Did these four free scanners return a cookie inventory?
No filled inventory. CookieYes finished and said it couldn't find any cookies on this URL. CookieScript said no report found, twice. Cookiebot stayed on Preparing data and was email-gated. Termly stayed on Scanning. A blurred Cookiebot overlay was not treated as a result.
Do these free checkers click Reject All?
These four did not. Their free pages, as checked on 2026-10-07, do not claim a Reject All recheck. The docs are doc-sourced, not verified by us.
What if the US banner has no Reject All?
Store F showed Reject All on the first layer, and that is the control this capture clicked. If a banner hides Reject All, write down the control that exists. Do not relabel a preference-center confirm as Reject All.
Did Reject All clear cookies on Store F?
No. _ga, _fbp, and cookies for Attentive, Northbeam, Heap, Contentsquare, TVSquared, and Ometria were still there after Reject All. This session did not check whether the values changed.
Is this legal advice?
No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
One US session on Store F, shell exit in Ashburn, Virginia, on October 7, 2026. The browser egress was assumed, not checked on its own. The profile was not empty. These notes do not describe Shopify stores in general or every OneTrust setup. California-specific rules were not tested. There is no HAR. Consent Mode parameters were not read. A host absent after the reload was absent in that window only. The four free scans are empty or unfinished screens. The capability table is doc-sourced, not verified by us. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Scanner inventory language sits on the cookie-audit versus cookie-scanner page. The testing hub picks the next pass.
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.