Checklist

WooCommerce pre-consent checklist: cookies and pixels before Accept

Start a free audit

Check WooCommerce plugins, pixels, analytics, and cache before Accept. Compare Fresh and Reject on the public shop URL. This is a test checklist.

In brief

On a WooCommerce storefront, a pre-consent check loads the public shop in a clean browser, skips Accept, and records whether marketing pixels and non-essential cookies stay off until a choice. Compare Fresh with Reject All, then use Accept All as a positive control. ConsentProbe can run those labeled scenarios. A free US-baseline scan is not an EU or California legal conclusion. This checklist is testing guidance, not legal advice.

Not legal advice

This checklist helps WooCommerce operators observe cookies, pixels, and scripts that fire before Accept. It is not legal advice (非正式法律意见), not a GDPR, ePrivacy, or CPRA certificate, and not an official WooCommerce or WordPress document. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 24, 2026. Plugin and admin labels change, so this page describes capabilities, not click-paths. The pre-consent checklist owns the platform-agnostic pass. The before-Accept audit owns the longer method. Shopify merchants use the Shopify pre-consent checklist. This page stays on WooCommerce and WordPress.

Short answer

Load the public shop in a clean browser, do not click Accept, and check that marketing pixels and non-essential cookies stay off until a choice. Pay attention to pixel plugins, analytics plugins, marketing suites, chat and review widgets, and theme or custom code that injects scripts in the head.

A page cache or CDN can serve a stale banner state, or HTML that already contains tags, before the CMP runs. List first-party and third-party cookies, capture the key requests, then compare after Reject All. Cite the storefront visit. The plugin screen in wp-admin does not replace that visit.

ConsentProbe can run labeled Fresh and Reject scenarios on the public URL and tie findings to a request, a cookie, or a screenshot. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP. This checklist is testing guidance.

Why WooCommerce gets its own list

WooCommerce shops combine a theme, a plugin stack, and often a cache or optimization layer. Those pieces can inject tags on first paint even when a CMP plugin is active in the admin. A closed SaaS theme has a different set of early-fire paths. Do not copy a Shopify embed checklist onto this stack.

Use the homepage and one product URL that a customer can open. Skip wp-admin previews for the pass that you will cite. Note whether a page cache, a CDN, or an optimization plugin is on. That note explains a stale result. It is not a ranking of cache vendors.

Prep the browser

One clean profile is enough for the first pass. Do not click Accept on that pass. If results flicker between loads, purge the cache you control and run the same URL again before you call it a tag bug.

  1. Open a clean browser profile.
  2. Load the public homepage, then one public product URL.
  3. Note whether a page cache, CDN, or optimization plugin is active.
  4. Leave the banner unclicked on this first pass.

Checklist

Read each row as an observation. A missing Reject control is a record of the UI you saw, not a legal ruling about the banner design. Analytics and ads IDs, including a _ga-style cookie, belong on the pre-Accept list when they appear before a choice. Permission for any of them stays with counsel.

WooCommerce storefront checks before Accept, after Reject, and after Accept.
CheckPass signalFail signal
Fresh load, no clickNo ads or marketing pixels on the public URLMeta, Google Ads, or TikTok-style hosts before Accept
Cookies before AcceptNo clear marketing or analytics IDs beyond what you are treating as essential for this testEarly analytics IDs, ads IDs, or similar values
Plugins and embedsOptional scripts wait until a choiceChat, reviews, upsell, or abandoned-cart tools inject trackers early
Cache or CDNFresh and Reject states match the live banner behaviorStale HTML fires tags or shows the wrong banner state
Reject All, then navigateMarketing stays off on the next pageThe same fan-out as Accept
Accept AllThe vendors you expect show up as a positive controlYou cannot tell on from off, so the earlier rows are hard to read

Plugins, pixels, and cache

Suspect list, not a brand ranking: pixel plugins, analytics plugins, chat widgets, review widgets, upsell modules, and abandoned-cart tools. If one of them sets an ID or sends a hit before a choice, write the plugin name and version when you know them, plus the host or cookie name.

Cache failures look like a tag that disappears after a hard reload, or a banner that still offers Accept after you already clicked Reject. Re-test after a purge when the two loads disagree. The first-party versus third-party guide covers party labels if you need them. This page only asks you to list both domains.

What to send engineering

Send state-labeled screenshots, the cookie list, and the key request rows. Add the plugin name and version when you have them. The evidence pack guide holds the fuller field list. Keep this handoff to the Fresh row, the Reject row, and the Accept control.

Run Fresh and Reject on the shop URL

Hand-checking plugins across a WooCommerce theme is slow. ConsentProbe runs labeled Fresh and Reject scenarios on the public URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not replace a CMP plugin, does not install a CMP, and does not issue a certificate.

FAQ

Is a CMP plugin enough on WooCommerce?

Only if the storefront runtime matches. Check Fresh and Reject in the browser. The admin screen is not that check.

Can caching break a consent test?

Yes. Stale HTML or a CDN copy can fire tags or show the wrong banner state. Purge and re-test when two loads disagree.

Do analytics plugins count before Accept?

Yes if they set IDs or send hits before a choice. List them. Whether they are permitted is a legal question.

Is this the same as the Shopify checklist?

No. The Shopify pre-consent checklist is the sibling page. This page covers WooCommerce plugins, theme injects, and caching paths.

Does a free US scan prove GDPR for EU shoppers?

No. A free US-baseline scan is not an EU legal conclusion. See the free versus paid guide.

Is this legal advice?

No (非正式法律意见). This is a technical checklist. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page is a WooCommerce pre-consent checklist for plugins, pixels, analytics, and cache. It is not legal advice (非正式法律意见), not a Shopify guide, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the pre-consent checklist for the platform-agnostic pass and the before-Accept audit for the longer method. The Shopify checklist is the sibling page for Shopify storefronts.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

WooCommerce pre-consent checklist | ConsentProbe