50-page smart crawl
Sitemap recursion, footer links, priority legal paths.
Tyrus · free cookie scanner
Find out what cookies and trackers a public website exposes in HTTP and HTML. Deep static crawl (up to 50 pages), 70+ tracker signatures, cookie Secure/HttpOnly/SameSite, consent-banner markup, privacy-policy checks, CSP review — clear Tyrus report in under two minutes.
Everything below runs on shared hosting — no Playwright, no headless Chrome.
Sitemap recursion, footer links, priority legal paths.
Ads, analytics, tag managers, chat, A/B tools.
Sequential fetches keep session cookies; attributes parsed.
Reject control, categories, dark-pattern hints.
Discovers and reads policy/cookie pages for key GDPR phrases.
unsafe-inline/eval, wildcards, Permissions-Policy.
Mixed content, embeds, Google Fonts on HTTPS pages.
CMS and framework signals from HTML/headers.
Server-side PHP maps everything visible in HTTP responses and HTML source — then groups severity-ranked findings with recommendations for GDPR-oriented review.
Type any public HTTPS address. The URL is normalized; the crawl starts from the homepage.
The engine crawls with a cookie jar, classifies 70+ tracker patterns, parses cookie flags, analyzes consent markup, fetches policy pages and merges security headers across pages.
Severity summary, top urgent items, score, tables and limits — ready to download or forward to developers and privacy leads.
Stop guessing which tags and cookies exist on your public pages.
Understand what may need consent before legal review or CMP implementation.
Built by Tyrus — no third-party widgets on this tool page.
Download a self-contained HTML report for stakeholders.
Honest boundaries — the report lists these explicitly. For proof after Accept/Reject with HAR evidence, use the professional Playwright audit.
Best free deep static overview on shared hosting. For consent-phase proof, choose the Playwright audit.
It scans public pages to list cookies, scripts and tracking patterns in the HTML and HTTP headers — the first step toward privacy compliance and consent design.
This Tyrus scanner is independent: multi-page crawl on the same host, robots.txt, sitemap, TLS and security headers, cookie flags, and a downloadable HTML report — no vendor lock-in. Many vendor checkers only inspect one page or promote their own CMP product. Neither replaces a real-browser consent test (Accept/Reject/HAR).
No tool can guarantee compliance. The scan surfaces technical signals; legal assessment belongs with the site owner and advisors.
Running JS in the cloud would need headless browsers (heavy and costly on shared hosting). The professional Tyrus audit (desktop Playwright) delivers that with HAR evidence and optional legal review via Jurist-Tiru.
Most sites finish in 15–90 seconds depending on size. You see a live progress bar (percentage and step) while the server crawls — similar to performance tools — then land on the full report.
No. It is an independent static reconnaissance tool — broader than many one-page checkers, but it does not click Accept/Reject, run JavaScript, or issue legal opinions. Use it to prepare questions for your CMP vendor or legal advisor.
Need Accept/Reject phases, HAR files and legal review on the report?
Professional GDPR services →