All checks
Compliance & Privacylowtrackers-without-consentchecked on every page we scan

Analytics or advertising tracker loads without a detected consent step

This page loads analytics or advertising trackers, and this scan saw no consent banner, consent-management platform, or consent-mode signal in the page's initial HTML.

Why it matters

This page loads analytics or advertising trackers, and this scan saw no consent banner, consent-management platform, or consent-mode signal in the page's initial HTML. Analytics and advertising trackers typically read or write identifiers used to profile visitors, which in the EU/EEA and UK usually requires the visitor's prior consent. Because this scan only sees the initial HTML, a consent banner that loads later via JavaScript would not be detected — so treat this as a prompt to confirm a consent step gates these trackers, not as a confirmed gap.

How ShipReady detects it

Per-page privacy signals read straight from the fetched HTML and response headers — no extra requests. Page-scoped because trackers, cookies and forms genuinely differ between routes (a marketing homepage vs a bare /login), and the route that carries the signup form is exactly the one worth seeing.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.0.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

Analytics or advertising trackers load on this page, and this scan saw no consent banner, consent-management platform, or consent-mode signal in the initial HTML. First confirm whether a consent step actually gates them: this scan only sees the page's initial HTML, so a banner that loads later via JavaScript, or Google Consent Mode configured in a tag manager, would not be visible here — if you already have one, no change is needed. If nothing gates them, add one: in the EU/EEA and UK these trackers generally require the visitor's prior consent, so they should not run until the visitor opts in. Use a consent-management platform (Cookiebot, Osano, OneTrust, CookieYes, Termly) or a hand-rolled banner wired to Google Consent Mode / a `dataLayer` gate, and load the tracking scripts only after opt-in. If you do not need behavioural analytics, a cookieless, consent-exempt alternative (Plausible, Fathom, Simple Analytics) avoids the requirement entirely. This is general privacy hygiene, not legal advice; confirm your own obligations for your audience.

Frequently asked questions

What does "Analytics or advertising tracker loads without a detected consent step" mean?
This page loads analytics or advertising trackers, and this scan saw no consent banner, consent-management platform, or consent-mode signal in the page's initial HTML.
How serious is it?
ShipReady rates this low. Worth fixing. Small individually, and they accumulate.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check. The free report lists every issue it finds and shows full evidence and a fix prompt for the critical and high-severity ones; medium and low findings are counted and unlock on Pro.

Related checks

Run this check on your site

ShipReady checks this and 193 other things across up to ten pages of your site, with an AI-ready fix for each. Free, no signup.