Full walkthrough on a live Odoo 19.0 database, with subtitles. It ends with what this app deliberately does not do.
Cookie Scanner & Consent Audit
An add-on for BambooForge Consent Pro. A cookie banner lists what
somebody typed into it eighteen months ago; a website loads what its
pages actually contain. This shows you the gap.
Install BambooForge Cookie Scanner. Sixteen known third parties are
created, and a monthly scan is scheduled for every website. Nothing is
fetched until the first scan runs.
Menus: SEO Pro → Trackers Found, and under Configuration, Cookie
Scans and Known Third Parties.
Configuration → Cookie Scans → New → Scan the site.
The scan fetches this website's own pages - the ones SEO Pro has indexed,
at most sixty, one at a time, each with a twelve second timeout and a
two megabyte cap. It never fetches another host: a scanner that can be
pointed elsewhere is a proxy.
For each page it records:
third parties, matched against the knowledge base;
cookies your server set, read from the response headers.
The log lists the pages that failed and why, capped at fifty lines so it
stays readable.
It does not run JavaScript. That matters, and it is stated on every
screen: it reports which vendor is present and which cookies that vendor
is known to set - not that it observed them. Cookies from the response
headers are labelled separately, because those really were observed.
That is the version of the report you can defend. A tool that shows a
cookie list it inferred is a tool that will be wrong in a meeting.
SEO Pro → Trackers Found opens on Not declared: findings that
Consent Pro has never been told about. A finding is treated as declared
when a Consent Pro script has the same name, or contains one of the
vendor's fingerprints in its URL, code or preset.
Declare in Consent Pro creates the entry with the vendor's category,
so the banner and the register agree with the site. Ignore is for the
ones you have decided about - a first-party analytics script, say.
Every website with Scan for undeclared trackers monthly on is scanned
at 02:20, so a script somebody added in a hurry shows up in the report
before it shows up in an audit. A website whose scan fails does not stop
the others.