Consent & tracking report for flamewax.com
Based on an automated pre-consent tracking scan on June 29, 2026.
High risk. A consent banner is present but NOT blocking — trackers fired before the visitor agreed.
On a cold page load — before any consent was given — this page sent data to 1 third-party tracker (1 request). A consent banner (Cookie banner (generic)) was detected, but it did not block these trackers.
Sending data to advertising and analytics third parties before a visitor consents is what powers the wave of CIPA "wiretapping" demand letters in the U.S. and GDPR / ePrivacy enforcement in the EU — and every item below is fixable.
Your consent banner isn’t blocking. Cookie banner (generic) is present on the page, but the trackers below still fired before any choice was made — the single most common real-world failure. A banner that loads alongside the trackers it’s meant to gate provides no protection.
What we found, and how to fix it
Google Tag Manager sends visitor data to a third-party analytics service before consent.
US: CIPA EU: GDPR/ePrivacy Sends identifiers: id
Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.
How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.
Fix these before a demand letter finds them — free
The free ForensicConsent browser extension finds every tracker that fires before consent on your own pages, flags the VPPA footprint, and gives you the fix recipe for each — at no cost. Run it, gate your trackers, and re-check this page anytime.
Own this site? Gate your trackers behind consent, then re-scan — this report updates automatically, and comes down entirely once you pass.
This is an automated scan of the page’s public behavior on a single cold load; it reports what the page transmitted before any consent, not a legal verdict. Exposure flags show the public legal basis these patterns are cited under — they are informational, not legal advice. See our methodology.
How this report was produced
Automated scan of flamewax.com as it publicly behaved on
, using the ForensicConsent detection
ruleset (2026.06.22). The captured pre-consent requests and these results are sealed
with a tamper-evident hash (10b78deda234d725…).
We report only what the page publicly transmitted before consent at that time.
This seal is anchored to a trusted RFC-3161 timestamp via freetsa.org on . Independently verify this receipt →