30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.4.01 | Validate consent banner loads before non-essential scripts | Yes |
| 7.4.02 | Validate no tracking occurs before user grants consent | None |
| 7.4.03 | Validate consent UI clearly states cookie categories | Clear |
| 7.4.04 | Detect forced opt-in patterns | None |
| 7.4.05 | Validate user can reject all non-essential cookies | Fully rejectable |
| 7.4.06 | Validate banner text aligns with GDPR/CCPA requirements | Aligned |
| 7.4.07 | Validate “Manage preferences” displayed on initial load | Displayed |
| 7.4.08 | Detect misleading UX patterns (dark patterns) | None |
| 7.4.09 | Validate consent banner reappears after policy updates | Reappears |
| 7.4.10 | Compute Consent Banner Compliance Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.4.11 | Validate cookies classified correctly into categories | Correct |
| 7.4.12 | Detect marketing cookies loading pre-consent | None |
| 7.4.13 | Validate analytics scripts load only after consent | After consent |
| 7.4.14 | Validate session cookies marked essential | Essential only |
| 7.4.15 | Detect unclassified or unknown cookies | None |
| 7.4.16 | Validate third-party cookie sources declared in policy | Declared |
| 7.4.17 | Validate expiration durations documented | Documented |
| 7.4.18 | Detect cookies storing personal identifiers | None unless essential |
| 7.4.19 | Validate cookie scanning implemented regularly | Regular |
| 7.4.20 | Compute Cookie Classification Accuracy Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.4.21 | Validate privacy policy includes GDPR/CCPA rights | Included |
| 7.4.22 | Validate users can request data deletion or export | Available |
| 7.4.23 | Detect missing Do-Not-Sell link (if applicable) | Provided |
| 7.4.24 | Validate consent can be modified at any time | Editable |
| 7.4.25 | Validate privacy metadata embedded (privacyPolicy, dataProtectionOfficer) | Embedded |
| 7.4.26 | Detect outdated privacy policy date | Updated |
| 7.4.27 | Validate auto-renewal period for consent set | Set |
| 7.4.28 | Detect broken links to policy/opt-out pages | None |
| 7.4.29 | Validate region-based privacy rules load correctly (EU/US/CA) | Correct |
| 7.4.30 | Compute Privacy Metadata & User Rights Score | Finalized |
← 7.3 CORS & Access-Control Exposure7.5 Security Headers →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).