Web Scanner
Monitor third-party scripts on your website with automated scans to maintain privacy compliance.
The Web Scanner monitors the third-party scripts running on your website with automated scans. It helps you find scripts that may affect your site's privacy posture or compliance with privacy regulations, with no code required.
It's built for privacy and compliance teams who need ongoing visibility into what loads on their pages, especially in HIPAA-regulated workflows where an unexpected tracker carries real risk.
Why use it
- No code required. Point the scanner at a URL and it discovers and scans your pages automatically.
- Monitoring on your schedule. Scan each site daily, weekly, or monthly, or on demand only. Set the frequency per site and change it whenever you want.
- Change alerts. When a scan finds a new or higher-risk script, your team is notified by email and in-app, so nothing slips by unnoticed. Each person picks their own channels, and findings can post to a shared Slack channel.
- Privacy-focused detection. Flags scripts that match known trackers, ad identifiers, and data-collection patterns.
- Pairs with real-time blocking. With the CMP in Enforce mode, an uncategorized third-party script is blocked in the visitor's browser before it executes, then reported at the next scan.
- CSP visibility. Surfaces gaps between your Content Security Policy and the resources actually loading.
- Accessibility checks. Runs automated WCAG checks on each page and scores your site's accessibility posture over time.
- Organized review. Suppress reviewed items and add notes to track decisions across scans.

Key features
- How scanning works: page discovery and how the crawler stays within your domain.
- Scan schedule: set how often each site is scanned, from daily to monthly or manual only.
- What the scanner detects: third-party scripts, privacy keywords, cookies, CSP analysis, and accessibility (WCAG) checks.
- Real-time script blocking: how the CMP blocks uncategorized scripts before they execute, and how that differs from scan reporting.
- Managing scan results: suppress alerts and add notes to organize your findings.
- Scanner configuration: exclude pages and set how much of your site each scan covers.
- Authenticated scanning: scan pages behind a login using a short-lived header or cookie credential.
- Allowing the scanner through a firewall: let the crawler reach sites behind a firewall or WAF.
Need help?
If you have questions about scan coverage, third-party scripts, or how to interpret results, reach out to support@oursprivacy.com. We're happy to help.
How is this guide?

