Web Scanner FAQs

Answers to common questions about the Web Scanner, including real-time script blocking, privacy scores and benchmarks, scan timing, and coverage.

Answers to the questions we're asked most often about the Web Scanner, what it blocks, and how to report on it.


Blocking and timing

Do you catch unexpected scripts in real time, or only at the next scan?

Both, doing different jobs. With the CMP in Enforce mode, an uncategorized third-party script is blocked in real time, in the visitor's browser, before it executes, on the first page view where it appears. It is reported at the next scan, which is when your team gets an email and in-app notification.

So your visitors are covered immediately, and your team is informed on the scan cycle. See Real-time script blocking.

Am I notified about scripts I have not categorized?

Yes. When a scan finds a host that is new since your last scan and is not covered by your configured consent services or a suppression rule, it is included in a findings notification to your team by email and in-app, alongside any newly high-risk and newly escalated hosts.

What you do not get is one alert per block. Blocking is a per-visitor decision in the browser, so a single uncategorized script would otherwise notify you on every page view. The scan aggregates those into one reviewable list instead.

Can I control who gets scan notifications and where they go?

Yes. Scanner notifications sit in the Security & scanning category, so each person turns email and in-app on or off for themselves on their notification preferences, and an admin can post Web scanner findings to a shared Slack channel for the whole team. See Slack notifications.

What stops a script nobody has classified yet?

Enforce mode. In Monitor mode (the default), a resource that matches none of your configured services is allowed. In Enforce mode, an uncategorized third-party resource is blocked. Resources from your own domain and its subdomains are always allowed in both modes. See Script Blocking.

Does blocking cover more than script tags?

Yes. It covers scripts present at load and injected after load, images created at runtime (including tracking pixels), iframes, stylesheet and preload links, and outbound requests made with fetch, XMLHttpRequest, or navigator.sendBeacon.

How often do scans run?

As often as you want them to. Each monitor has its own Scan Frequency setting: daily, weekly, monthly, or manual only, changeable at any time. You can also start a scan yourself with Rescan whatever the frequency is set to. See Scan schedule.

Can the scanner run daily?

Yes. Set a monitor's Scan Frequency to Daily and it is crawled every day. Frequency is set per monitor, so you can run your primary site daily and a stable microsite monthly.

Can we scan more often than daily?

Yes, we can configure a higher frequency for your plan, including continuous monitoring of critical flows. Tell your account representative or support@oursprivacy.com which properties need it and how often. Also consider pairing scanning with Enforce mode, which blocks an uncategorized third-party script in the browser regardless of when the next scan runs. See Scan schedule.

Can I turn scheduled scanning off for one site?

Yes. Set that monitor to Manual only. Scheduled crawls stop, your history and rules are kept, and you can still scan on demand with Rescan. Switching back to a recurring frequency resumes scheduled scanning. See Scan schedule.


Scores, benchmarks, and reporting

Do you provide a privacy score or privacy rating?

Yes, in the form of a scorecard rather than a single composite number. The Progress Report reports consent coverage percentage, high-risk hosts, total third-party hosts, and uncovered hosts, each as a before-and-after change across a date range you choose.

Consent coverage percentage is the number to lead with, because it stays meaningful even when crawl scope changes.

Can I show a before-and-after comparison of our privacy posture?

Yes. Set the Progress Report date range so it starts before the changes you made, then read the headline deltas. Download PDF gives you a formatted report card to share as-is; Download Excel gives you the same numbers as a workbook, with a dated scan-by-scan sheet behind the summary for audit evidence.

Why isn't there a single score out of 100?

Raw host counts move with how many pages a crawl reaches, so a composite number built on them can shift without your posture actually changing. Reporting coverage percentage and risk counts separately keeps each number interpretable and traceable to specific hosts.

Is a high coverage percentage a compliance certification?

No. It is a measurement of what the scanner observed: the share of detected hosts your consent configuration governs. It is evidence that your posture improved, not a guarantee of compliance with any regulation.


Coverage and results

Why is a resource marked Unknown?

Unknown means the resource has not been matched to a known vendor, so its risk is unconfirmed rather than confirmed safe. Many unknowns are your own CDN assets or subdomains. See Recommended fixes.

How many pages can the scanner cover?

As many as your site needs. Coverage is set per monitor and sized to your site, and sites with thousands of pages are supported. See Scanner configuration.

Will the scanner crawl other domains?

No. The scanner follows a hierarchical domain rule and stays within the domain you configure and its subdomains. See How scanning works.

Can I stop certain pages from being scanned?

Yes. Exclude pages or URL patterns in your monitor settings, which is useful for staging environments and authenticated pages. See Scanner configuration.

Should I treat scan results as a full security audit?

No. The scanner makes a best effort to detect third-party resources and is intended for ongoing monitoring. It is not a substitute for a full security audit or compliance certification.


Next steps

Still have a question? Reach out to support@oursprivacy.com.

How is this guide?

On this page