Web Scanner FAQs

Answers to common questions about the Web Scanner, including real-time script blocking, privacy scores and benchmarks, scan timing, and coverage.

Answers to the questions we're asked most often about the Web Scanner, what it blocks, and how to report on it.


Blocking and timing

Do you catch unexpected scripts in real time, or only at the next scan?

Both, doing different jobs. With the CMP in Enforce mode, an uncategorized third-party script is blocked in real time, in the visitor's browser, before it executes, on the first page view where it appears. It is reported at the next scan, which is when your team gets an email and in-app notification.

So your visitors are covered immediately, and your team is informed on the scan cycle. See Real-time script blocking.

Am I notified about scripts I have not categorized?

Yes. When a scan finds a host that is new since your last scan and is not covered by your configured consent services or a suppression rule, it is included in a findings notification to your team by email and in-app, alongside any newly high-risk and newly escalated hosts.

What you do not get is one alert per block. Blocking is a per-visitor decision in the browser, so a single uncategorized script would otherwise notify you on every page view. The scan aggregates those into one reviewable list instead.

What stops a script nobody has classified yet?

Enforce mode. In Monitor mode (the default), a resource that matches none of your configured services is allowed. In Enforce mode, an uncategorized third-party resource is blocked. Resources from your own domain and its subdomains are always allowed in both modes. See Script Blocking.

Does blocking cover more than script tags?

Yes. It covers scripts present at load and injected after load, images created at runtime (including tracking pixels), iframes, stylesheet and preload links, and outbound requests made with fetch, XMLHttpRequest, or navigator.sendBeacon.

How often do scans run?

Scans run on a regular schedule with no manual trigger needed. See How scanning works.


Scores, benchmarks, and reporting

Do you provide a privacy score or privacy rating?

Yes, in the form of a scorecard rather than a single composite number. The Progress Report reports consent coverage percentage, high-risk hosts, total third-party hosts, and uncovered hosts, each as a before-and-after change across a date range you choose.

Consent coverage percentage is the number to lead with, because it stays meaningful even when crawl scope changes.

Can I show a before-and-after comparison of our privacy posture?

Yes. Set the Progress Report date range so it starts before the changes you made, then read the headline deltas. Download Excel produces a workbook whose Summary sheet is a one-page scorecard suitable for a board deck, with a dated scan-by-scan sheet behind it for audit evidence.

Why isn't there a single score out of 100?

Raw host counts move with how many pages a crawl reaches, so a composite number built on them can shift without your posture actually changing. Reporting coverage percentage and risk counts separately keeps each number interpretable and traceable to specific hosts.

Is a high coverage percentage a compliance certification?

No. It is a measurement of what the scanner observed: the share of detected hosts your consent configuration governs. It is evidence that your posture improved, not a guarantee of compliance with any regulation.


Coverage and results

Why is a resource marked Unknown?

Unknown means the resource has not been matched to a known vendor, so its risk is unconfirmed rather than confirmed safe. Many unknowns are your own CDN assets or subdomains. See Recommended fixes.

Will the scanner crawl other domains?

No. The scanner follows a hierarchical domain rule and stays within the domain you configure and its subdomains. See How scanning works.

Can I stop certain pages from being scanned?

Yes. Exclude pages or URL patterns in your monitor settings, which is useful for staging environments and authenticated pages. See Scanner configuration.

Should I treat scan results as a full security audit?

No. The scanner makes a best effort to detect third-party resources and is intended for ongoing monitoring. It is not a substitute for a full security audit or compliance certification.


Next steps

Still have a question? Reach out to support@oursprivacy.com.

How is this guide?

On this page