Complianz Configuration Audit for WordPress Cookies
Follow the checks on your own website. Install the free extension to compare cookie activity before and after a consent choice.
WordPress sites can load the same tracker from a plugin, a theme and GTM. A Complianz audit starts with that inventory. Record the cookie or request, its initiating script and the WordPress component responsible before changing the banner.
Prepare a logged-out baseline
Use a fresh browser profile and record the page URL, browser, time and test region. Open Network with Preserve log enabled. Run a free cookie audit for a passive server-browser observation, then compare it with your interactive test. Saved choices, geography and caches can explain different results.
Check each WordPress integration
- List analytics plugins, theme snippets, tag-manager containers and embeds. Find every installation using the same measurement ID.
- Review the Complianz wizard and enabled service integrations. Compare the services configured there with the actual requests on the page.
- For custom integrations, follow the Complianz Script Center documentation. Verify that the affected resource is controlled by the intended service.
- On staging, investigate optimization settings one at a time. Script delay, combining and caching may change loading order. Retest after restoring each setting.
- Follow the Complianz debugging workflow to identify the script setting an unexpected cookie. After publishing a fix, clear relevant caches and check logged-out production output.
Run four consent scenarios
| Scenario | Action | Record |
|---|---|---|
| Fresh visit | Load without interacting | New cookies, storage and request initiators |
| Reject | Start clean, reject and reload | Saved choice and subsequent optional requests |
| Partial acceptance | Start clean and accept analytics only | Whether marketing stays disabled |
| Withdrawal | Accept, reopen settings and revoke | New requests after the change and after navigation |
Common symptoms and next checks
| Symptom | Investigate | Next step |
|---|---|---|
| Works for admins only | Different cached or optimized HTML | Test logged-out production output |
| Cookie remains after Reject | Storage left from an accepted visit | Distinguish old storage from new writes |
| Embed ignores the choice | Missing service mapping or duplicate embed | Check the gate on this exact page |
| Two analytics requests | Plugin, theme and GTM duplication | Trace and remove the unintended installation |
Interpret tracking signals in context
A consent-preference cookie and an advertising identifier serve different purposes. Review classifications before reporting an issue. With advanced Google Consent Mode, a request under denied consent may be a cookieless ping. Compare the intended setup with the Consent Mode checker and inspect the request; a network entry alone is not a legal verdict.
Create a ticket another developer can reproduce
Include the URL, logged-out state, chosen categories, exact steps, expected behavior, cookie or endpoint, initiator and timestamp. Use Initiator Trace and a redacted debug snapshot to support the handoff. Review the exported data before sharing. Repeat the same test after the change.
For application-level issues, see the WordPress and Next.js consent test guide. For recurring client checks, compare the bulk scanner and dashboard plans.
Investigate the WordPress loading path before editing the banner
A WordPress site can install analytics in a theme setting, a header-snippet plugin, a marketing plugin and GTM at the same time. Start with that inventory. Compare the vendor identifier in the browser with the configuration in each candidate integration. Removing the wrong copy can break measurement while leaving the pre-consent copy running.
Use staging for controlled isolation where possible. Disable one candidate integration, clear the relevant caches and repeat the same test. Keep a record of what changed. On a production store, coordinate changes with the owner rather than switching off plugins during an active customer flow.
Test optimization and cache behavior as part of the release
An optimization plugin can alter script order or defer a callback. A cache may serve different output to administrators and ordinary visitors. Always include a logged-out test against the public URL after a Complianz or theme change. A passing editor preview is not enough.
Compare the affected page with a simpler template. If the failure occurs only on a page-builder layout, inspect custom HTML blocks and widget scripts. If it appears everywhere, investigate a shared theme or tag-manager installation first. These comparisons narrow the search without assuming Complianz is the component at fault.
Use a concrete retest for embeds and forms
| Integration | Scenario | Evidence to keep |
|---|---|---|
| Video or map | Open page before interacting, then enable its category | Placeholder behavior and the first external request |
| Contact form | Use test details after rejecting optional services | Whether unrelated analytics starts with form initialization |
| Shop template | Visit product page directly and through navigation | Route-specific pixels and category state |
| Chat widget | Reject, allow its service, then withdraw | New connections after each choice |
Do not place real contact details or payment data into a test merely to trigger a widget. Agree a safe test account or staging workflow with the owner. Browser exports and screenshots can preserve what was visible, so review them before attaching them to a client report.
Complianz audit FAQ
Why does it work while I am logged in as an administrator?
Logged-in users may receive uncached pages or different script output. Reproduce the public visitor path in a separate profile. Record the cache and optimization configuration when the two paths behave differently.
Is an old cookie after Reject a new violation?
First establish when it was written and whether new activity occurred after rejection. A retained identifier, a new write and a new network request are distinct observations. Report the actual sequence instead of drawing a conclusion from the cookie list alone.
Where should an agency start with several client sites?
Group sites by theme and integration pattern, but test each client's public deployment. Shared templates can spread the same problem, while one client's extra plugin can create an exception. Use bulk baselines to find candidates and the application consent test guide for manual follow-up.
Does your Complianz setup stop cookies before consent?
Follow this checklist with ConsentScope. Compare cookie activity before and after your consent choice, then investigate anything unexpected.
Free page-level checks. No account or payment required.
Related CMP guides
Cookiebot Guide
Check Cookiebot blocking, script order and consent categories. Test a fresh visit, rejection and acc...
OneTrust Guide
Audit OneTrust domain scripts, published rules and GTM category mappings. Compare pre-consent, rejec...
Didomi Guide
Find why scripts run before Didomi consent. Check vendor IDs, purpose settings, SDK readiness and co...
Usercentrics Guide
Test Usercentrics service consent, blocked resources and consent-change events. Compare fresh visits...