Cookiebot

cookiebot.comcontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

A cookie consent banner with an automatic scan of what your site actually sets, plus a record of each visitor's choice for compliance purposes.

Promptfree, for everyone, and the only version there is
Build me a consent banner that replaces Cookiebot — and read the first paragraph, because this is the one category where getting it wrong has a legal consequence rather than a technical one.

What you are paying for is **a crawler that finds every cookie and tracker on your site, including the ones a third-party script sets without telling you**, and a stored consent record you can produce if a regulator asks. The banner is an afternoon. The scanner is the product, and none of this is legal advice — the point of building it is to know what your own site does, which is a good reason on its own.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode
- Playwright for the scanner
- A banner script under 8KB gzipped, from my own domain
- Caddy in front

THE DATA MODEL
- sites: id, domain, name, languages_json, categories_json, banner_config_json
- scans: id, site_id, started_at, finished_at, pages_crawled, status
- findings: id, scan_id, kind, name, domain, category, first_seen_path, purpose, expiry, is_third_party, provider — a cookie, a local storage key, a pixel, a script, a beacon
- declarations: id, site_id, finding_key, category, purpose_text, expiry_text, is_published, updated_at — the reviewed, published list
- consents: id, site_id, consent_id, categories_json, given_at, expires_at, method, banner_version, policy_version, ip_hash, user_agent_bucket, language — the record
- consent_events: append-only, so a change of mind is a new row and the history is intact

THE SCANNER, WHICH IS THE PRODUCT
- Crawl the site with a real browser, visiting a representative set of pages, and record everything written to storage and every outbound request
- Do it twice: once with consent refused and once with consent granted. The difference is the whole compliance question, and the first run is where you discover the tag that fires before anybody agreed to anything
- Classify findings against a maintained list of known providers, and leave the unknown ones for a human to categorise rather than guessing
- Re-scan on a schedule and alert on anything new. A marketing tag added by somebody with tag-manager access is the usual way a compliant site stops being one
- Report what fires before consent, which is the finding that matters

THE BANNER
- Categories: strictly necessary, preferences, statistics, marketing. Necessary cannot be switched off and everything else is off until chosen
- **Reject must be as easy as accept.** One click, same prominence, same styling. A banner where refusing takes three clicks is the pattern regulators have been fining, and it is also just rude
- No pre-ticked boxes, no legitimate-interest toggles hidden behind a second screen, no interface that nags after a refusal
- Granular consent per category, with a link to the detail
- Loads before anything else and blocks non-necessary scripts until a decision. A banner that appears after the tags have fired is decoration
- Accessible: keyboard operable, focus trapped, announced, and usable at 320px
- A way to change or withdraw consent later, reachable from every page. Withdrawal must be as easy as giving it

BLOCKING, WHICH IS THE TECHNICAL HALF
- Scripts declared with a type that stops the browser executing them, activated only when their category is allowed
- Iframes held until consent, with a placeholder saying what it is and a button to load it
- Cookies set by your own server gated at the server, using the consent cookie
- The consent state itself is strictly necessary and may be stored without consent

THE RECORD
- Every consent stored with what was agreed, when, how, which banner and policy version, and a salted address hash. That is what a regulator asks for
- An expiry, after which the banner asks again — a year is common
- Exportable by consent id, and deletable on request

OPERATIONS
- .env: DATABASE_PATH, BASE_URL, HASH_SALT, SESSION_SECRET
- Migrations on boot, each once; nightly backup — the consent log is the record
- Health endpoint reporting the age of the last scan

WHAT MATTERS MOST
The two-pass scan and equal-prominence rejection. The first tells you what your site actually does before anybody agreed to it; the second is the difference between a consent mechanism and a dark pattern.

What you lose

  • A crawler that finds every cookie and tracker on your site, including ones a third-party script sets without telling you
  • A stored consent record you can produce if a regulator asks
  • Wording kept current as guidance changes across jurisdictions

If you would rather not build

  • No third-party scripts, which removes the problem entirely

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$15/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Klaro

$0

Open-source consent management that blocks scripts until consent.

klaro-org/klaro-jsfree · open source

cookieconsent

$0

A small, dependency-free consent banner with categories.

orestbida/cookieconsentfree · open source

Why this verdict

our own opinion · changed only by a person

58/100

Verdict kinda at 58. The banner is an afternoon; the scan that tells you what to declare, and the stored record, are what the fee covers.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 1/day
views0130 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Cookiebot

answered from the record above

Is Cookiebot free?

No — the plan we track is $15 a month. From around €15/month billed monthly per domain, priced on the number of pages scanned.

Can you replace Cookiebot by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 58 out of 100, build time a weekend. Read what you lose before you decide.

How much does Cookiebot cost?

$15 a month on Starter — $180 a year. Recorded 10 Aug 2026.

What do you lose by replacing Cookiebot?

A crawler that finds every cookie and tracker on your site, including ones a third-party script sets without telling you; A stored consent record you can produce if a regulator asks; Wording kept current as guidance changes across jurisdictions. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Cookiebot?

Yes: Klaro, cookieconsent. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 24 in Security & cloud storage

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc