Declarations tell you who a publisher authorizes. They don’t tell you what the live homepage does to a reader: how hard it’s monetized, which trackers fire, or whether identifiers leave the page before anyone clicks Accept.
High-density ad wrappers live in that gap. So does “premium” inventory that still ships session replay, and the CMP banner that’s pure theatre. Ad+Privacy Metrics is how we close it. One lab visit (real Chrome, consent handling, scroll and dwell) produces two independent scores, ad density and privacy, plus a pre-consent vs post-consent split, so you can see what already happened while the visitor had agreed to nothing.
Two questions, two scores, one crawl
Ad density asks how hard the live page is monetized:
coverage, sticky and interstitial units, chumboxes, refresh, thin copy.
Grades are low / medium / high /
very_high (0–100). High and very high include
MFA-adjacent traits; a homepage measurement is suspicion-only and cannot
reach those two grades. Privacy / tracking asks what
happens to the reader: minimal through aggressive.
A site can look editorial and still land heavy on tracking.
Desktop and Mobile are separate crawls (US/EU or any other country),
and Auto-Investigate takes the worse of the two devices when both exist.
Scan the corpus
Filter labbed hosts by ad-density grade, privacy grade, consent boundary, pre-consent trackers, session replay, identity graph, or social pixel. High / very-high density surfaces quickly that way, and so do the “respectable” domains that fire session replay before consent. Then open the row.
The host profile is the case file
Dual ad-density + privacy gauges, Ad metrics, Privacy flags, screenshots, and the HAR data evidence when it was captured. You get the whole crawl you would otherwise have to run yourself.
Ad metrics. Above-the-fold and full-page ad coverage, ads in view, sticky units, interstitials, chumbox vendors, slot refresh rate, ad-related bytes, third-party domains, article vs body word count, redirect hops (including off-domain). Screenshots at pre-consent and final.
Privacy flags. Use the score to sort; the flags are what you actually work from. They’re compliance-grade facts pulled from the same crawl: pre-consent leakage, high-risk vendors, identifier sharing, surveillance breadth, transparency. Each flag carries points and a note you can drop straight into a case file.
Data evidence. When the crawl captured the network, the host profile shows Data evidence (full network capture) HAR available for this crawl. That’s the raw HAR for the same visit that produced the scores, not a summary of it.
Trackers by purpose. Advertising, analytics, session replay, social pixels, identity graphs, fingerprinting, tag managers, content recommendation, customer-data platforms, plus CMPs and ad verification (observed, but not scored as “tracking”).
Cookies and storage. We try to provide nuance and
insights into the cookies being collected and used on publisher websites.
We’re identifying: first- vs third-party, session vs persistent,
SameSite=None, Secure, HttpOnly, cookie lifetime, cookie
domains, localStorage / sessionStorage size, IndexedDB names, and user ID
cookies (_ga, _fbp, UUIDs).
We extract 21 kinds of vendor account identifiers from the same visit. Click an ID to see every other labbed host that carries it. When the same pixel turns up on a “news” site and a high-density wrapper, that’s a diligence finding rather than a coincidence. Kinds are namespaced, so a numeric id on two vendors is never treated as the same account.
Before anyone clicks Accept
Most “privacy scores” are a single number taken at the end of the visit, which hides the question that matters most for GDPR diligence: what already fired while the banner was still up?
We dwell and scroll in front of the CMP, then click Accept. Cookies, fingerprinting, and network requests are snapshotted at that click and again at the end of the dwell, so all three families agree on where the boundary sits. Anything in the first window happened with no consent. Legal evidence exports use the same split: pre vs post, Desktop/Mobile, US/EU or any other country.
Each of these is counted pre-consent and for the full crawl:
- Tracker requests and tracker vendors
- Third-party domains contacted
- Identifier shares (an ID in a query string, which is a transfer rather than just a ping)
- Page-URL shares (reading history handed to a third party)
- Third-party tracking pixels
- Beacons (
sendBeacon/ beacon-shaped endpoints) - Tracker cookies and third-party cookies (CDP, including HttpOnly)
- Fingerprint APIs touched
Empty pre-consent columns don’t mean clean. They mean we didn’t observe a CMP accept click, usually because there was no banner, or because it was a US exit where GDPR isn’t asserted. A banner that vanished without a click may already be post-implied-consent, since some CMPs treat scroll as acceptance. We only score pre-consent leakage when the accept click was actually observed.
Consent window. This goes well past a yes/no banner: whether we observed a CMP accept click, how long the pre-consent window lasted, whether we scrolled in it, whether the banner vanished unclicked, plus TCF (present vs readable, GDPR applies, purposes, GVL vendor ids), GPP, US Privacy, DNT, and Global Privacy Control. A broken CMP still isn’t a clean one.
Built for investigation
The same crawls feed Auto-Investigate, the API, and MCP. Per-hostname Ad density and Privacy lookups are available on researcher and paid plans. Open Research → Ad+Privacy Metrics, or check plans if you need evidentiary exports (Desktop/Mobile, US/EU or any other country) on Legal.