Skip to content
CookieTosser

What does pandasecurity.com track?

Before any consent, pandasecurity.com loaded 3 tracking companies and set 2 advertising or analytics cookies.

That's more tracking companies than 58% of the 2,450 sites we scanned.

Scanned October 2, 2026 from Germany, loading www.pandasecurity.com once and clicking nothing. How we scan

Tracking companies
3
Tracking cookies
2
Third-party hosts
6
Cookies in total
5

Consent banner

The page loaded OneTrust, a consent management platform. Everything below was recorded before anyone answered it. 3 tracking companies still loaded while it was unanswered.

Companies contacted before consent

3 of the 4 companies it contacted before consent were analytics companies.

Other third parties (content delivery, consent, functional, unclassified)

  • OneTrust

    cdn.cookielaw.org, geolocation.onetrust.com

    12 requestsConsent banner

Cookies set before consent

The longest-lived tracking cookie it set was mbox, from Adobe, lasting about 13 months.

CookiePurposeSet byLasts
mboxAdvertisingpandasecurity.com13 months
mboxEdgeClusterAnalyticspandasecurity.comUnder a day
ai_sessionFunctionalwww.pandasecurity.comUnder a day
ai_userFunctionalwww.pandasecurity.com12 months
at_checkFunctionalpandasecurity.comSession

The page also wrote 1 key to local storage, which works like a cookie but isn't sent with requests.

Understanding this page

  • How to see which cookies and trackers a website loads

    A hands-on walkthrough for checking what a site sets before you've clicked anything, using Chrome and Firefox's built-in tools, plus how CookieTosser automates the same check every month.

  • What counts as valid cookie consent in the EU

    The rules that actually govern cookie banners — the ePrivacy Directive, the GDPR consent standard, the Planet49 ruling, the strictly-necessary exemption, and what "reject" has to offer compared with "accept.

  • Consent management platforms explained

    What a CMP banner is actually doing behind the scenes, how the IAB's TCF standard and Google's Consent Mode v2 fit in, and why a banner being present is no guarantee that nothing loads before you answer it.