Skip to content
CookieTosser

What does threatlocker.com track?

Before any consent, threatlocker.com loaded 5 tracking companies and set 5 advertising or analytics cookies.

That's more tracking companies than 78% of the 2,450 sites we scanned.

Scanned October 2, 2026 from Germany, loading www.threatlocker.com once and clicking nothing. How we scan

Tracking companies
5
Tracking cookies
5
Third-party hosts
28
Cookies in total
10

Consent banner

The page loaded Cookiebot, a consent management platform. Everything below was recorded before anyone answered it. 5 tracking companies still loaded while it was unanswered.

Companies contacted before consent

4 of the 13 companies it contacted before consent were analytics companies.

  • The Trade Desk

    js.adsrvr.org, insight.adsrvr.org, match.adsrvr.org

    5 requestsAdvertising
  • Adobe

    use.typekit.net, p.typekit.net

    30 requestsAnalytics
  • HubSpot

    js.hsforms.net, hubspotonwebflow.com, forms-na1.hsforms.com, forms.hsforms.com

    7 requestsAnalytics
  • Google Analytics

    www.googletagmanager.com, region1.google-analytics.com

    3 requestsAnalytics
  • VWO

    dev.visualwebsiteoptimizer.com

    1 requestAnalytics

Other third parties (content delivery, consent, functional, unclassified)

  • bc0a.com

    cdn.bc0a.com, ixfd2-api.bc0a.com, app-cf.bc0a.com

    3 requestsUnclassified
  • Cookiebot

    consent.cookiebot.com, consentcdn.cookiebot.com

    4 requestsConsent banner
  • Google

    fonts.gstatic.com, www.gstatic.com, www.google.com, fonts.googleapis.com

    26 requestsFunctional
  • ipify

    api.ipify.org

    1 requestFunctional
  • Webflow

    cdn.prod.website-files.com

    66 requestsContent delivery
  • Font Awesome

    ka-p.fontawesome.com, kit.fontawesome.com

    4 requestsContent delivery
  • Amazon Web Services

    d3e54v103j8qbb.cloudfront.net

    1 requestContent delivery
  • jsDelivr

    cdn.jsdelivr.net

    1 requestContent delivery

Cookies set before consent

The longest-lived tracking cookie it set was utm_campaign, lasting about 13 months.

CookiePurposeSet byLasts
utm_campaignAnalyticswww.threatlocker.com13 months
utm_contentAnalyticswww.threatlocker.com13 months
utm_mediumAnalyticswww.threatlocker.com13 months
utm_sourceAnalyticswww.threatlocker.com13 months
utm_termAnalyticswww.threatlocker.com13 months
google_click_idUnclassifiedwww.threatlocker.com13 months
microsoft_click_idUnclassifiedwww.threatlocker.com13 months
__cf_bmFunctionalhsforms.net (third party)Under a day
__cf_bmFunctionalhsforms.com (third party)Under a day
_cfuvidFunctionalthreatlocker.comSession

The page also wrote 3 keys to local storage, which works like a cookie but isn't sent with requests.

Understanding this page

  • How to see which cookies and trackers a website loads

    A hands-on walkthrough for checking what a site sets before you've clicked anything, using Chrome and Firefox's built-in tools, plus how CookieTosser automates the same check every month.

  • What counts as valid cookie consent in the EU

    The rules that actually govern cookie banners — the ePrivacy Directive, the GDPR consent standard, the Planet49 ruling, the strictly-necessary exemption, and what "reject" has to offer compared with "accept.

  • Consent management platforms explained

    What a CMP banner is actually doing behind the scenes, how the IAB's TCF standard and Google's Consent Mode v2 fit in, and why a banner being present is no guarantee that nothing loads before you answer it.