What does threatlocker.com track?
Before any consent, threatlocker.com loaded 5 tracking companies and set 5 advertising or analytics cookies.
That's more tracking companies than 78% of the 2,450 sites we scanned.
Scanned October 2, 2026 from Germany, loading www.threatlocker.com once and clicking nothing. How we scan
- Tracking companies
- 5
- Tracking cookies
- 5
- Third-party hosts
- 28
- Cookies in total
- 10
Consent banner
The page loaded Cookiebot, a consent management platform. Everything below was recorded before anyone answered it. 5 tracking companies still loaded while it was unanswered.
Companies contacted before consent
4 of the 13 companies it contacted before consent were analytics companies.
- The Trade Desk5 requestsAdvertising
js.adsrvr.org, insight.adsrvr.org, match.adsrvr.org
- Adobe30 requestsAnalytics
use.typekit.net, p.typekit.net
- HubSpot7 requestsAnalytics
js.hsforms.net, hubspotonwebflow.com, forms-na1.hsforms.com, forms.hsforms.com
- Google Analytics3 requestsAnalytics
www.googletagmanager.com, region1.google-analytics.com
- VWO1 requestAnalytics
dev.visualwebsiteoptimizer.com
Other third parties (content delivery, consent, functional, unclassified)
- bc0a.com3 requestsUnclassified
cdn.bc0a.com, ixfd2-api.bc0a.com, app-cf.bc0a.com
- Cookiebot4 requestsConsent banner
consent.cookiebot.com, consentcdn.cookiebot.com
- Google26 requestsFunctional
fonts.gstatic.com, www.gstatic.com, www.google.com, fonts.googleapis.com
- ipify1 requestFunctional
api.ipify.org
- Webflow66 requestsContent delivery
cdn.prod.website-files.com
- Font Awesome4 requestsContent delivery
ka-p.fontawesome.com, kit.fontawesome.com
- Amazon Web Services1 requestContent delivery
d3e54v103j8qbb.cloudfront.net
- jsDelivr1 requestContent delivery
cdn.jsdelivr.net
Cookies set before consent
The longest-lived tracking cookie it set was utm_campaign, lasting about 13 months.
| Cookie | Purpose | Set by | Lasts |
|---|---|---|---|
| utm_campaign | Analytics | www.threatlocker.com | 13 months |
| utm_content | Analytics | www.threatlocker.com | 13 months |
| utm_medium | Analytics | www.threatlocker.com | 13 months |
| utm_source | Analytics | www.threatlocker.com | 13 months |
| utm_term | Analytics | www.threatlocker.com | 13 months |
| google_click_id | Unclassified | www.threatlocker.com | 13 months |
| microsoft_click_id | Unclassified | www.threatlocker.com | 13 months |
| __cf_bm | Functional | hsforms.net (third party) | Under a day |
| __cf_bm | Functional | hsforms.com (third party) | Under a day |
| _cfuvid | Functional | threatlocker.com | Session |
The page also wrote 3 keys to local storage, which works like a cookie but isn't sent with requests.
Understanding this page
- How to see which cookies and trackers a website loads
A hands-on walkthrough for checking what a site sets before you've clicked anything, using Chrome and Firefox's built-in tools, plus how CookieTosser automates the same check every month.
- What counts as valid cookie consent in the EU
The rules that actually govern cookie banners — the ePrivacy Directive, the GDPR consent standard, the Planet49 ruling, the strictly-necessary exemption, and what "reject" has to offer compared with "accept.
- Consent management platforms explained
What a CMP banner is actually doing behind the scenes, how the IAB's TCF standard and Google's Consent Mode v2 fit in, and why a banner being present is no guarantee that nothing loads before you answer it.