English
consentglass · GDPR scanner for websites

liocont.md

Checked on 9/18/2026 · https://liocont.md/

C
73 / 100
Cookie banner: Cookie Consent (Osano/Insites) · Privacy-policy link: no · Legal-notice link: no

Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.

Critical items: 2 · also to review: 1.

Since the last scan (9/17/2026)Score +13
How is the score calculated? (100 starting points)
Third-party CDN: jsDelivr CDN-5
Third-party CDN: unpkg CDN (additional)-2
Google Fonts (loaded externally): Google Fonts (CSS)-10
Cookie banner detected (Cookie Consent (Osano/Insites))+5
No link to the privacy policy found-15
Result73 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. Because a cookie banner (Cookie Consent (Osano/Insites)) is active, the actual trackers almost always load only afterwards and don't appear here. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Cookies set on first load: ci_session

Findings

Critical

Google Fonts is loaded directly from Google

On page load the visitor's IP address goes to Google (USA). In the DACH region the most common cease-and-desist reason.

What you should do: Embed the fonts locally: download the font files, serve them from your own server via @font-face and remove the calls to fonts.googleapis.com / fonts.gstatic.com. In WordPress, plugins such as “OMGF” handle this.

LG München I, judgment of 20 Jan 2022 – 3 O 17493/20 (€100 damages for dynamically loaded Google Fonts).

To review

Cookie banner detected (Cookie Consent (Osano/Insites)) — does it load before consent anyway?

A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.

What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

Critical

No link to the privacy policy found

A privacy policy must be directly reachable from every page.

What you should do: Place a “Privacy” link permanently in the footer so it is visible on every subpage.

Art. 13 GDPR — duty to inform when collecting personal data.

Next steps

  1. Google Fonts is loaded directly from Google. Embed the fonts locally: download the font files, serve them from your own server via @font-face and remove the calls to fonts.googleapis.com / fonts.gstatic.com. In WordPress, plugins such as “OMGF” handle this.
  2. No link to the privacy policy found. Place a “Privacy” link permanently in the footer so it is visible on every subpage.
  3. Cookie banner detected (Cookie Consent (Osano/Insites)) — does it load before consent anyway?. Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

Third parties detected (3)

ServicePurposeVendorCountryLegal basis
jsDelivr CDN
cdn.jsdelivr.net
Delivery of libraries or maps via third-party servers jsDelivr EU Grey area — better to self-host; otherwise consent
unpkg CDN
unpkg.com
Delivery of libraries or maps via third-party servers Cloudflare/npm US ⚠ Grey area — better to self-host; otherwise consent
Google Fonts (CSS)
fonts.googleapis.com
Web fonts; the request transmits the visitor's IP to the provider Google LLC US ⚠ Consent required — or host the fonts locally

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/18/2026 we checked the HTML that liocont.md delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website