English
consentglass · GDPR scanner for websites

liocont.md

Checked on 9/17/2026 · https://liocont.md/

C
60 / 100
No cookie banner in the initial HTML · Privacy-policy link: no · Legal-notice link: no

Critical items: 3 · also to review: 1.

How is the score calculated? (100 starting points)
Third-party CDN: jsDelivr CDN-5
Third-party CDN: unpkg CDN (additional)-2
Google Fonts (loaded externally): Google Fonts (CSS)-10
1 cookie(s) set on first load-8
No link to the privacy policy found-15
Result60 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Cookies set on first load: ci_session

Findings

Critical

Google Fonts is loaded directly from Google

On page load the visitor's IP address goes to Google (USA). In the DACH region the most common cease-and-desist reason.

What you should do: Embed the fonts locally: download the font files, serve them from your own server via @font-face and remove the calls to fonts.googleapis.com / fonts.gstatic.com. In WordPress, plugins such as “OMGF” handle this.

LG München I, judgment of 20 Jan 2022 – 3 O 17493/20 (€100 damages for dynamically loaded Google Fonts).

Critical

3 services requiring consent, no cookie banner in the initial HTML

Analytics, advertising or social services load without any consent solution being detectable.

What you should do: Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.

§ 25 (1) TDDDG together with Art. 6 (1) GDPR — access to terminal equipment only with prior consent.

To review

1 cookie(s) set on first load

Set without a consent banner: ci_session. Only technically necessary cookies are permitted without consent.

What you should do: Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.

§ 25 (2) TDDDG — exception only for strictly necessary cookies.

Critical

No link to the privacy policy found

A privacy policy must be directly reachable from every page.

What you should do: Place a “Privacy” link permanently in the footer so it is visible on every subpage.

Art. 13 GDPR — duty to inform when collecting personal data.

Next steps

  1. Google Fonts is loaded directly from Google. Embed the fonts locally: download the font files, serve them from your own server via @font-face and remove the calls to fonts.googleapis.com / fonts.gstatic.com. In WordPress, plugins such as “OMGF” handle this.
  2. 3 services requiring consent, no cookie banner in the initial HTML. Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.
  3. No link to the privacy policy found. Place a “Privacy” link permanently in the footer so it is visible on every subpage.

Third parties detected (3)

ServicePurposeVendorCountryLegal basis
jsDelivr CDN
cdn.jsdelivr.net
Delivery of libraries or maps via third-party servers jsDelivr EU Grey area — better to self-host; otherwise consent
unpkg CDN
unpkg.com
Delivery of libraries or maps via third-party servers Cloudflare/npm US ⚠ Grey area — better to self-host; otherwise consent
Google Fonts (CSS)
fonts.googleapis.com
Web fonts; the request transmits the visitor's IP to the provider Google LLC US ⚠ Consent required — or host the fonts locally

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/17/2026 we checked the HTML that liocont.md delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website