Platforms
The same product. What it can do depends on where your site lives.
Consentinel works the same way everywhere: hold the trackers, watch what happens, keep the record. What changes is how much your website platform lets us hold. We tell you what we can block on yours, what we can only watch — and where we haven't tested a platform ourselves yet, we say that too.
WordPress is where we block the most. Our plugin runs on your server and removes tracking scripts before the page is ever sent to your visitor — including scripts your other plugins added, which no browser-based tool can reach. Two things need mentioning. Scripts a plugin writes straight into the page need one extra setting switched on; it is off when you install it. And scripts your hosting company adds go in after WordPress has finished its work, so no plugin can reach them.
Findings from our tests
Measured 2026-07-30 · two live sites running the plugin, with that extra setting switched on
Requests to Google before anyone agreed, on a live site running our plugin
Requests to any outside company before anyone agreed, on a second site, same plugin version, same day
Tracking services confirmed at zero: Google Tag Manager, Google Analytics, Facebook, and two Zoho services
- Scripts your other plugins add the normal way are removed before the page is sent. On by default.
- Scripts a plugin writes straight into the page need one extra setting switched on. It is off when you install it.
- Scripts your hosting company adds — Cloudflare's own analytics, for example — go in after WordPress is done. Beyond any plugin. We find them and tell you.
- A font loaded by a style file is not held, and setting it to “Always block” does not change that.
- If your site uses page caching, a copy made before you switched this on can still be served to visitors. Nothing in the plugin can detect that.
What you can do about these
The font one is fixable: host the font on your own server instead of loading it from an outside company, and it stops being an outside request at all. The CDN one is a switch in your Cloudflare dashboard. The cache one is a purge after you turn server-side blocking on. None of these are things our code can reach from inside your page — all of them are things you can reach from your own admin.
Install
WordPress
WordPress plugin directory
Free, works on the server. Install it from your WordPress admin like any other plugin — search for Consentinel Cookie Consent.
Wix loads its own marketing tags before any code you add can run. That is a race no tool of this kind wins, ours included. So on Wix we do two things and we are straight about both. For Wix's own tags, we send the consent signal and clear the tracking cookies. For anything you pasted in yourself — a screen recorder, an ad pixel — we stop it running outright. Wix's own tags cannot be prevented from sending data by any browser-based consent tool. Not us, not Wix's own banner, not CookieYes. What we can do is tell you when it is happening, and show you.
Findings from our tests
Measured 2026-07-20 · same page twice on a client’s live site, with their permission
Zoho tracking cookies
Screen-recording signals sent
The screen-recording script itself
Google Analytics. This is the Wix limit, and no tool of this kind changes it.
- Code you pasted in yourself — screen recorders, ad pixels — is stopped before it runs.
- Wix's own marketing tags get the consent signal and have their cookies cleared. Watched and reported, not stopped. Nobody stops these from a browser.
- We do not currently suggest moving Google Analytics into custom code on Wix. The technique works, but we are not certain Wix lets a site owner remove their own integration — and we would rather not give you advice that fails in front of your client.
What you can do about these
Wix's own marketing tags cannot be held back by any consent tool — ours or anyone else's. What knowing changes is the decision. Once you can see which integrations are firing before your visitors agree, you can decide in Wix whether each one is worth keeping. That is a judgment call about your business, and it is yours. We just make sure you are making it with the facts in front of you.
Install
Wix
Custom code embed
Paste one script tag into Wix Custom Code, set to load in the head.
Shopify locks down checkout, and no tool of this kind reaches it. Honestly, none should try. Consentinel goes into your theme as one line of code, as high up the page as the theme allows.
We tested this and it did not go our way, so here is the result. On a live store with a perfect installation — our code first on the page, 23 blocking rules active — Shopify's own tracking still sent data to Facebook before visitors agreed, across 195 page loads. Shopify runs its own tracking in a separate sandbox with its own connection to the internet, which no code on the page can reach. That is one store and one test. Enough to say we do not block Shopify's own tracking. Not enough to make a general claim about the platform, and we will not pretend otherwise in either direction.
Findings from our tests
Measured 2026-08-13 · a live store, with the owner’s approval
The result on the store as we found it
Page loads where Shopify's own tracking sent data before anyone agreed, despite our blocking rules being active
Pages running a screen recorder before anyone agreed (from an earlier scan of the same store, July 17, 2026)
Cookies set before anyone agreed
- Trackers you pasted into your theme below our code are held before they run — the same way they are everywhere else. We have not tested this on Shopify specifically.
- Shopify's own tracking runs in a sandbox we cannot reach. Watched and reported, not stopped. Measured.
- Checkout belongs to Shopify. Anything there is watched and written down, not stopped.
What you can do about these
Shopify's own pixels run in a separate sandbox that no code on your page can reach. Knowing which ones fire before consent tells you which apps to review — and an app you are not using is an app you can remove.
Install
Shopify
Theme code embed
Paste one line into your theme, as high up the page as it allows.
Squarespace loads its own analytics and shop scripts before your page reaches the visitor; anything you add goes in through Code Injection. We hold the Code Injection scripts. Squarespace's own analytics load before our code does, and we do not have a way to send consent signals to Squarespace's system — so those get watched and reported, not stopped. Same limit as every locked-down website builder.
Findings from our tests
We have not tested a live Squarespace site yet. When we do, the numbers go here with a date on them — whichever way they come out.
- Anything in Code Injection is held before it runs.
- Squarespace's own analytics load before us. Reported, not stopped. No tool of this kind changes that.
- Not yet tested on a live Squarespace site. Same standard as everywhere else on this page: no test, no number.
What you can do about these
Anything Squarespace renders before our code loads is outside what any consent tool can hold back. What you can control is whether it is there at all — an integration you switch off in your Squarespace settings stops firing for everyone.
Install
Squarespace
Code Injection
No app listing — paste the code into Code Injection.
If your site is not on a platform we have named, Consentinel still works. Paste one line at the top of your page and you get the same thing: trackers held, a real browser checking what happened, and a dated record. How much we can hold comes down to where your platform lets our code run — which is what the rest of this page is about.
What you get on any site
Pages we check per site on the free plan. 600 on Pro and Agency, 4,000 on Scale.
Visits per check: one refusing cookies, one accepting
Short line of text added to your domain settings, to prove the site is yours before we check it properly
- Anything added by code in your page is held, as long as our code loads first.
- Anything your server puts above our code is watched and reported, not stopped.
- Tracking that happens server-to-server — Facebook's Conversions API, server-side tag managers — cannot be seen from a browser at all, by us or anyone.
What you can do about these
Server-to-server tracking never touches a browser, so no browser-based tool can see it, ours included. But you set it up — which means you can scope it down, delay it until after consent, or turn it off. The same goes for anything your host or CDN injects.
Install
Any site
One line of code
One line, at the top of the page. Works on any site you can edit.
Every number on this page comes from a dated test on a real site, or it isn't here. These are the trackers we found, and there may be more: browsers hide some cookies from any tool, and the deeper we look the more we find. Consentinel is software and documentation, not legal advice.