gafaro.lt
Last scanned September 20, 2026
A cookie scan of gafaro.lt conducted on September 20, 2026 found 10 cookies and 11 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site employs CookieYes as its consent management platform. Neither IAB TCF v2.3 nor Google Consent Mode v2 was observed on our check. 11 third-party requests were detected from 9 vendors.
Consent behaviour grade
24 / 100
This site set multiple tracking cookies before the visitor consented. Under ePrivacy Article 5(3), these require prior consent.
Automated point-in-time check of the scanned pages; not legal advice. How our check works.
Consent enforcement level
-
1
Nothing non-essential runs before consent is given. This is the strict reading of ePrivacy Article 5(3) and the strongest position.
-
2
Google tags load with storage defaulted to denied and send only cookieless pings before consent. Permitted in Google's model, but not the strict reading of Article 5(3).
-
3
Google Consent Mode v2 restrains Google tags, but other trackers or cookies were observed before consent.
-
4
Runs before consent This site
A consent banner is present but does not restrain tracking. Trackers and cookies run before the visitor consents.
Consent banner as encountered
No Reject option on the first layer; declining requires extra steps.
Load timeline before consent
Milliseconds from navigation start until each request fired or each cookie was set.
and 4 more
Observed before consent
Cookies set before consent (9)
-
_fbpmarketing · Facebook -
tk_lrmarketing · WordPress -
tk_ormarketing · WordPress -
pvc_visits[0]analytics · Postviewscounter -
tk_r3danalytics · WordPress -
_lscache_varyunknown -
mtk_src_trkunknown -
__stripe_midnecessary · Stripe -
__stripe_sidnecessary · Stripe
Tracking requests before consent (6)
- Automattic stats.wp.com at 143 ms
- Stripe Inc. m.stripe.com set a cookie set by m.stripe.network/out-4.5.45.js · at 2027 ms
- MailerLite static.mailerlite.com at 582 ms
- Meta Platforms, Inc. connect.facebook.net at 583 ms
- Meta Platforms, Inc. www.facebook.com at 836 ms
- Stripe m.stripe.network set by js.stripe.com/m-outer-15a2b40a058ddff1cffdb63779fe3de1.js · at 1974 ms
How we tested
Browser: Chrome/150.0.7871.124 · Scan origin: EU · Viewport: 1440×900 · Checked: 20 Sep 2026 14:13
Cookies
10
Third-party
0
Trackers
11
Vendors
9
Consent banner
CookieYes
Scans
1
What this setup is missing
- No Reject option on the first layer; declining requires extra steps.
Compliance by audience
European Union
✗ Not metGDPR + ePrivacy · Prior consent (opt-in)
United Kingdom
✗ Not metUK GDPR + PECR · Consent-based
United States
✓ Meets this modelCCPA/CPRA + state laws · Notice & opt-out
Canada
! Needs attentionPIPEDA + Québec Law 25 · Consent-based
Brazil
! Needs attentionLGPD · Consent-based
Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.
Connection security
HTTPS supported
✓Redirects HTTP to HTTPS
✓HSTS
✗Content Security Policy
✓
Third-Party Trackers
11 requests detected from 9 vendors: Automattic, Stripe Inc., MailerLite, Meta Platforms, Inc., CookieYes...
Third-Party Trackers
11 requests detected from 9 vendors: Automattic, Stripe Inc., MailerLite, Meta Platforms, Inc., CookieYes...
Analytics
2
Marketing
3
Necessary
5
Functional
0
Other
1
| Vendor | Category | Type | Domain |
|---|---|---|---|
| Automattic before consent Automattic tracker domain (source: Disconnect.me, category: Content) | Analytics | script | stats.wp.com |
| Stripe Inc. before consent Stripe fraud detection | Analytics | script | m.stripe.com |
| MailerLite before consent MailerLite tracker domain (source: Disconnect.me, category: EmailAggressive) | Marketing | script | static.mailerlite.com |
| Meta Platforms, Inc. before consent Facebook SDK / Pixel | Marketing | script | connect.facebook.net |
| Meta Platforms, Inc. before consent Facebook tracking pixel | Marketing | pixel | www.facebook.com |
| CookieYes CookieYes consent management | Necessary | script | cdn-cookieyes.com |
| Shopify Inc. Shopify platform | Necessary | script | cdn.shopify.com |
| Stripe Inc. Stripe payment processing | Necessary | script | js.stripe.com |
| UNPKG UNPKG tracker domain (source: Disconnect.me, category: Content) | Necessary | script | unpkg.com |
| Volentio JSD Volentio JSD tracker domain (source: Disconnect.me, category: Content) | Necessary | script | cdn.jsdelivr.net |
| Stripe before consent Stripe tracker domain (source: Disconnect.me, category: FingerprintingInvasive) | Unknown | script | m.stripe.network |
Scan history
One completed scan: cookies and trackers from the scan on September 20, 2026.
Recent scans
| September 20, 2026 | 10 11 |
More Cookie Compliance Reviews
Pagrindinis - Gyvos samanų sienos, vertikalūs...
gajadecor.lt
Gaisrine
gaisrine.lt
Divine Mercy in the Holy Scripture | The Shrine...
gailestingumas.lt
503 Service Temporarily Unavailable
gailestingumokoplycia.lt
430-ojo sezono uždarymas. Mėnesienos sonata -...
gacioniudvaras.lt
Dantų pastos - Gabrielė Bizienė
gabrielebiziene.lt
Gintaras ir gintaro papuošalai bei dirbiniai |...
g-amber.lt
One moment, please...
fysioline.lt
Is gafaro.lt your website?
Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.