A scanner can only prove what it can see. This demo sets first-party cookies from the server, writes storage from JavaScript, sends beacons to real endpoints, reads fingerprinting surfaces and calls a CNAME-cloaked subdomain.
Run a scan and the report should read like a site that tracks first and asks later – which is exactly what a real audit finds.
Leave a Reply