Borlabs Scanner is the website scanning service operated by Borlabs GmbH for Borlabs Cookie, a consent management plugin for WordPress.
The scanner is started by the site owner from inside their own WordPress installation. It is not an unsolicited crawler and it does not discover sites on its own: it only visits URLs it has been asked to scan. The site owner selects which pages to scan; if they select none, Borlabs Cookie proposes a representative set: the homepage, one page per post type, one archive per post type, and common pages such as a contact page or a page containing a map.
For each requested URL the scanner opens the page once in a headless Chrome browser, waits for the page to finish loading, optionally scrolls to the bottom and back to trigger lazy-loaded content, and takes a screenshot. It then records which cookies were set, which external connections the page made, which JavaScript globals were defined, and the response headers. The result is reported back to the site owner so they can configure their consent settings to match what their site actually loads.
The scanner requests only the pages it is given. It does not follow links, does not submit forms, does not log in, and does not fetch robots.txt. It acts on the site owner’s own instruction about their own site. A scan produces a short burst of page loads, typically a handful per site, and runs only when the site owner triggers it.
If Borlabs Scanner is causing load or other problems on your infrastructure, please contact us before blocking it and select “Cooperation request” as the topic. Include the affected domain and roughly when the requests arrived. That lets us identify the site owner and follow up with them directly.
| Operator | Borlabs GmbH |
| Product | Borlabs Scanner, the scanning service for Borlabs Cookie |
| User-Agent | Borlabs-Scanner/1.0.0 (+https://borlabs.io/borlabs-scanner/) |
| Browser engine | Headless Chrome (Chromium), driven by Puppeteer |
| Trigger | Site-owner initiated from Borlabs Cookie. Never scheduled by Borlabs. |
| Scope | Only URLs supplied by the site owner. No link following, no form submission, no login unless the owner supplies HTTP Basic credentials. |
| Frequency | Per scan, on demand. Typically a handful of page loads per site. |
| Timeouts | 45 s per page by default; at most one retry per page. |
| robots.txt | Not fetched. Owner-initiated scan of the owner’s own site. |
| Hosting | Google Cloud Run, region europe-west3 |