A free, open-source browser extension that forensically audits every cookie consent banner you encounter — scoring it against GDPR and India's DPDP Act 2023 in real time.
ConsentFair runs a fully autonomous forensic audit the moment you land on any website. No clicking required. No data leaves your device.
In bulk mode, all domain cookies and cache are cleared first to ensure a pristine, first-visit environment for accurate scanning.
browsingData APIThe content script searches the entire DOM — including nested iframes — using 60+ CSS selectors and banner keyword matches across 7 languages.
content.jsThe page is scrolled to the bottom and back to trigger lazy-loaded and scroll-dependent banners. Up to 15 retry cycles are attempted.
Auto-retryAll 10 dark pattern detectors fire: button styles, pre-ticked checkboxes, confusing language, hidden info, nagging visits, visual hierarchy and more.
rules.jsA 100-point compliance score, Consent Asymmetry Index (CAI), cookie inventory, and a downloadable forensic HTML report are generated instantly.
background.jsConsentFair is the only free tool that actively detects all 10 categories defined by GDPR regulators. Each pattern carries a weighted point deduction.
No explicit reject button provided. Users can only accept, with no way to decline without hunting for alternatives.
−25 pts · CriticalNon-essential cookie categories arrive pre-selected. Valid consent must be an active opt-in, never a passive default.
−20 pts · CriticalAccepting is one click; rejecting requires navigating into a settings panel. Effort asymmetry by design.
−15 pts · HighAll cookie purposes lumped into one binary choice. No granular control over analytics vs. marketing vs. essential.
−15 pts · HighAccept button is bold, coloured, prominent. Reject button is grey, small, or outlined — steering users visually.
−15 pts · HighUnequal backgrounds, sizes, or font weights between Accept and Reject buttons that nudge users toward consent.
−10 pts · MediumLanguage like "less secure", "limited features", or "not recommended" attached to the reject path to create anxiety.
−10 pts · MediumKey details buried in tiny text (<10px), collapsed accordions, or a wall of text over 1200 characters long.
−10 pts · MediumDouble negatives like "uncheck to opt-out" or "untick if you do not want" make it impossible to understand what you're agreeing to.
−10 pts · MediumThe consent banner reappears on repeat visits even after a user has already made their choice — wearing users down.
−10 pts · MediumA complete forensic toolkit built for researchers, developers, compliance officers, and privacy-conscious users.
Banner and button keywords now cover 7 languages so the scanner works on French, German, Spanish, Portuguese, Italian, and Dutch sites — not just English.
Detects tracking cookies (Google Analytics, Meta Pixel, DoubleClick, TikTok and 30+ others) that fire before any user consent is given — a direct GDPR Art. 6 violation.
A quantitative score measuring how many times harder it is to reject consent vs. accept it.
CAI 0.00 = perfect parity | CAI 1.00 = 2× more effort to reject
Every cookie set by the site is listed with its name, domain, expiry, category (Essential / Analytics / Marketing / Functional), and Secure flag.
The last 30 audited sites are saved locally so you can track compliance trends, compare results, and revisit past findings without rescanning.
Hit the re-scan button to instantly re-audit the current page without refreshing. Essential for developers testing their own banners.
Download a printable, professional audit report with score, issue citations, button inventory, cookie inventory table, and a viewport screenshot — ready for legal or academic use.
Paste up to hundreds of URLs and run automated batch audits. Each site gets a forensic wipe, isolated fresh-session navigation, and a full compliance score. Results populate a live analytics chart and are exportable as a research CSV including Base64-encoded screenshots.
Generate a downloadable 600×320px PNG score card after every audit — showing the site score, tier badge, top 3 violations colour-coded by severity, breakdown bars, and ConsentFair branding. Ready to share on Twitter, LinkedIn, or attach to reports.
One click opens the correct Data Protection Authority complaint page for the site's jurisdiction — MEITY for India, ICO for UK, CNIL for France, BfDI for Germany, and 8 more. Pro users also get a pre-filled complaint letter copied to clipboard, ready to paste.
Sites scoring 70+ unlock a downloadable SVG certificate of compliance — professionally designed with corner ornaments, gold title, score ring, COMPLIANT badge, and audit metadata. Infinitely scalable for printing, embedding in reports, or displaying on websites.
Every Monday, ConsentFair sends a Chrome notification summarising your past 7 days — total sites scanned, average score, how many were compliant vs. non-compliant, your best and worst site of the week. No server. Computed entirely from your local audit history.
Every detected dark pattern is mapped to the specific article or section of the relevant regulation — giving you citation-ready evidence.
The world's most comprehensive data protection law, in force since May 2018. Applies to any organisation processing EU residents' personal data, regardless of where the organisation is located.
India's landmark data protection legislation passed in August 2023. Applies to processing of digital personal data within India and to processing outside India if related to offering goods/services in India.
Every scan, score, and report is computed entirely inside your browser. No data is sent to any server, API, or third party — ever.
ConsentFair does not collect, store, or sell any personal data. We have no analytics, no user accounts, and no telemetry.
Every line of code is publicly auditable on GitHub under the MIT License. Fork it, study it, improve it — it belongs to everyone.
ConsentFair began as rigorous academic research at Amity University, grounded in peer-reviewed literature on dark patterns and consent manipulation.
This tool is the practical implementation of a 6-page IEEE conference paper on forensic detection of dark patterns in cookie consent interfaces. The research maps real-world deceptive UX practices to specific GDPR and DPDP violations using a reproducible, quantitative scoring methodology.
The core audit — score, dark pattern detection, DPA report — is free forever. Pro unlocks the tools that make your findings shareable, reportable, and publishable.
Enter your key directly in the extension popup · Works on Chrome & Edge
Install ConsentFair, pin it to your toolbar, and browse the web. Every site you visit gets automatically audited and scored. No configuration required.
// Free forever · Open source · No account required · No data collected