Esatto.CookieScan.Core 1.1.0

dotnet add package Esatto.CookieScan.Core --version 1.1.0
                    
NuGet\Install-Package Esatto.CookieScan.Core -Version 1.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Esatto.CookieScan.Core" Version="1.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Esatto.CookieScan.Core" Version="1.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Esatto.CookieScan.Core" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Esatto.CookieScan.Core --version 1.1.0
                    
#r "nuget: Esatto.CookieScan.Core, 1.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Esatto.CookieScan.Core@1.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Esatto.CookieScan.Core&version=1.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Esatto.CookieScan.Core&version=1.1.0
                    
Install as a Cake Tool

Esatto.CookieScan.Core

The rules behind the Esatto cookie scanner, with no dependencies at all.

  • Known-cookie catalogue with wildcard patterns and most-specific-wins matching
  • Consent-category inference from which passes a cookie appeared in
  • The violation rule: set outside the consent it needed
  • Append-only merge planning against what a policy page already declares
  • Localised duration formatting (sv, en) from a machine-readable day count
  • Scan-to-scan diffing: appeared, disappeared, recategorised

Why it exists as its own package

The scanner is a browser automation tool; the endpoint it writes through is an Umbraco web application. Both have to agree exactly on what counts as a violation, what category an unrecognised cookie gets and how a duration reads in Swedish — a site that declared a cookie differently from the way the tool proposed it would be the one bug this whole design exists to prevent.

So the shared rules live here, and having no PackageReference whatsoever is what enforces it: the Umbraco package can depend on the rules without dragging Playwright into a web application, and the rules can be unit tested without a browser or a published content graph.

Install

dotnet add package Esatto.CookieScan.Core

You want this package directly only if you are building your own front end or your own write-back. To run a scan, install Esatto.CookieScan.Cli.

The catalogue

CookieCatalogue is loaded from JSON rather than declared in code, because its purpose text becomes public legal wording on a policy page and must be changeable without a rebuild. One entry looks like this:

{
  "pattern": "_ga_*",
  "provider": { "sv": "Google Analytics", "en": "Google Analytics" },
  "category": "statistics",
  "tracker": true,
  "durationDays": 730,
  "purpose": { "sv": "Mäter användningen av webbplatsen.", "en": "Measures use of the site." }
}
  • pattern — * is the only wildcard. The most specific match wins: fewest characters absorbed by wildcards, then the longest literal prefix. A name nothing matches returns null rather than a guess, which is what routes it into the needs-review path instead of a confident wrong declaration.
  • expected — this site's own stack sets it, so its absence from a scan is itself a finding. Third-party entries leave it off: an absent Google cookie is normal.
  • consentCookie — marks the banner's own consent cookie, the one entry whose name is per-site configuration. WithConsentCookieNamed rewrites it for a site that renamed it.
  • durationDays — a number rather than pre-written text, so DurationFormatter can render it in either language. 0 is a session cookie; omitted means no documented lifetime, so use what the browser reported.

The shipped catalogue deliberately has no catch-all entry. With one, nothing could ever reach needs-review, and every unknown cookie would be declared with the catch-all's wording.

License

MIT.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Esatto.CookieScan.Core:

Package Downloads
Esatto.Umbraco.Backoffice.CookieScan

The site-side half of the Esatto cookie scanner. Adds one management-API endpoint that appends a scan's findings to the cookie policy page as a draft - append-only, never publishing, never rewriting an editor's legal wording - plus the API user and client credentials that authenticate the post. Companion to Esatto.Umbraco.Backoffice.CookieBanner, whose cookieDefinition element type and cookiePolicy page it writes into. Run the scan itself with the Esatto.CookieScan.Cli tool. Wiring is one AddCookieScan() call and one SeedCookieScanApiUserAsync() on start.

Esatto.CookieScan.Engine

The cookie consent audit engine behind the esatto-cookiescan tool. Crawls a site with a real headless browser, replays it once per consent decision a visitor can make, and reports every cookie and storage entry set outside the consent it needed. Reference it to build your own front end; install Esatto.CookieScan.Cli if you just want to run it. Pairs with the Esatto.Umbraco.Backoffice.CookieScan endpoint to append findings to an Umbraco cookie policy page as a draft.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.0 145 9/1/2026