Cookie Consent for
Webflow That Actually
Blocks Scripts.
Webflow added a native cookie consent component in 2022 — but it manages Webflow integrations and Google Analytics, not the third-party scripts you embed yourself. Custom code embeds, GTM containers, Meta Pixels, and session-replay tools fire regardless of what your visitor chose. ConsentPixel — Privacy · Verified blocks every registered script with one custom code embed. No Webflow app. No plan upgrade required.
The Gap in Webflow's Native Cookie Consent
Webflow added a native cookie consent component in 2022, and for a design-led platform it was a meaningful step. The component can display a banner, remember a visitor's choice, and conditionally load the integrations Webflow manages directly — including the Google Analytics connection you add through Webflow's Project Settings.
But the majority of trackers on a real Webflow marketing site are not Webflow-managed integrations. They are scripts you add yourself: a Google Tag Manager container in the head code, a Meta Pixel in a custom code embed, a Hotjar snippet, a LinkedIn Insight tag. Webflow's native component does not block these.
Webflow's consent component gates Webflow-added integrations and the Webflow Google Analytics connection. It has no awareness of scripts you place in Custom Code or embed elements — which is where most marketing and advertising tags live.
A visitor can decline cookies, watch the banner disappear, and still have GA4, Meta Pixel, and Hotjar firing in the background because those were added as custom code rather than as Webflow integrations.
✗ Custom-code GTM still fires
A GTM container placed in your head custom code initialises and fires all its tags regardless of the visitor's choice in Webflow's banner.
✗ Embedded Meta Pixel still fires
A Meta Pixel added via an embed element or custom code executes on load — the native component has no hook to hold it.
✗ Hotjar / Clarity still fire
Session-replay snippets in custom code run before consent — creating $5,000/visitor CIPA exposure for California traffic.
✗ No GCM v2 / GPC handling
Webflow's component does not set Google Consent Mode v2 parameters or detect the Global Privacy Control signal at all.
For a portfolio site with no tracking this may not matter. For the agency client sites, SaaS marketing sites, and lead-generation sites that make up most serious Webflow projects, it leaves the exact scripts regulators care about firing before consent.
Trackers Commonly Running on Webflow Sites
Webflow's audience skews toward agencies, startups, and marketing teams — which means Webflow sites tend to carry a full marketing and analytics stack added through custom code. These are the integrations most commonly found, and the privacy exposure each creates.
Webflow Native Consent vs. ConsentPixel
Webflow's component and ConsentPixel solve different problems. The native component manages Webflow integrations; ConsentPixel blocks the external scripts the native component cannot reach.
| Capability | Webflow Native Component | ConsentPixel |
|---|---|---|
| Blocks external JS before consent | ✗ Not supported | ✓ All registered scripts |
| Blocks GA4 / GTM tags | ✗ No | ✓ Yes |
| Google Consent Mode v2 (all 4 params) | ✗ No | ✓ All plans |
| Global Privacy Control (GPC) detection | ✗ No | ✓ Auto-detected |
| CIPA session-replay blocking | ✗ No | ✓ Yes |
| US state law opt-out (19 states) | ✗ No | ✓ All plans |
| Timestamped consent audit log | ⚠ Basic / none | ✓ Full log, exportable |
| Page-scoped consent enforcement | ✗ No | ✓ Yes |
| Works without platform plan upgrade | ⚠ Often gated | ✓ Any plan |
See what fires on your Webflow site despite the banner
ConsentPixel scans your published Webflow site in a fresh session — no cache, no prior consent — and shows every script transmitting data before any consent is recorded.
How to Install ConsentPixel on Webflow
ConsentPixel installs on Webflow as a single script in your site's head custom code — no Webflow app, no Marketplace install, and it works on every plan including the free Starter plan. It must load before all other scripts so pre-consent blocking works correctly.
Create your ConsentPixel account and scan your site
Sign up at consentpixel.com, add your Webflow site's domain, and run the auto-scanner. ConsentPixel maps every tracker across your published site — including custom-code embeds and GTM tags. Copy your unique pixel snippet from the dashboard.
Add the snippet to Webflow head custom code
In the Webflow Designer, open Project Settings → Custom Code. Paste the ConsentPixel snippet into the Head Code field as the first entry, before any GTM, GA4, or other tracking embeds.
<!-- ConsentPixel — must be first in head --> <script src="https://pixel.consentpixel.com/YOUR-SITE-ID.js" async></script> <!-- Your GTM / GA4 / Meta embeds below -->
If you add tracking on individual pages via Page Settings → Custom Code, ConsentPixel in the project head still loads first — project head code renders before page head code in Webflow.
Publish your site
Click Publish in the Designer. Custom code only goes live on published sites — it does not run in Designer preview. ConsentPixel begins blocking registered scripts immediately on the live site.
Register your external scripts and configure GCM v2
In the ConsentPixel dashboard, register each tracking tool by consent category: Analytics (GA4), Marketing (Meta, LinkedIn, TikTok), Functional (live chat), Session Recording (Hotjar, Clarity). ConsentPixel holds each category until the visitor consents.
Enable Google Consent Mode v2 — ConsentPixel injects all four GCM v2 parameters as the first head script, before your GTM container loads, the firing order Webflow's native component cannot guarantee.
Decide how to handle Webflow's native banner
Layered: keep Webflow's component for its managed Google Analytics integration and let ConsentPixel handle all custom-code scripts. ConsentPixel only: turn off Webflow's native component and let ConsentPixel handle everything, giving you a single consent experience and a single exportable consent log. Either approach closes the custom-code gap.
What ConsentPixel Does for Your Webflow Site
Blocks your custom-code scripts
Intercepts GA4, Meta Pixel, GTM tags, Hotjar, and LinkedIn embeds added through Webflow custom code — the scripts the native component cannot reach — and holds them until consent.
Google Consent Mode v2 — correct order
Injects all four GCM v2 parameters as the first head script, before your GTM container initialises. Protects Google Ads conversion measurement for EU and UK visitors.
GPC browser signal detection
Automatically honours the Global Privacy Control signal for California, Colorado, Virginia, and Connecticut visitors — a requirement Webflow's native component does not address.
CIPA session-replay protection
Blocks Hotjar, Clarity, and Lucky Orange before consent — eliminating the $5,000/visitor CIPA exposure California traffic creates on Webflow sites running these tools.
Designed to match your Webflow brand
The consent banner is fully styleable to match the design system you built in Webflow — no clashing default widget. Agency Lite and Pro plans add white-label branding.
Works on every Webflow plan
Added as standard custom code, ConsentPixel runs on the free Starter plan through Enterprise. No Webflow plan upgrade and no Marketplace app required.
Webflow Privacy Compliance Checklist (2026)
Frequently Asked Questions
One embed in your head code.
Every custom script covered.
ConsentPixel — Privacy · Verified blocks the GA4, GTM tags, Meta Pixel, and session-replay scripts your Webflow custom code loads — while passing all four GCM v2 parameters and honouring GPC signals. No app. No plan upgrade. Works on every Webflow plan.