About the IsPixelWorking checker
If you found IsPixelWorking in your server logs or analytics, this page explains what it is, what it did on your site, and how to opt out.
What it is
IsPixelWorking is an independent tool that checks whether a website's ad tracking (such as the Meta Pixel) works correctly: whether it respects the cookie banner, whether events are duplicated, whether click IDs from ads are stored. Someone, usually the site owner, a marketer or an agency working on the site, pasted a URL into ispixelworking.com, and our checker loaded that page in a browser to look at its tracking.
How to recognize it
The checker is a headless Chrome browser. Its User-Agent is a normal Chrome User-Agent (desktop or mobile) with this token added:
IsPixelWorking/0.1 (+https://ispixelworking.com/bot)
The traffic comes from Cloudflare's network in the EU: the browser runs on Cloudflare Browser Run (formerly called Browser Rendering). If your site is behind Cloudflare, Cloudflare tags these requests with its own bot detection ID for Browser Run, which you can use in a WAF rule to allow or block them.
We do not hide that we are automated: the browser reports itself as automated to scripts on your page.
What it does on your site
For one check, the checker:
- Loads the URL the user entered, in two separate browser sessions on desktop: once without interacting, and once with test ad click IDs in the URL (for example
fbclid=TRACKCHECK_TEST_FBCLID) and the cookie banner accepted. Monitoring plans add a third session on a phone-sized screen. - Clicks "accept" on the cookie banner, if there is one.
- Clicks a few call-to-action buttons (at most six on desktop; on monitoring plans also at most four on mobile, plus one internal link).
- Records the tracking requests your page tries to send, the cookies it sets and a screenshot.
In total, a check is usually two page loads (three on monitoring plans), plus a few same-site pages if a clicked button leads to one.
It never:
- types into fields or submits forms;
- clicks buy, add to cart, checkout, payment or subscribe buttons;
- sends form-style requests (POST and similar) to your server during clicks: our browser answers those itself;
- lets tracking data reach ad platforms: requests to Meta, Google, TikTok and similar endpoints are answered by our browser and not delivered.
The test click IDs in the URL are obviously fake, and the tracking requests that carry them are stopped before they leave the browser.
One known limitation: a browser can open a secure connection to a server in advance, before sending anything. We cannot always prevent that early handshake to an ad platform, but no tracking data is sent over it. We also cannot see or stop server-to-server forwarding: if your server forwards events it receives to an ad platform in a way we do not recognize, that forwarding happens outside our browser. We stop clicking buttons as soon as we see a request that looks like an unrecognized tracking event. More detail is in our methodology.
How often
- A given URL is checked again at most once per hour, however many people request it.
- Results are cached for 24 hours: within that time, new requests for the same URL get the existing report instead of a new visit.
- Each person can only start a limited number of checks per day.
How to opt out
Stop all checks of your site: email us at bot@ispixelworking.com from an address at your domain (or tell us how we can confirm you run the site), and we will add your domain to our opt-out list. The checker will then refuse to check it, including when users request it.
Research scans: we occasionally run aggregated research scans over many public sites (for example, to measure how often consent and tracking problems occur on a platform). These scans use the same User-Agent token, but they do not run on Cloudflare: they run from a computer we operate ourselves in the EU (a Node.js script driving Chromium with Playwright), so they come from an ordinary IP address, not from Cloudflare's network. They honor robots.txt and wait between requests to the same site. To exclude your site, add:
User-agent: IsPixelWorking
Disallow: /
Note: robots.txt applies to our research scans. A check that a person requests for a specific URL is treated like that person visiting the page in their own browser, so use the email opt-out above to stop those too.
Questions
If the checker caused a problem on your site, or you have questions about what it did, write to bot@ispixelworking.com. Include the time of the visit and the URL, and we will look into it.