BOT

CookieOfficerBot

You are seeing cookieofficer.pl/bot in your server logs because our bot visited your website. Below you will find all the details: who sends it, why, how to recognise it and how to stop it if you would rather it did not visit.

Who sends it

CookieOfficer, a product of DataWolves, NIP (Polish tax identification number): 7722307415. We provide cookie consent management: our customers deploy a cookie banner on their websites, and we check which cookies are actually set and which tracking scripts actually run on their pages.

The bot visits a website only to analyse it. It does not fill in forms, create accounts, add anything to a basket or try to access an admin panel.

How to recognise it

The bot identifies itself with one of two User-Agent strings. Both contain the token CookieOfficerBot and the address of our bot information page (cookieofficer.pl/bot, the Polish version of this page).

When we render the page the way a browser sees it (compliance scan, screenshot):

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 CookieOfficerBot/1.0 (+https://cookieofficer.pl/bot)

When we fetch raw HTML, sitemaps or robots.txt (subpage counting):

Mozilla/5.0 (compatible; CookieOfficerBot/1.0; +https://cookieofficer.pl/bot)

The first one starts like a standard Chrome User-Agent string, because some websites do not serve the page at all to clients they do not recognise, and we would then be measuring something your visitors never see. The CookieOfficerBot token at the end is there so that this traffic can be clearly attributed to us.

The User-Agent alone is not proof of identity - anyone can put any text in it. If you want to be sure the traffic comes from us, write to contact@cookieofficer.com with the date, time and IP address from your log. We will confirm or deny it and send you the current IP address our scans come from.

Why it visits your website

We run the bot in three situations. None of them is continuous crawling of the web - each one is triggered by someone asking about a specific address.

TaskWhat it doesScale
Compliance scan Opens the page in a browser and checks which cookies are set: before any decision, after consent is accepted and after it is rejected. To do this, it clicks the buttons in the cookie banner, if there is one. Up to 40 subpages per run
Screenshot A single visit to the home page to capture an image of it for the background of the scan report. 1 page
Subpage counting Fetches robots.txt, sitemaps and HTML to count the unique URLs on the website (the price of our service depends on the size of the website). It does not render pages or run scripts. Up to 15,000 URLs, one request at a time, 400 ms apart

The compliance scan and the screenshot run on demand: requested either by the website owner, who added the website to our customer panel, or by someone who entered its address in the public scanner on cookieofficer.pl. This means your website may have been scanned by someone who does not manage it. If that has happened and you object, write to us - we will delete the scan result and look into your report.

robots.txt

Subpage counting respects robots.txt: rules for CookieOfficerBot and for * are read and followed, Disallow: / stops the count entirely, and a 5xx error when fetching this file is treated as a full disallow.

The compliance scan and the screenshot do not read robots.txt, because they are not crawling - each is a single visit to an address someone gave us, just like a visit from an ordinary browser. To stop them too, block our User-Agent on your server or WAF (see “How to block us” below) or write to us.

User-agent: CookieOfficerBot Disallow: /

How to let us in

If the panel shows “The site refused access”, your website's firewall rejected our scanner before it reached the page. The subpage count then stays empty - we do not report a number we have not measured. The most common cause is an anti-bot rule at the edge (Cloudflare, your host's WAF, a security plugin in your shop software), not robots.txt.

  • An exception for our User-Agent - the simplest option and usually enough. Allow requests whose User-Agent contains the token CookieOfficerBot. In Cloudflare: a WAF custom rule with the Skip action and the expression http.user_agent contains "CookieOfficerBot".
  • An exception for our IP address - safer, because anyone can fake the User-Agent header. Write to us for the current IP address our scans come from and add it to your allowlist.
  • robots.txt - check that there is no Disallow: / rule covering CookieOfficerBot or *. We respect this file unconditionally.

Once the block is removed, go back to the Domains tab in the panel and recount the subpages. While the block is in place, recounting changes nothing - every request is rejected in the same way.

How to block us

  • robots.txt - the rule above. It stops subpage counting.
  • A rule on your WAF or server - matching the User-Agent header against the token CookieOfficerBot. It stops everything.
  • An IP address block - write to us for the current IP address our scans come from.
If you are a CookieOfficer customer, do not block this bot. The panel checks whether the banner and Google Consent Mode are deployed correctly by looking at what the bot sees on the live page. If it is blocked at the edge (WAF, Cloudflare, a server rule), it will not reach the page, and your panel will show “No script on the site” despite a correct installation.

Contact

Questions about this traffic, requests to exclude a domain and abuse reports: contact@cookieofficer.com. We reply on working days. If the bot puts more load on your server than is acceptable, write to us instead of blocking it - we will lower our request rate.