Free WordPress Plugin

Stop guessing what's loading on your site.

Nahnu Asset Scanner scans your front end and builds a precise, attributed inventory of every JS file, CSS file, cookie, and external domain. Configure your cache plugin and cookie consent from real data, not guesswork.

No account required
No external API
GPL licensed
96 assets identified
JS, CSS, cookies, domains
Nahnu Asset Scanner pages tab showing page selection before a scan
The Problem

Cache and consent configs are only as good as your data.

Which scripts should you exclude from defer?

Generic guides list common ones. But your site has plugins those guides have never heard of. Deferring the wrong script breaks things, and you won't always know why.

Which cookies actually need consent?

Cookie consent plugins scan your site, but they don't always attribute cookies to the plugin that sets them or categorize them correctly. You end up over-blocking or missing things entirely.

What third-party services is your site calling?

Every plugin can silently phone home to an external domain. Until you look, you have no idea what belongs on your GDPR processor list or what is slowing your site down.

Why it exists

The missing step before you configure anything.

Run a scan first. Then configure your cache plugin and cookie consent from real data, not assumptions.

01

Cache optimization

See every JS and CSS file loaded on your site: the exact handle, file path, size, and the plugin that registered it. Know what to exclude before you flip a defer setting.

Practical use Copy file paths directly into your cache plugin's exclude list for defer, delay, or minification.
02

Cookie consent accuracy

Get a categorized cookie inventory from a real scan of your site. Each cookie is labeled Necessary, Preferences, Analytics, or Marketing, with the plugin that sets it already identified.

Practical use Feed the results into Complianz, CookieYes, or Real Cookie Banner instead of starting from scratch.
03

Third-party auditing

Every external domain your site contacts during a page load, captured and listed in one tab. Use it as the starting point for your Content Security Policy or GDPR processor list.

Practical use Use as a starting point for your Content Security Policy or GDPR third-party processor list.
How it works

Three steps. No setup. No account.

The scanner only runs when you click the button. Zero impact on your visitors.

1

Select your pages

Choose up to 10 pages to include: homepage, shop, checkout, blog. Run multiple scans to cover different sections of your site.

2

Run the scan

Click Run Scan. The plugin visits each page on your server with no external API calls and no data leaving your site. Results stored in your own database.

3

Use the results

Browse the JS, CSS, Cookies, and Domains tabs. Filter, search, and export. Copy exactly what you need into your cache plugin or consent platform.

Asset Scanner pages tab showing page selection before a scan
What you get

Four tabs. Complete picture.

JavaScript tab showing all scripts with plugin attribution

Every script, attributed.

See every JavaScript file loaded on each scanned page, inline or external, with the WordPress handle, file path, file size, and the plugin or theme that registered it.

  • Exact file paths ready to paste into WP Rocket, Perfmatters, or LiteSpeed
  • Third-party badges: Analytics, Marketing, Payment, CDN, Chat, and more
  • Inline script detection and size reporting
  • Filter by first-party / third-party or search by filename
  • Export with one click
CSS tab showing all stylesheets with file size and plugin attribution

Every stylesheet, identified.

Every CSS file with its WordPress handle, full path, file size, and the plugin or theme it came from. Know exactly which stylesheets to exclude from combine or minify.

  • Plugin attribution for every stylesheet handle
  • File size at a glance so you can spot bloated stylesheets
  • First-party vs. third-party classification
  • Filter, search, export
Cookies tab showing categorized cookies with plugin attribution

Every cookie, categorized.

A complete cookie inventory from a real scan of your site, not a template list. Each cookie is matched against 600+ patterns, categorized, and attributed to the plugin that sets it.

  • Necessary / Preferences / Analytics / Marketing categories
  • Plugin attribution for every detected cookie
  • Cookie expiry and domain details
  • Export ready for your consent platform
Domains tab showing third-party domains detected during scan

Every external call, exposed.

See every third-party domain your site contacts during a page load. Every external call logged, no external service required.

  • Every third-party domain logged per scanned page
  • Foundation for a Content Security Policy
  • Starting point for your GDPR processor list
  • Export
Cookie Database

600+ patterns. Bundled. No setup.

The plugin ships with a curated database covering the WordPress ecosystem: WooCommerce, membership plugins, LMS platforms, builders, security plugins, analytics, ad networks, chat widgets, and more.

600+ bundled patterns
400+ plugins covered
WooCommerce MemberPress LearnDash Elementor WP Rocket Wordfence Google Analytics Meta Pixel Klaviyo HubSpot Tawk.to Stripe CookieYes Complianz + many more
Necessary
Session, login, cart, language, and security cookies. These must always be active and bypass your cache.
Preferences
User settings, display preferences, currency selection, and similar functional cookies.
Analytics
Traffic measurement, heatmaps, session recording, and A/B testing. Covers Google Analytics, Hotjar, Clarity, Matomo, and more.
Marketing
Ad retargeting and conversion tracking. Covers Meta Pixel, Google Ads, LinkedIn, TikTok, Pinterest, and others.
Works with

Feeds directly into the tools you already use.

Asset Scanner is not a replacement for your cache or consent plugin. It is the preparation step that makes them work correctly.

Cache & Performance
WP Rocket LiteSpeed Cache Perfmatters Asset CleanUp W3 Total Cache WP Fastest Cache Hummingbird
Use JS/CSS tab results to populate defer, delay, and exclusion lists accurately.
Cookie Consent
Complianz CookieYes Real Cookie Banner Borlabs Cookie Cookiebot Cookie Notice
Use Cookies tab results and export as input for your consent platform configuration.
Privacy & Security
Content Security Policy GDPR Processor List Privacy Policy
Use the Domains tab as a foundation for your CSP allowlist and GDPR third-party processor documentation.

Free. No license key. No account.

Install it, run a scan, and walk away with a complete inventory of your site. Everything works out of the box with no signup required and no data leaving your server.

GPL-2.0 Licensed
Scans run on your server
No background requests
Export on every tab

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only