Skip to content
Features
Pricing Free Cookie Scanner Consent Mode Checker Script Audit TCF String Decoder Cookie Database GDPR Scanner Compliance Blog
Start Free → Login

Platform & operations

iFrame blocking: embeds that wait to be let in

Cookie consent iFrame blocking stops embedded third-party content, such as YouTube and Vimeo players, Google Maps and social media posts, from loading until the visitor accepts the relevant cookie category. Kukie replaces each embed with a styled placeholder in the same space, naming the service and its category, and loads the real content in place once consent is given.

What an embedded video does before anyone presses play

A visitor opens your about page. There is a YouTube player half way down that they never scroll to, and they leave after twenty seconds. In those twenty seconds their browser has already fetched the player from Google, and the player can already have written cookies to their device. The play button has nothing to do with it: an embed starts working the moment the page renders it.

YouTube does offer a privacy-enhanced embed mode, and it helps. It does not remove the issue, because the frame is still served by a third party that the visitor never chose to contact. The same is true of an embedded map, an embedded social post and any other window onto somebody else's site.

Without embed blocking

The banner asks, the embed does not

  • The player, the map or the feed loads with everything else on the page, before the visitor has answered anything.
  • A visitor who then presses reject has already been reached by the third party. The banner records a refusal that the page did not honour.
  • Anyone can see it. Open the page, refuse everything, look at the stored cookies. This is the gap between what a banner promises and what a page does, and it is the easiest thing in the world to check.

With embed blocking

Nothing is fetched until there is a yes

  • The embed is intercepted before it can load, so no request reaches the provider and no cookie of theirs is written.
  • The visitor sees a placeholder in the same space, telling them what is being held back and offering to allow it in one click.
  • Accept and the content appears where the placeholder was. Refuse and the page simply never loaded it, which is the answer the visitor gave.

Kukie provides the technical infrastructure for holding embeds back until consent exists. Whether your site as a whole is compliant depends on how you configure it and may require further legal measures specific to your organisation. If you would like to see what your own pages currently load, the free cookie scanner reports the cookies a public page sets, and the free script audit lists the third parties it reaches.

What is an embed placeholder?

A placeholder is what stands in for a blocked embed. It is not an error message and not an empty box. It explains what is missing, why, and what to do about it, and it does all of that without contacting the service it is standing in for.

It names the service
"YouTube", not "blocked content". A visitor who wanted to watch a video knows immediately that the video is still there and still available to them.
It names the consent category
The placeholder states which of your categories the embed belongs to, so the decision in front of the visitor is a specific one rather than a vague request for permission.
It carries its own accept button
One click allows that category and nothing more. There is also a way through to the full preferences panel for anyone who would rather see everything before deciding.
It keeps the layout still
The placeholder is sized from the embed it replaced and hands that space straight back when the embed returns, so the article around it does not jump.
It speaks the visitor's language
The placeholder wording is translated along with the rest of the banner, and it picks up the banner's colour and font so it reads as part of your site rather than a browser warning.
An illustration of the placeholder a visitor meets where a blocked YouTube embed would be. The category name is whichever one you have assigned the service to, and the wording follows your banner's language.

How does Kukie block an embed before it loads?

Four things happen, none of which need any change to how your pages are built. You keep writing embeds the way your editor or your theme writes them.

1

It recognises the embed

Kukie reads the address each embedded frame points at and compares it against the services it knows, including YouTube, Vimeo, Google Maps and social media embeds. The check happens before the frame is allowed to fetch anything.

2

It swaps in the placeholder

The embed is replaced by a placeholder that takes its place and its dimensions. The settings the embed was written with are kept aside rather than discarded, which matters for step four.

3

It keeps watching the page

Embeds are not always present when a page first loads. A slider, a tab, a lazy loader or a page-builder block can add one seconds later. Kukie watches for frames appearing after load and treats them exactly the same way.

4

It puts the embed back

When the category is accepted, the original embed returns to the same position with the settings it started with, so it plays, scrolls and sizes as intended. No page reload, no lost scroll position.

Blocking is switched on by default, and it applies wherever the site is asking for consent before setting cookies, which is the opt-in model your EU and UK visitors are normally shown. If you run other regions under different rules, see geo-targeting. You can switch blocking off, or narrow it to certain services, in the banner editor.

Which parts of your page does this cover?

An embed is a piece of another website placed inside a window on yours. If you pasted a block of code from a video host, a map service or a social network and something visible appeared, that is an embed. Invisible code that measures or advertises is a different job, handled by script blocking.

What each kind of third-party content on a page is, and which Kukie feature holds it back until consent
On your page What it really is How Kukie handles it
A video player A window served by the video host, which can store identifiers as soon as it renders, played or not Replaced with a placeholder until the visitor accepts the category the service sits in
An embedded map A window served by the map provider, often repeated in a site-wide footer or contact block Replaced with a placeholder, so a map on every page is not a tracker on every page
A social post or feed A window served by the social network, which may recognise a visitor who is signed in to it Replaced with a placeholder naming the network, so the visitor knows exactly who is being let in
An analytics or advertising tag Invisible code with nothing on the page to show for it Held back by script blocking, which needs no placeholder because there is nothing to replace
Your own cookies First-party items such as the login session, the basket or the chosen language Generally needed for the site to work and left alone, but still listed in your cookie policy

Not sure which of these your site has? A scan lists what a page actually loads, which is usually more than the person who built it remembers. See automatic cookie scanning.

When does embed blocking matter most?

Any site with a single embedded video benefits. These are the cases where the embed is doing more work than the owner realises.

The video is above the fold

A product tour or a founder's welcome at the top of the home page is the first thing the browser fetches, which makes it the first third party your visitor meets. Blocking moves that meeting to after the decision instead of before it.

There is a map in the footer

Restaurants, clinics, studios and shops often put a map in a template that renders site-wide. One contact page is a small exposure. Every page is a different conversation.

Your pages are built from blocks

Page builders, sliders, accordions and tabs frequently insert their embeds after the page has loaded. Anything that only inspects a page at load time misses those entirely, which is why Kukie keeps watching. Relevant to most WordPress sites.

Somebody else added the embed

A marketing colleague pastes a social feed into a landing page and nobody tells the person responsible for privacy. Recognised embeds are held back whether or not anyone remembered to configure them, which is the point of a default.

Embed blocking is part of the banner script itself rather than a paid extra, so every site you add has it from the moment the script goes live. See pricing if you need more sites, longer retention of your consent records or access for a team.

Related features

Embeds are one of three things that must not load before consent. These are the other two, and the banner that collects the answer.

See the full feature set

More on embeds and third-party content

Background on the services most often embedded in a page, and what they store.

All articles

iFrame blocking questions

What site owners ask before they put a video, a map or a feed behind consent.

Do embedded YouTube videos need cookie consent?
In the EU and the UK, in almost every case yes. A standard YouTube embed contacts Google and can store identifiers on the visitor device as soon as the player appears, whether or not anyone presses play. You chose to place the embed on your page, so that storage happens under your responsibility and needs to wait for consent in the same way an analytics tag does.
Does the privacy-enhanced YouTube embed remove the need for consent?
It reduces the problem without eliminating it. YouTube offers a privacy-enhanced embed mode that limits what the player stores before someone interacts with it, but the frame is still fetched from a Google server and the visitor browser still reaches a third party. Kukie treats a privacy-enhanced embed exactly as it treats a standard one, so the choice of embed mode does not quietly change what your visitors are exposed to.
What does a visitor see in place of a blocked embed?
A placeholder that fills the space the embed would have taken. It names the service being held back, states which consent category that service belongs to, and carries a button that accepts just that category, plus a second control that opens the full preferences panel. Nothing is requested from the embed provider while the placeholder is on screen.
Will blocking embeds break my page layout?
It should not. The placeholder is sized from the embed it replaced, so it occupies the same space rather than collapsing it, and when the visitor accepts, the embed takes that space back. The content around the embed stays where it was in both directions.
Does the page have to reload after the visitor accepts?
No. The embed loads in place the moment consent is given, with the attributes it was originally written with rather than a stripped-down version, so a visitor who accepts in order to watch a video sees the player appear where the placeholder was instead of losing their position on the page.
What is the difference between blocking embeds and blocking scripts?
An embed is visible content borrowed from another site, such as a video player or a map, so blocking it leaves a gap the visitor can see and act on. A script is invisible, such as an analytics or advertising tag, so blocking it simply means nothing runs. Both have to wait for consent, but only embeds need something for the visitor to look at in the meantime.

Stop your embeds loading before consent

Free plan, no card required. Add the script and recognised embeds wait for a yes.

Listed On