Script blocking
Tags wait for consent
Platform & operations
Cookie consent iFrame blocking stops embedded third-party content, such as YouTube and Vimeo players, Google Maps and social media posts, from loading until the visitor accepts the relevant cookie category. Kukie replaces each embed with a styled placeholder in the same space, naming the service and its category, and loads the real content in place once consent is given.
A visitor opens your about page. There is a YouTube player half way down that they never scroll to, and they leave after twenty seconds. In those twenty seconds their browser has already fetched the player from Google, and the player can already have written cookies to their device. The play button has nothing to do with it: an embed starts working the moment the page renders it.
YouTube does offer a privacy-enhanced embed mode, and it helps. It does not remove the issue, because the frame is still served by a third party that the visitor never chose to contact. The same is true of an embedded map, an embedded social post and any other window onto somebody else's site.
Without embed blocking
The banner asks, the embed does not
With embed blocking
Nothing is fetched until there is a yes
Kukie provides the technical infrastructure for holding embeds back until consent exists. Whether your site as a whole is compliant depends on how you configure it and may require further legal measures specific to your organisation. If you would like to see what your own pages currently load, the free cookie scanner reports the cookies a public page sets, and the free script audit lists the third parties it reaches.
A placeholder is what stands in for a blocked embed. It is not an error message and not an empty box. It explains what is missing, why, and what to do about it, and it does all of that without contacting the service it is standing in for.
Four things happen, none of which need any change to how your pages are built. You keep writing embeds the way your editor or your theme writes them.
It recognises the embed
Kukie reads the address each embedded frame points at and compares it against the services it knows, including YouTube, Vimeo, Google Maps and social media embeds. The check happens before the frame is allowed to fetch anything.
It swaps in the placeholder
The embed is replaced by a placeholder that takes its place and its dimensions. The settings the embed was written with are kept aside rather than discarded, which matters for step four.
It keeps watching the page
Embeds are not always present when a page first loads. A slider, a tab, a lazy loader or a page-builder block can add one seconds later. Kukie watches for frames appearing after load and treats them exactly the same way.
It puts the embed back
When the category is accepted, the original embed returns to the same position with the settings it started with, so it plays, scrolls and sizes as intended. No page reload, no lost scroll position.
Blocking is switched on by default, and it applies wherever the site is asking for consent before setting cookies, which is the opt-in model your EU and UK visitors are normally shown. If you run other regions under different rules, see geo-targeting. You can switch blocking off, or narrow it to certain services, in the banner editor.
An embed is a piece of another website placed inside a window on yours. If you pasted a block of code from a video host, a map service or a social network and something visible appeared, that is an embed. Invisible code that measures or advertises is a different job, handled by script blocking.
| On your page | What it really is | How Kukie handles it |
|---|---|---|
| A video player | A window served by the video host, which can store identifiers as soon as it renders, played or not | Replaced with a placeholder until the visitor accepts the category the service sits in |
| An embedded map | A window served by the map provider, often repeated in a site-wide footer or contact block | Replaced with a placeholder, so a map on every page is not a tracker on every page |
| A social post or feed | A window served by the social network, which may recognise a visitor who is signed in to it | Replaced with a placeholder naming the network, so the visitor knows exactly who is being let in |
| An analytics or advertising tag | Invisible code with nothing on the page to show for it | Held back by script blocking, which needs no placeholder because there is nothing to replace |
| Your own cookies | First-party items such as the login session, the basket or the chosen language | Generally needed for the site to work and left alone, but still listed in your cookie policy |
Not sure which of these your site has? A scan lists what a page actually loads, which is usually more than the person who built it remembers. See automatic cookie scanning.
Any site with a single embedded video benefits. These are the cases where the embed is doing more work than the owner realises.
The video is above the fold
A product tour or a founder's welcome at the top of the home page is the first thing the browser fetches, which makes it the first third party your visitor meets. Blocking moves that meeting to after the decision instead of before it.
There is a map in the footer
Restaurants, clinics, studios and shops often put a map in a template that renders site-wide. One contact page is a small exposure. Every page is a different conversation.
Your pages are built from blocks
Page builders, sliders, accordions and tabs frequently insert their embeds after the page has loaded. Anything that only inspects a page at load time misses those entirely, which is why Kukie keeps watching. Relevant to most WordPress sites.
Somebody else added the embed
A marketing colleague pastes a social feed into a landing page and nobody tells the person responsible for privacy. Recognised embeds are held back whether or not anyone remembered to configure them, which is the point of a default.
Embed blocking is part of the banner script itself rather than a paid extra, so every site you add has it from the moment the script goes live. See pricing if you need more sites, longer retention of your consent records or access for a team.
Embeds are one of three things that must not load before consent. These are the other two, and the banner that collects the answer.
Tags wait for consent
Layouts, categories and consent modes
Async, CDN, no round-trips
Background on the services most often embedded in a page, and what they store.
Cookies
March 20, 2026 · 6 min read
YouTube's privacy-enhanced mode does not make your embeds compliant by default. The youtube-nocookie...
Read more →
Cookies
March 19, 2026 · 10 min read
Social media cookies are set by platforms like Meta, LinkedIn, TikTok and X when your website embeds...
Read more →
Cookies
March 20, 2026 · 7 min read
Live chat widgets set cookies that track visitors, store conversations, and identify returning users...
Read more →
Cookies
March 19, 2026 · 9 min read
Blocking non-essential cookies before consent is a legal requirement under the GDPR and ePrivacy Dir...
Read more →What site owners ask before they put a video, a map or a feed behind consent.
Free plan, no card required. Add the script and recognised embeds wait for a yes.
Quick Profiles
Adjustments
Settings are saved in your browser only. Accessibility Statement