Scan only crawls static pages and ignores the sitemap, skipping all CMS items

Description

Consent Pro v2.2.9 on a Webflow site. The scan only crawls our static pages
(~16) and skips every CMS collection page (~175 CMS items). The scan UI also
keeps showing the “turn on the auto-generated sitemap.xml” notice even though the
sitemap is already enabled and valid.

I’ve already verified, before posting:

  1. Auto-generated sitemap is ON in Webflow (Site Settings → SEO); site
    republished.
  2. The sitemap is live and complete/sitemap.xml returns ~190 URLs (all
    CMS items + static pages). Confirmed by loading it directly.
  3. robots.txt advertises the sitemap — it contains a Sitemap: directive
    pointing at the sitemap URL.
  4. The site is published and not password-protected.
  5. Re-ran the scan after all of the above — no change; still only the static
    pages, still showing the “enable sitemap” notice.

So the sitemap exists, is complete, and is referenced in robots.txt, yet the
scanner isn’t using it.Site URL

Required: Please provide a staging/production URL where we can see the issue

Steps to Reproduce

  1. Enable auto-generated sitemap in Webflow (Site Settings → SEO) and republish.
  2. Confirm /sitemap.xml lists all CMS items and /robots.txt has a Sitemap:
    directive.
  3. Run (or re-run) the Consent Pro scan.

Expected Behavior

The scan reads the sitemap and crawls all pages including CMS items (~190 total),
so trackers on CMS/blog pages are detected.

Actual Behavior

The scan crawls only ~16 static pages, skips all CMS items, and continues to show
the “turn on the auto-generated sitemap.xml” notice as if no sitemap were enabled.

Questions

  1. How does the scanner discover the sitemap — does it read the Sitemap:
    directive in robots.txt, or fetch /sitemap.xml directly? Is anything else
    required for detection?
  2. Is there a page-count cap by plan tier that would limit the crawl
    regardless of the sitemap?
  3. The license/scan was first configured while the site was still
    password-protected.
    Could cached state be keeping it on the static-only
    crawl? Is there a way to force a fresh sitemap-based scan?

Video/Screenshots

Required: Please provide a short screen recording showing the issue

Additional Context

  • Browser: Chrome Version 149.0.7827.116
  • Device: Desktop macOS 26.5.1

NDA Notice: If you’re under an NDA, please feel free to send us a Direct Message/Email with the above information.