
AM Cookies Security & Risk Analysis
wordpress.org/plugins/am-cookiesSimple and versatile GDPR compatible Cookie Compliance Plugin for WordPress.
Is AM Cookies Safe to Use in 2026?
Generally Safe
Score 100/100AM Cookies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "am-cookies" plugin version 1.2.12 exhibits a generally good security posture in several key areas. Static analysis reveals a complete absence of dangerous functions, SQL queries not using prepared statements, and all output is properly escaped. The plugin also does not perform file operations or make external HTTP requests, further limiting potential attack vectors. There is no recorded vulnerability history, indicating a mature and well-maintained codebase.
However, a significant concern arises from the identified attack surface. The plugin exposes two REST API routes without any permission callbacks. This means that any unauthenticated user can potentially interact with these endpoints, creating a serious security risk if these endpoints handle sensitive data or perform actions that could be exploited. While taint analysis shows no identified issues, the lack of authentication on REST API routes is a critical oversight that bypasses standard WordPress security practices.
In conclusion, while "am-cookies" demonstrates strong coding hygiene in many aspects, the unprotected REST API endpoints are a major weakness. This needs immediate attention to implement proper permission checks. The lack of historical vulnerabilities is a positive sign, but the current attack surface presents a clear and present danger that overshadows the other positive findings.
Key Concerns
- REST API routes exposed without permission checks
AM Cookies Security Vulnerabilities
AM Cookies Code Analysis
Output Escaping
AM Cookies Attack Surface
REST API Routes 2
WordPress Hooks 5
Maintenance & Trust
AM Cookies Maintenance & Trust
Maintenance Signals
Community Trust
AM Cookies Alternatives
Goolytics – Simple Google Analytics
goolytics-simple-google-analytics
A simple Google Analytics solution that works without slowing down your WordPress installation.
etracker analytics
etracker
Consent-free, despite ad blockers and tracking prevention: Web analytics, tag and consent manager for best data quality, ad returns and conversions.
SV Tracking Manager
sv-tracking-manager
SV Tracking Manager allows you to implement tracking scripts on your website - GDPR (DSGVO) compatible with Usercentrics support.
UTM Master
utm-master
Store UTM parameters in cookies, append them to links automatically, and manage GDPR compliance easily.
Check Permission Dialogue
check-permission-dialogue
This plugin adds an opt-in permission for certain known tracking scripts and tracking cookies.
AM Cookies Developer Profile
2 plugins · 800 total installs
How We Detect AM Cookies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/am-cookies/build/settings.js/wp-content/plugins/am-cookies/scripts/am-gdpr.min.js/wp-content/plugins/am-cookies/scripts/add-text.js/wp-content/plugins/am-cookies/styles/dist/admin.min.css/wp-content/plugins/am-cookies/styles/dist/preview.min.cssscripts/am-gdpr.min.jsscripts/add-text.jsbuild/settings.jsam-cookies/scripts/am-gdpr.min.js?ver=am-cookies/scripts/add-text.js?ver=am-cookies/build/settings.js?ver=HTML / DOM Fingerprints
alignPromptalignMiniPromptaccentColorbackgroundColorfontFamilyborderWidth+5 moreaamd_cookiesaamd_cookies_adminaamd_cookies_frontendamCookiesElement/wp-json/am-cookies-settings/v1/options<am-cookies