ATR Cookie Notice Security & Risk Analysis

wordpress.org/plugins/atr-cookie-notice

Cookie consent banner aligned with Israel's Privacy Protection Law (Amendment 13).

600 active installs v1.2.0 PHP 7.4+ WP 5.0+ Updated Feb 8, 2026
ammendment-13consentcookiesisraeli-lawprivacy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ATR Cookie Notice Safe to Use in 2026?

Generally Safe

Score 100/100

ATR Cookie Notice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "atr-cookie-notice" plugin v1.2.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the code analysis reveals a commendable lack of dangerous functions, raw SQL queries, and external HTTP requests. The plugin also demonstrates good practice with a significant number of nonce and capability checks, suggesting an effort to secure its functionalities. The high percentage of properly escaped output further contributes to a reduced risk of cross-site scripting (XSS) vulnerabilities.

However, a notable concern arises from the presence of one file operation. While not explicitly flagged as problematic, file operations can introduce risks if not meticulously handled, such as unauthorized file modifications or deletions. The absence of any taint analysis flows, while seemingly positive, could also indicate that the analysis was not sufficiently comprehensive to detect potential issues in this area, or that the plugin's functionality does not involve data flows that would trigger taint analysis. The lack of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events, suggests a limited attack surface, but the absence of auth checks on these zero entry points is technically not a concern as there are none to check.

Overall, the plugin's security is reassuring due to its clean history and the presence of numerous security best practices. The single file operation is the primary area that warrants a closer look to ensure it is implemented securely and does not pose a hidden risk. The absence of any past vulnerabilities is a positive indicator of the developers' commitment to security, but continuous vigilance and comprehensive security auditing are always recommended.

Key Concerns

  • File operations present
Vulnerabilities
None known

ATR Cookie Notice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ATR Cookie Notice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
175 escaped
Nonce Checks
7
Capability Checks
8
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped204 total outputs
Attack Surface

ATR Cookie Notice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_initadmin\class-atr-cookie-notice-admin-settings.php:89
actionadmin_post_atr_cookie_notice_purge_cachesadmin\class-atr-cookie-notice-admin-settings.php:91
actionadmin_post_atr_cookie_notice_reset_defaultsadmin\class-atr-cookie-notice-admin-settings.php:93
actionadmin_post_atr_cookie_notice_reset_styleadmin\class-atr-cookie-notice-admin-settings.php:95
actionadmin_noticesadmin\class-atr-cookie-notice-admin.php:156
actionadmin_post_atr_cookie_notice_purge_cachesatr-cookie-notice.php:121
actionplugins_loadedincludes\class-atr-cookie-notice.php:164
actionadmin_enqueue_scriptsincludes\class-atr-cookie-notice.php:180
actionadmin_enqueue_scriptsincludes\class-atr-cookie-notice.php:181
actionadmin_enqueue_scriptsincludes\class-atr-cookie-notice.php:182
actionadmin_menuincludes\class-atr-cookie-notice.php:186
filterplugin_row_metaincludes\class-atr-cookie-notice.php:191
actionadmin_initincludes\class-atr-cookie-notice.php:194
actionadmin_initincludes\class-atr-cookie-notice.php:195
actionwp_enqueue_scriptsincludes\class-atr-cookie-notice.php:209
actionwp_enqueue_scriptsincludes\class-atr-cookie-notice.php:210
actionwp_headincludes\class-atr-cookie-notice.php:212
actionwp_footerincludes\class-atr-cookie-notice.php:213
actionwp_footerincludes\class-atr-cookie-notice.php:214
Maintenance & Trust

ATR Cookie Notice Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings12
Active installs600
Developer Profile

ATR Cookie Notice Developer Profile

yehudaT

7 plugins · 940 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ATR Cookie Notice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atr-cookie-notice/admin/css/atr-cookie-notice-admin.css/wp-content/plugins/atr-cookie-notice/admin/js/atr-cookie-notice-admin.js/wp-content/plugins/atr-cookie-notice/public/css/atr-cookie-notice-public.css/wp-content/plugins/atr-cookie-notice/public/js/atr-cookie-notice-public.js
Script Paths
/wp-content/plugins/atr-cookie-notice/admin/js/atr-cookie-notice-admin.js/wp-content/plugins/atr-cookie-notice/public/js/atr-cookie-notice-public.js
Version Parameters
atr-cookie-notice/css/atr-cookie-notice-admin.css?ver=atr-cookie-notice/js/atr-cookie-notice-admin.js?ver=atr-cookie-notice/css/atr-cookie-notice-public.css?ver=atr-cookie-notice/js/atr-cookie-notice-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
atr-cookie-notice-banneratr-cookie-notice-buttonatr-cookie-notice-settings
HTML Comments
<!-- ATR Cookie Notice by Yehuda Tiram --><!-- ATR Cookie Notice banner --><!-- ATR Cookie Notice settings -->
Data Attributes
data-atr-cookie-notice-iddata-atr-cookie-notice-style
JS Globals
atrCookieNoticeAdmin
FAQ

Frequently Asked Questions about ATR Cookie Notice