Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Security & Risk Analysis

wordpress.org/plugins/conzent

Easily set up cookie banner or cookie notice and cookie policy page for GDPR (DSGVO, RGPD) compliance. Also supports CCPA/CPRA and other major global …

100 active installs v1.0.12 PHP 7.3+ WP 5.8+ Updated Jun 25, 2025
ccpacookie-consentcookie-noticedsgvogdpr
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Safe to Use in 2026?

Generally Safe

Score 100/100

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "conzent" v1.0.12 plugin exhibits a generally good security posture with several positive indicators. The absence of known CVEs, unpatched vulnerabilities, and critical or high-severity taint flows is a significant strength. The code also demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and includes a nonce check. The attack surface appears minimal with no unprotected entry points identified.

However, there are areas for improvement. The static analysis reveals that 33% of output escaping is not properly handled, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped output is user-controllable. Furthermore, while only one external HTTP request is made, its security implications depend heavily on the target and how the data is handled. The taint analysis, despite no critical or high-severity flows, did identify two flows with unsanitized paths, which, while not categorized as critical in this analysis, warrants caution and further investigation for potential low-impact vulnerabilities.

In conclusion, "conzent" v1.0.12 is in a reasonably secure state, particularly regarding its low attack surface and lack of historical critical vulnerabilities. The primary concern stems from the unescaped output and the presence of unsanitized paths in taint flows, which represent potential vectors for exploitation, albeit likely of lower severity. Addressing these specific areas would further harden the plugin's security.

Key Concerns

  • 33% of output not properly escaped
  • Taint flows with unsanitized paths (2)
Vulnerabilities
None known

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
41 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

67% escaped61 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
cnz_setting_actions (conzent.php:206)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[CONZENT_CONSENT_ID] conzent.php:309
[conzent_consent_id] conzent.php:310
WordPress Hooks 10
actionwp_enqueue_scriptsconzent.php:24
actioninitconzent.php:25
actioninitconzent.php:26
actionadmin_menuconzent.php:27
actionplugins_loadedconzent.php:28
actionactivated_pluginconzent.php:29
actionadmin_enqueue_scriptsconzent.php:30
actionwp_body_openconzent.php:31
actionwp_headconzent.php:143
actionwp_headconzent.php:144
Maintenance & Trust

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 25, 2025
PHP min version7.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified Developer Profile

Conzent ApS

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/conzent/assets/css/conzent-banner.css/wp-content/plugins/conzent/assets/js/conzent-banner.js/wp-content/plugins/conzent/assets/css/conzent-banner-admin.css
Script Paths
https://conzent.net/app/sites_data/

HTML / DOM Fingerprints

CSS Classes
cnz-btncnz-btn-normalopt_welcomeopt_box_welcomeopt_itemopt_keyopt_val
Data Attributes
id='conzentbanner'data-consent='necessary'
JS Globals
_cnzWca_cnzGsk
FAQ

Frequently Asked Questions about Conzent – Cookie Banner – Conzent CMP – Google CMP & IAB TCF Certified