Cookie Law Bar Security & Risk Analysis

wordpress.org/plugins/cookie-law-bar

Cookie Law Bar show bottom or top bar to inform users that your website uses cookie according to EU law.

2K active installs v1.2.1 PHP + WP 2.8+ Updated Nov 28, 2017
consentcookiecookie-barcookie-compliancecookies
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMay 24, 2021
Safety Verdict

Is Cookie Law Bar Safe to Use in 2026?

Use With Caution

Score 64/100

Cookie Law Bar has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: May 24, 2021Updated 8yr ago
Risk Assessment

The "cookie-law-bar" plugin v1.2.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no immediately apparent major vulnerabilities related to a broad attack surface, dangerous functions, raw SQL queries, file operations, or external HTTP requests. The presence of a nonce check and a capability check, along with 100% of SQL queries using prepared statements, are good security practices. However, a significant concern arises from the output escaping, where only 38% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities that were not fully captured or mitigated by the taint analysis in this specific version.

The vulnerability history for this plugin is a notable red flag. It shows one known CVE, which is currently unpatched, and categorized as medium severity. The common vulnerability type being Cross-Site Scripting directly aligns with the concerns raised by the insufficient output escaping found during static analysis. The fact that this vulnerability is unpatched suggests a lack of ongoing maintenance and security responsiveness from the plugin developers. While the current static analysis might not directly pinpoint this specific unpatched vulnerability, its historical presence strongly suggests a persistent risk that users of this version are exposed to.

In conclusion, while the code in v1.2.1 doesn't present an extremely large or complex attack surface, the poor output escaping and the existence of an unpatched medium-severity XSS vulnerability in its history make it a moderate to high risk. Users should be aware of the potential for XSS attacks and the lack of recent security updates. The strengths lie in its limited attack vectors and use of prepared statements, but these are overshadowed by the identified security weaknesses.

Key Concerns

  • Unpatched medium severity CVE
  • Low output escaping percentage
Vulnerabilities
1

Cookie Law Bar Security Vulnerabilities

CVEs by Year

1 CVE in 2021 · unpatched
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-f65cb1f6-e72e-4848-b72c-99b83e5401e8-cookie-law-barmedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cookie Law Bar <= 1.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

May 24, 2021Unpatched
Code Analysis
Analyzed Mar 16, 2026

Cookie Law Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
12 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<cookie-law-bar-setting> (cookie-law-bar-setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cookie Law Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionactivate_cookie-law-bar/cookie-law-bar.phpcookie-law-bar.php:59
actionadmin_menucookie-law-bar.php:72
filterplugin_action_linkscookie-law-bar.php:87
actionwp_enqueue_scriptscookie-law-bar.php:101
actionwp_footercookie-law-bar.php:112
Maintenance & Trust

Cookie Law Bar Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedNov 28, 2017
PHP min version
Downloads27K

Community Trust

Rating90/100
Number of ratings4
Active installs2K
Developer Profile

Cookie Law Bar Developer Profile

richplugins

5 plugins · 114K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect Cookie Law Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookie-law-bar/static/css/cookie-law-bar.css/wp-content/plugins/cookie-law-bar/static/js/cookie-law-bar.js
Script Paths
/wp-content/plugins/cookie-law-bar/static/js/cookie-law-bar.js
Version Parameters
cookie-law-bar.js?ver=cookie-law-bar.css?ver=

HTML / DOM Fingerprints

CSS Classes
cookie-law-bar
HTML Comments
Cookie BarEnd Cookie Bar
Data Attributes
id="cookie-law-bar"id="cookie-law-btn"
FAQ

Frequently Asked Questions about Cookie Law Bar