Cookie Notify Security & Risk Analysis

wordpress.org/plugins/cookie-notify

Cookie Notification about using cookie files on Your website. Easy and fast configuration of position, view, colors, links, buttons and text content.

500 active installs v1.0.1 PHP + WP 3.3+ Updated Sep 7, 2022
ciasteczkacookiecookie-noticecookiesgdpr
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cookie Notify Safe to Use in 2026?

Generally Safe

Score 85/100

Cookie Notify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "cookie-notify" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks, is a significant strength. Furthermore, the code demonstrates good security practices with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of nonce and capability checks further reinforces its secure design. The plugin's history is also clean, with no recorded vulnerabilities, indicating a consistent effort towards maintaining security.

However, even with these positive indicators, a comprehensive risk assessment must consider the potential for undiscovered issues. The taint analysis, while reporting no critical or high severity flows, only analyzed a small number of flows. The lack of any identified attack surface entry points also means that any future introduction of such points, if not properly secured, could become immediate vulnerabilities. The plugin's strong adherence to security best practices and its unblemished vulnerability record are its primary strengths. The primary concern lies in the limited scope of the analysis, suggesting that while it's currently secure, vigilance is still required.

Vulnerabilities
None known

Cookie Notify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cookie Notify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
61 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped65 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
zp20_cnpl_update_settings (cookie-notify.php:260)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cookie Notify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initcookie-notify.php:138
actionwp_print_stylescookie-notify.php:213
actionwp_footercookie-notify.php:214
actionadmin_menucookie-notify.php:237
actionplugins_loadedcookie-notify.php:257
actioninitcookie-notify.php:258
Maintenance & Trust

Cookie Notify Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 7, 2022
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Cookie Notify Developer Profile

zp20

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cookie Notify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookie-notify/css/cookie-notify.css/wp-content/plugins/cookie-notify/js/cookie-notify.js
Script Paths
/wp-content/plugins/cookie-notify/js/cookie-notify.js
Version Parameters
cookie-notify/css/cookie-notify.css?ver=cookie-notify/js/cookie-notify.js?ver=

HTML / DOM Fingerprints

CSS Classes
cnpl-cookie-boxcnpl-cookie-box-inner
Data Attributes
data-cnpl-positiondata-cnpl-hide-effectdata-cnpl-backgrounddata-cnpl-button-textdata-cnpl-button-colordata-cnpl-button-hover-color+13 more
JS Globals
cnpl_script
FAQ

Frequently Asked Questions about Cookie Notify