Cookie-Script.com Security & Risk Analysis

wordpress.org/plugins/cookie-script-com

Cookie-Script.com WordPress plugin.

10K active installs v1.4.3 PHP 5.6+ WP 5.6+ Updated Jan 19, 2026
complianceconsentcookiecookiescriptgdpr
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 19, 2025
Download
Safety Verdict

Is Cookie-Script.com Safe to Use in 2026?

Generally Safe

Score 99/100

Cookie-Script.com has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 19, 2025Updated 2mo ago
Risk Assessment

The cookie-script-com plugin version 1.4.3 exhibits a generally good security posture with several strong practices in place. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events indicates a well-defined and secured attack surface. The plugin also demonstrates robust code hygiene with 100% of SQL queries using prepared statements and a high percentage (97%) of output escaping, significantly reducing the risk of common web vulnerabilities like SQL injection and Cross-Site Scripting. The presence of nonce and capability checks further bolsters its security. However, two flows with unsanitized paths identified during taint analysis, while not categorized as critical or high, warrant attention as they represent potential avenues for exploitation if input validation is not consistently applied. The plugin's vulnerability history shows one past medium vulnerability, suggesting that while the developers have addressed past issues, continuous vigilance and security audits are still necessary. The current unpatched status of all past vulnerabilities is a positive indicator. Overall, the plugin is well-developed from a security standpoint, but the identified unsanitized paths suggest a need for more thorough input validation in specific areas to achieve an even stronger security posture.

Key Concerns

  • Flows with unsanitized paths identified
  • One medium vulnerability in history
Vulnerabilities
1

Cookie-Script.com Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49993medium · 5.3Missing Authorization

Cookie-Script.com <= 1.2.1 - Missing Authorization

Jun 19, 2025 Patched in 1.2.2 (13d)
Code Analysis
Analyzed Mar 16, 2026

Cookie-Script.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
172 escaped
Nonce Checks
9
Capability Checks
8
File Operations
1
External Requests
6
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

97% escaped177 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
cookie_script_save_options (cookie-script-with-plan.php:208)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cookie-Script.com Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_cookie_script_check_scan_status_callbackcookie-script-without-plan.php:50
authwp_ajax_cookie_script_save_optionscookie-script-without-plan.php:51
authwp_ajax_cookie_script_start_scancookie-script-without-plan.php:52
authwp_ajax_cookie_script_get_scanner_statuscookie-script-without-plan.php:53
authwp_ajax_cookie_script_get_update_scriptcookie-script-without-plan.php:54
WordPress Hooks 13
actionadmin_enqueue_scriptscookie-script-with-plan.php:26
actionadmin_initcookie-script-with-plan.php:39
actionadmin_enqueue_scriptscookie-script-without-plan.php:27
actionwp_headcookie-script-without-plan.php:47
actionadmin_initcookie-script-without-plan.php:48
actionadmin_menuindex.php:39
actionadmin_menuindex.php:40
actionadmin_initindex.php:41
actionadmin_enqueue_scriptsindex.php:42
actionwp_enqueue_scriptsindex.php:51
actionadmin_menuindex.php:183
actioninitupgrader.php:15
actionadmin_initutility\cswpca.php:7
Maintenance & Trust

Cookie-Script.com Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version5.6
Downloads110K

Community Trust

Rating62/100
Number of ratings14
Active installs10K
Developer Profile

Cookie-Script.com Developer Profile

csarturas

1 plugin · 10K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Cookie-Script.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookie-script-com/assets/js/cookie_script_api.js/wp-content/plugins/cookie-script-com/assets/css/cookie_script_admin.css
Script Paths
https://cookie-script.com/script.js
Version Parameters
cookie-script-com/assets/js/cookie_script_api.js?ver=1.4.1cookie-script-com/assets/css/cookie_script_admin.css?ver=1.4.1

HTML / DOM Fingerprints

JS Globals
wpConsentData
FAQ

Frequently Asked Questions about Cookie-Script.com