CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Security & Risk Analysis

wordpress.org/plugins/cookiehub

Take control effortlessly with CookieHub – GDPR-compliant solution for cookie management and compliance.

3K active installs v1.2.2 PHP + WP 5.2+ Updated Sep 17, 2025
ccpacookie-consentcookie-noticedsgvogdpr
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Safe to Use in 2026?

Generally Safe

Score 99/100

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 22, 2024Updated 6mo ago
Risk Assessment

The Cookiehub plugin v1.2.2 demonstrates a generally good security posture, with several positive indicators. Notably, the absence of any critical or high-severity vulnerabilities in its history, along with a complete lack of raw SQL queries and a high percentage of properly escaped output, are strong points. The plugin also correctly implements nonce checks for all its AJAX handlers, preventing a common class of vulnerabilities. However, the static analysis reveals a potential area of concern: all three analyzed taint flows resulted in unsanitized paths. While the severity is not explicitly stated as critical or high, the presence of unsanitized paths, even if not leading to direct exploitation in this version, indicates a latent risk that could be exploited with different inputs or in conjunction with other factors. Furthermore, the plugin's vulnerability history shows a past "Missing Authorization" vulnerability, and while currently patched, it highlights a potential weakness in how user permissions were handled previously. The plugin has a small attack surface, and all entry points are protected by authentication, which is a positive sign. Despite the taint flow concerns, the overall security is reasonable, but proactive code review and testing for the identified taint flows are recommended.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Past vulnerability type: Missing Authorization
  • 73% output escaping is not 100%
Vulnerabilities
1

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32784medium · 5.3Missing Authorization

CookieHub <= 1.1.0 - Missing Authorization

Apr 22, 2024 Patched in 1.1.1 (8d)
Code Analysis
Analyzed Mar 16, 2026

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
29 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

73% escaped40 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
update_domain_code (includes\ch-api.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_update_domain_codeincludes\ch-api.php:2
authwp_ajax_update_advanced_settingsincludes\ch-api.php:79
authwp_ajax_register_accountincludes\ch-api.php:107
authwp_ajax_register_domain_codeincludes\ch-api.php:147
WordPress Hooks 9
actionadmin_noticescookiehub.php:32
actionwp_enqueue_scriptscookiehub.php:55
filterwp_get_consent_typecookiehub.php:60
actionadmin_menuincludes\ch-admin.php:14
actionadmin_initincludes\ch-admin.php:15
actionadmin_footerincludes\ch-api.php:36
actionwp_headincludes\ch-generate.php:2
actionwp_footerincludes\ch-generate.php:4
actionwp_headincludes\ch-generate.php:5
Maintenance & Trust

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 17, 2025
PHP min version
Downloads55K

Community Trust

Rating100/100
Number of ratings1
Active installs3K
Developer Profile

CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) Developer Profile

CookieHub

1 plugin · 3K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookiehub/includes/js/dcc-wp-consent.js
Script Paths
/wp-content/plugins/cookiehub/includes/js/dcc-wp-consent.js/wp-content/plugins/cookiehub/js/dcchub-test.js/wp-content/plugins/cookiehub/css/dcchub-admin.css
Version Parameters
dcc-wp-consent.js?1.2.0dcchub-test.js?1.2.0dcchub-admin.css?1.2.0

HTML / DOM Fingerprints

Data Attributes
data-cookiehub-script
JS Globals
window.dcchub_ajax_object
FAQ

Frequently Asked Questions about CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance)