CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Security & Risk Analysis

wordpress.org/plugins/cookiepilot

Affordable Cookiebot alternative — 29 PLN/month, unlimited subpages, full GDPR & Google Consent Mode v2. Polish support included.

0 active installs v1.0.0 PHP 8.0+ WP 6.0+ Updated Mar 10, 2026
cookie-bannercookie-consentcookiebot-alternativegdprgoogle-consent-mode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Safe to Use in 2026?

Generally Safe

Score 100/100

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The cookiepilot plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, use of prepared statements for all SQL queries, and proper output escaping are significant strengths. Furthermore, the plugin's attack surface is well-protected, with all REST API routes implementing permission callbacks. The lack of any recorded vulnerabilities, including critical or high severity ones, further reinforces this positive outlook. The plugin also avoids bundled libraries, which can often be a source of outdated and vulnerable code.

However, there are a couple of areas that warrant attention, although they do not immediately indicate critical flaws. The presence of external HTTP requests without explicit mention of security considerations could potentially lead to issues if the external services are compromised or if data is transmitted insecurely. More importantly, the absence of nonce checks on AJAX handlers is a notable omission. While there are no AJAX handlers without authentication checks in this analysis, nonce checks are a crucial layer of defense against Cross-Site Request Forgery (CSRF) attacks for any AJAX functionality, even when authenticated. The single capability check, while present, might be insufficient depending on the actions performed by the plugin. Overall, cookiepilot v1.0.0 appears to be a securely coded plugin with a clean history, but the lack of nonce checks on AJAX and potential considerations for external HTTP requests represent minor areas for improvement in its security hardening.

Key Concerns

  • No nonce checks on AJAX handlers
  • External HTTP requests present
Vulnerabilities
None known

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Attack Surface

Entry Points16
Unprotected0

REST API Routes 16

GET/wp-json/cookiepilot/v1/settingsincludes\class-admin.php:105
POST/wp-json/cookiepilot/v1/loginincludes\class-admin.php:112
POST/wp-json/cookiepilot/v1/registerincludes\class-admin.php:119
POST/wp-json/cookiepilot/v1/logoutincludes\class-admin.php:126
POST/wp-json/cookiepilot/v1/activate-tokenincludes\class-admin.php:133
POST/wp-json/cookiepilot/v1/domainsincludes\class-admin.php:140
GET/wp-json/cookiepilot/v1/domains/(?P<id>[a-zA-Z0-9-]+)includes\class-admin.php:147
PUT/wp-json/cookiepilot/v1/domains/(?P<id>[a-zA-Z0-9-]+)/configincludes\class-admin.php:154
GET/wp-json/cookiepilot/v1/billing/subscriptionincludes\class-admin.php:161
POST/wp-json/cookiepilot/v1/billing/checkoutincludes\class-admin.php:168
POST/wp-json/cookiepilot/v1/billing/portalincludes\class-admin.php:175
POST/wp-json/cookiepilot/v1/save-settingsincludes\class-admin.php:182
POST/wp-json/cookiepilot/v1/verify-emailincludes\class-admin.php:189
POST/wp-json/cookiepilot/v1/resend-verificationincludes\class-admin.php:196
GET/wp-json/cookiepilot/v1/agency/domainincludes\class-admin.php:203
PUT/wp-json/cookiepilot/v1/agency/domain/configincludes\class-admin.php:209
WordPress Hooks 5
actionplugins_loadedcookiepilot.php:40
actionadmin_menuincludes\class-admin.php:25
actionadmin_enqueue_scriptsincludes\class-admin.php:26
actionrest_api_initincludes\class-admin.php:30
actionwp_enqueue_scriptsincludes\class-frontend.php:18
Maintenance & Trust

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version8.0
Downloads130

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative Developer Profile

mlemiesz

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookiepilot/admin/css/admin.css
Script Paths
/wp-content/plugins/cookiepilot/admin/js/admin.js
Version Parameters
cookiepilot/admin/css/admin.css?ver=cookiepilot/admin/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
cookiepilotAdmin
REST Endpoints
/wp-json/cookiepilot/v1/settings/wp-json/cookiepilot/v1/login/wp-json/cookiepilot/v1/register/wp-json/cookiepilot/v1/logout/wp-json/cookiepilot/v1/activate-token/wp-json/cookiepilot/v1/domains/wp-json/cookiepilot/v1/domains/(?P<id>[a-zA-Z0-9-]+)/wp-json/cookiepilot/v1/domains/(?P<id>[a-zA-Z0-9-]+)/config/wp-json/cookiepilot/v1/billing/subscription/wp-json/cookiepilot/v1/billing/checkout/wp-json/cookiepilot/v1/billing/portal/wp-json/cookiepilot/v1/save-settings
FAQ

Frequently Asked Questions about CookiePilot – Cookie Consent & GDPR | Cookiebot Alternative