WP CookieScan by code.je Security & Risk Analysis

wordpress.org/plugins/cookiescan

The CookieScan plugin is your complete cookie management system, solving all your cookie law worries in one simple installation.

0 active installs v1.0.1 PHP 7.2+ WP 5.1+ Updated Jun 7, 2021
cookiescookiescangdpr
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP CookieScan by code.je Safe to Use in 2026?

Generally Safe

Score 85/100

WP CookieScan by code.je has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The cookiescan plugin v1.0.1, based on the static analysis, exhibits an exceptionally small attack surface with zero identified entry points. This is a strong positive indicator of good security practice as it minimizes opportunities for external interaction. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests further bolsters its security posture. The plugin also utilizes prepared statements for all its SQL queries, which is a critical defense against SQL injection vulnerabilities.

However, a significant concern arises from the complete lack of output escaping. With two total outputs identified and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin without proper sanitization could be exploited by attackers. The absence of nonce and capability checks, while seemingly less critical given the zero attack surface, could become a vector for privilege escalation or unwanted actions if new entry points are introduced in future versions or if the plugin's intended functionality inadvertently exposes sensitive operations.

The plugin's vulnerability history is completely clean, with zero known CVEs. This suggests a well-maintained codebase or a plugin that has not yet been a target for extensive security research. While this is a positive sign, it should not be relied upon as a sole indicator of security, especially given the identified output escaping issue. The overall security is strong due to minimal attack surface and secure database practices, but the lack of output escaping is a notable weakness that requires immediate attention.

Key Concerns

  • 0% output escaping on 2 outputs
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP CookieScan by code.je Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP CookieScan by code.je Release Timeline

v1.0.2
v1.0.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

WP CookieScan by code.je Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

WP CookieScan by code.je Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menucookiescan.php:45
actionadmin_initcookiescan.php:119
actionwp_enqueue_scriptscookiescan.php:155
Maintenance & Trust

WP CookieScan by code.je Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 7, 2021
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP CookieScan by code.je Developer Profile

matt.chatterley

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP CookieScan by code.je

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookiescan/assets/img/cookiescan.png
Script Paths
https://www.cookiescan.com/domain/getVariableshttps://www.cookiescan.com/plugins/cookiescanplugin.js

HTML / DOM Fingerprints

HTML Comments
<!-- SETTINGS LINK --><!-- SETTINGS FORM --><!-- SETTINGS --><!-- INPUT FIELD -->+1 more
FAQ

Frequently Asked Questions about WP CookieScan by code.je