CookieTrust Security & Risk Analysis

wordpress.org/plugins/cookietrust

Cookie consent management powered by CookieTrust.io - GDPR & CCPA compliant cookie banner for WordPress.

0 active installs v1.1.0 PHP 7.4+ WP 5.8+ Updated Feb 17, 2026
ccpacompliancecookie-consentgdprprivacy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CookieTrust Safe to Use in 2026?

Generally Safe

Score 100/100

CookieTrust has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "cookietrust" v1.1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The absence of known CVEs and historical vulnerabilities is also a significant strength, suggesting a generally well-maintained and secure codebase.

However, the analysis reveals a critical concern: an unprotected AJAX handler. This unprotected entry point represents a direct attack vector. Furthermore, the taint analysis indicates two flows with unsanitized paths, specifically flagged as high severity. While these might not have manifested as public CVEs, they represent potential vulnerabilities that could be exploited, especially when combined with the unprotected AJAX endpoint.

In conclusion, while "cookietrust" v1.1.0 benefits from good general coding hygiene and a clean vulnerability history, the presence of an unprotected AJAX handler and high-severity unsanitized taint flows introduces significant risk. These are areas that require immediate attention and remediation to ensure the plugin's security.

Key Concerns

  • Unprotected AJAX handler
  • High severity unsanitized taint flows
Vulnerabilities
None known

CookieTrust Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CookieTrust Release Timeline

v1.1.0Current
v1.0.4
v1.0.2
Code Analysis
Analyzed Mar 17, 2026

CookieTrust Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
12 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped12 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle (includes\Controllers\OAuth\CallbackController.php:59)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

CookieTrust Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_cookietrust_oauth_callbackplugin.php:82
WordPress Hooks 9
actionplugins_loadedcookietrust.php:39
actionadmin_menuincludes\Admin\Menu.php:37
actionadmin_enqueue_scriptsincludes\Assets\Admin.php:55
actionwp_enqueue_scriptsincludes\Assets\Frontend.php:56
actionwp_enqueue_scriptsincludes\Assets\Frontend.php:59
filtertheme_page_templatesincludes\Core\Template.php:35
filtertemplate_includeincludes\Core\Template.php:36
filterwp_get_consent_typeincludes\Services\WPConsentAPIService.php:51
actionwp_enqueue_scriptsviews\templates\frontend-template.php:49
Maintenance & Trust

CookieTrust Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads242

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CookieTrust Developer Profile

cookietrust

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CookieTrust

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cookietrust/assets/frontend/dist/src/frontend/main.jsx
Script Paths
https://cmp.cookietrust.io/gdpr/autoblocker.umd.js

HTML / DOM Fingerprints

CSS Classes
cookietrust-app
JS Globals
cookieTrustFrontend
FAQ

Frequently Asked Questions about CookieTrust