eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Security & Risk Analysis

wordpress.org/plugins/ecookies-by-hostriver

Quickly activate Google Consent Mode v2 to ensure GDPR compliance for your site, also compatible with PixelYourSite plugin

30 active installs v1.0 PHP 7.4+ WP 5.8+ Updated Jan 6, 2025
cookie-bannercookie-consentcookie-noticegdprgoogle-consent-mode-v2
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Safe to Use in 2026?

Generally Safe

Score 92/100

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "ecookies-by-hostriver" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The plugin effectively utilizes prepared statements for all SQL queries and demonstrates excellent output escaping practices, with 97% of outputs properly escaped. The presence of nonce checks on all identified entry points (AJAX handlers) further contributes to a secure foundation, preventing common cross-site request forgery attacks. The complete absence of known CVEs and vulnerabilities in its history is a significant positive indicator of the developer's commitment to security.

However, a notable area for improvement lies in the lack of capability checks. While nonce checks protect against unauthorized actions, capability checks are crucial for ensuring that only users with the appropriate permissions can access and interact with the plugin's functionalities. The absence of these checks, combined with the presence of AJAX handlers, could potentially expose sensitive actions or data to authenticated users who do not have the necessary privileges. The plugin's attack surface is small and currently appears protected, but the absence of capability checks represents a potential oversight that could be exploited in certain scenarios, albeit with a lower likelihood given the other security measures in place.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
60 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped62 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ecookies_hostriver_save_disable_page_interaction_option (custom-cookie-consent.php:179)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_handle_ajax_requestincludes\cookies-dashboard.php:584
noprivwp_ajax_handle_ajax_requestincludes\cookies-dashboard.php:587
WordPress Hooks 18
actionadmin_menucustom-cookie-consent.php:24
actionadmin_initcustom-cookie-consent.php:38
actionwp_headcustom-cookie-consent.php:131
actionwp_footercustom-cookie-consent.php:135
actionwp_enqueue_scriptscustom-cookie-consent.php:147
actionwp_enqueue_scriptscustom-cookie-consent.php:175
actionadmin_initcustom-cookie-consent.php:177
actionwp_footercustom-cookie-consent.php:238
actionadmin_enqueue_scriptsincludes\cookies-dashboard.php:14
actionadmin_enqueue_scriptsincludes\cookies-dashboard.php:499
actionadmin_enqueue_scriptsincludes\cookies-dashboard.php:512
filterpys_disable_all_cookieincludes\cookies-dashboard.php:591
filterpys_disable_facebook_by_gdprincludes\cookies-dashboard.php:595
filterpys_disable_google_ads_by_gdprincludes\cookies-dashboard.php:596
filterpys_disable_pinterest_by_gdprincludes\cookies-dashboard.php:597
filterpys_disable_bing_by_gdprincludes\cookies-dashboard.php:598
filterpys_disable_analytics_by_gdprincludes\cookies-dashboard.php:599
filterpys_gdpr_ajax_enabledincludes\cookies-dashboard.php:600
Maintenance & Trust

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJan 6, 2025
PHP min version7.4
Downloads821

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration Developer Profile

flaviubutean

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecookies-by-hostriver/includes/cookieconsent.js/wp-content/plugins/ecookies-by-hostriver/includes/modal-options.js/wp-content/plugins/ecookies-by-hostriver/includes/cookieconsent.css
Script Paths
/wp-content/plugins/ecookies-by-hostriver/includes/cookieconsent.js/wp-content/plugins/ecookies-by-hostriver/includes/modal-options.js
Version Parameters
ecookies-by-hostriver/includes/cookieconsent.js?ver=1.0.0ecookies-by-hostriver/includes/modal-options.js?ver=1.0.0ecookies-by-hostriver/includes/cookieconsent.css?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
cookieconsent_vars
FAQ

Frequently Asked Questions about eCookies by HostRiver – Google Consent Mode v2 and GDPR Cookie Banner Integration