EU Cookie Law Compliance Security & Risk Analysis

wordpress.org/plugins/eu-cookie-law-compliance

Elegant and responsive EU Cookie Law Compliance.

2K active installs v1.0.3 PHP + WP 3.8+ Updated Apr 27, 2019
cookie-barcookie-categoriescookie-compliancecookie-consentcookie-law
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EU Cookie Law Compliance Safe to Use in 2026?

Generally Safe

Score 85/100

EU Cookie Law Compliance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'eu-cookie-law-compliance' plugin v1.0.3 presents a mixed security posture. On the positive side, the plugin exhibits strong adherence to modern WordPress development practices. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, all SQL queries are prepared statements, and there are no file operations or external HTTP requests, which are excellent indicators of secure coding. The presence of a nonce check is also a good sign. However, a significant concern arises from the use of the deprecated `create_function` function, which is considered a dangerous practice and can lead to security vulnerabilities if not handled with extreme care. Additionally, the output escaping is only 32% proper, indicating a high potential for cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is a strength, suggesting a historically stable plugin, but this does not negate the risks identified in the static analysis. Overall, while the plugin has a small attack surface and good SQL handling, the use of dangerous functions and poor output escaping requires immediate attention.

Key Concerns

  • Use of dangerous function create_function
  • Low percentage of properly escaped output
Vulnerabilities
None known

EU Cookie Law Compliance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EU Cookie Law Compliance Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
63
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function( '', 'echo "' . str_replace( '"', '\"', $section[ 'desc' ] ) . '";' )includes\admin\settings\class-settings-api.php:144

Output Escaping

32% escaped92 total outputs
Attack Surface

EU Cookie Law Compliance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_menuincludes\admin\admin-menus.php:15
actionadmin_enqueue_scriptsincludes\admin\settings\class-settings-api.php:60
actionadmin_initincludes\admin\settings\class-settings.php:41
filtermce_buttonsincludes\admin\settings\class-settings.php:377
filtermce_buttons_2includes\admin\settings\class-settings.php:378
actionadmin_initincludes\admin\settings\class-settings.php:415
actionadmin_headincludes\admin\settings\class-settings.php:431
actionadmin_headincludes\admin\settings\class-settings.php:472
actionwp_headincludes\class-model.php:125
actionwp_footerincludes\class-model.php:127
actionafter_setup_themeincludes\functions.php:49
actionwp_enqueue_scriptsincludes\functions.php:102
actionadmin_initincludes\install.php:19
actionadmin_initinstall.php:19
actionadmin_noticestplis-cookies.php:97
actionadmin_inittplis-cookies.php:145
actioninittplis-cookies.php:182
Maintenance & Trust

EU Cookie Law Compliance Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 27, 2019
PHP min version
Downloads24K

Community Trust

Rating96/100
Number of ratings9
Active installs2K
Developer Profile

EU Cookie Law Compliance Developer Profile

Damian Góra

4 plugins · 111K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
282 days
View full developer profile
Detection Fingerprints

How We Detect EU Cookie Law Compliance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eu-cookie-law-compliance/assets/css/admin-style.css
Version Parameters
eu-cookie-law-compliance/assets/css/admin-style.css?ver=tplis-cookies?ver=

HTML / DOM Fingerprints

CSS Classes
tplis-cl-admin-style
HTML Comments
TP Cookies - EU Cookie Law ComplianceA simple way to show the Cookie Compliance with UK, Dutch and EU laws. Relevant and universal banner informs visitors about the acceptance of cookies.
Data Attributes
data-tplis-cl-event
JS Globals
TPLIS_CL_VERSIONTPLIS_CL_NAMETPLIS_CL_FILETPLIS_CL_DIRTPLIS_CL_URLTPLIS_CL_DOMAIN+4 more
FAQ

Frequently Asked Questions about EU Cookie Law Compliance