EU Cookie Law Notice/Banner Security & Risk Analysis

wordpress.org/plugins/eu-cookie-notification

EU Cookie Law Notice/Banner. Responsive and customizable position, color and text. Option to lock website. Display to EU visitors only.

80 active installs v1.1.7 PHP 7.0+ WP 3.0.1+ Updated Apr 14, 2025
cookie-noticecookie-notificationeu-cookie-laweu-cookie-notificationzotabox
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EU Cookie Law Notice/Banner Safe to Use in 2026?

Generally Safe

Score 100/100

EU Cookie Law Notice/Banner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "eu-cookie-notification" v1.1.7 plugin exhibits a generally strong security posture based on the provided static analysis. It boasts no critical or high severity taint flows, no known CVEs, and all SQL queries are properly prepared. The plugin also implements nonce checks on its entry points and avoids dangerous functions, file operations, and external HTTP requests. However, a notable area of concern is the absence of capability checks on its AJAX handlers. While the attack surface is small and these handlers have nonce checks, the lack of capability checks means that any authenticated user, regardless of their role, could potentially interact with these AJAX endpoints. Furthermore, while the majority of output is properly escaped, a third of the outputs are not, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped data originates from an untrusted source.

The vulnerability history is clean, indicating a lack of past security issues. This, combined with the positive findings in the static analysis, suggests that the developers are likely security-conscious. However, the missing capability checks and the percentage of unescaped output are weaknesses that should be addressed to further harden the plugin. The absence of capability checks on AJAX handlers is the most significant security gap, even with nonce checks present.

Key Concerns

  • AJAX handlers lack capability checks
  • Unescaped output found (33%)
Vulnerabilities
None known

EU Cookie Law Notice/Banner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EU Cookie Law Notice/Banner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_zb_cn_code (eu-cookie-notification.php:181)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EU Cookie Law Notice/Banner Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_zb_cn_codeeu-cookie-notification.php:178
noprivwp_ajax_update_zb_cn_codeeu-cookie-notification.php:179
WordPress Hooks 4
actionadmin_initeu-cookie-notification.php:15
actionadmin_noticeseu-cookie-notification.php:46
actionadmin_menueu-cookie-notification.php:82
actionwp_headeu-cookie-notification.php:175
Maintenance & Trust

EU Cookie Law Notice/Banner Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 14, 2025
PHP min version7.0
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

EU Cookie Law Notice/Banner Developer Profile

Zotabox

12 plugins · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1712 days
View full developer profile
Detection Fingerprints

How We Detect EU Cookie Law Notice/Banner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eu-cookie-notification/assets/css/style.css/wp-content/plugins/eu-cookie-notification/assets/js/main.js
Script Paths
/wp-content/plugins/eu-cookie-notification/assets/js/main.js
Version Parameters
eu-cookie-notification/style.css?ver=eu-cookie-notification/main.js?v=

HTML / DOM Fingerprints

CSS Classes
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-title
Data Attributes
zb-plugin="zb_cn"
JS Globals
ZBT_WP_ADMIN_URLZTB_BASE_URL
FAQ

Frequently Asked Questions about EU Cookie Law Notice/Banner