[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYZWKO4OzlrkoJBZ5cAoSocIWBm3bvvw_XIFP1eYzw-Q":3,"$fyQH5CDgMgEV-GCxxRQVD3WQGRPlZRIhUy2COdlQo_dI":247,"$flDr7jNJ9RyE_JQGU5rUoGkYMCOItHVAOMVMhU-arwmY":252},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":22,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":36,"analysis":137,"fingerprints":207},"free-ccpa-cookie","Free CCPA Cookie","1.0","uniqcoder","https:\u002F\u002Fprofiles.wordpress.org\u002Fmerajali294\u002F","\u003Cp>Free CCPA Cookie provides a simple, customizable website notice banner that can be used to help your website comply with certain cookie consent requirements under the CCPA regulations. You can display Cookie notice to the users accessing website from California using this free plugin.\u003Cbr \u002F>\nI’m using IP Geolocation API to simply obtain the Location so that I can display the CCPA only for California users. I use https:\u002F\u002Fip-api.com\u002F\u003C\u002Fp>\n\u003Ch4>NOTICE FEATURES INCLUDE:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Customizable notice message.\u003C\u002Fli>\n\u003Cli>Customizable Accept\u002FDecline message.\u003C\u002Fli>\n\u003Cli>Consent on click\u003C\u002Fli>\n\u003Cli>cookie expiry options\u003C\u002Fli>\n\u003Cli>Link to Privacy Policy page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How to Use?\u003C\u002Fh3>\n\u003Col>\n\u003Cli>One Step Setup to get up and running, Just Go to \u003Ccode>WP-Admin -> Settings -> CCPA For WP\u003C\u002Fcode> to configure the plugin.\u003C\u002Fli>\n\u003Cli>Simply edit the Text Fields to add your Customizable notice message else can you by default text as well.\u003C\u002Fli>\n\u003C\u002Fol>\n","Free CCPA Cookie provides a simple, customizable website notice banner that can be used to help your website comply with certain cookie consent requir &hellip;",0,1008,"2021-03-17T16:33:00.000Z","5.7.15","3.0","",[18,19,20,21],"ccpa","compliance","consent","cookies","https:\u002F\u002Fgraspers.000webhostapp.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffree-ccpa-cookie.1.0.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":32,"avg_security_score":24,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"merajali294",3,10,30,84,"2026-08-28T23:46:33.079Z",[37,60,78,96,118],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":56,"download_link":57,"security_score":47,"vuln_count":58,"unpatched_count":11,"last_vuln_date":59,"fetched_at":26},"cookie-notice","Compliance by Hu-manity.co","3.1.4","Humanityco","https:\u002F\u002Fprofiles.wordpress.org\u002Fhumanityco\u002F","\u003Cp>\u003Cstrong>Compliance by Hu-manity.co\u003C\u002Fstrong> (formerly known as Cookie Notice) provides a simple, customizable website banner that can be used to help your website comply with cookie consent requirements under the EU GDPR, CCPA, and other data privacy laws — with \u003Cstrong>seamless integration\u003C\u002Fstrong> with Cookie Compliance to help your site comply with the latest updates to existing consent laws.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cookie Compliance\u003C\u002Fstrong> is a fully featured Consent Management Platform (CMP) that provides automated compliance features and enhanced design controls in a state-of-the-art web application. Cookie Compliance enables websites to \u003Cstrong>take a proactive approach to data protection and consent laws\u003C\u002Fstrong>. It is the first solution to offer Intentional Consent, a new consent framework that incorporates the latest guidelines from over 100+ countries, and emerging standards from leading international organizations like the IEEE and European Center for Digital Rights (noyb.eu). Cookie Compliance provides a beautiful, multi-level experience and includes new choices and controls for site visitors to better understand and engage in data privacy decisions.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>Our Cookie Compliance web application introduces a more ethical, proactive way to capture and manage consent.  This early version of the emerging Intentional Consent framework is a result of Hu-manity.co’s ongoing work with top Fortune 500 companies, governments, and standards organizations, who believe that the imbalanced relationship between consumers and corporations is unsustainable when it comes to data privacy and consent online. We are making it available for all website owners and operators who share this belief and support our mission to eliminate the dark patterns in online consent.\u003Cbr \u002F>\n  Matt Sinderbrand – Chief Platform Officer, Hu-manity.co\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Compliance (plugin only)\u003C\u002Fh3>\n\u003Cp>Compliance by Hu-manity.co provides a simple, customizable website banner to help your website comply with certain cookie consent requirements.\u003C\u002Fp>\n\u003Ch4>Banner features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Customizable notice message\u003C\u002Fli>\n\u003Cli>Consent on click, scroll or close\u003C\u002Fli>\n\u003Cli>Multiple cookie expiry options\u003C\u002Fli>\n\u003Cli>Link to Privacy Policy page\u003C\u002Fli>\n\u003Cli>WordPress Privacy Policy page synchronization\u003C\u002Fli>\n\u003Cli>WPML and Polylang compatible\u003C\u002Fli>\n\u003Cli>SEO friendly\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Cookie Compliance (plugin + web application)\u003C\u002Fh3>\n\u003Cp>Cookie Compliance gives you access to the most up-to-date formatting guidelines and technical compliance requirements for over 100 countries and legal jurisdictions.\u003C\u002Fp>\n\u003Ch4>Banner features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Intentional Consent\u003C\u002Fstrong> provides 3 equal buttons to give site visitors the ability to accept none, some, or all cookies through packaged choices called Data Access Levels. Data Access Levels improve consent conversion and eliminate the dark pattern of deceptive, non-equal choices in the first layer. \u003Cem>Complies with equal choice principle prescribed under GDPR and other data protection laws.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent duration selector\u003C\u002Fstrong> gives visitor control over how long their consent remains valid for your site.  \u003Cem>Enables your site to align with recent guidelines from EU Data Protection Authorities, which state that cookie consent should be valid for no longer than a period of 6 months.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cookie purpose categories\u003C\u002Fstrong> make it easy for website visitors to customize their consent by category. \u003Cem>Complies with affirmative, opt-in consent requirements prescribed under GDPR and other data protection laws.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent metrics\u003C\u002Fstrong> displays the visitor’s consent record and a list of blocked \u002F allowed 3rd parties directly in the expanded level of the banner. \u003Cem>Complies with latest guidance from EU Data Protection Authorities like CNIL (France) and ICO (UK). \u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Privacy Paper\u003C\u002Fstrong> provides helpful information to improve visitor comprehension and understanding of the data sharing risks and benefits. Allows you to summarize core components of your sites privacy notice and \u003Cem>aligns with the informed principle prescribed by GDPR rules for valid consent capture. \u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Privacy Contact\u003C\u002Fstrong> allows you to provide contact information for a business’ data privacy admin, as well as helpful links to data subject request forms and other data privacy resources. \u003Cem>Aligns with the informed principle prescribed by GDPR rules for valid consent capture.\u003C\u002Fem>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Web Application features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Consent analytics dashboard\u003C\u002Fstrong> shows event data for number of visits and provides a “trust score” to help you track how site visitors are setting their consent. Make adjustments to your banner to improve your cookie acceptance rate and monitor progress via the consent activity graph.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Default configurations\u003C\u002Fstrong> for GDPR, CCPA and more help to remove dark patterns and allow for quick and easy deployment of the consent banner without any guesswork. Customize the design of any default configuration to match the look and feel of your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic script blocking\u003C\u002Fstrong> blocks all non-essential cookie scripts and iFrames by default and \u003Cem>complies with valid consent rules under GDPR and other data protection laws\u003C\u002Fem>; in order to be compliant, your site must record visitor consent before setting or sending cookies.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Consent Mode\u003C\u002Fstrong> ensures that your website can still gather valuable insights and perform effectively while respecting users’ privacy preferences by \u003Cem>dynamically adjusting the behavior of Google services according to user consent.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Facebook Consent Mode\u003C\u002Fstrong> allows your website to \u003Cem>measure the impact of your ads on Facebook\u003C\u002Fem>, track website activities and conversions and automatically deliver ads to Facebook if the user has agreed to.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent record storage\u003C\u002Fstrong> automatically stores a record of each consent and makes these records available for export. \u003Cem>Complies with proof-of-consent requirements prescribed under GDPR and other data protection laws.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual support\u003C\u002Fstrong> automatically translates all banner text strings and allows you to provide custom translations for every text field to ensure visitors get a consistent consent experience.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multidomain management\u003C\u002Fstrong> allows you to manage additional Free or Professional domains under a single account and enables you to customize banner configuration and design for each domain independently.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Cookie Compliance proactive approach:\u003C\u002Fh4>\n\u003Cp>For all businesses, the resources required to stay ahead of the latest regulations increases with the passage of each new law. With enforcement of compliance violations increasing daily, we believe it is critical for us as a trusted consent vendor to do everything in our power to help you stay ahead of these laws and remove the risk to your business\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cookie Compliance covers all current and upcoming regulations:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>GDPR (EU)\u003C\u002Fli>\n\u003Cli>ePrivacy Directive (EU)\u003C\u002Fli>\n\u003Cli>ePrivacy Regulation (EU)\u003C\u002Fli>\n\u003Cli>PECR (UK)\u003C\u002Fli>\n\u003Cli>LGPD (Brazil)\u003C\u002Fli>\n\u003Cli>PIPEDA (Canada)\u003C\u002Fli>\n\u003Cli>PDPB (India)\u003C\u002Fli>\n\u003Cli>CCPA (California, US)\u003C\u002Fli>\n\u003Cli>VCDPA (Virginia, US)\u003C\u002Fli>\n\u003Cli>Colorado Privacy Act (US)\u003C\u002Fli>\n\u003Cli>CPRA (California, US)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Cookie Compliance incorporates all recent formatting guidance:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>European Data Protection Supervisor (EDPS)\u003C\u002Fli>\n\u003Cli>ICO (United Kingdom)\u003C\u002Fli>\n\u003Cli>CNIL (France)\u003C\u002Fli>\n\u003Cli>GPDP (Italy)\u003C\u002Fli>\n\u003Cli>BfDl (Germany)\u003C\u002Fli>\n\u003Cli>AEPD (Spain)\u003C\u002Fli>\n\u003Cli>European Center for Digital Rights (noyb.eu)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Cookie Compliance targets dark patterns\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Dark Patterns are user interface (UI) techniques that push site visitors to make decisions (such as agreeing to the installation of cookies on their devices) that they might not otherwise make. The most common Dark Pattern is the lack of an equal “reject all” button on the first layer of the consent notice. Dark Patterns are explicitly banned under GDPR and other data protection laws.\u003C\u002Fp>\n\u003Cp>As a part of our proactive approach, Cookie Compliance is configured by default to prevent Dark Patterns through our unique Intentional Consent design.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>Compliance by Hu-manity.co is a Consent Management Platform client. Depending on how you use it, the plugin may send data to Hu-manity.co services on your behalf. This section describes what data leaves your WordPress server and when. It is kept up to date as the plugin evolves; material changes are noted in the changelog.\u003C\u002Fp>\n\u003Ch4>Plugin-only mode (Banner Only \u002F Basic)\u003C\u002Fh4>\n\u003Cp>If you install the plugin and choose “Banner Only” in the Welcome screen — or never open the Welcome screen at all — the plugin operates entirely on your WordPress site. No account is created and the plugin does not initiate calls to Hu-manity.co services.\u003C\u002Fp>\n\u003Ch4>Connected mode (Free or Professional)\u003C\u002Fh4>\n\u003Cp>If you create a Cookie Compliance account from the Welcome screen (or log into an existing one), the plugin connects your site to the Hu-manity.co platform. While connected, the plugin sends data over HTTPS to Hu-manity.co’s platform services (hosted under \u003Ccode>*-api.hu-manity.co\u003C\u002Fcode>) for the following purposes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Account sign-up and sign-in, and registering your site as an application.\u003C\u002Fli>\n\u003Cli>Fetching and updating your banner configuration.\u003C\u002Fli>\n\u003Cli>Fetching consent analytics and individual consent records shown in the Audit Trail.\u003C\u002Fli>\n\u003Cli>Processing subscription payments (Professional plans only).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The data sent depends on the feature you are using and typically includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Account-identifying data\u003C\u002Fstrong> such as the email address and password used for sign-up or sign-in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site-identifying data\u003C\u002Fstrong> such as your site’s URL, title, description, and language.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Application credentials\u003C\u002Fstrong> (App ID and Secret Key) issued to your site at registration, included with subsequent platform requests.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Subscription and billing data\u003C\u002Fstrong> for Professional plans, such as the selected plan identifier and a one-time payment token described below.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Integration telemetry\u003C\u002Fstrong> such as the plugin version and which admin interface (React or Legacy) you are using, sent as HTTP headers so we can understand integration adoption and support the plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Operational metadata\u003C\u002Fstrong> such as the timestamp and locale of a request, as is normal for HTTPS API calls.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>As the plugin evolves, additional non-personal fields of the same categories listed above may be sent to support new features. Material changes are noted in the changelog.\u003C\u002Fp>\n\u003Ch4>Payments (Professional plans only)\u003C\u002Fh4>\n\u003Cp>Payment card details are collected by Braintree’s hosted-fields SDK running in your browser and are tokenized there. The plugin and Hu-manity.co servers do not receive raw card data. A one-time, non-replayable Braintree token is sent to Hu-manity.co’s platform to create the subscription.\u003C\u002Fp>\n\u003Ch4>Deactivation feedback\u003C\u002Fh4>\n\u003Cp>If you deactivate the plugin and fill in the optional deactivation feedback form, the reason you select, any free-text comment you type, and your site URL are sent once to Hu-manity.co so we can improve the product. Submitting the form is optional; clicking “Skip” sends nothing. This applies to both Plugin-only and Connected modes.\u003C\u002Fp>\n\u003Ch4>The banner shown to your site visitors\u003C\u002Fh4>\n\u003Cp>The consent banner shown to your site visitors is served from \u003Ccode>cdn.hu-manity.co\u002Fhu-banner.min.js\u003C\u002Fcode>. When a visitor interacts with the banner, the banner script (running in the visitor’s browser, not the plugin) communicates directly with Hu-manity.co services to record the consent decision — this is what makes consent records available to you in the Audit Trail. This data flow is between the visitor’s browser and Hu-manity.co and does not pass through your WordPress server. Because these requests originate in the visitor’s browser, the visitor’s IP address is visible to Hu-manity.co as part of standard HTTPS network handling.\u003C\u002Fp>\n\u003Ch4>Local state set by the plugin\u003C\u002Fh4>\n\u003Cp>The plugin stores operational state in three places. None of this is transmitted to Hu-manity.co:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>On your WordPress server (options and transients)\u003C\u002Fstrong> — for example, a welcome-modal dismissal timestamp (\u003Ccode>cookie_notice_welcome_dismissed\u003C\u002Fcode>) and short-lived caches of API tokens and configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>In the admin user’s browser (localStorage)\u003C\u002Fstrong> — for example, first-run setup flags such as \u003Ccode>cn_setup_wizard_complete_*\u003C\u002Fcode> and \u003Ccode>cn_has_platform_config_*\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>In visitor browsers (a short-lived \u003Ccode>hu-form\u003C\u002Fcode> cookie, 5 minutes)\u003C\u002Fstrong> — set when forms with consent integration are submitted. Used locally by the form-consent flow.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>As the plugin evolves, additional keys may be stored in any of these locations. They remain local state on your site or in the user’s browser — not data sent to Hu-manity.co. Material changes to this pattern would be noted in the changelog.\u003C\u002Fp>\n\u003Ch4>Data the plugin does not send\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The plugin does not transmit visitor IP addresses, cookies, page URLs, or page content as data fields. IP addresses are, as with any HTTPS request, visible to the receiving server as part of standard network handling.\u003C\u002Fli>\n\u003Cli>The plugin does not transmit the content of your posts, pages, users, or WordPress database.\u003C\u002Fli>\n\u003Cli>The plugin does not send data to third parties other than Hu-manity.co and, for Professional plan payments, Braintree (a PayPal service).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Service providers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Hu-manity.co \u002F Cookie Compliance — primary service provider.\n\u003Cul>\n\u003Cli>Terms of Service: https:\u002F\u002Fcookie-compliance.co\u002Fterms-of-service\u002F\u003C\u002Fli>\n\u003Cli>Privacy contact: https:\u002F\u002Fcookie-compliance.co\u002Fdocumentation\u002Fprivacy-contact\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Braintree (a PayPal service) — processes Professional plan signups initiated from the plugin (not invoked for Basic or Free).\u003C\u002Fli>\n\u003Cli>When you manage your subscription from the Cookie Compliance web application, additional payment gateway providers may process your billing information.\u003C\u002Fli>\n\u003Cli>Hu-manity.co’s email subscription service — receives your account email address and name to manage newsletter and operational email preferences. You can unsubscribe at any time via the email footer or by deleting your account.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Account and consent data is processed in the European Union (AWS Ireland region). Hu-manity.co’s public marketing websites (hu-manity.co, cookie-compliance.co) are hosted separately in the United States.\u003C\u002Fp>\n\u003Ch4>How long we retain your data\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Plugin-side caches on your WordPress server (API tokens, subscription data, configuration) are short-lived, with TTLs typically up to 24 hours. The visitor \u003Ccode>hu-form\u003C\u002Fcode> cookie expires after 5 minutes.\u003C\u002Fli>\n\u003Cli>On the Hu-manity.co platform, account information and consent records are retained as long as your Cookie Compliance account is active, and are removed when the account is deleted or via an erasure request.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What rights you have over your data\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Stop further sends.\u003C\u002Fstrong> Deactivate the plugin from the Plugins screen — no further plugin-initiated API calls will be made.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export consent records.\u003C\u002Fstrong> Site owners can export cookie-consent and privacy-consent logs as CSV from the Cookie Compliance web application.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delete your account and all associated data.\u003C\u002Fstrong> The Cookie Compliance web application has an account-deletion flow. Triggering it cancels active subscriptions, deletes your apps and banner configuration, removes your consent records from the platform, and nullifies free-text personal data before deleting the account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Erasure of visitor data (GDPR Article 17 \u002F CCPA Delete).\u003C\u002Fstrong> To request erasure of a specific visitor’s records (by email, session ID, IP, or consent ID), contact Hu-manity.co via the privacy contact page above. Hu-manity.co processes the request and erases the matching records from its storage systems within 30 days, in line with GDPR Article 12.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manage consent (visitors).\u003C\u002Fstrong> Site visitors can adjust their consent at any time through the consent banner.\u003C\u002Fli>\n\u003C\u002Ful>\n","Intentional Consent for WordPress — GDPR, CCPA, CPRA & ePrivacy compliance with consent records, autoblocking, Google Consent Mode v2 & GPC support.",900000,40380361,96,3024,"2026-07-21T14:02:00.000Z","7.0.2","4.9.6","7.4",[18,20,21,54,55],"gdpr","privacy","https:\u002F\u002Fcookie-compliance.co\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcookie-notice.3.1.4.zip",6,"2025-11-21 16:28:14",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":70,"num_ratings":71,"last_updated":72,"tested_up_to":50,"requires_at_least":73,"requires_php":52,"tags":74,"homepage":76,"download_link":77,"security_score":70,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"wp-consent-api","WP Consent API","2.0.1","Rogier Lankhorst","https:\u002F\u002Fprofiles.wordpress.org\u002Frogierlankhorst\u002F","\u003Cp>WP Consent API is a plugin that standardizes the communication of accepted consent categories between plugins. It requires a cookie banner plugin and, at least, one other plugin that supports the WP Consent API.\u003C\u002Fp>\n\u003Cp>With this plugin, all supporting plugins can use the same set of methods to read and register the current consent category, allowing consent management plugins and other plugins to work together, improving compliance with privacy laws.\u003C\u002Fp>\n\u003Cp>WARNING: the plugin itself will not handle consent. It will show you how many plugins you have without Consent API support and will improve compliance on your site by ensuring smooth communication between cookie banner plugins and plugins that set cookies or track user data.\u003C\u002Fp>\n\u003Ch4>What problem does this plugin solve?\u003C\u002Fh4>\n\u003Cp>Currently, it is possible for a consent management plugin to block third-party services like Facebook, Google Maps, Twitter, etc. But if a WordPress plugin places a PHP cookie, a consent management plugin cannot prevent this.\u003C\u002Fp>\n\u003Cp>Secondly, some plugins integrate the tracking code on the clientside in javascript files that, when blocked, break the site.\u003C\u002Fp>\n\u003Cp>Or, if such a plugin’s javascript is minified, causing the URL to be unrecognizable and won’t get detected by an automatic blocking script.\u003C\u002Fp>\n\u003Cp>Lastly, the blocking approach requires a list of all types of URL’s that tracks data. A generic API where plugins adhere to can greatly\u003Cbr \u002F>\nfacilitate a webmaster in getting a site compliant.\u003C\u002Fp>\n\u003Ch4>Does usage of this API prevent third-party services from tracking user data?\u003C\u002Fh4>\n\u003Cp>Primary this API is aimed at compliant first-party cookies or tracking by WordPress plugins. If such a plugin triggers, for example, Facebook,\u003Cbr \u002F>\nusage of this API will be of help. If a user embeds a Facebook iframe, a blocking tool is needed that initially disables the iframe and or scripts.\u003C\u002Fp>\n\u003Cp>Third-party scripts have to blocked by blocking functionality in a consent management plugin. To do this in core would be to intrusive, and is also not applicable to all users: only users with visitors from opt-in regions such as the European Union require such a feature. Such a feature also has a risk of breaking things. Additionally, blocking these and showing a nice placeholder requires even more sophisticated code, all of which should in my opinion not be part of WordPress core, for the same reasons.\u003C\u002Fp>\n\u003Ch4>How does it work?\u003C\u002Fh4>\n\u003Cp>There are two indicators that together tell if consent is given for a specific consent category, e.g., “marketing”:\u003Cbr \u002F>\n1) the region based consent_type, which\u003Cbr \u002F>\ncan be opt-in, opt-out, or other possible consent_types;\u003Cbr \u002F>\n2) and the visitor’s choice: not set, allow, or deny.\u003C\u002Fp>\n\u003Cp>The consent_type is a function that wraps a filter, “wp_get_consent_type”. If there’s no consent management plugin to set it, it will return false. This will cause all consent categories to return true, allowing cookies to be set on all categories.\u003C\u002Fp>\n\u003Cp>If opt-in is set using this filter, a category will only return true if the value of the visitor’s choice is “allow”.\u003C\u002Fp>\n\u003Cp>If the region based consent_type is opt-out, it will return true if the visitor’s choice is not set or is “allow”.\u003C\u002Fp>\n\u003Cp>Clientside, a consent management plugin can dynamically manipulate the consent type and set several cookie categories.\u003C\u002Fp>\n\u003Cp>A plugin can use a hook to listen for changes or check the value of a given category.\u003C\u002Fp>\n\u003Cp>Categories and most other stuff can be extended with a filter.\u003C\u002Fp>\n\u003Ch3>Existing integrations\u003C\u002Fh3>\n\u003Cp>Categorized, and sorted alphabetically\u003C\u002Fp>\n\u003Ch4>Example plugin\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frlankhorst\u002Fconsent-api-example-plugin\" rel=\"nofollow ugc\">Example plugin\u003C\u002Fa>. The plugin basically consists of a shortcode, with a div that shows a tracking or not tracking message. No actual tracking is done 🙂\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Consent Management Providers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsirdata-cmp\u002F\" rel=\"ugc\">Abconsent Sirdata CMP\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbeautiful-and-responsive-cookie-consent\u002F\" rel=\"ugc\">Beautiful Cookie Consent Banner\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fclickio-consent\u002F\" rel=\"ugc\">Clickio Consent\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcomplianz-gdpr\u002F\" rel=\"ugc\">Complianz GDPR\u002FCCPA\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fconsent.studio\u002F\" rel=\"nofollow ugc\">Consent Studio\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fconsent-manager\u002F\" rel=\"ugc\">consentmanager\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fconzent.net\u002F\" rel=\"nofollow ugc\">Conzent\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcookiebot\u002F\" rel=\"ugc\">Cookiebot\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcookiefirst-gdpr-cookie-consent-banner\u002F\" rel=\"ugc\">CookieFirst\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcookiehub\u002F\" rel=\"ugc\">CookieHub\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcookietractor\u002F\" rel=\"ugc\">CookieTractor\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcookie-law-info\u002F\" rel=\"ugc\">CookieYes – Cookie Banner for Cookie Consent\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fgdpr-cookie-compliance\u002F\" rel=\"ugc\">GDPR Cookie Compliance\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.webtoffee.com\u002Fproduct\u002Fgdpr-cookie-consent\u002F\" rel=\"nofollow ugc\">GDPR Cookie Consent Plugin – CCPA Ready\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgetterms.io\u002Fconsent-manager\u002F\" rel=\"nofollow ugc\">GetTerms\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fiubenda-cookie-law-solution\u002F\" rel=\"ugc\">iubenda | All-in-one Compliance\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fibamu\u002F\" rel=\"ugc\">Lawwwing\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpressidium-cookie-consent\u002F\" rel=\"ugc\">Pressidium Cookie Consent\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftrustarc-cookie-consent-manager\u002F\" rel=\"ugc\">TrustArc Cookie Consent Manager\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Consent Requiring Plugins\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fadd-to-any\u002F\" rel=\"ugc\">AddToAny\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.appfromlab.com\u002Fproduct\u002Fwoocommerce-utm-tracker-plugin\u002F\" rel=\"nofollow ugc\">AFL UTM Tracker Plugin\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fburst-statistics\u002F\" rel=\"ugc\">Burst Statistics\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fgoogle-site-kit\u002F\" rel=\"ugc\">Google Site Kit\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoocommerce-google-adwords-conversion-tracking-tag\u002F\" rel=\"ugc\">Pixel Manager for WooCommerce\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoocommerce\u002F\" rel=\"ugc\">Woo\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-statistics\u002F\" rel=\"ugc\">WP Statistics\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Demo site\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpconsentapi.org\u002F\" rel=\"nofollow ugc\">wpconsentapi.org\u003C\u002Fa>\u003Cbr \u002F>\nBelow are the plugins used to set up the demo site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Complianz\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frlankhorst\u002Fconsent-api-example-plugin\" rel=\"nofollow ugc\">The example plugin\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>javascript, consent management plugin\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>\u002F\u002Fset consent type\nwindow.wp_consent_type = 'optin'\n\n\u002F\u002Fdispatch event when consent type is defined. This is useful if the region is detected server side, so the consent type is defined later during the pageload\nlet event = new CustomEvent('wp_consent_type_defined');\ndocument.dispatchEvent( event );\n\n\n\u002F\u002Fconsent management plugin sets cookie when consent category value changes\nwp_set_consent('marketing', 'allow');\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>javascript, tracking plugin\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>\u002F\u002Flisten to consent change event\ndocument.addEventListener(\"wp_listen_for_consent_change\", function (e) {\n  var changedConsentCategory = e.detail;\n  for (var key in changedConsentCategory) {\n    if (changedConsentCategory.hasOwnProperty(key)) {\n      if (key === 'marketing' && changedConsentCategory[key] === 'allow') {\n        console.log(\"just given consent, track user\")\n      }\n    }\n  }\n});\n\n\u002F\u002Fbasic implementation of consent check:\nif (wp_has_consent('marketing')){\n  activateMarketing();\n  console.log(\"set marketing stuff now!\");\n} else {\n  console.log(\"No marketing stuff please!\");\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>PHP\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>\u002F\u002Fdeclare compliance with consent level API\n$plugin = plugin_basename( __FILE__ );\nadd_filter( \"wp_consent_api_registered_{$plugin}\", '__return_true' );\n\n\u002F**\n* Example how a plugin can register cookies with the consent API\n * These cookies can then be shown on the front-end, to the user, with wp_get_cookie_info()\n *\u002F\n\nfunction my_wordpress_register_cookies(){\n    if ( function_exists( 'wp_add_cookie_info' ) ) {\n        wp_add_cookie_info( 'AMP_token', 'AMP', 'marketing', __( 'Session' ), __( 'Store a unique User ID.' ) );\n    }\n}\nadd_action('plugins_loaded', 'my_wordpress_register_cookies');\n\n\nif (wp_has_consent('marketing')){\n\u002F\u002Fdo marketing stuff\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Service-level consent\u003C\u002Fh4>\n\u003Cp>In addition to category-based consent, the API supports service-level consent control. This allows consent management plugins to grant or deny consent for specific services (like ‘google-analytics’ or ‘facebook-pixel’) independently from their category. When checking service consent with wp_has_service_consent(), the API first checks if explicit consent exists for that service. If no explicit consent is set, it falls back to the consent status of the service’s category. This enables fine-grained control: a user might accept statistics cookies in general, but explicitly deny a specific analytics service.\u003C\u002Fp>\n\u003Cp>Service consent can be checked and set both server-side (PHP) and client-side (JavaScript):\u003C\u002Fp>\n\u003Cp>PHP:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002F\u002Fcheck if a specific service has consent\nif ( wp_has_service_consent( 'google-analytics' ) ) {\n    \u002F\u002Factivate google analytics\n}\n\n\u002F\u002Fcheck if a service is explicitly denied\nif ( wp_is_service_denied( 'facebook-pixel' ) ) {\n    \u002F\u002Fservice was explicitly denied by user\n}\n\n\u002F\u002Fset service consent\nwp_set_service_consent( 'google-analytics', true ); \u002F\u002Fgrant consent\nwp_set_service_consent( 'facebook-pixel', false ); \u002F\u002Fdeny consent\n\n\u002F\u002Flisten for service consent changes\nadd_action( 'wp_consent_service_changed', function( $service, $consented ) {\n    error_log( \"Service {$service} consent changed to: \" . ( $consented ? 'granted' : 'denied' ) );\n}, 10, 2 );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>JavaScript:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002F\u002Fcheck service consent\nif ( wp_has_service_consent( 'youtube' ) ) {\n    \u002F\u002Factivate tracking\n}\n\n\u002F\u002Fcheck if explicitly denied\nif ( wp_is_service_denied( 'facebook-pixel' ) ) {\n    \u002F\u002Fservice denied\n}\n\n\u002F\u002Fset service consent\nwp_set_service_consent( 'youtube', true );\n\n\u002F\u002Flisten for service consent changes\ndocument.addEventListener( 'wp_consent_api_status_change_service', function( e ) {\n    console.log( 'Service: ' + e.detail.service + ', consented: ' + e.detail.value );\n});\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Any code suggestions? We’re on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FWordPress\u002Fwp-consent-level-api\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa> as well!\u003C\u002Fp>\n","Simple Consent API to read and register the current consent category.",200000,952016,100,2,"2026-06-18T06:57:00.000Z","5.0",[75,19,20,21,55],"api","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-consent-api","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-consent-api.2.0.1.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":88,"num_ratings":89,"last_updated":90,"tested_up_to":50,"requires_at_least":91,"requires_php":52,"tags":92,"homepage":94,"download_link":95,"security_score":70,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"cookiez","Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager","0.0.8","Elementor","https:\u002F\u002Fprofiles.wordpress.org\u002Felemntor\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F-rPbbBeadu8?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>🍪 What Cookie Consent Does\u003C\u002Fh4>\n\u003Ch4>Scans your site for cookies.\u003C\u002Fh4>\n\u003Cp>Cookie Consent detects cookies by loading your pages in a full headless browser (Chromium), the same way a real visitor experiences your site. This catches cookies set by JavaScript execution, third-party embeds, analytics snippets, and dynamically loaded content that simpler HTTP-based scanners often miss. Detected cookies are automatically categorized into Necessary, Analytics, Marketing, Functional, or Uncategorized. You can scan your homepage, crawl your full site, or specify custom URLs. Results merge into your cookie manager without overwriting any manual edits.\u003C\u002Fp>\n\u003Ch4>Blocks scripts until consent is given.\u003C\u002Fh4>\n\u003Cp>In GDPR (opt-in) mode, non-essential scripts don’t execute until the visitor consents to the relevant category. This applies to analytics scripts, advertising pixels, tracking tags, and any other third-party script that sets non-essential cookies. Cookie Consent intercepts both WordPress-enqueued scripts and inline scripts, modifying them to wait for consent before firing. Essential cookies, like those used for login sessions, shopping carts, and basic site functionality, are never blocked. In CCPA (opt-out) mode, scripts load by default and visitors can choose to opt out of specific categories.\u003C\u002Fp>\n\u003Ch4>Displays a customizable consent banner.\u003C\u002Fh4>\n\u003Cp>Visitors see a cookie banner with clear options to accept, reject, or manage preferences by category. The banner, preferences dialog, and revisit button are all customizable including layout, position, colors, text, button styles, and border radius. A live preview shows you what visitors will see as you make changes.\u003C\u002Fp>\n\u003Ch4>Logs every consent decision.\u003C\u002Fh4>\n\u003Cp>Each time a visitor makes a choice, Cookie Consent records the decision type (accept all, reject all, or custom), the specific category preferences, and a timestamp. These records create an audit trail you can reference if compliance questions arise.\u003C\u002Fp>\n\u003Ch4>Keeps everything in one place.\u003C\u002Fh4>\n\u003Cp>Cookie list, scan results, script rules, consent logs, banner design, and compliance settings, all in one admin area. No separate platform to sign up for, no external app to connect, no additional accounts to manage.\u003C\u002Fp>\n\u003Ch4>⚙️ Setup\u003C\u002Fh4>\n\u003Cp>A guided wizard gets your banner live in three steps:\u003Cbr \u002F>\n1. \u003Cstrong>Choose your compliance model\u003C\u002Fstrong> – Select GDPR (opt-in) or CCPA (opt-out) based on your audience and the regulations that apply to your site.\u003Cbr \u002F>\n2. \u003Cstrong>Configure your banner\u003C\u002Fstrong> – Pick a layout, adjust colors and text, and preview what visitors will see.\u003Cbr \u002F>\n3. \u003Cstrong>Scan your site\u003C\u002Fstrong> – Cookie Consent visits your pages with a real browser, finds active cookies, and categorizes them. Your banner goes live with accurate cookie data from the start.\u003C\u002Fp>\n\u003Cp>After setup, you can re-scan anytime, refine your design, recategorize cookies, and adjust script rules, all from the same dashboard.\u003C\u002Fp>\n\u003Ch4>🎨 Banner Design & Customization\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Banner Templates\u003C\u002Fstrong>: Start with a pre-configured template during setup, then customize to fit your site. Templates are tailored to your selected compliance model (GDPR or CCPA) so the default structure, buttons, and consent flow match your requirements from the start.\u003Cbr \u002F>\n\u003Cstrong>Layouts\u003C\u002Fstrong>: Footer bar, slide-in, or center popup.\u003Cbr \u002F>\n\u003Cstrong>Positioning\u003C\u002Fstrong>: Control where and how the banner appears on the page.\u003Cbr \u002F>\n\u003Cstrong>Styling\u003C\u002Fstrong>: Background colors, text colors, button primary and secondary colors, border radius, and button sizing, enough control to match any brand or design.\u003Cbr \u002F>\n\u003Cstrong>Content\u003C\u002Fstrong>: Editable title, description, and button labels for the banner, preferences dialog, and revisit button. Write in your own voice.\u003Cbr \u002F>\n\u003Cstrong>Preferences Dialog\u003C\u002Fstrong>: When a visitor clicks Manage Preferences, they see a breakdown of each cookie category with descriptions and toggles. Necessary cookies are marked as always active. Visitors choose exactly which categories they\\’re comfortable with.\u003Cbr \u002F>\n\u003Cstrong>Revisit Consent Button\u003C\u002Fstrong>: A persistent button visitors can click anytime to reopen the preferences dialog and change their choices.\u003Cbr \u002F>\n\u003Cstrong>Responsive\u003C\u002Fstrong>: Automatically adapts to desktop and mobile.\u003Cbr \u002F>\n\u003Cstrong>Live Preview\u003C\u002Fstrong>: Desktop and mobile preview with a device toggle. Updates in real time as you edit — no publishing and refreshing the front end.\u003Cbr \u002F>\n\u003Cstrong>Elementor Editor Integration [Requires Elementor Pro]\u003C\u002Fstrong>: Open the banner and preferences dialog in the Elementor visual editor. Drag-and-drop widgets, styling panels, and your full design system, the same workflow you use for the rest of your site.\u003Cbr \u002F>\n\u003Cstrong>Cloud Templates [Requires Elementor Pro]\u003C\u002Fstrong>: Save a finished banner design to your cloud library and deploy it across other sites in one click. Useful for agencies and freelancers managing multiple client sites with consistent branding.\u003C\u002Fp>\n\u003Ch4>📋 Cookie & Script Management\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Cookie Manager\u003C\u002Fstrong>: A central dashboard showing every cookie on your site, organized by consent category. Each entry shows the cookie name, domain, category, duration, and a description field. Add cookies manually, edit any field, or delete entries you no longer need. Drag-and-drop cookies to reorder them within a category, the order you set here is the order visitors see in the preferences dialog.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Category View\u003C\u002Fstrong>: Categories display as expandable accordion sections: Necessary, Analytics, Marketing, Functional, and Uncategorized. Each shows a status badge: \\”Always Active\\” for Necessary, or an Active\u002FInactive toggle for other categories. Expand any section to see the individual cookies it contains.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scanning\u003C\u002Fstrong>: Run a scan anytime with homepage only, full-site crawl, or custom URLs you specify. Include and exclude lists let you control exactly which pages get scanned. Only one scan runs at a time. New cookies are added automatically; existing manual edits are never overwritten. A progress indicator shows scan status in real time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Script Manager\u003C\u002Fstrong>: Control how individual scripts behave, independent of their category\\’s default rule. Three options per script:\u003Cbr \u002F>\n– \u003Cem>Do Not Block\u003C\u002Fem> – Script always loads, bypassing the consent engine. Use for scripts you\\’ve verified as essential but that aren\\’t automatically detected as Necessary.\u003Cbr \u002F>\n– \u003Cem>Block Until Consent\u003C\u002Fem> – Script waits until the visitor consents to its assigned category. This is the default for non-essential scripts in GDPR mode.\u003Cbr \u002F>\n– \u003Cem>Always Block\u003C\u002Fem> – Script never loads under any circumstances. Use for scripts you want permanently disabled.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Script Input\u003C\u002Fstrong>: Add scripts by URL or paste inline code directly. Cookie Consent matches scripts using URL comparison or normalized snippet hashing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Inline Script Blocking\u003C\u002Fstrong>: An optional output buffering method catches inline and hardcoded scripts that aren\\’t loaded through the standard enqueue system. Toggle it off from Advanced Settings if you want to manage inline scripts manually or minimize server-side processing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Developer Hooks\u003C\u002Fstrong>: Advanced users and agencies can hook into the blocking engine via an MU-plugin snippet to delay dynamically injected scripts, including those created by page builders or loaded after DOM ready.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan History\u003C\u002Fstrong>: A table of past scans showing date (UTC), status (success\u002Ffailed), URLs scanned, categories found, and total cookies detected.\u003C\u002Fp>\n\u003Cp>= 🔒 Compliance Settings=\u003Cbr \u002F>\n\u003Cstrong>GDPR (Opt-in)\u003C\u002Fstrong>: Non-essential scripts are blocked by default. The banner presents three options: Accept All, Reject All, and Manage Preferences. Visitors who open the preferences dialog see each cookie category with a description and a toggle. Necessary cookies are labeled \\”Always Active\\” with no toggle, they can\\’t be disabled. Consent must be given before Analytics, Marketing, or Functional scripts execute.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>CCPA (Opt-out)\u003C\u002Fstrong>: All scripts load by default. The banner includes a Do Not Sell My Data option. Visitors who opt out trigger blocking of Marketing category scripts. Global Privacy Control (GPC) signals sent by the visitor\\’s browser are detected and respected automatically.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Consent Expiration\u003C\u002Fstrong>: Set how many days a visitor\\’s choice is remembered (1–365 days, default 180). When the period expires, the banner reappears and the visitor is prompted to choose again. Until expiration, the previous choice is respected and the banner stays hidden.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Banner Activation\u003C\u002Fstrong>: A global toggle to enable or disable the cookie banner.\u003C\u002Fp>\n\u003Ch4>🎁 Free Features\u003C\u002Fh4>\n\u003Cp>Everything you need for working cookie consent.\u003Cbr \u002F>\n– Guided 3-step setup wizard\u003Cbr \u002F>\n– GDPR (opt-in) and CCPA (opt-out) compliance models\u003Cbr \u002F>\n– Google Consent Mode v2 – Automatically send consent signals to Google so analytics and ad measurement continue working after consent is deployed\u003Cbr \u002F>\n– Cookie scanning with headless browser (Chromium) detection\u003Cbr \u002F>\n– Automatic categorization into Necessary, Analytics, Marketing, Functional, and Uncategorized\u003Cbr \u002F>\n– Automatic script blocking for non-essential cookies\u003Cbr \u002F>\n– Blocks both enqueued scripts and inline scripts\u003Cbr \u002F>\n– Global Privacy Control (GPC) and Do Not Sell support\u003Cbr \u002F>\n– Customizable consent banner with Accept All, Reject All, and Manage Preferences\u003Cbr \u002F>\n– Preferences dialog with per-category toggles and descriptions\u003Cbr \u002F>\n– Revisit consent button for visitors to update choices anytime\u003Cbr \u002F>\n– Banner templates tailored to GDPR and CCPA compliance models\u003Cbr \u002F>\n– Footer bar, slide-in, and center popup layouts\u003Cbr \u002F>\n– Full styling controls: colors, buttons, borders, sizing\u003Cbr \u002F>\n– Editable banner text, button labels, and dialog content\u003Cbr \u002F>\n– Responsive desktop and mobile design\u003Cbr \u002F>\n– Live banner preview with device toggle\u003Cbr \u002F>\n– Cookie manager with manual add\u002Fedit\u002Fdelete and sorting\u003Cbr \u002F>\n– Script manager with per-script overrides (always load, block until consent, always block)\u003Cbr \u002F>\n– Consent logging with timestamped audit trail\u003Cbr \u002F>\n– Configurable consent expiration (1–365 days)\u003Cbr \u002F>\n– Scan history with status and results tracking\u003Cbr \u002F>\n– Output buffering toggle for inline script blocking\u003Cbr \u002F>\n– No external dashboards\u003Cbr \u002F>\n– No CDN dependencies\u003C\u002Fp>\n\u003Ch4>🔥 Premium Cookie Consent features available with Elementor One\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>White-Label\u003C\u002Fstrong>: Remove Cookie Consent branding from the consent banner entirely.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual Translations\u003C\u002Fstrong>: Translate the banner and preferences dialog into additional languages for international visitors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent Log Export\u003C\u002Fstrong>: Download consent records in CSV format for audits, legal reviews, or internal documentation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Rule Exclusions\u003C\u002Fstrong>: Exclude specific paths or URLs from cookie scans. Useful for staging environments, admin areas, or sections that don\\’t need scanning.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Banner on Specific Pages\u003C\u002Fstrong>: Prevent the banner from loading on pages you select (e.g., internal dashboards, login screens).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor Editor Design [Requires Elementor Pro]\u003C\u002Fstrong>: Open the cookie banner and preferences dialog in the full Elementor visual editor. Drag-and-drop layout, widget-level control, and live editing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Templates [Requires Elementor Pro]\u003C\u002Fstrong>: Save banner designs to your cloud library and deploy them across multiple sites instantly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Tag Manager Integration [Premium]\u003C\u002Fstrong> – Pass consent signals to your GTM container for tag-level consent control.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔜 Coming Soon\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Cookie Policy Generator\u003C\u002Fstrong> – Auto-generate a cookie policy page based on the cookies detected on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic and Scheduled Scans [Premium]\u003C\u002Fstrong> – Set scans to run on a recurring schedule so your cookie list stays current without manual intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geo-Targeting [Premium]\u003C\u002Fstrong> – Automatically display the correct banner based on visitor location. GDPR opt-in for EU visitors, CCPA opt-out for US visitors without manual configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Region Banner Management [Premium]\u003C\u002Fstrong> – Configure and manage separate banner designs and compliance rules for different geographic regions from one dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>♿ Accessibility\u003Cbr \u002F>\nThe Cookie Consent consent banner is built following accessibility best practices. For full website accessibility compliance, Cookie Consent works alongside \u003Ca href=\"https:\u002F\u002Fgo.elementor.com\u002Fwp-repo-cookiez-ally\u002F\" rel=\"nofollow ugc\">Ally\u003C\u002Fa>, Elementor\\’s accessibility plugin that scans for and remediates accessibility issues across your site.\u003C\u002Fp>\n\u003Ch4>Installation\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install using the WordPress built-in Plugin installer, or Extract the zip file and drop the contents in the \u003Ccode>wp-content\u002Fplugins\u002F\u003C\u002Fcode> directory of your WordPress installation.\u003C\u002Fli>\n\u003Cli>Activate the plugin through the ‘Plugins’ menu in WordPress.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Cookie Consent requires a connection to an active Elementor account in order to:\u003Cbr \u002F>\n* Identify the user and provide the user with the purchased service.\u003Cbr \u002F>\n* Log website visitors consents for “proof of consent”\u003Cbr \u002F>\n* Preform an external scan of cookies generated by and on the website.\u003Cbr \u002F>\n* Collect manually submitted feedback, to improve the product.\u003C\u002Fp>\n\u003Cp>This connection is initiated manually by the user via the plugin’s settings panel.\u003Cbr \u002F>\nLearn more about our \u003Ca href=\"https:\u002F\u002Felementor.com\u002Fterms\u002F\" rel=\"nofollow ugc\">terms and conditions\u003C\u002Fa>and \u003Ca href=\"https:\u002F\u002Felementor.com\u002Fabout\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>. This plugin uses a 3rd party service operated by Elementor.\u003C\u002Fp>\n\u003Cp>Cookie Consent uses a 3rd party service operated by Mixpanel to collect interactions with the plugin but only for consenting users, meaning if the user has \u003Cem>Not\u003C\u002Fem> consented to “sharing data” (default) this is disabled and no collection is made.\u003C\u002Fp>\n","Simplify cookie consent with a customizable banner that helps you cover global privacy laws like GDPR and CCPA. Scan your site for cookies, block scri &hellip;",20000,68651,86,4,"2026-07-07T09:10:00.000Z","6.7",[18,19,93,54],"cookie-consent","https:\u002F\u002Felementor.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcookiez.0.0.8.zip",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":106,"num_ratings":107,"last_updated":108,"tested_up_to":109,"requires_at_least":110,"requires_php":16,"tags":111,"homepage":114,"download_link":115,"security_score":116,"vuln_count":71,"unpatched_count":11,"last_vuln_date":117,"fetched_at":26},"cookie-bar","Cookie Bar","2.2","Brontobytes","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrontobytes\u002F","\u003Cp>A simple, lightweight WordPress plugin for displaying a discreet notification bar that is dismissable and the dismissal is saved by cookie. Perfect for implementing the EU cookie law (GDPR)!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>The Cookie Bar plugin creates a small bar at the bottom of the website with a short customizable message about cookies and an accept button.\u003C\u002Fstrong> Once a visitor has accepted the Cookie Bar, it then disappears.\u003C\u002Fp>\n\u003Cp>Feel free to try out the plugin through our installation of \u003Ca href=\"https:\u002F\u002Fwww.brontobytes.com\u002Fblog\u002Fcookie-bar-free-wordpress-plugin\u002F\" rel=\"nofollow ugc\">Cookie Bar\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Troubleshooting: If you or your visitors are using an adblocker that can block cookie bars, the bar may not show up. Whitelist your website in your adblocker’s browser add-on\u002Fextension.\u003C\u002Fp>\n","Cookie Bar allows you to discreetly inform visitors that your website uses cookies.",10000,173399,98,22,"2025-10-29T18:54:00.000Z","6.8.6","3.8",[20,112,97,113,21],"cookie","cookie-compliance","https:\u002F\u002Fwww.brontobytes.com\u002Fblog\u002Fcookie-bar-free-wordpress-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcookie-bar.2.2.zip",99,"2023-10-24 00:00:00",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":104,"downloaded":126,"rating":127,"num_ratings":128,"last_updated":129,"tested_up_to":130,"requires_at_least":131,"requires_php":131,"tags":132,"homepage":16,"download_link":134,"security_score":116,"vuln_count":135,"unpatched_count":11,"last_vuln_date":136,"fetched_at":26},"cookie-script-com","Cookie-Script.com","1.4.3","csarturas","https:\u002F\u002Fprofiles.wordpress.org\u002Fcsarturas\u002F","\u003Cp>\u003Cstrong>CookieScript\u003C\u002Fstrong> helps your WordPress site meet privacy requirements like \u003Cstrong>GDPR, CPRA, PIPEDA\u003C\u002Fstrong> and more. It adds a cookie banner to your site—no need to edit files or write any code yourself.\u003C\u002Fp>\n\u003Cp>You can use it right after installing, \u003Cstrong>even without a CookieScript account\u003C\u002Fstrong>. Later on, if you want to adjust how the banner looks or behaves, you can link an account to unlock more options.\u003C\u002Fp>\n\u003Cp>The plugin works with \u003Cstrong>Google Consent Mode v2\u003C\u002Fstrong> and the \u003Cstrong>WP Consent API\u003C\u002Fstrong>, and can \u003Cstrong>block third-party cookies\u003C\u002Fstrong> until a visitor gives permission. It keeps your site compliant without interfering with tools like Google Analytics or ads.\u003C\u002Fp>\n\u003Cp>More details are available at \u003Ca href=\"https:\u002F\u002Fcookie-script.com\u002F\" rel=\"nofollow ugc\">cookie-script.com\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin utilizes Cookie-Script.com services to function.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Cookie-Script.com API\u003C\u002Fstrong>\u003Cbr \u002F>\n*   \u003Cstrong>Service:\u003C\u002Fstrong> Scans your website for cookies and retrieves configuration\u002Fstatus.\u003Cbr \u002F>\n*   \u003Cstrong>Data Sent:\u003C\u002Fstrong> Website URL, Privacy Policy URL, Language preference, and a unique scan identifier.\u003Cbr \u002F>\n*   \u003Cstrong>When:\u003C\u002Fstrong> During manual scan initiation via the plugin settings.\u003Cbr \u002F>\n*   \u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fcookie-script.com\u002Flegal\u002Fprivacy-policy\u003Cbr \u002F>\n*   \u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fcookie-script.com\u002Flegal\u002Fterms-and-conditions\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Cookie-Script.com CDN\u003C\u002Fstrong>\u003Cbr \u002F>\n*   \u003Cstrong>Service:\u003C\u002Fstrong> Delivers the JavaScript file for the cookie banner (for “With Account” mode).\u003Cbr \u002F>\n*   \u003Cstrong>Data Sent:\u003C\u002Fstrong> Standard web request data (IP address, User Agent) when fetching the script.\u003Cbr \u002F>\n*   \u003Cstrong>When:\u003C\u002Fstrong> On every page load where the banner is active.\u003Cbr \u002F>\n*   \u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fcookie-script.com\u002Flegal\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>\u003C\u002Fh3>\n","Cookie-Script.com WordPress plugin.",114196,62,14,"2026-01-19T09:00:00.000Z","6.9.5","5.6",[19,20,112,133,54],"cookiescript","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcookie-script-com.1.4.3.zip",1,"2025-06-19 00:00:00",{"attackSurface":138,"codeSignals":165,"taintFlows":192,"riskAssessment":193,"analyzedAt":206},{"hooks":139,"ajaxHandlers":161,"restRoutes":162,"shortcodes":163,"cronEvents":164,"entryPointCount":11,"unprotectedCount":11},[140,146,149,153,157],{"type":141,"name":142,"callback":143,"file":144,"line":145},"action","wp_footer","main_render_ccpa_for_wp","ccpa-free-cookie.php",59,{"type":141,"name":142,"callback":147,"file":144,"line":148},"freeccpacookie_scriptOne",91,{"type":141,"name":150,"callback":151,"file":144,"line":152},"wp_enqueue_scripts","freeccpacookie_scriptTwo",103,{"type":141,"name":154,"callback":155,"file":144,"line":156},"admin_menu","ccpa_forwp_settings_initiate",109,{"type":141,"name":158,"callback":159,"file":144,"line":160},"admin_init","ccpa_forwp_settings_data",115,[],[],[],[],{"dangerousFunctions":166,"sqlUsage":171,"outputEscaping":173,"fileOperations":11,"externalRequests":135,"nonceChecks":11,"capabilityChecks":11,"bundledLibraries":191},[167],{"fn":168,"file":144,"line":169,"context":170},"unserialize",47,"$geo_location_arr  = unserialize($geo_location_data['body']);",{"prepared":11,"raw":11,"locations":172},[],{"escaped":11,"rawEcho":174,"locations":175},7,[176,179,181,183,185,187,189],{"file":144,"line":177,"context":178},71,"raw output",{"file":144,"line":180,"context":178},178,{"file":144,"line":182,"context":178},191,{"file":144,"line":184,"context":178},203,{"file":144,"line":186,"context":178},216,{"file":144,"line":188,"context":178},229,{"file":144,"line":190,"context":178},242,[],[],{"summary":194,"deductions":195},"The \"free-ccpa-cookie\" v1.0 plugin presents a mixed security profile. On the positive side, it has a very small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, all SQL queries are properly prepared, and there are no known vulnerabilities or CVEs associated with this plugin, suggesting a history of responsible development or limited exposure. This lack of past vulnerabilities is a strong indicator of a generally secure codebase.\n\nHowever, there are significant concerns stemming from the static code analysis. The presence of the `unserialize` function is a high-risk indicator, as it can be exploited to execute arbitrary code if the serialized data is controllable by an attacker. Compounding this risk, zero percent of output escaping is performed, meaning any data processed by the plugin that is later displayed to users or within the WordPress environment could be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks further exacerbates these risks, as there are no built-in mechanisms to verify user intent or permissions for actions that might involve dangerous functions or unsafely handled data.\n\nIn conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the identified code signals like `unserialize` and unescaped output, coupled with a lack of security checks, create notable vulnerabilities. The lack of taint analysis data might be due to the static analysis tool's limitations or the specific nature of the plugin's code; however, the `unserialize` function itself warrants significant caution. The absence of properly escaped output is a particularly concerning weakness.",[196,199,201,204],{"reason":197,"points":198},"Dangerous function 'unserialize' used",15,{"reason":200,"points":174},"0% output escaping",{"reason":202,"points":203},"0 Nonce checks",5,{"reason":205,"points":203},"0 Capability checks","2026-03-17T06:46:28.195Z",{"wat":208,"direct":217},{"assetPaths":209,"generatorPatterns":212,"scriptPaths":213,"versionParams":214},[210,211],"\u002Fwp-content\u002Fplugins\u002Ffree-ccpa-cookie\u002Fcssforbar.css","\u002Fwp-content\u002Fplugins\u002Ffree-ccpa-cookie\u002Fjsforccpa.js",[],[211],[215,216],"free-ccpa-cookie\u002Fcssforbar.css?ver=","free-ccpa-cookie\u002Fjsforccpa.js?ver=",{"cssClasses":218,"htmlComments":236,"htmlAttributes":237,"restEndpoints":243,"jsGlobals":244,"shortcodeOutput":246},[219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235],"cb__b","cb__b_allow","cb__b_filled-rectangle","main-ccpa","cb_line","cb_bottom","cb_CodGrayWhite","cb_animation-no","cb_without-mr","cb_without-mb","cb_without-ml","cb__content-body","cb__content-text","cb__link","cb__aside","cb__aside_default","cb__b_decline",[],[238,239,240,241,242],"id=\"cookiebanner-root\"","id=\"mybtn2\"","onclick=\"Decline()\"","id=\"mybtn\"","onclick=\"Accept()\"",[],[245],"my_options",[],{"error":248,"url":249,"statusCode":250,"statusMessage":251,"message":251},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ffree-ccpa-cookie\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":135,"versions":253},[254],{"version":6,"download_url":23,"svn_tag_url":255,"released_at":25,"has_diff":256,"diff_files_changed":257,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":258,"is_current":248},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ffree-ccpa-cookie\u002Ftags\u002F1.0\u002F",false,[],[]]