GTM Cookie Consent Security & Risk Analysis

wordpress.org/plugins/gtm-cookie-consent

Do you use Google Tag Manager? Give your users control over their cookies with this simple plugin.

10 active installs v1.0.2 PHP 5.6+ WP 3.5+ Updated Nov 28, 2018
cookie-consentcookie-lawcookiesgdprgtm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GTM Cookie Consent Safe to Use in 2026?

Generally Safe

Score 85/100

GTM Cookie Consent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "gtm-cookie-consent" plugin v1.0.2 exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the plugin does not engage in file operations or external HTTP requests, and all SQL queries are properly prepared, which are excellent security practices. However, a significant concern arises from the low percentage of properly escaped output (11%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content could be rendered without proper sanitization, allowing attackers to inject malicious scripts.

The plugin's vulnerability history is clean, with no known CVEs recorded. This, combined with the limited attack surface and use of prepared statements, suggests the plugin has been developed with security in mind regarding common web application vulnerabilities. Despite the lack of identified taint flows and dangerous functions in the static analysis, the insufficient output escaping remains a critical weakness that could be exploited. While the plugin has a strong foundation in preventing certain types of attacks, the XSS risk due to poor output escaping needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

GTM Cookie Consent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GTM Cookie Consent Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
v0.1.1
Code Analysis
Analyzed Apr 16, 2026

GTM Cookie Consent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped19 total outputs
Attack Surface

GTM Cookie Consent Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_footergtm-cookie-consent.php:36
actioninitgtm-cookie-consent.php:39
actionwp_headinc/gtm.php:22
actionwp_enqueue_scriptsinc/scripts.php:21
actionadmin_enqueue_scriptsinc/scripts.php:24
actionwp_footerinc/scripts.php:27
actionadmin_initinc/settings.php:20
actionadmin_menuinc/settings.php:46
actionwp_enqueue_scriptsinc/styles.php:20
actionwp_headinc/styles.php:23
Maintenance & Trust

GTM Cookie Consent Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 28, 2018
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GTM Cookie Consent Developer Profile

Nfty Creative

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GTM Cookie Consent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gtm-cookie-consent/js/cookie-consent-init.js/wp-content/plugins/gtm-cookie-consent/css/cookie-consent-init.css
Script Paths
https://cdn.jsdelivr.net/npm/cookieconsent@3/build/cookieconsent.min.js

HTML / DOM Fingerprints

CSS Classes
cc-compliancesettings-dismisscc-revokecookie-settingssliderswitch-activecc-windowcc-logo+6 more
Data Attributes
id="cookie-consent"
JS Globals
cookieConsent
FAQ

Frequently Asked Questions about GTM Cookie Consent