
Hayona Cookie Consent Security & Risk Analysis
wordpress.org/plugins/hayona-cookiesA straightforward plugin to comply with the EU cookie law, including implied consent.
Is Hayona Cookie Consent Safe to Use in 2026?
Generally Safe
Score 85/100Hayona Cookie Consent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hayona-cookies" v1.1.4 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, and external HTTP requests are strong indicators of good coding practices. Furthermore, the lack of any recorded historical vulnerabilities (CVEs) suggests a mature and well-maintained codebase over time.
However, there are specific areas of concern. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the attack surface is currently reported as zero, any future addition of entry points without proper authentication and authorization mechanisms would immediately introduce critical vulnerabilities. The 74% output escaping rate also indicates a potential for Cross-Site Scripting (XSS) vulnerabilities in a quarter of the plugin's outputs, which warrants closer inspection of the unescaped portions.
In conclusion, while "hayona-cookies" v1.1.4 shows strengths in data sanitization and avoiding common vulnerabilities, the lack of any access control mechanisms (nonces, capability checks) on its entry points is a notable deficiency that leaves it exposed to potential privilege escalation or unauthorized actions if the attack surface were to expand. The partial output escaping is a less severe but still present risk.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
- 26% of outputs are not properly escaped
Hayona Cookie Consent Security Vulnerabilities
Hayona Cookie Consent Code Analysis
Output Escaping
Hayona Cookie Consent Attack Surface
WordPress Hooks 9
Maintenance & Trust
Hayona Cookie Consent Maintenance & Trust
Maintenance Signals
Community Trust
Hayona Cookie Consent Alternatives
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
gdpr-cookie-consent
WPLP Cookie Consent helps WordPress website owners display cookie consent banners, manage user preferences, and control third-party scripts in line wi …
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law
gdpr-cookie-compliance
Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode
cookiebot
Install your cookie banner in minutes. Automatically scan and block cookies to comply with the GDPR, CCPA, Google Consent Mode v2. Free plan option.
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
real-cookie-banner
Obtain GDPR (DSGVO/RGPD) and ePrivacy Directive (TDDDG/TTDSG, LOPD-GDD, DTA) compliant consents in your cookie banner. More than just a cookie notice!
Hayona Cookie Consent Developer Profile
1 plugin · 30 total installs
How We Detect Hayona Cookie Consent
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hayona-cookies/assets/css/min/style.css/wp-content/plugins/hayona-cookies/assets/js/min/cookie-banner.min.js/wp-content/plugins/hayona-cookies/assets/js/min/cookie-banner.min.jshayona-cookies/assets/css/min/style.css?ver=hayona-cookies/assets/js/min/cookie-banner.min.js?ver=HTML / DOM Fingerprints
hc-stylinghc-styling--lighthc-styling--darkhc-bannerhc-banner__bodyhc-toolbarhc-buttonaccept-cookies+3 morehc_is_enabledhc_consent_timestamphc_implied_consent_enabledhc_banner_texthc_privacy_statement_urlhc_cookie_expiration+2 morehayonaCookies<!-- Privacy settings -->