Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Security & Risk Analysis

wordpress.org/plugins/kukie-cookie-consent

Free cookie consent plugin for WordPress. GDPR, CCPA & ePrivacy compliance with Google Consent Mode v2, cookie scanning and 70+ languages.

10 active installs v1.6.1 PHP 8.1+ WP 6.0+ Updated Apr 15, 2026
ccpacookie-consentgdprpolylangwpml
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Safe to Use in 2026?

Generally Safe

Score 100/100

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "kukie-cookie-consent" v1.6.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent adherence to secure coding practices, with all identified entry points (AJAX handlers) protected by nonce and capability checks. Crucially, there are no unescaped outputs, no dangerous functions, no file operations, and all SQL queries are executed using prepared statements. This indicates a robust defense against common web vulnerabilities like SQL injection and cross-site scripting (XSS). The absence of any known CVEs, past or present, further solidifies this positive assessment, suggesting a well-maintained and secure codebase over time.

While the plugin's security is commendable, a single external HTTP request is noted. While this might be benign, it represents a potential, albeit minor, vector for supply chain attacks if the external resource were compromised or malicious. The taint analysis revealing zero flows with unsanitized paths is also a significant strength. However, the attack surface, while protected, consists of 11 AJAX handlers. Although all are secured, a larger number of entry points can inherently increase the complexity of security maintenance and the potential for future oversight.

In conclusion, "kukie-cookie-consent" v1.6.1 appears to be a highly secure WordPress plugin. Its developers have implemented strong security measures, as evidenced by the lack of critical vulnerabilities in static analysis and a clean vulnerability history. The primary area for potential minor concern is the single external HTTP request, which warrants awareness. The overall security is excellent, with strong protections against common attack vectors.

Key Concerns

  • Single external HTTP request
Vulnerabilities
None known

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Release Timeline

v1.6.1Current
v1.6.0
v1.5.0
v1.4.1
v1.4.0
v1.2.2
v1.2.1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
Code Analysis
Analyzed Apr 16, 2026

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
250 escaped
Nonce Checks
11
Capability Checks
13
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped250 total outputs
Attack Surface

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 11

authwp_ajax_kukie_dismiss_wp_rocket_noticeincludes/class-kukie-admin.php:24
authwp_ajax_kukie_connectincludes/class-kukie-admin.php:25
authwp_ajax_kukie_disconnectincludes/class-kukie-admin.php:26
authwp_ajax_kukie_get_statusincludes/class-kukie-admin.php:27
authwp_ajax_kukie_get_settingsincludes/class-kukie-admin.php:28
authwp_ajax_kukie_save_settingsincludes/class-kukie-admin.php:29
authwp_ajax_kukie_save_gcmincludes/class-kukie-admin.php:30
authwp_ajax_kukie_save_uetincludes/class-kukie-admin.php:31
authwp_ajax_kukie_save_banner_designincludes/class-kukie-admin.php:32
authwp_ajax_kukie_trigger_scanincludes/class-kukie-admin.php:33
authwp_ajax_kukie_verifyincludes/class-kukie-admin.php:34
WordPress Hooks 23
actionadmin_menuincludes/class-kukie-admin.php:16
actionadmin_enqueue_scriptsincludes/class-kukie-admin.php:17
actionadmin_initincludes/class-kukie-admin.php:18
actionadmin_noticesincludes/class-kukie-admin.php:19
actionadmin_noticesincludes/class-kukie-admin.php:20
actionadmin_noticesincludes/class-kukie-admin.php:21
actionplugins_loadedincludes/class-kukie-plugin.php:30
actionwp_enqueue_scriptsincludes/class-kukie-script-injector.php:30
filterscript_loader_tagincludes/class-kukie-script-injector.php:31
actionadmin_bar_menuincludes/class-kukie-script-injector.php:34
filterautoptimize_filter_js_excludeincludes/class-kukie-script-injector.php:61
filterrocket_exclude_jsincludes/class-kukie-script-injector.php:67
filterrocket_delay_js_exclusionsincludes/class-kukie-script-injector.php:74
filterrocket_minify_excluded_external_jsincludes/class-kukie-script-injector.php:81
filterrocket_exclude_defer_jsincludes/class-kukie-script-injector.php:89
filterwpfc_minify_js_excludeincludes/class-kukie-script-injector.php:98
filterlitespeed_optimize_js_excludesincludes/class-kukie-script-injector.php:107
filterw3tc_minify_js_do_tag_minificationincludes/class-kukie-script-injector.php:116
filtersgo_js_minify_excludeincludes/class-kukie-script-injector.php:124
filtersgo_javascript_combine_excludeincludes/class-kukie-script-injector.php:128
filterwp_get_consent_typeincludes/class-kukie-wp-consent-api.php:41
actionwp_enqueue_scriptsincludes/class-kukie-wp-consent-api.php:45
actioninitkukie-cookie-consent.php:52
Maintenance & Trust

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version8.1
Downloads504

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA) Developer Profile

kukieio

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kukie-cookie-consent/assets/css/admin.css/wp-content/plugins/kukie-cookie-consent/assets/js/admin.js
Version Parameters
kukie-cookie-consent/assets/css/admin.css?ver=kukie-cookie-consent/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
kukie-cookie-consent
Data Attributes
data-kukie-site-id
JS Globals
kukieAdmin
FAQ

Frequently Asked Questions about Kukie – Cookie Banner and Consent Management (GDPR, CCPA, DSVGO, CNIL, PIPEDA)