Pieeye: GDPR+CPRA+Cookie Consent+DSR Security & Risk Analysis

wordpress.org/plugins/pieeye-gdpr-cpra-cookie-consent-dsr

PieEye simplifies GDPR/CPRA compliance with Cookie Consent and Data Subject Request Management. The Cookie Manager lets you customise the Cookie Banne …

10 active installs v1.0.1 PHP + WP + Updated Unknown
cookie-bannercookiescpradsrgdpr
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pieeye: GDPR+CPRA+Cookie Consent+DSR Safe to Use in 2026?

Generally Safe

Score 100/100

Pieeye: GDPR+CPRA+Cookie Consent+DSR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "pieeye-gdpr-cpra-cookie-consent-dsr" v1.0.1 exhibits a concerning security posture primarily due to its unprotected entry points. While the code shows good practices in avoiding dangerous functions, using prepared statements for SQL, and properly escaping output, the presence of two AJAX handlers without any authentication or capability checks is a significant weakness. This opens the door for unauthenticated users to potentially interact with sensitive functionality, even if the code itself doesn't immediately appear to be exploitable for critical vulnerabilities.

The taint analysis, while not revealing critical or high-severity issues, did identify two flows with unsanitized paths. Combined with the unprotected AJAX handlers, this suggests a potential for logic flaws or unintended data manipulation if an attacker can trigger these paths. The complete absence of a vulnerability history is a positive sign, indicating that the plugin has not had publicly disclosed critical or high-severity flaws. However, this does not negate the risks identified in the static analysis, particularly the lack of authorization on entry points.

In conclusion, the plugin demonstrates strengths in its SQL and output handling but suffers from a critical deficiency in securing its AJAX endpoints. The vulnerability history is clean, which is encouraging, but the identified attack surface without authentication requires immediate attention. The lack of nonce checks and capability checks on the AJAX handlers significantly increases the risk profile.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Pieeye: GDPR+CPRA+Cookie Consent+DSR Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pieeye: GDPR+CPRA+Cookie Consent+DSR Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped30 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pieeye_update_consent (index.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Pieeye: GDPR+CPRA+Cookie Consent+DSR Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pieeye_update_consentindex.php:56
noprivwp_ajax_pieeye_update_consentindex.php:57
WordPress Hooks 3
actionadmin_enqueue_scriptsindex.php:30
actionadmin_menuindex.php:60
actionwp_enqueue_scriptsindex.php:117
Maintenance & Trust

Pieeye: GDPR+CPRA+Cookie Consent+DSR Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Pieeye: GDPR+CPRA+Cookie Consent+DSR Developer Profile

PieEye

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pieeye: GDPR+CPRA+Cookie Consent+DSR

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/css/pieeye-styles.css/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/toggleSwitch.js/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/cmsInstall.js
Script Paths
/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/toggleSwitch.js/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/cmsInstall.js

HTML / DOM Fingerprints

JS Globals
banner
REST Endpoints
/wp-json/pieeye/v1/consent
FAQ

Frequently Asked Questions about Pieeye: GDPR+CPRA+Cookie Consent+DSR