
Pieeye: GDPR+CPRA+Cookie Consent+DSR Security & Risk Analysis
wordpress.org/plugins/pieeye-gdpr-cpra-cookie-consent-dsrPieEye simplifies GDPR/CPRA compliance with Cookie Consent and Data Subject Request Management. The Cookie Manager lets you customise the Cookie Banne …
Is Pieeye: GDPR+CPRA+Cookie Consent+DSR Safe to Use in 2026?
Generally Safe
Score 100/100Pieeye: GDPR+CPRA+Cookie Consent+DSR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "pieeye-gdpr-cpra-cookie-consent-dsr" v1.0.1 exhibits a concerning security posture primarily due to its unprotected entry points. While the code shows good practices in avoiding dangerous functions, using prepared statements for SQL, and properly escaping output, the presence of two AJAX handlers without any authentication or capability checks is a significant weakness. This opens the door for unauthenticated users to potentially interact with sensitive functionality, even if the code itself doesn't immediately appear to be exploitable for critical vulnerabilities.
The taint analysis, while not revealing critical or high-severity issues, did identify two flows with unsanitized paths. Combined with the unprotected AJAX handlers, this suggests a potential for logic flaws or unintended data manipulation if an attacker can trigger these paths. The complete absence of a vulnerability history is a positive sign, indicating that the plugin has not had publicly disclosed critical or high-severity flaws. However, this does not negate the risks identified in the static analysis, particularly the lack of authorization on entry points.
In conclusion, the plugin demonstrates strengths in its SQL and output handling but suffers from a critical deficiency in securing its AJAX endpoints. The vulnerability history is clean, which is encouraging, but the identified attack surface without authentication requires immediate attention. The lack of nonce checks and capability checks on the AJAX handlers significantly increases the risk profile.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Pieeye: GDPR+CPRA+Cookie Consent+DSR Security Vulnerabilities
Pieeye: GDPR+CPRA+Cookie Consent+DSR Code Analysis
Output Escaping
Data Flow Analysis
Pieeye: GDPR+CPRA+Cookie Consent+DSR Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Pieeye: GDPR+CPRA+Cookie Consent+DSR Maintenance & Trust
Maintenance Signals
Community Trust
Pieeye: GDPR+CPRA+Cookie Consent+DSR Alternatives
My Agile Privacy® – CMP, Cookie Consent & Privacy Tools
myagileprivacy
Effortlessly set up cookie notices and privacy policies. Avoid fines by staying compliant with GDPR, nFADP, PIPEDA, LGPD, CCPA/CPRA and 14 more.
CookieLegit
cookielegit
Setup a GDPR compliant cookie banner in minutes. Google Consent mode v2 ready!
CYTRIO Consent Management
cytrio-consent-management
Short Description: The CYTRIO consent plugin enables global data privacy regulations compliance.
GDPR Cookie Banner
gdpr-cookie-banner
GDPR Cookie Banner helps website owners to display a notice that they are using cookies. This plugin assists website owners to comply with European pr …
Cookied Cookie Consent
cookied-cookie-consent
The cheapest global cookie consent solution. GDPR, CCPA, LGPD compliant cookie banner starting at just €9.99/year.
Pieeye: GDPR+CPRA+Cookie Consent+DSR Developer Profile
1 plugin · 10 total installs
How We Detect Pieeye: GDPR+CPRA+Cookie Consent+DSR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/css/pieeye-styles.css/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/toggleSwitch.js/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/cmsInstall.js/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/toggleSwitch.js/wp-content/plugins/pieeye-gdpr-cpra-cookie-consent-dsr/assets/js/cmsInstall.jsHTML / DOM Fingerprints
banner/wp-json/pieeye/v1/consent