SimaCookie Security & Risk Analysis

wordpress.org/plugins/simasicher-dsgvo-cookie

Block all cookies without consent and customize the cookie note as you wish.

60 active installs v1.3.2 PHP + WP 4.9+ Updated Dec 17, 2018
analyticscookieseuropeanlawprivacy
42
D · High Risk
CVEs total2
Unpatched2
Last CVESep 5, 2025
Safety Verdict

Is SimaCookie Safe to Use in 2026?

High Risk

Score 42/100

SimaCookie carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Sep 5, 2025Updated 7yr ago
Risk Assessment

The 'simasicher-dsgvo-cookie' plugin v1.3.2 exhibits a mixed security posture. On the positive side, the code analysis shows a complete absence of dangerous functions and SQL queries that are not prepared, which are significant strengths. Furthermore, file operations and external HTTP requests are not utilized, reducing potential attack vectors. However, there are notable concerns, particularly regarding the output escaping, where only 71% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to improper neutralization, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled correctly.

The vulnerability history is a major red flag, with two currently unpatched medium severity CVEs. The types of past vulnerabilities, including XSS and Cross-Site Request Forgery (CSRF), align with the potential risks identified in the static analysis (unescaped output). The fact that the last vulnerability was in the future (2025-09-05) strongly suggests this data is either hypothetical or has been manipulated, but if treated as real, it implies a recurring pattern of security weaknesses that have not been adequately addressed.

In conclusion, while the plugin demonstrates good practices in areas like SQL handling and avoiding dangerous functions, the unpatched vulnerabilities and incomplete output escaping present significant risks. The presence of unpatched medium severity issues necessitates immediate attention, and the historical pattern suggests a need for more robust security development and testing practices.

Key Concerns

  • Unpatched CVE (2 medium severity)
  • Incomplete output escaping (29% unescaped)
  • Missing nonce checks (0 found)
Vulnerabilities
2 published

SimaCookie Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58868medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SimaCookie <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
CVE-2025-58869medium · 4.3Cross-Site Request Forgery (CSRF)

SimaCookie <= 1.3.2 - Cross-Site Request Forgery

Sep 5, 2025Unpatched
Version History

SimaCookie Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

SimaCookie Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
32 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

71% escaped45 total outputs
Attack Surface

SimaCookie Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[cookie] class-frontend.php:194
[cookie-control] class-frontend.php:293
[cookie-list] class-frontend.php:313
WordPress Hooks 16
actionadmin_initclass-admin.php:3
actionadmin_enqueue_scriptsclass-admin.php:10
actionadmin_menuclass-admin.php:334
actionsend_headersclass-frontend.php:5
actionwp_headclass-frontend.php:15
actionwp_footerclass-frontend.php:125
actionwp_headclass-frontend.php:219
actionwp_footerclass-frontend.php:220
filterinfinite_scroll_js_settingsclass-frontend.php:236
filterwidget_textclass-frontend.php:241
filtermce_external_pluginsinc\tinymce.php:10
filtermce_buttonsinc\tinymce.php:11
actionadmin_headinc\tinymce.php:14
actioninitsimasicher-dsgvo-cookie.php:27
actionadmin_initsimasicher-dsgvo-cookie.php:42
actionplugins_loadedsimasicher-dsgvo-cookie.php:55
Maintenance & Trust

SimaCookie Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 17, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

SimaCookie Developer Profile

Simasicher

1 plugin · 60 total installs

53
trust score
Avg Security Score
42/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SimaCookie

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simasicher-dsgvo-cookie/css/style_admin.css/wp-content/plugins/simasicher-dsgvo-cookie/js/eucookiesettings.js/wp-content/plugins/simasicher-dsgvo-cookie/css/style.css/wp-content/plugins/simasicher-dsgvo-cookie/js/cookieconsent.js
Script Paths
/wp-content/plugins/simasicher-dsgvo-cookie/js/eucookiesettings.js/wp-content/plugins/simasicher-dsgvo-cookie/js/cookieconsent.js
Version Parameters
simasicher-dsgvo-cookie/css/style_admin.css?ver=simasicher-dsgvo-cookie/js/eucookiesettings.js?ver=simasicher-dsgvo-cookie/css/style.css?ver=simasicher-dsgvo-cookie/js/cookieconsent.js?ver=

HTML / DOM Fingerprints

CSS Classes
sima_containersima_columnsima_column_leftsima_input_smallcc_divcc_bannercc_btncc_btn_accept+2 more
Data Attributes
data-cc-animatedata-cc-bgdata-cc-colordata-cc-button-colordata-cc-button-text-colordata-cc-text-color+1 more
JS Globals
cc_init
Shortcode Output
[simacookie]
FAQ

Frequently Asked Questions about SimaCookie