
SimaCookie Security & Risk Analysis
wordpress.org/plugins/simasicher-dsgvo-cookieBlock all cookies without consent and customize the cookie note as you wish.
Is SimaCookie Safe to Use in 2026?
High Risk
Score 42/100SimaCookie carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The 'simasicher-dsgvo-cookie' plugin v1.3.2 exhibits a mixed security posture. On the positive side, the code analysis shows a complete absence of dangerous functions and SQL queries that are not prepared, which are significant strengths. Furthermore, file operations and external HTTP requests are not utilized, reducing potential attack vectors. However, there are notable concerns, particularly regarding the output escaping, where only 71% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to improper neutralization, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled correctly.
The vulnerability history is a major red flag, with two currently unpatched medium severity CVEs. The types of past vulnerabilities, including XSS and Cross-Site Request Forgery (CSRF), align with the potential risks identified in the static analysis (unescaped output). The fact that the last vulnerability was in the future (2025-09-05) strongly suggests this data is either hypothetical or has been manipulated, but if treated as real, it implies a recurring pattern of security weaknesses that have not been adequately addressed.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and avoiding dangerous functions, the unpatched vulnerabilities and incomplete output escaping present significant risks. The presence of unpatched medium severity issues necessitates immediate attention, and the historical pattern suggests a need for more robust security development and testing practices.
Key Concerns
- Unpatched CVE (2 medium severity)
- Incomplete output escaping (29% unescaped)
- Missing nonce checks (0 found)
SimaCookie Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SimaCookie <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
SimaCookie <= 1.3.2 - Cross-Site Request Forgery
SimaCookie Release Timeline
SimaCookie Code Analysis
Bundled Libraries
Output Escaping
SimaCookie Attack Surface
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
SimaCookie Maintenance & Trust
Maintenance Signals
Community Trust
SimaCookie Alternatives
Mr Cookies
mrcookies
MrCookies plugin adapts your Wordpress to satisfy the European cookies laws.
ATR Cookie Notice
atr-cookie-notice
Cookie consent banner aligned with Israel's Privacy Protection Law (Amendment 13).
Lawwwing | Textos legales web y Banner de cookies
ibamu
Lawwwing te permite tener actualizados todos los textos legales de tu web: Aviso legal, Política de Privacidad y Cookies, Términos de uso, Condiciones …
ELAN42-disclaimer
disclaimer-by-elan42
Adds configurable Credits / Privacy Policy for the European Cookies Law and GDPR, with links / ajax / hover box.
GDPR Simple Notification
simple-cookie-notification
GDPR Simple Notification is a lightweight plugin inform users about using cookies and about your privacy policy according to GDPR privacy policy
SimaCookie Developer Profile
1 plugin · 60 total installs
How We Detect SimaCookie
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simasicher-dsgvo-cookie/css/style_admin.css/wp-content/plugins/simasicher-dsgvo-cookie/js/eucookiesettings.js/wp-content/plugins/simasicher-dsgvo-cookie/css/style.css/wp-content/plugins/simasicher-dsgvo-cookie/js/cookieconsent.js/wp-content/plugins/simasicher-dsgvo-cookie/js/eucookiesettings.js/wp-content/plugins/simasicher-dsgvo-cookie/js/cookieconsent.jssimasicher-dsgvo-cookie/css/style_admin.css?ver=simasicher-dsgvo-cookie/js/eucookiesettings.js?ver=simasicher-dsgvo-cookie/css/style.css?ver=simasicher-dsgvo-cookie/js/cookieconsent.js?ver=HTML / DOM Fingerprints
sima_containersima_columnsima_column_leftsima_input_smallcc_divcc_bannercc_btncc_btn_accept+2 moredata-cc-animatedata-cc-bgdata-cc-colordata-cc-button-colordata-cc-button-text-colordata-cc-text-color+1 morecc_init[simacookie]