Simple GDPR Cookie Compliance Security & Risk Analysis

wordpress.org/plugins/simple-gdpr-cookie-compliance

Simple GDPR Cookie Compliance is a simple plugin that helps to display cookie notice on your WordPress website.

5K active installs v2.0.1 PHP 7.4+ WP 5.6+ Updated Feb 15, 2026
ccpacookie-consentcookie-noticecookie-privacygdpr
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 14, 2026
Safety Verdict

Is Simple GDPR Cookie Compliance Safe to Use in 2026?

Generally Safe

Score 99/100

Simple GDPR Cookie Compliance has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 14, 2026Updated 1mo ago
Risk Assessment

The static analysis of simple-gdpr-cookie-compliance v2.0.1 indicates a generally good security posture, with several positive indicators. The absence of dangerous functions, SQL queries without prepared statements, and unsanitized paths in taint analysis are strong points. The high percentage of properly escaped output further suggests diligent coding practices regarding data handling. The plugin also demonstrates a commitment to security by incorporating capability checks for its cron events.

However, there are areas for concern. The lack of nonce checks and the presence of external HTTP requests without clear details on their handling could potentially introduce vulnerabilities if not implemented securely. The vulnerability history, while showing no currently unpatched CVEs, does reveal a past medium vulnerability attributed to missing authorization. This historical pattern, combined with the absence of nonce checks, warrants a cautious approach, as authorization weaknesses can be exploited if input validation or authorization checks are insufficient.

Overall, the plugin exhibits good coding practices in many areas. The primary weaknesses lie in the potential for authorization bypasses (indicated by historical CVEs and lack of explicit nonce checks on certain entry points) and the handling of external HTTP requests. While the attack surface appears small and well-protected from a code perspective, the historical vulnerability and certain code signals suggest areas where ongoing vigilance and potentially further hardening are advisable.

Key Concerns

  • Past medium vulnerability: Missing Authorization
  • External HTTP requests without auth/sanitization details
  • No nonce checks on identified entry points
Vulnerabilities
1

Simple GDPR Cookie Compliance Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-24604medium · 5.3Missing Authorization

Simple GDPR Cookie Compliance <= 2.0.0 - Missing Authorization

Jan 14, 2026 Patched in 2.0.1 (42d)
Code Analysis
Analyzed Mar 16, 2026

Simple GDPR Cookie Compliance Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
38 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped40 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
process_user_tracking_choice (includes\udp\class-udp-agent.php:174)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple GDPR Cookie Compliance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_enqueue_scriptsapp.php:11
actionrest_api_initincludes\class-simple-gdpr-cookie-compliance-rest-api.php:39
actionplugins_loadedincludes\class-simple-gdpr-cookie-compliance.php:172
actionadmin_menuincludes\class-simple-gdpr-cookie-compliance.php:188
filterplugin_row_metaincludes\class-simple-gdpr-cookie-compliance.php:193
actionwp_enqueue_scriptsincludes\class-simple-gdpr-cookie-compliance.php:210
actionwp_enqueue_scriptsincludes\class-simple-gdpr-cookie-compliance.php:211
actionwp_footerincludes\class-simple-gdpr-cookie-compliance.php:212
actionwp_enqueue_scriptsincludes\class-simple-gdpr-cookie-compliance.php:213
filtersimple_gdpr_cookie_compliance_basic_option_fieldsincludes\setting-functions\fields\basic-options.php:48
filtersimple_gdpr_cookie_compliance_button_options_fieldsincludes\setting-functions\fields\button-options.php:83
filtersimple_gdpr_cookie_compliance_developer_options_fieldsincludes\setting-functions\fields\developer-options.php:30
filtersimple_gdpr_cookie_compliance_layout_options_fieldsincludes\setting-functions\fields\layout-options.php:125
filtersimple_gdpr_settings_fieldsincludes\setting-functions\settings.php:149
actioninitincludes\udp\class-udp-agent.php:76
actionadmin_initincludes\udp\class-udp-agent.php:77
actioninitincludes\udp\class-udp-agent.php:80
actionadmin_initincludes\udp\init.php:53
actionload-index.phpincludes\udp\init.php:113
actionadmin_noticesincludes\udp\init.php:116
actioncc_udp_agent_send_dataincludes\udp\init.php:179
actionafter_switch_themeincludes\udp\init.php:184
actionactivate_pluginincludes\udp\init.php:213
actiondeactivate_pluginincludes\udp\init.php:223
actionswitch_themeincludes\udp\init.php:254

Scheduled Events 3

cc_udp_agent_send_data
cc_udp_agent_send_data
cc_udp_agent_send_data
Maintenance & Trust

Simple GDPR Cookie Compliance Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 15, 2026
PHP min version7.4
Downloads46K

Community Trust

Rating98/100
Number of ratings12
Active installs5K
Developer Profile

Simple GDPR Cookie Compliance Developer Profile

themebeez

8 plugins · 27K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
135 days
View full developer profile
Detection Fingerprints

How We Detect Simple GDPR Cookie Compliance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-gdpr-cookie-compliance/public/css/cookie-notice.css/wp-content/plugins/simple-gdpr-cookie-compliance/public/js/cookie-notice.js/wp-content/plugins/simple-gdpr-cookie-compliance/public/css/bootstrap.min.css
Script Paths
/wp-content/plugins/simple-gdpr-cookie-compliance/public/js/cookie-notice.js
Version Parameters
simple-gdpr-cookie-compliance/public/css/cookie-notice.css?ver=simple-gdpr-cookie-compliance/public/js/cookie-notice.js?ver=simple-gdpr-cookie-compliance/public/css/bootstrap.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
simple-gdpr-cookie-compliancetb-cookie-notice-btntb-cookie-notice-main
HTML Comments
<!--TB_cookie_notice--><!--TB_cookie_notice-->
Data Attributes
data-cookie-notice-id
JS Globals
simple_gdpr_cookie_compliance_obj
REST Endpoints
/wp-json/simple-gdpr-cookie-compliance/v1/accept-cookie
FAQ

Frequently Asked Questions about Simple GDPR Cookie Compliance