
Site Cookie Setting Security & Risk Analysis
wordpress.org/plugins/site-cookie-settingDescription The plugin adds a HTML snippet of Cookie on a Web Page. Installation Upload the plugin files to the /wp-content/plugins/site-cookie-setti …
Is Site Cookie Setting Safe to Use in 2026?
Generally Safe
Score 85/100Site Cookie Setting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "site-cookie-setting" plugin, version 1.0, exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the static analysis did not reveal dangerous functions, file operations, or external HTTP requests, the absence of authentication checks on all six identified AJAX entry points presents a substantial risk. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if the underlying functionality is not robustly secured.
The lack of capability checks and nonce checks further exacerbates this risk. The absence of proper authorization and CSRF protection on AJAX endpoints is a major security oversight. Although the plugin has no recorded vulnerability history, this should not be interpreted as a sign of strong security. It may simply indicate that no vulnerabilities have been discovered or reported yet. The plugin's reliance on prepared statements for SQL queries and generally good output escaping are positive aspects, but they do not mitigate the fundamental issue of unprotected entry points.
In conclusion, while the plugin demonstrates some good coding practices in areas like SQL query handling and output sanitization, the critical vulnerability of unprotected AJAX handlers casts a long shadow over its security. The absence of any security checks on these entry points makes it highly susceptible to attacks, and immediate remediation is strongly advised. The lack of past vulnerabilities should not breed complacency; proactive security measures are essential for this plugin.
Key Concerns
- 6 AJAX handlers without auth checks
- 0 Nonce checks
- 0 Capability checks
Site Cookie Setting Security Vulnerabilities
Site Cookie Setting Code Analysis
SQL Query Safety
Output Escaping
Site Cookie Setting Attack Surface
AJAX Handlers 6
WordPress Hooks 5
Maintenance & Trust
Site Cookie Setting Maintenance & Trust
Maintenance Signals
Community Trust
Site Cookie Setting Alternatives
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
Simple Sitemap – Create a Responsive HTML Sitemap
simple-sitemap
Create a HTML sitemap and preview directly inside the editor! No more complicated shortcodes. Boost the SEO performance of your WordPress site.
Animate It!
animate-it
Add cool CSS3 animations to your content.
Raw HTML
raw-html
Lets you use raw HTML or any other code in your posts. You can also disable smart quotes and other automatic formatting on a per-post basis.
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
Site Cookie Setting Developer Profile
1 plugin · 0 total installs
How We Detect Site Cookie Setting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-cookie-setting/assets/css/scs_style.css/wp-content/plugins/site-cookie-setting/assets/js/scs_script.jssite-cookie-setting/assets/css/scs_style.css?ver=site-cookie-setting/assets/js/scs_script.js?ver=HTML / DOM Fingerprints
wpAjax