Smart Cookie Kit Security & Risk Analysis

wordpress.org/plugins/smart-cookie-kit

Preventive blocking of third party cookies for GDPR/EU Cookie Law/ePrivacy. Translatable, cacheable, lightweight, powerful!

3K active installs v2.3.2 PHP + WP 4.6+ Updated Oct 6, 2023
bannercookiecookie-laweprivacygdpr
85
A · Safe
CVEs total1
Unpatched0
Last CVEOct 6, 2023
Safety Verdict

Is Smart Cookie Kit Safe to Use in 2026?

Generally Safe

Score 85/100

Smart Cookie Kit has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 6, 2023Updated 2yr ago
Risk Assessment

The smart-cookie-kit plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no critical security signals such as dangerous functions, raw SQL queries, or unsanitized paths in taint flows. It also has no known unpatched vulnerabilities. However, significant concerns arise from the complete lack of output escaping, meaning that all 59 identified outputs are vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on any entry points (AJAX, REST API, shortcodes, cron jobs) leaves all potential attack vectors exposed to unauthorized or unauthenticated users. The vulnerability history shows a past medium severity XSS vulnerability, which, combined with the current lack of output escaping, suggests a persistent issue with handling user-supplied data safely.

Key Concerns

  • 0% of outputs properly escaped
  • 0 nonce checks found
  • 0 capability checks found
  • 1 medium severity CVE in history
Vulnerabilities
1 published

Smart Cookie Kit Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-45608medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smart Cookie Kit <= 2.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 6, 2023 Patched in 2.3.2 (109d)
Version History

Smart Cookie Kit Release Timeline

v2.3.2Current
v2.3.11 CVE
v2.3.01 CVE
v2.2.41 CVE
v2.2.31 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.31 CVE
v2.1.21 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.2.51 CVE
Code Analysis
Analyzed Mar 16, 2026

Smart Cookie Kit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
59
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped59 total outputs
Attack Surface

Smart Cookie Kit Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Smart Cookie Kit Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedOct 6, 2023
PHP min version
Downloads62K

Community Trust

Rating100/100
Number of ratings40
Active installs3K
Developer Profile

Smart Cookie Kit Developer Profile

Nicola Modugno

1 plugin · 3K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
109 days
View full developer profile
Detection Fingerprints

How We Detect Smart Cookie Kit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-cookie-kit/css/sck.css/wp-content/plugins/smart-cookie-kit/css/smart-cookie-kit.css/wp-content/plugins/smart-cookie-kit/js/admin.js/wp-content/plugins/smart-cookie-kit/js/frontend.js/wp-content/plugins/smart-cookie-kit/js/vendors/cookieConsent.js/wp-content/plugins/smart-cookie-kit/js/vendors/pretty-checkbox.min.js/wp-content/plugins/smart-cookie-kit/js/vendors/vue.js
Script Paths
/wp-content/plugins/smart-cookie-kit/js/admin.js/wp-content/plugins/smart-cookie-kit/js/frontend.js
Version Parameters
smart-cookie-kit/css/sck.css?ver=smart-cookie-kit/css/smart-cookie-kit.css?ver=smart-cookie-kit/js/admin.js?ver=smart-cookie-kit/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
scc-cookie-wrapperscc-cookie-buttonsscc-privacy-link
HTML Comments
<!-- SmartCookieKit --><!-- SmartCookieKit : START --><!-- SmartCookieKit : END --><!-- SmartCookieKit : IMPORTANT : PLEASE DO NOT REMOVE THIS COMMENT -->
Data Attributes
data-cookie-consentdata-scc-iddata-scc-close-textdata-scc-btn-text
JS Globals
SmartCookieKitscc_config
REST Endpoints
/wp-json/nmod/sck/v1/settings/wp-json/nmod/sck/v1/privacy-policy
Shortcode Output
[smart_cookie_kit][scc_cookie_banner][scc_privacy_policy_link][scc_accept_cookies_button]
FAQ

Frequently Asked Questions about Smart Cookie Kit