
Surbma | GDPR Proof Cookie Consent & Notice Bar Security & Risk Analysis
wordpress.org/plugins/surbma-gdpr-proof-google-analyticsThis plugin helps your website to comply with GDPR cookie regulations by asking every visitors to accept or decline cookie tracking.
Is Surbma | GDPR Proof Cookie Consent & Notice Bar Safe to Use in 2026?
Generally Safe
Score 100/100Surbma | GDPR Proof Cookie Consent & Notice Bar has a strong security track record. Known vulnerabilities have been patched promptly.
The "surbma-gdpr-proof-google-analytics" plugin version 17.9.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no raw SQL queries (all prepared), no file operations, no external HTTP requests, and a commendable lack of direct entry points like AJAX handlers, REST API routes, or shortcodes without proper authentication checks. The presence of capability checks and a small number of total outputs, even with a concerning percentage unescaped, suggests some effort towards security. However, the significantly low percentage of properly escaped output (24%) is a major concern and represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history shows a past medium-severity XSS vulnerability, which aligns with the findings from the static analysis regarding unescaped output. While there are no currently unpatched CVEs, the pattern of XSS vulnerabilities, coupled with the high rate of unescaped output, indicates a recurring weakness. The bundled Freemius library, while not explicitly flagged as outdated, warrants attention as bundled libraries can introduce vulnerabilities if not maintained. Overall, while the plugin has a small attack surface and avoids common pitfalls like direct SQL injection, the prevalent issue of unescaped output presents a tangible risk that could be exploited by attackers.
Key Concerns
- Low percentage of properly escaped output
- Past medium-severity XSS vulnerability
- Bundled Freemius v1.0 library
Surbma | GDPR Proof Cookie Consent & Notice Bar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Surbma | GDPR Proof Cookie Consent & Notice Bar <= 17.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Surbma | GDPR Proof Cookie Consent & Notice Bar Code Analysis
Bundled Libraries
Output Escaping
Surbma | GDPR Proof Cookie Consent & Notice Bar Attack Surface
WordPress Hooks 17
Maintenance & Trust
Surbma | GDPR Proof Cookie Consent & Notice Bar Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | GDPR Proof Cookie Consent & Notice Bar Alternatives
CookiePro | Simplify Compliance with GDPR & EU Cookie Laws
cookiepro
CookiePro is the most mature and trusted cookie consent tool that is purpose-built for compliance with GDPR, ePrivacy and IAB framework.
Mini WP GDPR
mini-wp-gdpr
A lightweight and easy-to-use tool to help you with your GDPR compliance tasks.
PrivacyPillar | Get compliant with GDPR, CCPA, and Global cookie policy
adzapier
PrivacyPillar is a highly secure and seamless application to collect and manage your website visitors’ consent and preferences.
CookieGo | Streamlining Cookie Compliance Management
cookiego
CookieGo is a cookie consent tool specifically designed for adherence to privacy compliance.
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
Surbma | GDPR Proof Cookie Consent & Notice Bar Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | GDPR Proof Cookie Consent & Notice Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/css/frontend.css/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend.js/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend-gtag.js/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend-fb.js/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend.js/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend-gtag.js/wp-content/plugins/surbma-gdpr-proof-google-analytics/assets/js/frontend-fb.jssurbma-gdpr-proof-google-analytics/assets/css/frontend.css?ver=surbma-gdpr-proof-google-analytics/assets/js/frontend.js?ver=surbma-gdpr-proof-google-analytics/assets/js/frontend-gtag.js?ver=surbma-gdpr-proof-google-analytics/assets/js/frontend-fb.js?ver=HTML / DOM Fingerprints
surbma-gpga-popup<!-- SURBMA GPGA: START GTAG CONFIGURATION --><!-- SURBMA GPGA: END GTAG CONFIGURATION --><!-- SURBMA GPGA: START FACEBOOK PIXEL CONFIGURATION --><!-- SURBMA GPGA: END FACEBOOK PIXEL CONFIGURATION -->data-cookie-durationdata-cookie-namedata-noncedata-gprdata-policy-idsurbma_gpga_frontendsurbma_gpga_frontend_gtagsurbma_gpga_frontend_fb