
tarteaucitron.io Security & Risk Analysis
wordpress.org/plugins/tarteaucitronjsCompliant and accessible cookie banner.
Is tarteaucitron.io Safe to Use in 2026?
Generally Safe
Score 96/100tarteaucitron.io has a strong security track record. Known vulnerabilities have been patched promptly.
The "tarteaucitronjs" v1.31.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified SQL queries utilize prepared statements. The presence of nonce and capability checks, though limited, is also a good sign. However, a significant concern arises from the output escaping, with only 19% of outputs being properly escaped. This low rate indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities, which aligns with the plugin's vulnerability history. Furthermore, the taint analysis shows one flow with unsanitized paths, which, while not classified as critical or high, still represents a potential security weakness that could be exploited. The plugin's vulnerability history, with 3 known CVEs including high and medium severity issues related to XSS and CSRF, reinforces the concerns about input sanitization and output escaping. The most recent vulnerability in 2025 suggests a continued pattern of such issues. While the current version has no unpatched vulnerabilities and a contained attack surface, the recurring nature of XSS and CSRF in its history, coupled with poor output escaping, warrants caution.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized paths
- Known high severity CVE in history
- Known medium severity CVE in history
- Recurring XSS and CSRF vulnerability types
tarteaucitron.io Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
tarteaucitron.io <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
tarteaucitron.js – Cookies legislation & GDPR (WordPress plugin) <= 1.6 - Cross-Site Scripting
tarteaucitron.js – Cookies legislation & GDPR <= 1.5.4 - Cross-Site Request Forgery to Cross-Site Scripting
tarteaucitron.io Code Analysis
Output Escaping
Data Flow Analysis
tarteaucitron.io Attack Surface
WordPress Hooks 24
Maintenance & Trust
tarteaucitron.io Maintenance & Trust
Maintenance Signals
Community Trust
tarteaucitron.io Alternatives
Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch
axeptio-sdk-integration
Axeptio is the best solution to make your website GDPR compatible and make your visitors smile!
Cookie Dough Compliance and Consent for GDPR
cookie-dough-compliance-and-consent-for-gdpr
Cookie Dough Compliance and Consent for GDPR is a GDPR cookie consent extension. Style your modal cookie.
GDPR Settings for WooCommerce
gdpr-settings-for-wc
Adapt your e-commerce to the GDPR rules. This plugin allows you to easily add a check box to the woocommerce checkout to obtain the consent of the us …
HOB Advanced Cookies for WordPress
advanced-cookies
Bring your site into compliance with the GDPR and Cookies legislation.
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
tarteaucitron.io Developer Profile
2 plugins · 14K total installs
How We Detect tarteaucitron.io
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tarteaucitronjs/css/user.css/wp-content/plugins/tarteaucitronjs/css/admin-bar.min.csshttps://cdntag.tarteaucitron.io/load.jstarteaucitronjs/css/user.css?ver=tarteaucitronjs/css/admin-bar.min.css?ver=HTML / DOM Fingerprints
youtube_playervimeo_playerdailymotion_player<!--cloudflare-no-transform-->videoIDthemerelcontrolsshowinfoautoplaytarteaucitron.job