
Third Party Cookie Eraser Security & Risk Analysis
wordpress.org/plugins/third-party-cookie-eraserRemove all the occurence of third party embed inside posts, pages and widgets until consent. Plugin requirement PHP >= 5.3
Is Third Party Cookie Eraser Safe to Use in 2026?
Use With Caution
Score 64/100Third Party Cookie Eraser has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "third-party-cookie-eraser" plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed and unprotected. The code also shows a commitment to secure database interactions, with all SQL queries utilizing prepared statements. However, there are significant concerns, particularly regarding output escaping, where 100% of outputs are unescaped. This presents a strong risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The vulnerability history is also a major red flag, with one unpatched medium-severity CVE for Cross-Site Request Forgery (CSRF) dating from late 2024. The presence of an unpatched vulnerability, even if medium, indicates a lack of ongoing maintenance and a potential entry point for attackers. While the plugin has strengths in its limited attack surface and secure database practices, the critical lack of output escaping and the existence of an unpatched CSRF vulnerability significantly elevate the risk profile.
Key Concerns
- Unpatched CVE
- All outputs unescaped
- Capability check present, but 0% output escaping
Third Party Cookie Eraser Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Third Party Cookie Eraser <= 1.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Third Party Cookie Eraser Code Analysis
Output Escaping
Data Flow Analysis
Third Party Cookie Eraser Attack Surface
WordPress Hooks 6
Maintenance & Trust
Third Party Cookie Eraser Maintenance & Trust
Maintenance Signals
Community Trust
Third Party Cookie Eraser Alternatives
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
gdpr-cookie-consent
WPLP Cookie Consent helps WordPress website owners display cookie consent banners, manage user preferences, and control third-party scripts in line wi …
Italy Cookie Choices (for EU Cookie Law & Cookie Notice)
italy-cookie-choices
The most complete cookie consent to easily comply with the european cookie law, display cookie notice and block third party cookie without degrading w …
LuckyWP Cookie Notice (GDPR)
luckywp-cookie-notice-gdpr
The plugin allows you to notify visitors about the use of cookies (necessary to comply with the GDPR in the EU).
WF Cookie Consent
wf-cookie-consent
The wunderfarm-way to show how your website complies with the EU Cookie Law - very easy, 100% responsive and with multi-language support!
EU Cookies Bar for WordPress
eu-cookies-bar
Ensure GDPR (General Data Protection Regulation) compliance (EU Cookie Law) with our straightforward cookie bar
Third Party Cookie Eraser Developer Profile
6 plugins · 1K total installs
How We Detect Third Party Cookie Eraser
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/third-party-cookie-eraser/third-party-cookie-eraser.phpthird-party-cookie-eraser/third-party-cookie-eraser.php?ver=