Third Party Cookie Eraser Security & Risk Analysis

wordpress.org/plugins/third-party-cookie-eraser

Remove all the occurence of third party embed inside posts, pages and widgets until consent. Plugin requirement PHP >= 5.3

100 active installs v1.0.2 PHP + WP 2.6+ Updated May 26, 2015
cookiecookie-lawthird-party-cookiethird-party-script
64
C · Use Caution
CVEs total1
Unpatched1
Last CVENov 28, 2024
Safety Verdict

Is Third Party Cookie Eraser Safe to Use in 2026?

Use With Caution

Score 64/100

Third Party Cookie Eraser has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Nov 28, 2024Updated 10yr ago
Risk Assessment

The "third-party-cookie-eraser" plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed and unprotected. The code also shows a commitment to secure database interactions, with all SQL queries utilizing prepared statements. However, there are significant concerns, particularly regarding output escaping, where 100% of outputs are unescaped. This presents a strong risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The vulnerability history is also a major red flag, with one unpatched medium-severity CVE for Cross-Site Request Forgery (CSRF) dating from late 2024. The presence of an unpatched vulnerability, even if medium, indicates a lack of ongoing maintenance and a potential entry point for attackers. While the plugin has strengths in its limited attack surface and secure database practices, the critical lack of output escaping and the existence of an unpatched CSRF vulnerability significantly elevate the risk profile.

Key Concerns

  • Unpatched CVE
  • All outputs unescaped
  • Capability check present, but 0% output escaping
Vulnerabilities
1

Third Party Cookie Eraser Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-53755medium · 6.1Cross-Site Request Forgery (CSRF)

Third Party Cookie Eraser <= 1.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Nov 28, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Third Party Cookie Eraser Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ThirdPartyCookieEraserOptions (third-party-cookie-eraser.php:129)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Third Party Cookie Eraser Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuthird-party-cookie-eraser.php:53
filterthe_contentthird-party-cookie-eraser.php:61
filterwidget_display_callbackthird-party-cookie-eraser.php:63
filterwidget_display_callbackthird-party-cookie-eraser.php:97
actionadmin_menuthird-party-cookie-eraser.php:121
actioninitthird-party-cookie-eraser.php:221
Maintenance & Trust

Third Party Cookie Eraser Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 26, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Third Party Cookie Eraser Developer Profile

Andrea Pernici

6 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Third Party Cookie Eraser

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/third-party-cookie-eraser/third-party-cookie-eraser.php
Version Parameters
third-party-cookie-eraser/third-party-cookie-eraser.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Third Party Cookie Eraser