
TLCC GDPR Cookie Consent Security & Risk Analysis
wordpress.org/plugins/tlcc-gdpr-cookie-consentProfessional GDPR/ePrivacy cookie consent with modern UI, category consent, script & content blocking, optional Google Consent Mode v2, and anonym …
Is TLCC GDPR Cookie Consent Safe to Use in 2026?
Generally Safe
Score 100/100TLCC GDPR Cookie Consent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of tlcc-gdpr-cookie-consent v2.0.1 indicates a generally good security posture with several positive findings. The plugin utilizes 100% proper output escaping and implements nonce checks and capability checks for its entry points, which are crucial for preventing common WordPress vulnerabilities. There are no recorded vulnerabilities or CVEs for this plugin, suggesting a history of secure development and maintenance.
However, there are notable concerns regarding its database interaction. All three identified SQL queries are not using prepared statements, which significantly increases the risk of SQL injection vulnerabilities. While no taint flows with unsanitized paths were identified, the direct execution of raw SQL queries without proper sanitization and parameterization is a serious weakness. The presence of file operations also warrants attention, although without further context or taint analysis, it's difficult to assess its specific risk. The absence of external HTTP requests is a positive sign, as these can sometimes be vectors for attacks.
In conclusion, while the plugin demonstrates strong practices in output escaping and access control, the lack of prepared statements for all SQL queries is a critical security flaw that needs immediate attention. The vulnerability history is clean, which is a strength, but this does not negate the risks identified in the current code. Addressing the SQL query issue should be the top priority.
Key Concerns
- All SQL queries use raw SQL without prepared statements
- Presence of file operations without explicit risk assessment
TLCC GDPR Cookie Consent Security Vulnerabilities
TLCC GDPR Cookie Consent Code Analysis
SQL Query Safety
Output Escaping
TLCC GDPR Cookie Consent Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 7
Maintenance & Trust
TLCC GDPR Cookie Consent Maintenance & Trust
Maintenance Signals
Community Trust
TLCC GDPR Cookie Consent Alternatives
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
real-cookie-banner
Obtain GDPR (DSGVO/RGPD) and ePrivacy Directive (TDDDG/TTDSG, LOPD-GDD, DTA) compliant consents in your cookie banner. More than just a cookie notice!
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode
cookiebot
Install your cookie banner in minutes. Automatically scan and block cookies to comply with the GDPR, CCPA, Google Consent Mode v2. Free plan option.
Termly – GDPR/CCPA Cookie Consent Banner
uk-cookie-consent
Our easy to use cookie consent plugin can assist in your GDPR, CCPA, and ePrivacy Directive compliance efforts.
GDPR Compliance & Cookie Consent
gdpr-compliance-cookie-consent
This plugin adds GDPR-compliant cookie management to websites, ensuring legal compliance and enhancing user privacy.
Avacy CMP
avacy
Overview
TLCC GDPR Cookie Consent Developer Profile
2 plugins · 0 total installs
How We Detect TLCC GDPR Cookie Consent
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tlcc-gdpr-cookie-consent/public/css/consent.css/wp-content/plugins/tlcc-gdpr-cookie-consent/public/js/consent.js/wp-content/plugins/tlcc-gdpr-cookie-consent/admin/css/admin.css/wp-content/plugins/tlcc-gdpr-cookie-consent/admin/js/admin.jstlcc-gdpr-cookie-consent/public/css/consent.css?ver=tlcc-gdpr-cookie-consent/public/js/consent.js?ver=tlcc-gdpr-cookie-consent/admin/css/admin.css?ver=tlcc-gdpr-cookie-consent/admin/js/admin.js?ver=HTML / DOM Fingerprints
tlcc-hiddentlcc-fabtlcc-inline-btntlcc-embedtlcc-embed-iframetlcc-blockTLCC blocked scripts: preferencesTLCC blocked scripts: analyticsTLCC blocked scripts: marketingdata-tlcc-categorydata-tlcc-blockdata-srcTLCCwindow.TLCC_OPENwindow.TLCC_RESET<button type="button" class="tlcc-inline-btn" onclick="window.TLCC_OPEN && window.TLCC_OPEN()"><button type="button" class="tlcc-inline-btn" onclick="window.TLCC_RESET && window.TLCC_RESET()">