
Termly – GDPR/CCPA Cookie Consent Banner Security & Risk Analysis
wordpress.org/plugins/uk-cookie-consentOur easy to use cookie consent plugin can assist in your GDPR, CCPA, and ePrivacy Directive compliance efforts.
Is Termly – GDPR/CCPA Cookie Consent Banner Safe to Use in 2026?
Generally Safe
Score 99/100Termly – GDPR/CCPA Cookie Consent Banner has a strong security track record. Known vulnerabilities have been patched promptly.
The 'uk-cookie-consent' plugin v3.3.1 exhibits a generally good security posture based on the static analysis. It demonstrates a low attack surface with no unprotected entry points. The code follows many security best practices, including 100% use of prepared statements for SQL queries and a high percentage of properly escaped output. Nonce and capability checks are also present, indicating an awareness of common WordPress security vulnerabilities. However, the plugin's history of two medium-severity vulnerabilities, specifically related to Missing Authorization and Cross-site Scripting, raises a significant concern. While these appear to be patched, their existence suggests potential weaknesses in input validation or authorization logic that could be re-introduced or exploited in future versions if not rigorously maintained. The presence of external HTTP requests, while not inherently insecure, could be a vector for supply chain attacks if the external services are compromised, though this is a general consideration for many plugins.
Key Concerns
- Two medium severity CVEs in history
- External HTTP requests present
Termly – GDPR/CCPA Cookie Consent Banner Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GDPR/CCPA Cookie Consent Banner <= 3.2 - Missing Authorization via handle_consent_toggle()
Catapult UK Cookie Consent <= 2.3.9 - Stored Cross-Site Scripting
Termly – GDPR/CCPA Cookie Consent Banner Code Analysis
Output Escaping
Data Flow Analysis
Termly – GDPR/CCPA Cookie Consent Banner Attack Surface
REST API Routes 1
WordPress Hooks 29
Scheduled Events 1
Maintenance & Trust
Termly – GDPR/CCPA Cookie Consent Banner Maintenance & Trust
Maintenance Signals
Community Trust
Termly – GDPR/CCPA Cookie Consent Banner Alternatives
DigiConsent – Cookie Consent Banner for GDPR, CCPA & ePrivacy Compliance
digiconsent
Cookie consent solution for WordPress. GDPR, CCPA, LGPD & ePrivacy compliant banners with analytics and geolocation support.
PN Cookies Manager
pn-cookies-manager
Manage cookies on your website. Configure cookie consent banners, categorize cookies, and ensure compliance with privacy regulations.
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law
gdpr-cookie-compliance
Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode
cookiebot
Install your cookie banner in minutes. Automatically scan and block cookies to comply with the GDPR, CCPA, Google Consent Mode v2. Free plan option.
Termly – GDPR/CCPA Cookie Consent Banner Developer Profile
1 plugin · 90K total installs
How We Detect Termly – GDPR/CCPA Cookie Consent Banner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uk-cookie-consent/dist/css/termly.cssuk-cookie-consent/style.css?ver=uk-cookie-consent/script.js?ver=uk-cookie-consent/dist/css/termly.css?ver=HTML / DOM Fingerprints
termly-cookie-banner-containertermly-modal-overlaytermly-modal-content<!-- Termly Cookie Consent --><!-- End Termly Cookie Consent -->data-termly-iddata-termly-domaindata-termly-urlwindow.Termly/wp-json/termly/v1/settings/wp-json/termly/v1/scan[termly_cookie_banner][termly_privacy_policy][termly_terms_of_service]