Zestard Cookie Consent Security & Risk Analysis

wordpress.org/plugins/zestard-cookie-consent

Display cookie bar in your website which is fully customizable.

0 active installs v1.0.5 PHP 7.0+ WP 5.0+ Updated Apr 17, 2025
cookie-barcookie-consentcookieszestard
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zestard Cookie Consent Safe to Use in 2026?

Generally Safe

Score 92/100

Zestard Cookie Consent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of zestard-cookie-consent v1.0.5 appears generally positive based on the static analysis. There are no identified dangerous functions, SQL queries use prepared statements exclusively, and no file operations or external HTTP requests were detected. The absence of vulnerability history, including CVEs, further suggests a stable and well-maintained code base.

However, a significant concern arises from the "Output escaping" metric, with 55% of outputs being properly escaped. This indicates a substantial portion of dynamic content displayed by the plugin might be vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being rendered. Additionally, the complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron events) is a major oversight. While the attack surface is currently reported as zero, any future addition of these features without proper authentication and authorization mechanisms would expose the plugin to significant risks.

In conclusion, while the plugin benefits from a clean vulnerability history and secure database practices, the poor output escaping and the absence of robust authentication/authorization checks on potential entry points represent critical weaknesses that need immediate attention. The lack of taint analysis flows could be due to the static analysis tool's limitations or the plugin's simplicity, but the output escaping issue is a clear and present danger.

Key Concerns

  • Inadequate output escaping
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Zestard Cookie Consent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zestard Cookie Consent Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Zestard Cookie Consent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
78 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped143 total outputs
Attack Surface

Zestard Cookie Consent Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptszestard-cookie-consent.php:86
actionadmin_enqueue_scriptszestard-cookie-consent.php:88
actionadmin_menuzestard-cookie-consent.php:90
actionadmin_initzestard-cookie-consent.php:92
actionwp_enqueue_scriptszestard-cookie-consent.php:96
actionwp_footerzestard-cookie-consent.php:98
Maintenance & Trust

Zestard Cookie Consent Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zestard Cookie Consent Developer Profile

Zestard Technologies

3 plugins · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zestard Cookie Consent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zestard-cookie-consent/admin/css/ztpl-admin-settings.css/wp-content/plugins/zestard-cookie-consent/admin/js/ztpl-admin-settings.js/wp-content/plugins/zestard-cookie-consent/admin/js/ztpl-clr-picker.js/wp-content/plugins/zestard-cookie-consent/public/css/ztpl-public-settings.css/wp-content/plugins/zestard-cookie-consent/public/js/ztpl-public-settings.js
Script Paths
/wp-content/plugins/zestard-cookie-consent/admin/js/ztpl-admin-settings.js/wp-content/plugins/zestard-cookie-consent/admin/js/ztpl-clr-picker.js/wp-content/plugins/zestard-cookie-consent/public/js/ztpl-public-settings.js
Version Parameters
zestard-cookie-consent/admin/css/ztpl-admin-settings.css?ver=zestard-cookie-consent/admin/js/ztpl-admin-settings.js?ver=zestard-cookie-consent/admin/js/ztpl-clr-picker.js?ver=zestard-cookie-consent/public/css/ztpl-public-settings.css?ver=zestard-cookie-consent/public/js/ztpl-public-settings.js?ver=

HTML / DOM Fingerprints

HTML Comments
Copyright 2019 Zestard TechnologiesThis program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+8 more
Data Attributes
ztpl-cookie-consentztpl-cookie-bar
JS Globals
ztpl_cookie_consent
FAQ

Frequently Asked Questions about Zestard Cookie Consent