{"id":365681,"date":"2026-09-08T17:35:18","date_gmt":"2026-09-08T17:35:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cookiefix-cookie-consent-compliance\/"},"modified":"2026-09-21T04:27:47","modified_gmt":"2026-09-21T04:27:47","slug":"cookiefix-cookie-consent-compliance","status":"publish","type":"plugin","link":"https:\/\/vec.wordpress.org\/plugins\/cookiefix-cookie-consent-compliance\/","author":23458858,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.5","stable_tag":"1.0.5","tested":"7.1.2","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"CookieFix - Cookie Consent & Compliance","header_author":"CookieFix","header_description":"GDPR\/CCPA cookie consent banner, automatic script blocking, and cookie declaration for your WordPress site.","assets_banners_color":"1a3d8a","last_updated":"2026-09-21 04:27:47","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/cookiefix.ro\/wordpress-plugin","header_author_uri":"https:\/\/cookiefix.ro","rating":0,"author_block_rating":0,"active_installs":0,"downloads":163,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.4":{"tag":"1.0.4","author":"inksect","date":"2026-09-08 17:34:41","revision":3687086},"1.0.5":{"tag":"1.0.5","author":"inksect","date":"2026-09-21 04:27:47","revision":3704824}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3687086,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3687086,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3687086,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3687086,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.4","1.0.5"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[166295,20272,16626,131785,396],"plugin_category":[54],"plugin_contributors":[279753],"plugin_business_model":[],"class_list":["post-365681","plugin","type-plugin","status-publish","hentry","plugin_tags-ccpa","plugin_tags-cookie-banner","plugin_tags-cookie-consent","plugin_tags-gdpr","plugin_tags-privacy","plugin_category-security-and-spam-protection","plugin_contributors-inksect","plugin_committers-inksect"],"banners":{"banner":"https:\/\/ps.w.org\/cookiefix-cookie-consent-compliance\/assets\/banner-772x250.png?rev=3687086","banner_2x":"https:\/\/ps.w.org\/cookiefix-cookie-consent-compliance\/assets\/banner-1544x500.png?rev=3687086","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/cookiefix-cookie-consent-compliance\/assets\/icon-128x128.png?rev=3687086","icon_2x":"https:\/\/ps.w.org\/cookiefix-cookie-consent-compliance\/assets\/icon-256x256.png?rev=3687086","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>CookieFix is a Consent Management Platform (CMP) that helps your WordPress site comply with GDPR, CCPA, and ePrivacy regulations.<\/p>\n\n<p><strong>Features:<\/strong><\/p>\n\n<ul>\n<li>Automatic third-party script blocking until visitor consent<\/li>\n<li>Customizable consent banner (colors, text, position)<\/li>\n<li>Cookie declaration table via shortcode<\/li>\n<li>Google Consent Mode v2 support<\/li>\n<li>TCF 2.0 compatible<\/li>\n<li>Multi-language support (auto-detection)<\/li>\n<li>WooCommerce compatible<\/li>\n<li>Works with all caching plugins<\/li>\n<\/ul>\n\n<p><strong>How it works:<\/strong><\/p>\n\n<ol>\n<li>The plugin injects a lightweight inline script into your site's <code>&lt;head&gt;<\/code><\/li>\n<li>This script automatically blocks third-party cookies and tracking scripts<\/li>\n<li>A consent banner appears asking visitors for their preferences<\/li>\n<li>Scripts are only unblocked after the visitor gives consent<\/li>\n<li>All consent records are stored for GDPR compliance proof<\/li>\n<\/ol>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the CookieFix consent management service (operated by CookieFix, https:\/\/cookiefix.ro). It is a client for that service and does not work without a CookieFix account and Domain Key.<\/p>\n\n<p><strong>What is loaded and sent, and when:<\/strong><\/p>\n\n<ul>\n<li>On every front-end page load, the plugin outputs an inline script that fetches the consent widget from <code>https:\/\/cdn.cookiefix.ro\/cc.js<\/code> (with <code>https:\/\/cookiefix.ro\/api\/public\/widget<\/code> as a fallback) and the banner configuration for your Domain Key from <code>https:\/\/cookiefix.ro\/api\/public\/config\/{domain-key}<\/code>. The request includes the visitor's IP address and user agent, as any HTTP request does.<\/li>\n<li>When a visitor accepts, rejects or customizes cookie categories, the choice is sent to <code>https:\/\/cookiefix.ro\/api\/public\/consent<\/code> together with an anonymous consent identifier, the chosen categories, the page URL, the banner version and the visitor's user agent. The IP address is used only to derive the country and is stored hashed. This record is the site owner's proof of consent under GDPR.<\/li>\n<li>When you save the Domain Key in Settings &gt; CookieFix, the plugin validates it against <code>https:\/\/cookiefix.ro\/api\/public\/config\/{domain-key}<\/code>.<\/li>\n<li>The <code>[cookiefix_declaration]<\/code> shortcode loads the cookie declaration table for your domain from <code>https:\/\/cdn.cookiefix.ro\/cd.js<\/code>.<\/li>\n<\/ul>\n\n<p>No data is sent to CookieFix from the WordPress admin other than the Domain Key validation above. The plugin does not send any data about your WordPress users.<\/p>\n\n<p>Terms of service: https:\/\/cookiefix.ro\/en\/terms\nPrivacy policy: https:\/\/cookiefix.ro\/en\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>cookiefix<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' menu<\/li>\n<li>Go to Settings &gt; CookieFix<\/li>\n<li>Enter your Domain Key from the <a href=\"https:\/\/cookiefix.ro\/dashboard\">CookieFix Dashboard<\/a><\/li>\n<li>Save settings - the banner will appear on your site immediately<\/li>\n<\/ol>\n\n<p><strong>To display a cookie declaration table:<\/strong><\/p>\n\n<p>Add the shortcode <code>[cookiefix_declaration]<\/code> to any page or post.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"my%20site%20uses%20a%20content-security-policy.%20what%20do%20i%20need%20to%20allow%3F\"><h3>My site uses a Content-Security-Policy. What do I need to allow?<\/h3><\/dt>\n<dd><p>Add <code>https:\/\/cdn.cookiefix.ro<\/code> and <code>https:\/\/cookiefix.ro<\/code> to both <code>script-src<\/code> and <code>connect-src<\/code>. The embed loads the widget with <code>fetch()<\/code> and evaluates it inline, so <code>'unsafe-inline'<\/code> and <code>'unsafe-eval'<\/code> are also needed in <code>script-src<\/code>. If the widget cannot load, the plugin releases the blocked scripts (so the site keeps working) and prints an explanation in the browser console.<\/p><\/dd>\n<dt id=\"the%20banner%20blocks%20a%20script%20that%20is%20required%20for%20my%20site.%20how%20do%20i%20exclude%20it%3F\"><h3>The banner blocks a script that is required for my site. How do I exclude it?<\/h3><\/dt>\n<dd><p>Add <code>data-cc-ignore<\/code> to that script tag, or set the \"Allowed hosts\" option (or the <code>data-cc-allow=\"host1.com,host2.com\"<\/code> attribute on the embed) with the domains that must always load. Analytics domains are classified as \"statistics\", advertising domains as \"marketing\", and consent tools such as Google Funding Choices are never blocked.<\/p><\/dd>\n<dt id=\"where%20do%20i%20get%20a%20domain%20key%3F\"><h3>Where do I get a Domain Key?<\/h3><\/dt>\n<dd><p>Sign up for a free account at <a href=\"https:\/\/cookiefix.ro\">cookiefix.ro<\/a> and add your domain. The Domain Key will be shown in the \"Your Scripts\" section.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. The plugin automatically whitelists WooCommerce core scripts and payment gateway scripts so they are never blocked.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. The banner script is inline HTML and is preserved by all caching plugins including WP Super Cache, W3 Total Cache, WP Rocket, and LiteSpeed Cache.<\/p><\/dd>\n<dt id=\"what%20is%20blocking%20mode%3F\"><h3>What is Blocking Mode?<\/h3><\/dt>\n<dd><p><strong>Automatic<\/strong> (recommended): All third-party scripts are blocked until the visitor consents. This is the safest option for GDPR compliance.<\/p>\n\n<p><strong>Manual<\/strong>: Only scripts you have categorized in the CookieFix dashboard are blocked. Use this if automatic blocking causes issues.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Auto-blocker now classifies analytics scripts (Google Analytics, Tag Manager, Hotjar, Clarity...) as \"statistics\" instead of \"marketing\" even before the widget loads<\/li>\n<li>Consent and security tools (Google Funding Choices, reCAPTCHA, Cloudflare Turnstile) are never blocked<\/li>\n<li>New <code>data-cc-allow<\/code> attribute support and <code>data-cc-ignore<\/code> on individual tags for site-specific allow-lists<\/li>\n<li>If the widget cannot be loaded (e.g. Content-Security-Policy), blocked scripts are released and a console error explains what to allow<\/li>\n<li>Banner language follows the page language (<code>&lt;html lang&gt;<\/code>) before the browser language<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Removed the self-hosted update mechanism; updates are delivered through WordPress.org<\/li>\n<li>Documented external services in the readme<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>WordPress.org compliance: proper output escaping throughout<\/li>\n<li>Updated text domain to match WordPress.org plugin slug<\/li>\n<li>Removed remote image loading from settings page<\/li>\n<li>Tested up to WordPress 6.9<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Self-hosted auto-update system - updates appear in WordPress like any other plugin<\/li>\n<li>Plugin info popup with changelog in \"View Details\"<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Domain Key validation against CookieFix API on save<\/li>\n<li>Error message when Domain Key is invalid or not found<\/li>\n<li>Success message showing the connected domain name on valid key<\/li>\n<li>Green \"Connected to: domain.com\" badge displayed next to the field<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Cookie consent banner with auto-blocking<\/li>\n<li>Cookie declaration shortcode and widget<\/li>\n<li>WooCommerce compatibility<\/li>\n<li>Multi-language support<\/li>\n<\/ul>","raw_excerpt":"GDPR\/CCPA cookie consent banner with automatic script blocking and cookie declaration for WordPress.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/365681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=365681"}],"author":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/inksect"}],"wp:attachment":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=365681"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=365681"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=365681"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=365681"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=365681"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=365681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}