What it does

From the banner to the policies, in a single plugin.

Banner

  • Small, in a corner on desktop and full width at the bottom on the phone.
  • "Accept all" and "Reject" look the same; "Customise" opens the necessary, statistics and marketing categories.
  • The X closes and counts as a refusal; the Esc key never chooses for the visitor. No cookie wall, scrolling is not consent.
  • Texts, colours and position are changed from the settings. Italian and English included; on multilingual sites the default texts follow the language of each page and the hand-written ones are translated with WPML and Polylang, thanks to the included wpml-config.xml file.
  • No libraries and no external resources, compatible with page caching.

Consent and withdrawal

  • The choice is saved in a technical cookie with the consent ID, categories, policy version and date; the duration is configurable.
  • When the policy version is raised, the banner asks all visitors again.
  • The preferences recall is always available: floating cookie icon, or a «Cookie preferences» link at the bottom of every page.
  • The icon moves by itself above the other fixed elements it would cover, for example a chat button.
  • Withdrawal denies consent to the services, deletes the category's cookies and reloads the page if its scripts had already started.

Integrations

  • Google Analytics 4 with Consent Mode v2: in basic mode, the default one, nothing is downloaded from Google before consent.
  • Google Tag Manager, loaded after the first consent, and Meta Pixel, loaded only after marketing consent.
  • Custom scripts by category, inert in the page until consent.
  • Any other script is kept blocked with an attribute, or with a filter for those enqueued by WordPress.
  • Cautious defaults: Google Signals and personalised ads disabled, Analytics cookies at 13 months.

Cookie scanning

  • Catalogue of the most common cookies: WordPress, WooCommerce, Elementor, Google, Meta, YouTube, Vimeo, Cloudflare, Hotjar, Clarity and others.
  • Scanning from three sources: active plugins and connected services, server responses on a sample of pages, cookies present in the administrator's browser.
  • Table with provider, category, purpose and duration of each cookie: it can be edited, excluded and completed by hand.
  • A cookie without a category stays out of the policy until it is classified.

Cookie Policy

  • The page is created through a guided three-step process (data controller, site cookies, page) and is linked to the banner; then you can view it, edit it or repeat the guided setup.
  • It updates itself when the list changes. Text in Italian and English, with tables by category, other companies and transfers, withdrawal and rights.
  • A new optional cookie, a new company or a change of category prompts a new version, published only after the administrator confirms it.
  • On the phone each cookie becomes a card, with no sideways scrolling.
  • The page fits the site width and respects its margins even in themes built for Elementor and other page builders; the title is printed by the plugin in line with the text, even in themes that do not allow it to be removed. The space above and below the page is adjusted from the settings, for desktop and phone.
  • On multilingual sites the page is translated like the others (WPML, Polylang): the text appears in the page language, and the banner link, the links between the two policies, the title and the spacing follow the translation.

Privacy Policy

  • Five steps of questions, saved at each step: what the site does, data and retention periods, recipients, special cases, changes.
  • The features found on the site are already suggested: contact forms, comments, registration, shop, newsletter.
  • The legal basis is set for each function; retention periods are suggested and can be changed.
  • At the end of the steps the page is created and becomes the WordPress privacy page; Privacy Policy, Cookie Policy and banner link to each other. From then on you can view it, edit it or repeat the guided setup.
  • This page too is translated like the others on multilingual sites; the hand-written answers, such as retention periods or the recipients' country, go through string translation in WPML and Polylang.

Consent log

  • Every choice ends up in a dedicated table, with a truncated IP (or hashed, or not stored).
  • List with search, filters and detail with the history of the same ID.
  • CSV export and clearing with a confirmation word.
  • Automatic deletion after a configurable period.

Export and import

  • The configuration in a JSON file: settings with the service IDs and the scripts, data controller, cookie list, Privacy Policy answers.
  • A safety copy, or the starting point for another site.
  • Before importing you see, part by part, what would change, and you choose the parts to write.
  • The linked pages remain those of the site; new optional cookies in the list prompt a new version of the policy.

Accessibility

  • Banner, preferences panel and generated pages checked against the WCAG 2.2 AA criteria.
  • The banner is the first keyboard stop but does not block the site; on closing, focus returns where it was.
  • A warning in the settings, while you pick the colours, if text and background are hard to read.
  • The policy tables can also be scrolled from the keyboard on small screens.

Screenshots

How it looks, on the site and in WordPress.

The banner with the Reject, Accept all and Customise buttons
The banner: «Reject» and «Accept all» with the same weight.
The preferences panel with the necessary, statistics and marketing categories
"Customise": choice by category and consent ID.
The banner on mobile, full width at the bottom
On the phone the banner takes the full width, at the bottom.
The Integrations tab with Google Analytics 4, Google Tag Manager, Consent Mode v2 and Meta Pixel
Integrations: just the service ID is enough, and it only starts after consent.
The Cookie tab with the scan and the table of the site's cookies
Scanning and table of the site's cookies.
The generated Cookie Policy page, with the data controller and the cookie tables by category
The generated Cookie Policy; bottom left, the icon that reopens the preferences.
The Privacy Policy tab with the questions about what the site does
Privacy Policy: the questions, with the features found on the site already suggested.
The consent log with filters and CSV export
Consent log: search, filters and CSV export.
The Tools tab with the preview of an import, part by part
Tools: before importing, what would change in each part.
The Banner tab with the low contrast warning between text and background
The warning that appears when the chosen colours are hard to read.

How it is used

From installation to the policies, in seven steps.

1. Install and activate

In WordPress go to Plugins → Add new → Upload plugin, choose the plugin zip and activate it. The «Cookie Consent» item appears in the menu.

2. Configure the banner

Choose the position, the colours, how long the choice lasts and how preferences are recalled: floating icon or footer link. Texts left empty use the default ones, in the site language or, on multilingual sites, in the language of each page. If the site only uses technical cookies, turn the banner off.

3. Connect the services

In the Integrations tab you enter the Google Analytics 4, Google Tag Manager or Meta Pixel ID: each service starts only when the visitor allows its category. For the other services you paste the code into the custom scripts.

4. Scan the cookies

Visit the site accepting all cookies, then start the scan from the Cookie tab. Check the table: classify the unrecognised cookies and manually add the missing ones.

5. Create the Cookie Policy

In the Owner tab you enter the owner's details, then from the Cookie Policy tab you create the page: the plugin links it to the banner and keeps it up to date. When cookies change significantly it proposes a new version, and after your confirmation the banner asks everyone again.

6. Create the Privacy Policy

In the Privacy Policy tab you answer the questions, one step at a time, and create the page. The text follows the answers: when the site changes, you update the answers and the page updates with them.

7. Keep or reuse the configuration

From the Tools tab you download the export file: it is a backup copy, and on another site with the plugin you import it from the same tab. After the import run a scan, to compare the cookie list with the new site.

Shortcode: link to preferences, policies and cookie tables

[custcc_preferences label="Manage cookies"]
[custcc_cookie_policy]
[custcc_privacy_policy]
[custcc_cookie_table category="statistics"]

Custom link, in a menu or in a button

<a href="#custcc-preferences">Cookie preferences</a>

HTML: keeping a script blocked until consent

<script type="text/plain" data-custcc-category="statistics"
	data-src="https://example.com/tracker.js"></script>

PHP: blocking a script enqueued by WordPress

add_filter( 'custcc_blocked_handles', function ( $handles ) {
	$handles['some-tracker'] = 'marketing';
	return $handles;
} );

JavaScript: reacting to the visitor's choice

document.addEventListener( 'custcc:change', function ( event ) {
	// event.detail.categories: [ 'necessary', 'statistics' ]
} );

window.custcc.has( 'statistics' ); // true / false
window.custcc.open();              // reopens the panel

Other filters: custcc_banner_active, custcc_client_ip (for sites behind a proxy), custcc_rate_limit, custcc_catalog and custcc_catalog_providers (to extend the catalogue), custcc_scan_urls, custcc_policy_width and custcc_policy_own_title (frame and title of the policy pages), custcc_page_id and custcc_text (for multilingual systems that do not respond to wpml_object_id or do not translate the options).

Coming soon. With version 1.0 the development phases are complete. The next step:

  • Published in the WordPress.org directory.

Legal notices. The plugin is a technical tool and not legal advice. The site owner remains responsible for which cookies are used, how they are classified and what the notices say. The scan does not see everything and the generated texts must be checked: have your configuration and texts reviewed by a lawyer.

Questions or reports

Want to use it on your site?

The plugin is free (GPL) and being prepared for the WordPress.org directory. In the meantime, write to me: to try it out, to report a problem or to have it configured on your site.