BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Plain Cookie Consent icon
Actively maintained Tested with WP 7.1 #36 in consent mode

Plain Cookie Consent

Plain Cookie Consent is a no-frills GDPR + ePrivacy consent banner for WordPress. It ships a single banner, Google Consent Mode v2 defaults, a server-side audit log with pseudonymised subject hashing, a DSAR lookup…

Active installs<10New
Downloads · 30d67▼ -5.6% vs prev. 30d
Rating—0 reviews
Health score60/100Fair
All-time downloads457Since Jun 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d14▲ +7.7% week over week
Our verdict

Use with caution

Plain Cookie Consent works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61218Jul 5Aug 18Oct 2
Yesterday4
Daily average (1y)4
Peak day48Jul 1, 2026
Last 12 months463

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Plain Cookie Consent stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
consent mode >100 1,401 Best consent mode plugins →
cookie consent >100 1,165 Best cookie consent plugins →
ePrivacy #63 136 Best ePrivacy plugins →
GDPR >100 3,702 Best GDPR plugins →
privacy >100 10,000 Best privacy plugins →

About Plain Cookie Consent

From the official readme · v0.7.6

Description

Plain Cookie Consent is a no-frills GDPR + ePrivacy consent banner for WordPress. It ships a single banner, Google Consent Mode v2 defaults, a server-side audit log with pseudonymised subject hashing, a DSAR lookup helper, and constant-gated Meta Pixel / Microsoft Clarity / LinkedIn Insight Tag helpers — all under GPL v2, with no upsells and no external telemetry. Uninstalling keeps the consent log and settings by default (GDPR Art. 7.1 evidence), with an explicit opt-in to permanently delete via Settings → Data on uninstall.

The plugin is designed to support a GDPR/ePrivacy-compliant consent setup. Final compliance depends on the site owner’s configuration and linked privacy policy.

Core compliance features

  • Google Consent Mode v2 defaults injected at wp_head priority 1, before any tag manager or gtag snippet.
  • Early inline consent replay with a revision gate — consent recorded before a policy revision bump is not replayed; the banner re-prompts instead.
  • Server-side audit log (wp_plain_consent_log) with a privacy-preserving SHA-256 subject hash over a daily-rotating salt, and a 730-day default retention purge (filterable via constant).
  • Consent revision system with a “Force re-consent for all users now” admin action and strict rollback if the audit insert fails.
  • Two-step choice pattern: the first layer offers Accept All and Show Options; the preferences screen (one click away) offers equal-weight Accept All, Reject All, and Save Preferences buttons.
  • Server-mirror consent cookie via a cache-safe GET /mirror-nonce endpoint (Cache-Control: no-store), so full-page caching does not break nonce validation.
  • Geo targeting: the consent-required region set is the EEA (EU-27 plus Iceland, Liechtenstein, Norway) plus the United Kingdom. Detection uses the Cloudflare CF-IPCountry header when present, with a fail-safe default: if the country cannot be determined, the visitor is treated as in-scope.
  • CSV/JSON streamed export of the consent log, plus a Data on uninstall shortcut and contextual deactivation reminder when log rows exist.
  • DSAR lookup admin tool: recompute a visitor’s subject hash from IP + User-Agent and list matching consent-log entries (GDPR Art. 15 support).

Integrations

  • Meta Pixel: define PLAIN_COOKIE_CONSENT_FACEBOOK_PIXEL_ID in wp-config.php.
  • Microsoft Clarity: define PLAIN_COOKIE_CONSENT_CLARITY_PROJECT_ID in wp-config.php.
  • LinkedIn Insight Tag: define PLAIN_COOKIE_CONSENT_LINKEDIN_PARTNER_ID in wp-config.php.
  • Public window.plainCookieConsent JavaScript API (getCategories, hasConsent, onChange, onGrant, onRevoke) for site-specific vendors.
  • Cookie cleanup on revoke with curated defaults for LinkedIn, TikTok, Hotjar, Clarity, Yandex Metrica, and Snapchat (plain_cookie_consent_autoclear_cookies filter).
  • localStorage / sessionStorage cleanup on a real granted-to-revoked transition (plain_cookie_consent_clear_storage_keys filter).

Accessibility

  • The banner and preferences modal are attested against WCAG 2.1 AA.
  • axe-core smoke tests (wcag2a, wcag2aa, wcag21aa tags) run on every push and pull request via GitHub Actions.
  • Site-level accessibility remains the operator’s responsibility.

Languages

Translation catalogs ship for nine languages: English, German, Russian, Spanish, French, Italian, Dutch, Polish, and Portuguese. Banner language auto-resolution covers all nine shipped languages, including regional variants (for example de-AT or pt-BR), with any other locale falling back to English. Any shipped catalog can also be selected explicitly, and translators can override strings the standard WordPress gettext way.

Not included

  • TCF v2.2 (programmatic publishers).
  • Consent analytics dashboards beyond the read-only Consent Health widget.
  • Multi-domain consent sync.
  • Banner A/B testing.
  • Script auto-blocking beyond Consent Mode and the documented vendor helpers.

External services

This plugin has no telemetry and never sends data to its own or the author’s servers. Consent records stay in your own WordPress database.

The plugin can optionally load three well-known third-party marketing/analytics tags on your behalf. Each one is OFF by default and only ever loads when BOTH of the following are true:

  1. You explicitly enable it by defining the matching constant in wp-config.php, and
  2. The visitor grants the relevant consent category in the banner.

If you do not define these constants, the plugin makes no third-party requests at all. Once enabled, the tag still loads only after the visitor grants the relevant consent category in the banner.

Meta (Facebook) Pixel

Optional advertising measurement. Enabled by defining PLAIN_COOKIE_CONSENT_FACEBOOK_PIXEL_ID. When a visitor grants advertising consent, the plugin loads https://connect.facebook.net/en_US/fbevents.js and initialises the Pixel with your Pixel ID. From then on, on each page view, Meta receives standard Pixel data: your Pixel ID, the page URL and referrer, the visitor’s IP address and browser/user-agent, and a PageView event. Nothing is sent before advertising consent.
Provider: Meta Platforms, Inc. Privacy Policy: https://www.facebook.com/privacy/policy/ — Business Tools Terms: https://www.facebook.com/legal/terms/businesstools

Microsoft Clarity

Optional session analytics (heatmaps and session insights). Enabled by defining PLAIN_COOKIE_CONSENT_CLARITY_PROJECT_ID. When a visitor grants analytics consent, the plugin loads https://www.clarity.ms/tag/<your-project-id>. From then on, on each page view, Microsoft receives Clarity analytics data: your project ID, the page URL, the visitor’s IP address and browser/user-agent, and interaction events such as clicks and scrolls. Nothing is sent before analytics consent.
Provider: Microsoft Corporation. Privacy Statement: https://www.microsoft.com/privacy/privacystatement — Clarity Terms of Service: https://clarity.microsoft.com/terms

LinkedIn Insight Tag

Optional advertising measurement on LinkedIn. Enabled by defining PLAIN_COOKIE_CONSENT_LINKEDIN_PARTNER_ID. When a visitor grants advertising consent, the plugin loads https://snap.licdn.com/li.lms-analytics/insight.min.js with your Partner ID. From then on, on each page view, LinkedIn receives Insight Tag data: your Partner ID, the page URL, and the visitor’s IP address and browser/user-agent. Nothing is sent before advertising consent.
Provider: LinkedIn Corporation. Privacy Policy: https://www.linkedin.com/legal/privacy-policy — LinkedIn Ads Agreement: https://www.linkedin.com/legal/ads-agreement

Disclaimer

This plugin is provided “as is”, free of charge, for evaluation and use at
the site operator’s own discretion and risk.

  • The site operator alone chooses which plugins to install and run on their
    site, and bears full responsibility for that choice and its consequences.
  • The plugin is offered for informational and evaluation purposes. The
    authors make no guarantees and no promises of any kind — including
    correctness, completeness, fitness for a particular purpose, or
    uninterrupted operation.
  • Software may contain errors. Any errors, malfunctions, data loss, or
    legal consequences arising from the use of this plugin are the sole
    responsibility of the site operator.
  • Nothing in this plugin or its documentation constitutes legal advice.
    The plugin is designed to support a GDPR/ePrivacy-oriented consent setup,
    but it does not and cannot guarantee legal compliance of any specific
    site — final compliance always depends on the operator’s configuration,
    vendors, and policies.
  • The warranty disclaimer and limitation of liability are governed by
    sections 11 and 12 of the GNU GPL v2 license that ships with this plugin.

Installation

  1. Upload the plain-cookie-consent folder to /wp-content/plugins/.
  2. Activate the plugin via the Plugins menu.
  3. Visit Settings → Cookie Consent to configure the Privacy Policy URL, policy version, and optional data-controller name.
  4. For Meta Pixel / Microsoft Clarity / LinkedIn Insight: define the relevant constant in wp-config.php.

Frequently asked questions

Is reCAPTCHA covered?

The plugin does not auto-gate reCAPTCHA, because its legal basis is context-dependent: on contact forms it generally requires consent, while as payment anti-fraud it may be consent-exempt. The Diagnostics “reCAPTCHA / security CAPTCHA” probe flags its presence so you can decide. The bundled docs/INTEGRATION.md documents gating patterns.

Diagnostics says the public front page cache may be stale. What should I do?

After a fresh activation or update, full-page cache can keep serving HTML generated before the plugin was active. Diagnostics compares the normal public front page with a cache-busted front-page request for the bootstrap and consent-default source checks. If the cache-busted render contains the plugin markers but the normal public page does not, purge your WordPress page cache, Redis/Varnish/Nginx full-page cache, and Cloudflare/CDN cache, then rerun diagnostics before editing theme or tag-manager code.

Is Switzerland covered?

No. Switzerland (CH) is deliberately excluded from the consent-required region set. The Swiss revFADP has no prior-consent rule for cookies equivalent to ePrivacy Art. 5(3), so Swiss traffic falls under the rest-of-world (granted-by-default) branch. The in-scope set is the EEA (EU-27 + Iceland, Liechtenstein, Norway) plus the United Kingdom.

Does uninstalling the plugin delete its data?

No — not by default. The consent audit log and all plugin settings are preserved when you uninstall (GDPR Art. 7.1 evidence; a reinstall finds prior records and configuration intact). To permanently delete all data, go to Settings → Cookie Consent → Data on uninstall, switch to delete mode (type DELETE to confirm), and then proceed with the WordPress uninstall. The rotating subject salt is always removed in both modes. Exporting the log first (CSV or JSON) is recommended for portable evidence before any permanent deletion.

Does the plugin collect any data itself?

No. There is no external telemetry. Consent records stay in your own WordPress database, with the subject identifier stored only as a salted SHA-256 hash.

Changelog

Behavior change: an unanswered consent banner now re-appears on every page view until the visitor makes a choice. No data or schema changes.

0.7.6

  • Changed: a consent banner left unanswered now auto-shows again on the next page view in the same browsing session, instead of only once per session. The banner keeps appearing until the visitor makes a choice; visitors with a recorded choice are unaffected.

0.7.5

  • Fixed: removed the passive Plugins-page uninstall-data notice that could appear after a normal update or manual ZIP overwrite.
  • Fixed: Data-on-uninstall guidance is now contextual: the plugin row links to the dedicated settings section, and the deactivation modal mentions keep/delete behavior only when the consent log has rows.

0.7.4

  • Fixed: Data on uninstall actions now show visible success, no-op, and confirmation-required notices after saving the uninstall mode or deleting preserved data.
  • Fixed: dismissing the preserved-data reinstall notice no longer removes the marker needed for the settings-page cleanup path.
  • Fixed: the preserved-data reinstall notice no longer points to a DSAR review workflow that cannot subject-match records after reinstall.
  • Fixed: stale public-cache bootstrap/default misses now appear consistently as actionable diagnostics attention items across admin surfaces.
  • Changed: exposed the free front-end runtime configuration for Pro add-on reuse without changing the public browser object shape.

0.7.3

  • Fixed: the legacy DSAR admin URL now redirects to the DSAR tab on the main settings page instead of reaching a WordPress access-denied screen.
  • Changed: the Settings submenu now uses one compact Cookie Consent entry, with DSAR as a tab beside Settings, FAQ, and Diagnostics.
  • Changed: diagnostics indicators are less noisy; the red menu marker now appears only for fix-required findings, and the Plugins list uses plain action links without a diagnostics badge.

0.7.2

  • Changed: removed the legacy self-hosted Update URI header and unused self-hosted update constants so manually installed ZIPs can receive normal WordPress.org update offers for the plain-cookie-consent slug.

0.7.1

  • Fixed: diagnostics now compares the normal public front page with a cache-busted render for plugin-bootstrap and consent-default source checks, reducing false “Needs fix” guidance after fresh activation behind stale page/CDN cache.

Full changelog on WordPress.org →

Screenshots

Consent banner — first layer.
Consent banner — first layer.
Cookie preferences modal — equal-weight Accept / Reject.
Cookie preferences modal — equal-weight Accept / Reject.
Settings page — Privacy Policy URL, consent revision, policy version, controller name.
Settings page — Privacy Policy URL, consent revision, policy version, controller name.
Diagnostics panel — checks including policy-version drift, Google Fonts, and reCAPTCHA presence.
Diagnostics panel — checks including policy-version drift, Google Fonts, and reCAPTCHA…
Consent Health dashboard widget.
Consent Health dashboard widget.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Plain Cookie Consent alternatives

All consent mode plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 tarteaucitron.io – Cookie Banner & GDPR Consent Management tarteaucitron.io – Cookie Banner & GDPR Consent Management Add a customizable cookie banner and manage GDPR consent with tarteaucitron.io CMP… by Amauri 10K+ ★★★★★★★★★★ 4.5 (13) 3 weeks ago 72
2 WP Global Site Tag WP Global Site Tag Install a Google tag and view useful Google Analytics 4 reports inside WordPress with a… by digitalapps 7K+ ★★★★★★★★★★ 5 (2) 4 weeks ago 79
3 Tracking and Consent Manager – WP Full Picture Tracking and Consent Manager – WP Full Picture All-in-one tracking and consent management. Use Google Analytics, Google Ads, Meta Pixel… by Krzysztof Planeta 3K+ ★★★★★★★★★★ 5 (21) 1 week ago 92
4 Tag Pilot FREE – Google Tag Manager Integration for WooCommerce Tag Pilot FREE Complete GTM plugin for WooCommerce (Consent Mode v2 and Server-Side). Ready for GA4 and FB… by Tag Concierge 1K+ ★★★★★★★★★★ 5 (8) 3 months ago 73
5 Simple Google Analytics Tag Manager Simple Google Analytics Tag Manager Adds Google Analytics GA4 and Google Tag Manager snippets with simple privacy-friendly… by Miguel Fuentes 1K+ ★★★★★★★★★★ No reviews 3 months ago 61
6 Consent Mode Banner Consent Mode Banner Lightweight (~3kB) Consent/Cookies Banner compatible with Google Consent Mode (GTM & Google… by Tag Concierge 400+ ★★★★★★★★★★ 3.3 (4) 10 months ago 44
7 Lightweight Google Analytics Lightweight Google Analytics Easily add Google Analytics 4 to WordPress using just your Measurement ID. by Andy Feliciotti 400+ ★★★★★★★★★★ 5 (2) 3 weeks ago 77
8 Simple Consent Mode Simple Consent Mode Simple Consent Mode helps integrate GTM Consent Mode v2 on your website. by iworks (Marcin Pietrzak) 300+ ★★★★★★★★★★ No reviews 2 months ago 57
9 Lynbro Cookie Consent Lynbro Cookie Consent Free, multilingual cookie consent banner — GDPR/ePrivacy & Google Consent Mode v2 ready… by lynbro 70+ ★★★★★★★★★★ 5 (3) 3 months ago 64
10 Darwin Cookie Consent Darwin Cookie Consent Cookie banner for Google Consent Mode v2, GDPR & FADP. Includes four built-in languages… by Darwin Digital 50+ ★★★★★★★★★★ No reviews 3 months ago 53

FAQ

Plain Cookie Consent: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 3, 2026

Is Plain Cookie Consent free?

Yes. Plain Cookie Consent is free to download and use from the official WordPress.org plugin directory.

Is Plain Cookie Consent safe to use in 2026?

Plain Cookie Consent works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

How many websites use Plain Cookie Consent?

Plain Cookie Consent is active on <10 WordPress websites and has been downloaded 457 times since it launched in June 2026. It was downloaded 67 times in the last 30 days.

Does Plain Cookie Consent work with WordPress 7.1?

Yes. The developer has tested Plain Cookie Consent up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.

What PHP version does Plain Cookie Consent need?

Plain Cookie Consent requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Plain Cookie Consent last updated?

The latest version, 0.7.6, was released on August 26, 2026 (1 month ago).

Who makes Plain Cookie Consent?

Plain Cookie Consent is developed and maintained by Ontario.

What are the best alternatives to Plain Cookie Consent?

The most popular alternatives to Plain Cookie Consent are tarteaucitron.io (10K+ installs), WP Global Site Tag (7K+ installs) and Tracking and Consent Manager (3K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.