Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager
🍪 What Cookie Consent Does Scans your site for cookies. Cookie Consent detects cookies by loading your pages in a full headless browser (Chromium), the same way a real visitor experiences your site. This catches cookies set by JavaScript execution, third-party embeds, analytics snippets, and dynamically loaded content that simpler HTTP-based scanners often miss. Detected cookies are automatically categorized into Necessary, Analytics, Marketing, Functional, or Uncategorized. You can scan your homepage, crawl your full site, or specify custom URLs. Results merge into your cookie manager without overwriting any manual edits. Blocks scripts until consent is given. In GDPR (opt-in) mode, non-essential scripts don’t execute until the visitor consents to the relevant category. This applies to analytics scripts, advertising pixels, tracking tags, and any other third-party script that sets non-essential cookies. Cookie Consent intercepts both WordPress-enqueued scripts and inline scripts, modifying them to wait for consent before firing. Essential cookies, like those used for login sessions, shopping carts, and basic site functionality, are never blocked. In CCPA (opt-out) mode, scripts load by default and visitors can choose to opt out of specific categories. Displays a customizable consent banner. Visitors see a cookie banner with clear options to accept, reject, or manage preferences by category. The banner, preferences dialog, and revisit button are all customizable including layout, position, colors, text, button styles, and border radius. A live preview shows you what visitors will see as you make changes. Logs every consent decision. Each time a visitor makes a choice, Cookie Consent records the decision type (accept all, reject all, or custom), the specific category preferences, and a timestamp. These records create an audit trail you can reference if compliance questions arise. Keeps everything in one place. Cookie list, scan results, script rules, consent logs, banner design, and compliance settings, all in one admin area. No separate platform to sign up for, no external app to connect, no additional accounts to manage. ⚙️ Setup A guided wizard gets your banner live in three steps: 1. Choose your compliance model – Select GDPR (opt-in) or CCPA (opt-out) based on your audience and the regulations that apply to your site. 2. Configure your banner – Pick a layout, adjust colors and text, and preview what visitors will see. 3. Scan your site – Cookie Consent visits your pages with a real browser, finds active cookies, and categorizes them. Your banner goes live with accurate cookie data from the start. After setup, you can re-scan anytime, refine your design, recategorize cookies, and adjust script rules, all from the same dashboard. 🎨 Banner Design & Customization Banner Templates: Start with a pre-configured template during setup, then customize to fit your site. Templates are tailored to your selected compliance model (GDPR or CCPA) so the default structure, buttons, and consent flow match your requirements from the start. Layouts: Footer bar, slide-in, or center popup. Positioning: Control where and how the banner appears on the page. Styling: Background colors, text colors, button primary and secondary colors, border radius, and button sizing, enough control to match any brand or design. Content: Editable title, description, and button labels for the banner, preferences dialog, and revisit button. Write in your own voice. Preferences Dialog: When a visitor clicks Manage Preferences, they see a breakdown of each cookie category with descriptions and toggles. Necessary cookies are marked as always active. Visitors choose exactly which categories they\’re comfortable with. Revisit Consent Button: A persistent button visitors can click anytime to reopen the preferences dialog and change their choices. Responsive: Automatically adapts to desktop and mobile. Live Preview: Desktop and mobile preview with a device toggle. Updates in real time as you edit — no publishing and refreshing the front end. Elementor Editor Integration [Requires Elementor Pro]: Open the banner and preferences dialog in the Elementor visual editor. Drag-and-drop widgets, styling panels, and your full design system, the same workflow you use for the rest of your site. Cloud Templates [Requires Elementor Pro]: Save a finished banner design to your cloud library and deploy it across other sites in one click. Useful for agencies and freelancers managing multiple client sites with consistent branding. 📋 Cookie & Script Management Cookie Manager: A central dashboard showing every cookie on your site, organized by consent category. Each entry shows the cookie name, domain, category, duration, and a description field. Add cookies manually, edit any field, or delete entries you no longer need. Drag-and-drop cookies to reorder them within a category, the order you set here is the order visitors see in the preferences dialog. Category View: Categories display as expandable accordion sections: Necessary, Analytics, Marketing, Functional, and Uncategorized. Each shows a status badge: \”Always Active\” for Necessary, or an Active/Inactive toggle for other categories. Expand any section to see the individual cookies it contains. Scanning: Run a scan anytime with homepage only, full-site crawl, or custom URLs you specify. Include and exclude lists let you control exactly which pages get scanned. Only one scan runs at a time. New cookies are added automatically; existing manual edits are never overwritten. A progress indicator shows scan status in real time. Script Manager: Control how individual scripts behave, independent of their category\’s default rule. Three options per script: – Do Not Block – Script always loads, bypassing the consent engine. Use for scripts you\’ve verified as essential but that aren\’t automatically detected as Necessary. – Block Until Consent – Script waits until the visitor consents to its assigned category. This is the default for non-essential scripts in GDPR mode. – Always Block – Script never loads under any circumstances. Use for scripts you want permanently disabled. Script Input: Add scripts by URL or paste inline code directly. Cookie Consent matches scripts using URL comparison or normalized snippet hashing. Inline Script Blocking: An optional output buffering method catches inline and hardcoded scripts that aren\’t loaded through the standard enqueue system. Toggle it off from Advanced Settings if you want to manage inline scripts manually or minimize server-side processing. Developer Hooks: Advanced users and agencies can hook into the blocking engine via an MU-plugin snippet to delay dynamically injected scripts, including those created by page builders or loaded after DOM ready. Scan History: A table of past scans showing date (UTC), status (success/failed), URLs scanned, categories found, and total cookies detected. = 🔒 Compliance Settings= GDPR (Opt-in): Non-essential scripts are blocked by default. The banner presents three options: Accept All, Reject All, and Manage Preferences. Visitors who open the preferences dialog see each cookie category with a description and a toggle. Necessary cookies are labeled \”Always Active\” with no toggle, they can\’t be disabled. Consent must be given before Analytics, Marketing, or Functional scripts execute. CCPA (Opt-out): All scripts load by default. The banner includes a Do Not Sell My Data option. Visitors who opt out trigger blocking of Marketing category scripts. Global Privacy Control (GPC) signals sent by the visitor\’s browser are detected and respected automatically. Consent Expiration: Set how many days a visitor\’s choice is remembered (1–365 days, default 180). When the period expires, the banner reappears and the visitor is prompted to choose again. Until expiration, the previous choice is respected and the banner stays hidden. Banner Activation: A global toggle to enable or disable the cookie banner. 🎁 Free Features Everything you need for working cookie consent. – Guided 3-step setup wizard – GDPR (opt-in) and CCPA (opt-out) compliance models – Google Consent Mode v2 – Automatically send consent signals to Google so analytics and ad measurement continue working after consent is deployed – Cookie scanning with headless browser (Chromium) detection – Automatic categorization into Necessary, Analytics, Marketing, Functional, and Uncategorized – Automatic script blocking for non-essential cookies – Blocks both enqueued scripts and inline scripts – Global Privacy Control (GPC) and Do Not Sell support – Customizable consent banner with Accept All, Reject All, and Manage Preferences – Preferences dialog with per-category toggles and descriptions – Revisit consent button for visitors to update choices anytime – Banner templates tailored to GDPR and CCPA compliance models – Footer bar, slide-in, and center popup layouts – Full styling controls: colors, buttons, borders, sizing – Editable banner text, button labels, and dialog content – Responsive desktop and mobile design – Live banner preview with device toggle – Cookie manager with manual add/edit/delete and sorting – Script manager with per-script overrides (always load, block until consent, always block) – Consent logging with timestamped audit trail – Configurable consent expiration (1–365 days) – Scan history with status and results tracking – Output buffering toggle for inline script blocking – No external dashboards – No CDN dependencies 🔥 Premium Cookie Consent features available with Elementor One White-Label: Remove Cookie Consent branding from the consent banner entirely. Multilingual Translations: Translate the banner and preferences dialog into additional languages for international visitors. Consent Log Export: Download consent records in CSV format for audits, legal reviews, or internal documentation. Advanced Scan Rule Exclusions: Exclude specific paths or URLs from cookie scans. Useful for staging environments, admin areas, or sections that don\’t need scanning. Disable Banner on Specific Pages: Prevent the banner from loading on pages you select (e.g., internal dashboards, login screens). Elementor Editor Design [Requires Elementor Pro]: Open the cookie banner and preferences dialog in the full Elementor visual editor. Drag-and-drop layout, widget-level control, and live editing. Cloud Templates [Requires Elementor Pro]: Save banner designs to your cloud library and deploy them across multiple sites instantly. Google Tag Manager Integration [Premium] – Pass consent signals to your GTM container for tag-level consent control. Geo-Targeting [Premium] – Automatically display the correct banner based on visitor location. GDPR opt-in for EU visitors, CCPA opt-out for US visitors without manual configuration. Multi-Region Banner Management [Premium] – Configure and manage separate banner designs and compliance rules for different geographic regions from one dashboard. 🔜 Coming Soon Cookie Policy Generator – Auto-generate a cookie policy page based on the cookies detected on your site. Automatic and Scheduled Scans [Premium] – Set scans to run on a recurring schedule so your cookie list stays current without manual intervention. ♿ Accessibility The Cookie Consent consent banner is built following accessibility best practices. For full website accessibility compliance, Cookie Consent works alongside Ally, Elementor\’s accessibility plugin that scans for and remediates accessibility issues across your site. Installation Install using the WordPress built-in Plugin installer, or Extract the zip file and drop the contents in the wp-content/plugins/ directory of your WordPress installation. Activate the plugin through the ‘Plugins’ menu in WordPress. External Services Cookie Consent requires a connection to an active Elementor account in order to: * Identify the user and provide the user with the purchased service. * Log website visitors consents for “proof of consent” * Preform an external scan of cookies generated by and on the website. * Collect manually submitted feedback, to improve the product. This connection is initiated manually by the user via the plugin’s settings panel. Learn more about our terms and conditionsand Privacy Policy. This plugin uses a 3rd party service operated by Elementor. Cookie Consent uses a 3rd party service operated by Mixpanel to collect interactions with the plugin but only for consenting users, meaning if the user has Not consented to “sharing data” (default) this is disabled and no collection is made.
Top keywords
- consent40×2.18%
- banner33×1.79%
- cookie31×1.69%
- scripts21×1.14%
- cookies18×0.98%
- preferences15×0.82%
- script14×0.76%
- visitors14×0.76%
- cookie consent13×0.71%
- category12×0.65%
- elementor12×0.65%
- dialog11×0.60%
SureCookie – GDPR Cookie Consent Banner, Cookie Scanner & Script Blocking
SureCookie is a WordPress cookie consent plugin that helps you scan cookies, display a customizable cookie banner, block non-essential scripts before consent, and store consent logs inside your WordPress database. It is built for site owners, E-commerce stores, agencies, bloggers, and WordPress professionals who want more than a basic cookie notice. SureCookie helps you understand what cookies and third-party services are running on your site, lets visitors manage their choices, and gives you a practical consent workflow without visitor-based pricing. 👉 Try the live demo of SureCookie. Not Just a Cookie Banner A cookie notice can tell visitors that your site uses cookies, but that alone does not manage consent. If analytics scripts, marketing pixels, video embeds, maps, or tag manager scripts run before visitors choose, the banner is only cosmetic. SureCookie connects the banner to the rest of the workflow: scan the site, review detected cookies, block non-essential scripts before consent, store consent logs locally, and keep your cookie policy easier to maintain. How SureCookie Works SureCookie follows a simple WordPress cookie consent workflow: Scan selected pages with the real browser cookie scanner. Review detected cookies, scripts, resources, and third-party domains. Organize cookies into consent categories such as Essential, Functional, Analytics, and Marketing. Enable script blocking so non-essential scripts wait for consent. Show the cookie consent banner and preference modal to visitors. Store consent logs locally in WordPress for review and export. Generate or connect a cookie policy page that reflects your cookie setup. This makes SureCookie more than a WordPress cookie banner. Many cookie plugins focus only on the visitor-facing notice, while SureCookie focuses on what happens before and after it: cookie detection, script blocking, consent records, and policy support. Free Features Included The WordPress.org version of SureCookie includes the core consent workflow: Cookie consent banner: Show a clean banner or notice for visitors. Preference modal: Let visitors review and manage cookie categories. Accept, Accept All, Decline, and Preferences buttons: Control the button text and order. Real browser cookie scanner: Scan selected pages using a browser-based scanning service. Cookie categories: Use Essential, Functional, Analytics, Marketing, and Uncategorized categories. See managing cookie categories. Custom cookies: Add and manage cookies manually when needed. Script blocking: Block non-essential scripts before consent is given. Resource blocking: Manage scripts, iframes, embeds, and objects found during scans. Consent logs: Store visitor choices inside your WordPress database. Consent log filters: Search and filter logs by action, country, IP, and session ID. Consent PDF export: Export individual consent records for documentation. Consent retention settings: Control how long consent logs are kept. Monthly automatic scanning: Schedule recurring scans on the free plan. Scan history and change detection: See what changed between scans, including newly detected cookies and domains. Rule-based category suggestions: Get suggested categories for newly detected cookies. Cookie policy page: Generate a page with dynamic cookie tables. Re-consent controls: Add a Cookie Preferences link through a shortcode or menu item. Re-request consent: Ask all visitors to review choices again when needed. Google Consent Mode support: Send consent states to supported Google services. WP Consent API support: Share consent state with compatible WordPress plugins. Multilingual support: Work with WPML and Polylang for banner and admin text. RTL support: Display frontend cookie policy content correctly for RTL languages. MCP and WordPress Abilities support: Enable AI assistant access to SureCookie management actions when supported. No visitor-based limits: SureCookie does not charge by traffic or monthly visitors. Free vs Pro Clarity Everything listed above is in the free plugin. Advanced workflows are reserved for SureCookie Pro: weekly automatic scans, email scan digests, auto-apply behavior, compliance guard workflows, geographic targeting (which applies CCPA-style opt-out rules per region), and consent forwarding. Compare on the features page or see plans and pricing. Real Browser Cookie Scanner SureCookie uses a browser-based scanning service at https://library.surecookie.com/ to inspect selected pages. See how the cookie scanner works. Instead of only reading static HTML, the scanner loads your pages in a real browser environment. This helps detect cookies and resources that appear after page load, through tag managers, or through third-party scripts. The scanner can help identify: Analytics, marketing, advertising, functional, and preference cookies WooCommerce and WordPress session cookies Third-party domains and resources Tag manager loaded and dynamically injected scripts Monthly Automatic Scanning When enabled, SureCookie runs scheduled monthly scans through WP-Cron. The scan uses the same scanner engine, respects the configured scan scope, and records the latest scan history. Full setup is in the automatic scheduled scanning guide. The scan history can show: Newly detected cookies Removed cookies Recategorized cookies Newly detected third-party domains Whether the scan was manual or automatic The last scan date and cookie count Script Blocking Before Consent SureCookie can block non-essential scripts before the visitor gives consent. When blocking is enabled, SureCookie processes the frontend HTML and converts matching resources so they do not execute until the relevant cookie category is allowed. It can handle scripts as well as embedded content such as iframes, embeds, and objects. This matters because a banner alone does not stop tracking. SureCookie is designed to connect consent choices with technical enforcement. The script blocker also includes safeguards so it skips admin pages, REST requests, AJAX requests, feeds, JSON responses, XML responses, and scanner bypass requests. The resource and script blocking guide covers how scripts, iframes and embeds are matched. Customizable Banner and Preferences SureCookie gives you control over the visitor-facing consent experience. You can customize: Banner message and description Rich text banner content Accept, Accept All, Decline, and Preferences button labels Button order Banner position and width Banner logo Banner animation Background overlay Preference modal heading and description Cookie category labels and descriptions Custom CSS Visitors can accept all cookies, decline non-essential cookies, or open the preferences modal and choose specific categories. See customizing banner content and banner layout for every option, and custom CSS for banner styling if you need finer control. Consent Logs Stored Locally SureCookie stores consent records inside your WordPress database. This is different from many SaaS consent management platforms where consent records live on an external platform. With SureCookie, your consent logs stay on your WordPress site and can be reviewed from the admin area. Consent logs can include: User session ID Consent action, such as accepted, declined, or partially accepted Cookie category preferences Masked IP address Timestamp Country Admins can view, search, filter, delete, and export logs from WordPress. SureCookie also includes retention settings so you can control how long logs are kept. See understanding consent logs and exporting consent logs to PDF or CSV. Cookie Policy Page and Generator SureCookie includes a cookie policy generator that can create a Cookie Policy page for your website. The generated page uses native WordPress blocks and includes a dynamic shortcode that displays cookie tables grouped by category and provider. The cookie policy content can include: Cookie categories Cookie names Purpose or description Duration Domain Last updated timestamp A table of contents when multiple categories are available You can edit the generated policy page in the WordPress editor and keep the dynamic cookie table connected to your scanned and manually added cookies. Walkthrough: how to generate a cookie policy page. Re-Consent and Re-Request Consent Visitors should be able to change their choices later. SureCookie includes a re-consent shortcode: [surecookie_reconsent_button] You can use it to add a Cookie Preferences button on your site. SureCookie can also add a virtual Cookie Preferences item to a selected WordPress navigation menu. Admins can also re-request consent from all visitors. This is useful after updating your cookie policy, adding new tracking tools, changing categories, or making a major consent workflow change. See the re-consent guide. Google Consent Mode When enabled, SureCookie sends consent states for supported Google services and updates them when visitors change their preferences. Setup steps: setting up Google Consent Mode v2. It maps SureCookie categories to Google consent signals, detects Google services from enqueued scripts or the page HTML, and hides block toggles that Google Consent Mode already manages. WP Consent API SureCookie reads its consent cookie and syncs the visitor’s consent state so compatible WordPress plugins can check consent using the standardized WP Consent API flow. Default category mapping includes: Essential to functional Functional to preferences Analytics to statistics Marketing to marketing Developers can customize mappings through filters. Multilingual and RTL Support SureCookie includes multilingual compatibility for WPML and Polylang. It can register and translate banner text, button labels, preference modal text, category labels, and related frontend strings. It also includes RTL support for cookie policy layouts. MCP and WordPress Abilities When enabled, AI assistants and compatible tools can use structured SureCookie abilities to manage settings, cookie categories, consent logs, cookie management, and site scanner actions. Scanner start actions still require care because they contact an external scanning service. Who Should Use SureCookie? SureCookie is a good fit for: WordPress site owners and agencies who need a cookie consent banner across client sites E-commerce stores and publishers using analytics, ads, pixels, embeds, or marketing tools Businesses running tag managers, heatmaps, video embeds, maps, forms, or CRM and conversion tracking Developers who want a WordPress-native consent workflow with hooks and APIs, and consent logs kept inside WordPress Important Legal Note SureCookie provides technical tools for cookie scanning, script blocking, consent collection, consent logging, and cookie policy management. No WordPress plugin can guarantee legal compliance on its own. Privacy and cookie requirements depend on your website, visitors, region, policies, data processing practices, and legal obligations. For legal advice, consult a qualified legal professional. External Services SureCookie uses external services for cookie scanning, site verification, and geolocation. Cookie Scanning SureCookie connects to https://library.surecookie.com/ to provide real browser-based cookie scanning and smart categorization. When you run a scan, SureCookie sends the selected page URLs to the scanning service. A browser-based scanner visits those pages and detects cookies, scripts, resources, and third-party domains. Scanner Registration and Authentication Before the first scan, SureCookie performs a one-time registration handshake with library.surecookie.com/api/register. The request sends: Site URL WordPress admin email SureCookie version A temporary installation nonce (one-time, random) The scanning service verifies the site through a temporary REST endpoint, then returns site-specific credentials and a verification token. These credentials are stored locally in a non-autoloaded WordPress option and are used for authenticated scan requests. Consent IP Logs and Region Detection For consent logging and country detection, visitor IP addresses may be processed through MaxMind-backed region detection through SureCookie’s service. This helps SureCookie record the country in the consent log. IP addresses are masked before being stored in your WordPress database. MaxMind attribution: https://www.maxmind.com Service URLs SureCookie scanning and geolocation service: https://library.surecookie.com/ SureCookie privacy policy: https://surecookie.com/privacy-policy/ MaxMind: https://www.maxmind.com Data Stored Locally SureCookie stores plugin settings and consent data in your WordPress database. This can include: Banner and preference modal settings Cookie categories Custom cookies Scanned cookies Scanned resources Scan history Consent logs Cookie policy page ID Automatic scan settings Scanner credentials Consent logs and scan results can be viewed, exported, or deleted from the WordPress admin. Privacy and Data Processing SureCookie processes data through its API service at library.surecookie.com for cookie scanning, scanner authentication, and region-aware consent logging. Here is what happens and why. What We Send to SureCookie Services During the one-time scanner registration and site verification flow, SureCookie sends the site URL, the WordPress administrator email, the SureCookie version, and a temporary installation nonce. The scanning service uses these to verify your site and issue credentials, then returns a verification token that SureCookie exposes at a temporary REST endpoint for domain verification. After registration, scan requests use site-specific credentials stored locally in WordPress and do not resend the admin email. When a scan runs, SureCookie sends selected page URLs to the scanning service so a real browser can detect cookies, scripts, resources, and third-party domains. What Is Processed and Why Cookie scanning: Selected page URLs are scanned in a real browser environment to detect cookies, scripts, resources, and third-party domains. Cookie categorization: Detected cookie details, such as names, domains, and durations, are used to help categorize cookies. Region detection: Visitor IP addresses may be processed through MaxMind-backed region detection to determine country-level location for consent logs. IP addresses are masked before being stored in your WordPress database. Consent records: Consent choices, timestamps, category preferences, and session details are logged locally in your WordPress database. Where Data Lives Consent logs, scan results, settings, and scanner credentials are stored in your WordPress database. Data sent to library.surecookie.com for scanning and geolocation may be temporarily processed for those features. SureCookie does not sell this data or use it for advertising. Data Retention and Control Consent logs and scan results can be viewed, exported, or deleted from your WordPress admin. Consent log retention periods are configurable in plugin settings. Scanner credentials are stored locally in a non-autoloaded WordPress option. Security API communication uses HTTPS. Scan requests use authenticated site credentials after the registration flow. Site credentials are used to sign later scan requests. Because visitor data and selected page URLs can be processed through SureCookie services, you should mention this in your site’s privacy policy where appropriate. Full details: https://surecookie.com/privacy-policy/ For questions about data processing, visit https://surecookie.com/support/. Useful Links SureCookie Website Documentation Support Forum Privacy Policy Live Demo About Brainstorm Force SureCookie is built by Brainstorm Force, the team behind Astra and other widely used WordPress products.