CookieBoxs – GDPR/CCPA Cookie Consent & Google Consent Mode v2
CookieBoxs is a cookie consent plugin for WordPress that helps site owners manage visitor consent preferences and configure consent-aware integrations. Free features include: Google Consent Mode v2 support Automatic script blocker and cookie cleaner 25+ built-in integrations Content blockers for embedded media and maps 40 interface languages Region presets Consent logging in WordPress Floating settings badge Self-hosted plugin files Optional PRO features include two-phase Cookie Scanner (server + browser-based detection), geo-targeting, additional templates, cookie declaration, consent analytics, tamper-proof consent records with CSV export and printable certificates, A/B testing of banner variants, granular per-service consent, a live banner design editor, branding options, and custom CSS. Documentation: cookieboxs.com Source Code All JavaScript and CSS files included in this plugin are human-readable and not minified or compiled. No build tools (npm, webpack, composer) are required to work with this plugin’s source code. All plugin-authored JavaScript and CSS is written directly and included as-is. Third-party libraries and embed snippets: assets/js/chart.min.js — Chart.js library (MIT License). Source code and unminified version available at: https://github.com/chartjs/Chart.js assets/js/cookieboxs-consent-mode.js — Contains standard third-party integration embed snippets (e.g., Google Tag Manager, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar, LiveChat, Intercom, etc.). These are the official JavaScript snippets provided by each service for website embedding, written in their standard compact form. Each snippet includes a source URL comment pointing to the official documentation. A full list of source URLs is also available in the file header comments. The surrounding plugin logic (consent state management, Google Consent Mode v2 setup, custom script injection) is authored by this plugin and is fully human-readable. Official documentation URLs for all embedded third-party snippets: Google Tag Manager: https://developers.google.com/tag-platform/tag-manager/web Meta Pixel: https://developers.facebook.com/docs/meta-pixel/get-started TikTok Pixel: https://ads.tiktok.com/help/article/get-started-pixel Microsoft Clarity: https://learn.microsoft.com/en-us/clarity/setup-and-installation/clarity-setup Hotjar: https://help.hotjar.com/hc/en-us/articles/115011639927 Heap Analytics: https://developers.heap.io/docs/web Mixpanel: https://docs.mixpanel.com/docs/tracking-methods/sdks/javascript PostHog: https://posthog.com/docs/libraries/js LinkedIn Insight Tag: https://learn.microsoft.com/en-us/linkedin/marketing/integrations/ads-reporting/insight-tag Pinterest Tag: https://help.pinterest.com/en/business/article/install-the-pinterest-tag Snapchat Pixel: https://businesshelp.snapchat.com/s/article/snap-pixel-about Twitter/X Pixel: https://business.x.com/en/help/campaign-measurement-and-analytics/conversion-tracking-for-websites Microsoft Advertising UET: https://help.ads.microsoft.com/apex/index/3/en/56682 LiveChat: https://developers.livechat.com/docs/getting-started/installing-livechat Crisp: https://docs.crisp.chat/guides/chatbox-sdks/web-sdk/ Tawk.to: https://help.tawk.to/article/adding-a-tawk-to-widget-to-your-website Intercom: https://developers.intercom.com/installing-intercom/web/installation Yandex Metrica: https://yandex.com/support/metrica/code/counter-initialize.html Matomo: https://developer.matomo.org/guides/tracking-javascript-guide Privacy Policy CookieBoxs does not send visitor consent records to the plugin author’s servers. Consent records are stored in the WordPress database. Optional third-party integrations that you configure, such as analytics, advertising, chat, or embedded media services, connect directly from the visitor’s browser to those third-party providers after the relevant consent conditions are met. Admin-only connections used for plugin news, optional deactivation feedback, or optional license validation are described below. External Services This plugin uses external services only for user-configured integrations. Third-party integrations are optional, disabled by default, and only activated when the site administrator enables and configures them. The plugin does not offload any of its own assets (JavaScript, CSS, images) to external servers — all plugin files are included locally. Plugin services VisionSolutions API – plugin news and updates: used in the admin area only; sends plugin version, WordPress version, and site language when an administrator opens the settings page. Provider: VisionSolutions, https://visionsolutions.pl Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ VisionSolutions API – deactivation feedback (optional): sends selected reason, optional comment, site URL, WordPress version, and PHP version only if an administrator submits feedback during deactivation. Provider: VisionSolutions Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ VisionSolutions API – PRO license validation (optional): sends license key, site domain, and plugin version on activation and periodic validation. Provider: VisionSolutions Terms of use: https://visionsolutions.pl/regulamin/ Privacy policy: https://visionsolutions.pl/polityka-prywatnosci/ ipapi.co geolocation API (optional, PRO): used only when geo-targeting is enabled and fallback geolocation is needed; sends visitor IP address. Provider: ipapi Terms of use: https://ipapi.co/terms/ Privacy policy: https://ipapi.co/privacy/ Cookie Scanner (admin-initiated, PRO): two-phase scan. Phase 1 (server): sends requests from your server to your own website pages to detect cookies and tracking scripts from HTML. Phase 2 (browser): loads the scanned page in a hidden iframe within the administrator’s browser to detect cookies set by JavaScript (e.g. pixels loaded via Google Tag Manager). All scanning happens locally — no external provider is contacted. Optional integrations (services) These are third-party services that the site administrator can optionally enable. When enabled, the plugin loads the official embed snippet provided by each service, which connects the visitor’s browser directly to that service provider. These are service integrations, not offloaded plugin assets. Each integration is disabled by default and only activates when the administrator provides their account ID. Google Tag Manager – tag management service; may load on page view and use Consent Mode signals. Loaded from: www.googletagmanager.com. Provider: Google LLC. Terms of use: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy policy: https://policies.google.com/privacy Google Analytics 4 – analytics service; loaded from www.googletagmanager.com/gtag/js via wp_enqueue_script. Provider: Google LLC. Terms of use: https://marketingplatform.google.com/about/analytics/terms/us/ Privacy policy: https://policies.google.com/privacy Google Ads – conversion tracking and remarketing service; loaded from www.googletagmanager.com/gtag/js via wp_enqueue_script. Provider: Google LLC. Terms of use: https://ads.google.com/intl/en/home/terms/ Privacy policy: https://policies.google.com/privacy Meta Pixel – advertising measurement service; loaded from connect.facebook.net. Provider: Meta Platforms, Inc. Terms of use: https://www.facebook.com/legal/terms Privacy policy: https://www.facebook.com/privacy/policy/ TikTok Pixel – advertising measurement service; loaded from analytics.tiktok.com. Provider: TikTok Inc. / ByteDance Ltd. Terms of use: https://ads.tiktok.com/i18n/official/policy/business-products-terms Privacy policy: https://www.tiktok.com/legal/privacy-policy Microsoft Clarity – session analytics and heatmaps service; loaded from www.clarity.ms. Provider: Microsoft Corporation. Terms of use: https://clarity.microsoft.com/terms Privacy policy: https://privacy.microsoft.com/en-us/privacystatement Hotjar – heatmaps, recordings, and feedback service; loaded from static.hotjar.com. Provider: Hotjar Ltd. Terms of use: https://www.hotjar.com/legal/policies/terms-of-service/ Privacy policy: https://www.hotjar.com/legal/policies/privacy/ Matomo – analytics service; loaded from the site administrator’s configured Matomo instance URL. Provider: InnoCraft Ltd. or the site owner’s Matomo host. Terms of use: https://matomo.org/matomo-cloud-terms-of-service/ Privacy policy: https://matomo.org/matomo-cloud-privacy-policy/ Yandex Metrica – analytics service; loaded from mc.yandex.ru. Provider: Yandex LLC. Terms of use: https://yandex.com/legal/metrica_termsofuse/ Privacy policy: https://yandex.com/legal/confidential/ Heap Analytics – analytics service; loaded from cdn.heapanalytics.com. Provider: Heap Inc. Terms of use: https://heap.io/legal/heap-terms-of-service Privacy policy: https://heap.io/legal/privacy Mixpanel – analytics service; loaded from cdn.mxpnl.com. Provider: Mixpanel, Inc. Terms of use: https://mixpanel.com/legal/terms-of-use/ Privacy policy: https://mixpanel.com/legal/privacy-policy/ PostHog – analytics and feature flags service; loaded from the site administrator’s configured PostHog host. Provider: PostHog, Inc. Terms of use: https://posthog.com/terms Privacy policy: https://posthog.com/privacy LinkedIn Insight Tag – advertising measurement service; loaded from snap.licdn.com. Provider: LinkedIn Corporation. Terms of use: https://www.linkedin.com/legal/l/li-marketing-terms Privacy policy: https://www.linkedin.com/legal/privacy-policy Pinterest Tag – advertising measurement service; loaded from s.pinimg.com. Provider: Pinterest, Inc. Terms of use: https://policy.pinterest.com/en/terms-of-service Privacy policy: https://policy.pinterest.com/en/privacy-policy Snapchat Pixel – advertising measurement service; loaded from sc-static.net. Provider: Snap Inc. Terms of use: https://snap.com/en-US/terms Privacy policy: https://snap.com/en-US/privacy/privacy-policy Twitter/X Pixel – advertising measurement service; loaded from static.ads-twitter.com. Provider: X Corp. Terms of use: https://twitter.com/en/tos Privacy policy: https://twitter.com/en/privacy Microsoft Advertising UET – conversion tracking service; loaded from bat.bing.com. Provider: Microsoft Corporation. Terms of use: https://about.ads.microsoft.com/en-us/policies/legal Privacy policy: https://privacy.microsoft.com/en-us/privacystatement Intercom – customer messaging service; loaded from widget.intercom.io and api-iam.intercom.io. Provider: Intercom, Inc. Terms of use: https://www.intercom.com/legal/terms-and-policies Privacy policy: https://www.intercom.com/legal/privacy LiveChat – support chat service; loaded from cdn.livechatinc.com. Provider: LiveChat, Inc. Terms of use: https://www.livechat.com/legal/terms-of-service/ Privacy policy: https://www.livechat.com/legal/privacy-policy/ Crisp – customer messaging and chat service; loaded from client.crisp.chat. Provider: Crisp IM SAS. Terms of use: https://crisp.chat/en/terms/ Privacy policy: https://crisp.chat/en/privacy/ Tawk.to – support chat service; loaded from embed.tawk.to. Provider: Tawk.to Ltd. Terms of use: https://www.tawk.to/legal/terms-of-service/ Privacy policy: https://www.tawk.to/legal/privacy-policy/ Script blocker safe domains The automatic script blocker does not block scripts from essential service domains (payment gateways, CAPTCHAs, translation). These domains are whitelisted so the script blocker does not interfere with site-critical functionality provided by other plugins or themes. The CookieBoxs plugin itself does not load any files from these domains — they are only whitelisted to prevent breakage: Stripe – payment processing service; loaded by other plugins from js.stripe.com and checkout.stripe.com. Provider: Stripe, Inc. Terms of use: https://stripe.com/legal/ssa Privacy policy: https://stripe.com/privacy PayPal – payment processing service; loaded by other plugins from www.paypal.com and www.paypalobjects.com. Provider: PayPal Holdings, Inc. Terms of use: https://www.paypal.com/us/legalhub/useragreement-full Privacy policy: https://www.paypal.com/us/legalhub/privacy-full Google reCAPTCHA – spam protection service; loaded by other plugins from recaptcha.net. Provider: Google LLC. Terms of use: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy hCaptcha – spam protection service; loaded by other plugins from js.hcaptcha.com. Provider: Intuition Machines, Inc. Terms of use: https://www.hcaptcha.com/terms Privacy policy: https://www.hcaptcha.com/privacy Cloudflare Turnstile – bot protection service; loaded by other plugins from challenges.cloudflare.com. Provider: Cloudflare, Inc. Terms of use: https://www.cloudflare.com/terms/ Privacy policy: https://www.cloudflare.com/privacypolicy/ Google Translate – translation service widget; loaded by other plugins from translate.google.com and translate.googleapis.com. Provider: Google LLC. Terms of use: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy Content blockers Content blockers are an optional feature that replaces embedded third-party media (YouTube, Vimeo, Google Maps) with a placeholder until the visitor grants consent. When consent is given, the embed loads normally from the service provider. YouTube – video embeds can be blocked until consent; loaded from www.youtube.com and www.youtube-nocookie.com. Provider: Google LLC. Terms of use: https://www.youtube.com/t/terms Privacy policy: https://policies.google.com/privacy Vimeo – video embeds can be blocked until consent; loaded from player.vimeo.com and vimeo.com. Provider: Vimeo, Inc. Terms of use: https://vimeo.com/terms Privacy policy: https://vimeo.com/privacy Google Maps – map embeds can be blocked until consent; loaded from www.google.com/maps and maps.googleapis.com. Provider: Google LLC. Terms of use: https://cloud.google.com/maps-platform/terms Privacy policy: https://policies.google.com/privacy
Top keywords
- com95×4.90%
- https89×4.59%
- privacy56×2.89%
- terms50×2.58%
- policy39×2.01%
- provider37×1.91%
- privacy policy36×1.86%
- google35×1.81%
- policy https34×1.76%
- privacy policy https34×1.76%
- service33×1.70%
- loaded31×1.60%
FAZ Cookie Manager
Tired of cookie consent plugins that lock essential features behind paywalls, require cloud accounts, or send your visitors’ data to third-party servers? FAZ Cookie Manager is a WordPress plugin that helps you implement cookie consent and privacy workflows for international regulations — completely free, with no strings attached. No account to create. The plugin requires no cloud service connection. Basic features like consent logging and geo-targeting are included — no premium plan needed. Core consent features run on your own server, and you own all your data. Why FAZ Cookie Manager? Most cookie consent plugins follow the same pattern: a free version with crippled features, and a paid tier starting at $10-50/month that unlocks what you actually need (cookie scanning, consent logs, Google Consent Mode, IAB TCF). FAZ Cookie Manager breaks that model: Cookie scanner — scans your site directly from your browser. No external service, no API limits, no waiting. Finds the cookies a JavaScript scanner cannot see — cookies set by PHP before the page renders, including HttpOnly ones your browser hides from scripts, are captured from the server response itself: from pages, AJAX, REST calls and sub-resources, then replayed across the URLs the crawl actually visited. Those are exactly the cookies that get set before consent, so a declaration built without them is incomplete. Cookie Policy generator — a jurisdiction-aware policy page (GDPR / CCPA / LGPD / POPIA) built from your own company details and the scanner’s live cookie inventory, published with [faz_cookie_policy_complete]. Ships in en, it, fr, de, es, pt-BR, bg and cs, and every section can be rewritten per jurisdiction and language. Consent logging with CSV export — every consent is recorded locally in your database. Export anytime for audits. Google Consent Mode v2 — all 7 consent signals sent to Google tags. No premium required. IAB TCF v2.3 — full Transparency and Consent Framework API and UI. Operating as a recognised CMP needs your own registered IAB Europe CMP ID; without one the TCF interface stays inactive and no TC string is produced, so invalid signals are never broadcast to vendors. Script blocking — tag any script with data-faz-tag to hold it until its category is accepted. Geo-targeting and 180+ languages — serve the right banner per region and translate every string, or use a built-in translation. Guided setup wizard — a first-run wizard detects your environment (multilingual plugin, page cache, WooCommerce, existing consent data) and configures jurisdiction-appropriate defaults, explaining each choice in plain language. Existing sites are treated as already set up and are never nagged. A/B test your consent banner — run two or more existing banners with a persistent random split and read the accept rate per variant. Only active, independently compliant banners take part, so improving your wording can never quietly become a dark pattern. Off by default. Schrems II transfer disclosure — flag per cookie that a service sends personal data to a country without an EU adequacy decision, with the safeguard you rely on. Worded neutrally: it states the fact and your described safeguard, and never claims that safeguard is legally sufficient. Off by default. Age-appropriate consent (GDPR Art. 8) — an optional age-confirmation checkbox above the buttons. It gates only Accept, never Reject or withdraw, so the two keep equal weight. This is a self-declared affirmation and is not a substitute for the parental-consent verification Art. 8(2) requires. Off by default. Ad-blocker resilience — keeps the legally required notice visible when a cosmetic filter list hides elements whose class contains “cookie” or “consent”. A single deferred re-assert: no loop, no cookie wall. It protects a mandatory notice; it does not circumvent a privacy tool. Off by default. Editable “Do Not Sell” opt-out text — customise the title, description and toggle label of the CCPA / US State Laws opt-out popup, per language. E-commerce & payment friendly — a per-gateway opt-in (PayPal, Stripe, Square, Braintree, Klarna, Mollie, Amazon Pay) lets payment SDKs load before consent when you enable that gateway, so pre-consent blocking never breaks a payment button. Off by default; a real WooCommerce checkout/cart is exempt automatically. Cache & object-cache compatible — purges and bypasses FlyingPress, LiteSpeed, WP Rocket, W3 Total Cache and more on save, epoch-invalidates Redis / Memcached object caches, and keeps WPML, Polylang, TranslatePress and Weglot banners in the right language behind a full-page cache. Details in the FAQ. Microsoft UET/Clarity, revisit widget, accessibility — consent integration for Microsoft tags, a floating button so visitors can change their mind, and keyboard/screen-reader support throughout. Helps with these frameworks This plugin assists consent and privacy workflows. It does not itself create, provide, or guarantee legal compliance, and you remain responsible for the final configuration for your site and jurisdiction. GDPR (EU General Data Protection Regulation) — Opt-in consent, granular categories, right to withdraw CCPA / CPRA (California Consumer Privacy Act) — “Do Not Sell or Share” opt-out link ePrivacy Directive (EU Cookie Law) — Consent-based script blocking support Italian Garante Privacy — 6-month consent expiry setting and consent logging controls EDPB Guidelines — No scroll-as-consent, no pre-checked categories, equal button prominence options LGPD (Brazil General Data Protection Law) — Consent-based model POPIA (South Africa Protection of Personal Information Act) — Conservative consent-based preset under s.11(1)(a); other s.11(1)(b)-(f) justifications require separate assessment Try it Live Try FAZ Cookie Manager in WordPress Playground — no account, no install, runs entirely in your browser. How it works Install and activate — the cookie banner appears immediately with sensible defaults Scan your site to detect cookies automatically Customize the banner design, text, and colors to match your brand Enable Google Consent Mode or IAB TCF if you use advertising tools Monitor consent analytics on the dashboard Core banner functionality runs on your WordPress site. Optional update/download features may contact GitHub, IAB Europe, MaxMind, ipinfo.io (opt-in VPN detection), or the AMP CDN depending on which features you enable and use. Cookie Policy generator A dedicated Cookie Policy admin tab and the [faz_cookie_policy_complete] shortcode build a policy page from the cookies your site actually sets. Jurisdiction-aware — GDPR (EU/EEA/UK), CCPA/CPRA, LGPD or POPIA, each with the legal references and sections that framework requires. Auto-populated — the inventory renders live from the scanner, so a newly discovered cookie appears with its category, duration and description. Multilingual — en, it, fr, de, es, pt-BR, bg, cs; override per render with lang="it" or let the browser decide. Editable per jurisdiction and language — replace any section with your own Markdown, placeholders included; leave one empty and it keeps receiving reviewed updates. Your company data — name, address, DPO email, retention period. Never seeded from admin_email or blogname. Honest by default — a localised disclaimer states the templates are a starting point, not legal advice. The older [faz_cookie_policy] and [faz_cookie_table] shortcodes and the faz/cookie-table block are unchanged. Multi-banner geo-routing and multilingual content Two orthogonal features that combine freely: the visitor’s country decides which banner is served, the visitor’s browser language decides the translation shown inside it. Geo-routing picks a banner per country — typically a strict GDPR banner for the EU/EEA/UK and a CCPA opt-out banner for California — resolving the country from Cloudflare’s CF-IPCountry header (opt-in), then a server GeoIP module or extension, then the self-hosted MaxMind GeoLite2 database. All four are local to your server or your CDN edge; no visitor IP is sent to a third party for country resolution. When none of them is available the most-protective GDPR ruleset is applied to every visitor. Translations live inside each banner and are resolved client-side from navigator.languages, so a country-targeted banner still works behind a full-page cache. In practice that means two banner rows rather than eight: one EU banner holding English, Italian, German, French and Polish, one US banner holding English and Spanish. External Services Summary. This plugin is cloud-free: consent is stored on your own site and there is no vendor account, dashboard or telemetry. Below is the full outbound picture, one heading per item — the optional features that contact an external host (none run unless you enable them), the public REST endpoints this plugin exposes on your own domain, and a note on third-party domain strings that appear in the code as matching patterns and are never contacted. Each entry states its trigger, what leaves your server, and the provider’s terms. GitHub / Raw GitHubusercontent (Open Cookie Database) Used to refresh the built-in cookie definitions snapshot for the optional auto-categorize feature. Triggered when: you click the definitions update action in the Cookies screen. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://raw.githubusercontent.com/fabiodalez-dev/Open-Cookie-Database/master/open-cookie-database.json Terms of Service / Privacy Policy: * https://docs.github.com/en/site-policy/github-terms/github-terms-of-service * https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement IAB Europe / vendor-list.consensu.org Used to download the Global Vendor List and purpose translations for the optional IAB TCF feature. Triggered when: you manually update the vendor list, and weekly while IAB TCF is enabled. Data sent: your server IP address and standard HTTP request headers. Service URLs: * https://vendor-list.consensu.org/v3/vendor-list.json * https://vendor-list.consensu.org/v3/purposes-en.json Privacy Policy: * https://iabeurope.eu/privacy-policy/ MaxMind Used to download a GeoLite2 database for optional geo-targeting. You choose the edition in Settings → GeoIP Database: the smaller Country edition (default, country-level only) or the larger City edition (adds region/subdivision data for sub-national province/state routing such as Quebec Law 25). City is a much larger download; pick it only if you rely on region-level routing. Triggered when: you enter a MaxMind license key in Settings and start the database download. Data sent: your server IP address, the license key you provide, and standard HTTP request headers. Service URL: * https://download.maxmind.com/app/geoip_download Terms of Service / Privacy Policy: * https://www.maxmind.com/en/terms-of-use * https://www.maxmind.com/en/privacy-policy ipinfo.io (optional live VPN detection and admin preview) The live geo-ruleset runtime applies jurisdiction-specific consent defaults and mandatory controls. If an administrator explicitly enables ipinfo.io, the jurisdiction pipeline may use it to classify a visitor as VPN/proxy/Tor and apply the most-protective fallback; the Geo-routing admin preview uses the same detector. Leave this integration disabled to keep visitor geolocation entirely on trusted headers and the local GeoLite2 database. Triggered when: an administrator has configured an ipinfo API key, confirmed the transfer terms, and enabled the integration, then either a visitor-facing jurisdiction lookup or an admin preview runs the geo detector. Without that explicit opt-in, ipinfo is never called. Data sent: the visitor IP address or the IP entered/resolved for an admin preview, the configured API key, and standard HTTP request headers. The result is cached locally for 24 hours hash-keyed by IP. Service URL: * https://ipinfo.io/{ip}/privacy Terms of Service / Privacy Policy: * https://ipinfo.io/terms-of-service * https://ipinfo.io/privacy-policy * DPA (Data Processing Agreement) available on request: https://ipinfo.io/contact Plugin REST endpoint /faz/v1/banner (public) Serves the banner configuration to the visitor’s browser under Cache Compatibility Mode, so a full-page cache can store one visitor-invariant HTML document while the banner still resolves per request. Hosted by this WordPress install; no third-party host is involved. Triggered when: Cache Compatibility Mode is enabled and a visitor loads a page with no stored consent. Data sent: nothing about the visitor. The response carries banner text, categories and styling only. Service URL: * https://{your-site}/wp-json/faz/v1/banner Plugin REST endpoints /faz/v1/amp-consent/check and /update (public) Used by the plugin’s AMP banner to reconcile the AMP consent cache with the first-party FAZ consent cookie. Both are hosted by the same WordPress install. Requests must pass AMP CORS provenance checks — the publisher origin, or that publisher’s exact HTTPS Google AMP Cache origin with the matching __amp_source_origin. Arbitrary origins, another publisher’s cache subdomain, and requests without AMP provenance are rejected before consent can change. Sites on another registered AMP cache can add their own verified exact origin with the faz_amp_consent_allowed_cache_origin filter. Triggered when: an AMP page checks an existing decision, or the visitor saves AMP cookie preferences. Data sent: banner scope, consent state, per-category purpose choices, and the AMP-generated user ID that amp-consent includes. FAZ neither stores nor logs that ID, and does not derive its consent identifier from it. The update endpoint tries to synchronise the first-party cookie with SameSite=None; Secure; a browser that blocks third-party cookies may refuse it behind an AMP Cache, and the bridge then fails closed and asks again rather than claiming cross-origin parity it cannot guarantee. Service URLs: * https://{your-site}/wp-json/faz/v1/amp-consent/check * https://{your-site}/wp-json/faz/v1/amp-consent/update AMP Project CDN Used only on AMP pages when the AMP consent integration is active, to load the official amp-consent component required by AMP. Triggered when: an AMP page renders the AMP consent banner. Data sent: the visitor IP address and standard browser request data to the AMP CDN. Service URL: * https://cdn.ampproject.org/v0/amp-consent-0.1.js Documentation / Privacy: * https://amp.dev/documentation/components/amp-consent * https://policies.google.com/privacy Note on third-party domain strings inside the plugin codebase The source contains third-party domain names (js.stripe.com, connect.facebook.net, googletagmanager.com and others) purely as string patterns, for two purposes: Blocking detection — to recognise analytics, advertising and tracking scripts injected by the site’s other plugins, so they can be held until consent. This plugin loads none of them itself. Explicit exceptions — no whole third-party plugin is whitelisted and no profiling resource is: Google Fonts, Google Maps, OAuth endpoints and generic CDNs stay blocked until consent. The only defaults are four anti-abuse challenge endpoints (reCAPTCHA, its gstatic assets, Cloudflare Turnstile, hCaptcha), which gate a form the visitor is actively submitting and are therefore strictly necessary. An administrator can add a narrow audited exception in Settings, and can remove the CAPTCHA defaults too. Every outbound request documented above happens only when its feature is used. /faz/v1/banner is hosted by this plugin on the same site: no third-party call leaves the visitor’s browser. Cache Plugin Compatibility When multi-banner geo-routing is active, the rendered HTML can legitimately vary by visitor country. This plugin asks the page-cache layer to bypass caching on those requests by emitting: Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache X-LiteSpeed-Cache-Control: no-cache CDN-Cache-Control: no-store and Cloudflare-CDN-Cache-Control: no-store (banner REST endpoint only, so an edge that overrides the browser directive still refuses to store the country-dependent payload) Vary: CF-IPCountry (when the trust filter faz_trust_cf_ipcountry_header is enabled). It is emitted for symmetry but is inert on these responses: nothing is stored, so there is no cache key to vary. Vary only does work on the storable responses — the banner REST endpoint’s non-country-dependent answers, which are served public, max-age=300 and carry the same header. DONOTCACHEPAGE, …