MantaWeb Consent Shield – Cookie Consent Banner & Real Cookie Blocker (GDPR, CCPA, Tikun 13)
MantaWeb Consent Shield is a privacy consent management plugin for WordPress built by MantaWeb. It combines a configurable consent banner with an active script and cookie blocker, a full audit log, and a compliance checklist – all without sending any data to external servers.
Who it is for
Any WordPress site that needs to comply with:
- Israeli Privacy Law Amendment 13 (Tikun 13, in force August 2025)
- GDPR + ePrivacy Directive (EU / UK)
- CCPA “Do Not Sell My Personal Information” (California)
How it works
When a visitor lands on your site, Consent Shield shows a consent banner before any third-party scripts run. Scripts are blocked server-side using an output-buffer HTML rewriter – not just via the WordPress wp_enqueue_script filter. This means inline scripts (Google Tag Manager, Meta Pixel, GA4 config calls), iframes (YouTube, Vimeo, Google Maps), and tracking pixels are all held until the visitor gives consent, even when the page is served from a Cloudflare cache or WP-Rocket.
After consent, the plugin stores an immutable record (INSERT-only – no UPDATEs) in a local database table and fires Google Consent Mode v2 signals automatically for GA4 and Google Ads.
Key features – Free
4-category consent banner
* Necessary, Functional, Analytics, Marketing categories
* 1-button, 2-button, and 3-button layouts (configurable in the wizard)
* Fully customizable text – edit every word the visitor sees from the admin UI
* Floating privacy pill for post-consent withdrawal (required by Tikun 13)
* [mantacs_dsar_button] shortcode: adds a “Request my data” button that opens the visitor’s mail client with a pre-filled DSAR email addressed to your DPO
Real script and cookie blocker
* Output-buffer HTML rewriter – blocks scripts and iframes that bypass wp_enqueue_script
* Click-to-load placeholders for YouTube, Vimeo, and Google Maps embeds
* Cookie Sweeper removes cookies not belonging to consented categories on consent change
* Works behind Cloudflare cache, WP-Rocket, and other full-page caching systems
* ~50 built-in service definitions including Israeli payment gateways (Tranzila, Cardcom, Bit, iCount, ActiveTrail, Smoove)
Compliance tools * Google Consent Mode v2 automatic wiring for GA4 * IP anonymization – IPv4 masked to /24, IPv6 to /48 (default ON) * Tikun 13 compliance checklist with automatic checks and manual-check guidance * Policy versioning – one click forces re-consent from all visitors * Bot detection – hides the popup from search engine crawlers
Audit and data management
* Immutable consent log (INSERT-only) for a complete audit trail
* CSV export from the admin UI
* Admin activity log tracks every settings change
* WP-CLI commands: wp pcm status, wp pcm consents export, wp pcm policy bump, wp pcm tikun13 check, wp pcm wizard reset, wp pcm cache flush
Setup * 5-step guided setup wizard (~3 minutes) * All banner texts editable from the admin “Custom Texts” tab * Light/dark mode support via CSS custom properties
What makes it different
Real blocker, not just an enqueue filter. Most consent plugins only hook into wp_enqueue_script. Consent Shield rewrites the HTML output server-side, so GTM’s dataLayer push, inline fbq() calls, and hardcoded <script> tags are all blocked before the visitor even downloads the page.
Cloudflare-safe architecture. Because the HTML is identical for all visitors (scripts disabled by default), cached pages work correctly. The client-side bootstrap JS reads the consent cookie and re-enables the right scripts in real time – no PHP run required.
100% self-hosted – a privacy tool that respects privacy. Many popular consent solutions are SaaS platforms: every consent event, and with it your visitors’ data, flows through a third-party cloud. Consent Shield sends nothing anywhere – no telemetry, no phone-home, no external consent management platform. Consent records live in your own database, under your control.
Tikun 13-first. Built from scratch for Israeli Privacy Law compliance, not retrofitted from a GDPR-only plugin.
Fully functional, no locked features
Every feature described above is included and fully functional. This plugin contains no locked or disabled functionality: no license keys, no trials, no “Pro” badges on grayed-out controls.
Consent Shield Pro (separate full version)
A separate, paid Pro version (distributed by MantaWeb, not hosted on WordPress.org) contains everything in this plugin plus geo-routed banner text (GDPR/CCPA variants by visitor country), a visual banner-layout picker, per-button colors with gradients and hover effects, embedded Hebrew web fonts, and an auto-detect scanner. Installing Pro replaces this plugin; all settings and consent data carry over automatically. Full feature comparison: manta-web.co.il/consent-shield/en
MantaWeb also offers a separate, paid Tikun 13 implementation service (privacy-policy drafting and site setup); details are on the “MantaWeb Services” screen inside the plugin.
External services
This plugin does NOT connect to, call, or send any data to any external or third-party service. It makes no outbound HTTP requests. Every consent record, log entry and setting is stored only in your own WordPress database. No telemetry, no phone-home, no remote fonts, no remote analytics, and no license or activation checks.
Please note about the code: the plugin contains a built-in list of third-party tracker domain names (for example googletagmanager.com, connect.facebook.net, embed.tawk.to, widget.intercom.io). These strings are NOT services the plugin contacts. They are the plugin’s blocklist: the trackers the plugin looks for in your page’s HTML and BLOCKS (neutralizes) until the visitor consents. The plugin never loads or requests any of these domains itself; it only prevents your own theme/other plugins from loading them before consent.
The MantaWeb Services admin page contains plain HTML links to the MantaWeb website and to WhatsApp. Nothing is sent when the page loads; a link only opens the target site in a new tab if you click it.
