Privaro Cookie Consent Banner
Privaro Cookie Consent Banner helps you run a privacy-conscious WordPress site in the EU and beyond. Visitors get a clear, accessible cookie banner (powered by CookieConsent v3). Third-party scripts and embeds stay blocked until consent is granted — no “accept-only” dark patterns.
Why site owners choose Privaro
- Opt-in by default — Statistics and marketing are off until the visitor accepts. Reject all is always available.
- Real script blocking — GA4, GTM, Meta Pixel, Hotjar, Microsoft Clarity, and custom rules via output buffering.
- Embed placeholders — YouTube, Vimeo, and Google Maps load only after marketing consent.
- Cookie scanner — Discover cookies on your own site (no external SaaS scanner).
- Policy helpers — Shortcodes for cookie policy, declaration table, and “Cookie settings” footer link.
- Google Consent Mode v2 — Default
denied, updates on banner choice; works with Google Site Kit. - WP Consent API — Compatible bridge (includes polyfill when the API plugin is not installed).
- Multisite — Network defaults with per-site inherit or override.
- Consent log (optional) — Local audit trail with proof snapshots; data never leaves your server.
Key features
- Customizable banner — Light/dark themes, bar or box layout, primary color, live admin preview.
- Consent categories — Necessary, Preferences, Statistics, Marketing, plus custom categories.
- Cookie inventory — Manual edits, scanner import, CSV export.
- Integrations — Google Site Kit, Contact Form 7 (reCAPTCHA deferred), iframe placeholders.
- Tools — JSON export/import of settings between sites.
- Languages — Editable EN/DE strings; Polylang/WPML-friendly.
Quick setup
- Activate the plugin and open Privaro Cookie Consent Banner in wp-admin.
- Configure the Banner tab (texts, colors, policy URLs).
- Enable Integrations → Google Consent Mode v2 and Script blocker if you use analytics/ads.
- Run the Scanner and save cookies to your inventory.
- Add
[wpeu_cookie_policy]/[wpeu_cookie_declaration]to your legal pages and[wpeu_manage_consent]to the footer. - Test in a private browser window — analytics tags should stay blocked until consent.
Legal note: This plugin provides technical compliance tools, not legal advice. You are responsible for policy texts and regulatory compliance.
Privacy & Data Collection
By default, the plugin does not collect or transmit any personal data to third-party servers. If the “Consent Logging” feature is enabled in settings, the plugin stores anonymized records of consent decisions in your local database. These records include a random UUID, the selected categories, the page URL, and (optional) an anonymized IP hash. This data is used solely for compliance accountability and is not shared with any third parties.
Credits
This plugin bundles vanilla-cookieconsent v3 (MIT). See the plugin source headers and bundled assets for license details.
External services
This plugin does not load third-party scripts by itself. It blocks or allows scripts that your theme or other plugins add to the page, based on the visitor’s consent.
When a visitor grants consent, the following may be loaded by your site configuration (not by this plugin directly):
Google Tag Manager / Google Analytics (Google LLC) Used when your site enqueues gtag or GTM after statistics consent. Data sent: page URL, browser data, and analytics events as configured on your site. Terms: https://policies.google.com/terms Privacy: https://policies.google.com/privacy
Google Fonts (Google LLC) Used when your theme loads fonts from fonts.googleapis.com after marketing consent. Data sent: IP address and browser user-agent to Google font servers. Terms: https://policies.google.com/terms Privacy: https://policies.google.com/privacy
Facebook Pixel (Meta Platforms, Inc.) Used when your site loads connect.facebook.net after marketing consent. Data sent: browsing events as configured in your Pixel setup. Terms: https://www.facebook.com/legal/terms Privacy: https://www.facebook.com/privacy/policy
YouTube / Vimeo / Google Maps embeds Used when marketing consent enables blocked iframes. Data sent: per the embed provider when the iframe loads. YouTube terms: https://www.youtube.com/t/terms — privacy: https://policies.google.com/privacy Vimeo terms: https://vimeo.com/terms — privacy: https://vimeo.com/privacy
The built-in cookie scanner fetches your own site URLs via WordPress HTTP API to detect cookies; no off-site scanner service is used.
Script blocking patterns in ScriptRegistry match known third-party domains; the plugin does not fetch those URLs until consent is granted.
