plugin-icon

Attesso Cookie Consent

Av attesso·
Holds analytics, marketing and embed scripts until your visitor agrees, and keeps a signed record of every choice. Requires a free Attesso account.
Version
1.0.0
Senast uppdaterat
Aug 4, 2026
Attesso Cookie Consent

Most cookie banners ask for permission after the tracking has already started. The visitor sees a box, the pixels have long since fired, and the consent record describes something that never happened.

This one runs before them. It prints its script at the earliest point WordPress allows in the page head, ahead of Google Analytics, Meta Pixel, Google Tag Manager, Hotjar, Clarity and the tag managers that load them, so those scripts are held rather than caught. Nothing third party runs until somebody chooses.

Anything it does not recognise is held too. A new pixel added by a marketing agency next month is blocked on the day it appears, without anyone updating a list.

Setup

  1. Install and activate.
  2. Attesso, in the sidebar.
  3. Click Protect this site.

That is the whole setup. No account to create first, no key to copy: the plugin verifies the site with our servers and sets everything up, then emails you a link to claim the account whenever you like.

If you already use Attesso, Connect your account signs you in and attaches this site, or you can paste a pairing code from your dashboard. There is also a plain site-key field for hosts that block incoming requests.

What gets held

Trackers do not always arrive as a script tag, so a blocker that only looks for those misses the rest. This one also holds:

  • Tracking pixels, including invisible ones created in the background
  • Data sent as a visitor leaves the page, which is how some analytics tools report
  • Background requests to other companies’ servers
  • Embedded video, maps and players, replaced by a placeholder that loads on click

Embeds are stopped in the page itself, before your visitor’s browser ever sees them. Most tools cannot do this: a browser starts fetching an embedded video while it is still reading the page, before any blocking code has had a chance to run.

What you get in WordPress

The whole thing lives in your admin. There is no second dashboard to keep open.

  • Overview: how many people answered, and what they chose
  • Banner: wording, colours, position, with a live preview
  • Trackers: everything found on your site, with a plain-English explanation of each and a dropdown to recategorise it
  • Consent log: every choice, with CSV export
  • Cookie policy: written from what the scan actually found, publishable as a real WordPress page in one click
  • Scans: history, a live view while one runs, and control over how often they happen
  • Alerts: anything new that turned up

Caching and optimisation plugins

Read this if you use one. A consent blocker that gets delayed is worse than no blocker: the analytics tags it was holding run first, so tracking happens before consent while the banner still claims otherwise.

The plugin ships with the documented opt-out attributes for WP Rocket, LiteSpeed Cache and Cloudflare Rocket Loader, so those leave it alone automatically.

W3 Total Cache and Autoptimize have no attribute-based opt-out. If you use either, exclude a.js from JavaScript minify, combine and defer in its settings. One line in an exclusion box.

External services

This plugin connects to Attesso, a consent management service operated by Attesso. Using it requires an Attesso account, which the plugin can create for you during setup. Before setup, the plugin makes no external connections at all and adds nothing to your pages.

The short version: your visitors load one small script from our servers, and when somebody answers the banner their choice is saved with us as the record that proves consent was given. We never receive your WordPress login, your customers’ names or email addresses, or the pages anyone visited. Everything below is the same thing said precisely, because a consent tool that is vague about its own data handling has not understood the problem.

On every page of your site

Once a site is connected, every page view loads one script from https://cdn.getattesso.com/a.js. That request carries your site key and the normal information any browser sends when fetching a file, including the visitor’s IP address and user agent.

When a visitor answers the banner

Their choice, the categories they allowed, a timestamp, the version of your policy they saw and their coarse region are sent to https://getattesso.com/api/consent and stored as a consent record. This is the record that demonstrates consent was given, and it is the reason the plugin exists.

When the script holds a third-party host that Attesso has not seen on your site before, that hostname is sent to https://getattesso.com/api/observed so your cookie policy can describe it. The page URL is not sent, and no visitor identifier is sent.

During setup

  • https://getattesso.com/api/plugin/provision: creates your account. Sends this site’s address and name, your WordPress administrator email address, and a one-time secret.
  • https://your-site.com/wp-json/attesso/v1/challenge (or ?rest_route= on plain permalinks): this is a route on your own site, not ours. Our server fetches it once during setup to confirm you control the domain, the way a TLS certificate is validated. Nothing is sent to it; a one-time random value is read back and discarded.
  • https://getattesso.com/connect: opened in your browser if you connect an existing account.
  • https://getattesso.com/api/plugin/pair: exchanges a pairing code from your dashboard for this site’s credentials.

From the admin screens, when you open them

These carry an access token issued to this site, and no visitor data.

  • /api/plugin/dashboard: the figures and settings shown on the screens
  • /api/plugin/version: a small check for whether anything changed, so the screens stay current without refetching everything
  • /api/plugin/scan-status: live progress while a scan runs
  • /api/plugin/scan: one scan in detail
  • /api/plugin/banner: saves banner changes
  • /api/plugin/action: saves a tracker category, resolves an alert, requests a scan, changes the scan schedule, or builds a CSV export
  • /api/plugin/checkout: asks Stripe for a checkout link when you start a plan. Card details are entered on Stripe’s own pages and never touch WordPress.

No WordPress login, password or user data is sent at any point.

Service terms: https://getattesso.com/legal/terms Privacy policy: https://getattesso.com/legal/privacy

Gratispå betalda paket
Testat upp till
WordPress 7.0.2
Detta tillägg är tillgängligt för nedladdning för din .