Aprašymas
Cookie Rocket is a lightweight cookie consent plugin that actually blocks third-party tracking scripts until your visitors consent — not just a banner on top. Automatic blocking of Google Analytics, Meta Pixel, Hotjar and more, plus Google Consent Mode v2, a cookie scanner and a consent log, are all included in the free version. Native compliance for GDPR, LGPD (Brazil) and LFPDPPP (Mexico).
It is a fully self-hosted alternative to cloud cookie-consent services: no account, no monthly SaaS fee and no external calls. Real script blocking, Google Consent Mode v2 and on-demand cookie scanning are free here — features that comparable consent tools typically gate behind a paid plan or a remote service.
- Automatic script blocking: common third-party trackers (Google Analytics, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn, TikTok and more) are blocked until consent, with Google Consent Mode v2 built in.
- Built-in cookie scanner: detect on demand which known tracking services are present on your site and the cookies they set.
- Automatic cookie policy / cookie declaration: a single shortcode (or one-click page) publishes a table of every cookie your site uses — provider, purpose and duration — grouped by category and updated from your scans.
- Consent audit log with an admin viewer: every consent decision is recorded and browsable for compliance.
- Editable cookie categories: rename, re-describe and reorder the categories shown on the banner.
- Unified Cookie Banner editor: layout, content (text and labels) and colours, all in one place.
- Zero external scripts and zero CDN dependencies — everything is served from your own site.
- Native compliance for LFPDPPP (Mexico) and LGPD (Brazil).
- GDPR compatible out of the box.
- 100% local — no consent data is sent to third-party servers.
- WooCommerce aware: respects shop pages and checkout.
- Fully customizable colors, fonts sizes, copy and banner position.
- WCAG 2.1 AA accessible: keyboard navigation, focus states, ARIA labels.
- Multisite compatible.
- Five banner layouts: bottom bar, top bar, floating card, modal and drawer.
Shortcodes
[cookie-rocket-preferences]— renders a button that re-opens the cookie preferences modal.[cookie-rocket-withdraw]— renders a link that withdraws consent and clears stored preferences.[cookie_rocket_policy]— renders the automatic cookie declaration table (provider, purpose and duration per cookie, grouped by category).
Cookie Rocket Pro
A commercial Pro version adds Google Consent Mode advanced (keeps your Google Ads and GA4 measurement working while consent is denied), a tamper-evident consent ledger with one-click audit evidence, per-visitor legal routing (GDPR in Europe, CCPA in the United States, LFPDPPP in Mexico, LGPD in Brazil), a Latin America pack with a generated aviso de privacidad and a self-hosted ARCO / DSAR rights channel, Google Tag Manager integration, scheduled monthly re-scans with email alerts, CSV export of the consent log and extended log retention. It is available at templatesrocket.com. The free version published here is fully functional and does not require the Pro plugin to work.
Ekrano nuotraukos





Diegimas
- Upload the
cookie-rocketfolder to the/wp-content/plugins/directory, or install the plugin through the WordPress plugins screen directly. - Activate the plugin through the Plugins screen in WordPress.
- Go to Cookie Rocket in the admin menu to configure the banner copy, colors and behavior.
- Optionally, place the
[cookie-rocket-preferences]shortcode in your privacy policy page to let visitors update their choices at any time.
DUK
-
Does this plugin send any data to external services?
-
No. Cookie Rocket stores consent entirely in the visitor’s browser (cookie + localStorage) and logs events to your own WordPress database. Your visitors never generate a request to an external server: the plugin makes no third-party calls at runtime.
-
Is it compatible with caching plugins?
-
Yes. The banner state is read from a first-party cookie, so caching (page cache, object cache, CDN) does not interfere with consent storage or display.
-
Does it block third-party scripts automatically?
-
Yes. The free version automatically blocks the most common third-party tracking scripts — Google Analytics, Meta (Facebook) Pixel, Hotjar, Microsoft Clarity, LinkedIn, TikTok, Google Ads and more — until the visitor accepts the matching cookie category, and it ships Google Consent Mode v2 (default denied) out of the box. Enqueued scripts are blocked by default; an optional setting also blocks scripts pasted directly into your theme or header. Cookie Rocket Pro adds scheduled monthly re-scans that email you when a new tracker appears, plus Google Consent Mode advanced so your Google Ads and GA4 keep measuring while consent is denied.
-
Is it translation-ready?
-
Yes. The text domain is
cookie-rocketand a complete.potfile is included under/languages/. All banner and modal strings are wrapped for translation. The plugin ships in English by default with Spanish (es_ES) and Brazilian Portuguese (pt_BR) translations bundled, applied automatically on matching locales. WordPress also loads community translations for plugins hosted on WordPress.org, and you can translate the banner yourself with Loco Translate or Poedit, or via WPML/Polylang. -
Yes. Add the
[cookie_rocket_policy]shortcode to any page, or go to Cookie Rocket Cookie Policy and create the page in one click. It publishes a cookie declaration table — each cookie with its provider, purpose and duration, grouped by category — built from your latest scan plus a built-in catalog of the most common third-party cookies. Strictly-necessary cookies are always listed, and the table updates automatically as you re-scan. -
Does it work on WordPress Multisite?
-
Yes. Each site stores its own settings. Activate per-site or network-activate from the network admin.
Atsiliepimai
Įskiepis neturi atsiliepimų.
Programuotojai ir komandos nariai
“Cookie Rocket – Cookie Consent & Privacy Compliance” yra atviro kodo programa. Prie jos sukūrimo prisidėję žmonės surašyti toliau.
AutoriaiIšverskite “Cookie Rocket – Cookie Consent & Privacy Compliance” į savo kalbą.
Domina programavimas?
Peržiūrėkite kodą, naršykite SVN repozitorijoje, arba užsiprenumeruokite kodo pakeitimų žurnalą per RSS.
Pakeitimų istorija
2.15.6
New: declare your own services. Cookie Rocket recognizes nine common providers. Anything else on your site — a chat widget, a heatmap tool, a newsletter script — was neither blocked nor listed on your cookie policy. Blocking Your own services lets you name it, give the script address so it gets blocked, and describe its cookies so they appear on your policy with a real purpose and duration.
New: California. CCPA / CPRA joins GDPR, LGPD and LFPDPPP in the framework selector, with its own banner wording.
New: the scanner sees your shop. On WooCommerce sites it now also reads the shop, cart, checkout and account pages — where conversion pixels usually live and where a homepage-only scan never looked. It also tells you which trackers are new since your last scan.
Fixed: a failed scan no longer reads as a clean site. If a page could not be read, the result says so and lists which, instead of reporting zero trackers found.
Fixed: the scanner reports Google Tag Manager. The container is deliberately not blocked — Consent Mode governs it — but staying silent made a site that loads everything through GTM read „no trackers found”. It is now listed with its real status.
Fixed: the blocking status tells the truth. A tracker pasted straight into your theme is not reached by script blocking unless raw-HTML blocking is on. That row used to claim it was blocked; it now says it is pasted directly into the HTML and links to the switch that handles it.
New: consent-log retention is yours to set. Records were deleted after 90 days with no way to change it and nothing on screen saying so. There is now a field, and the log states how long it keeps records.
Free: the Glass, Graphite and Branded banner themes, and the self-hosted font option.
Updated design. Squared corners, no shadows, no transitions and no entrance animation, throughout the banner, the preferences dialog and the admin screens. If you are updating an existing site, the banner will lose its drop shadow and slide-in and gain a hairline border; your saved corner radius is untouched.
Accessibility. The floating preferences button’s focus ring is now visible on light backgrounds, and the category switches read clearly in both states.
Polish, hardening & fixes from a thorough audit — functionality, security, accessibility, reliability and translations. Nothing to reconfigure; your settings, banner and consent log are unchanged.
* Fixed (accessibility): the banner no longer traps keyboard focus in the bar layout (you can Tab past it), while the popup, side panel and drawer still contain focus while open. The preferences dialog is announced by its title, traps focus even for a returning visitor who opens it from the floating button, returns focus to the control that opened it, and its cookie-category switches carry accessible names (WCAG 2.1.2 / 2.4.3).
* Fixed (reliability): behind a full-page cache, a visitor’s consent could go unrecorded when the cached page carried an expired security token — recording no longer depends on it. The consent-endpoint rate limit is now keyed on the real connection IP with a fixed one-minute window, so it cannot be side-stepped with spoofed headers or become a permanent block.
* Fixed (privacy): blocked social/media embeds (X, Instagram, TikTok, Facebook and similar) fully restore after consent, including embeds that load their own script; and the raw-HTML script blocker now also catches trackers whose src/type attributes are unquoted.
* Fixed (Consent Mode): the „functionality_storage” signal now follows the visitor’s functional-cookie choice instead of always reporting granted.
* Fixed: „Save text” and the Layout / position / width / backdrop controls now report or roll back a failed save instead of showing an unsaved change as applied; consent-log stats and retention compute their window in the site’s own timezone; the preferences close button meets contrast; and the cookie-category grid no longer overflows on narrow phones.
* Improved (translations): the whole interface, the cookie-declaration table (each cookie’s purpose and duration) and the cleanup-schedule label are now complete in Spanish and Portuguese.
2.15.5
On some themes the Reject button could render unfilled; its fill now holds up against theme button styles.
2.15.4
Default banner aligned to the common consent-tool convention: Reject filled with equal prominence, Customize outline, subtle 2px corners.
2.15.3
Banner button order follows the common convention on every layout, and no button is pre-focused when the banner appears.
2.15.2
Banner buttons always take the same corner radius as the banner on every layout.
2.15.1
Live-preview button labels, a clean preview without the admin bar, instant style presets, contextual help tooltips, and a 0px default corner radius.
2.15.0
One-click setup, a live banner editor, blocked-embed placeholders that keep your layout, and consent that persists across localStorage clears.
2.14.x and earlier
Older release notes are available in the plugin’s development history on WordPress.org.
