Linux 软件免费装
Banner图

Cookie Rocket, Cookie Consent Banner and Script Blocker for GDPR, CCPA and LGPD

开发者 templatesrocketwp
更新时间 2026年8月29日 02:40
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

cookie consent cookie banner ccpa lgpd cookie scanner

下载

2.14.0 2.14.10 2.15.15 1.0.4 2.15.16 1.0.0 1.7.0 2.1.5 2.1.8 2.9.1 1.0.2 1.4.0 1.9.1 2.2.0 1.0.5 1.1.0 1.1.2 1.2.0 1.5.0 1.6.0 1.8.0 1.8.1 2.0.0 2.1.0 2.1.4 2.1.9 2.10.0 2.11.1 2.11.2 2.12.0 2.4.0 2.5.0 2.5.1 2.6.0 2.6.1 2.7.0 2.8.0 2.1.2 2.1.6 2.11.3 2.3.0 1.0.1 1.1.1 2.12.1 1.0.3 1.3.0 2.1.3 2.1.7 2.13.0 2.14.3 2.15.0 2.15.1 2.15.2 2.15.3 2.15.4 2.15.6 2.9.0 2.15.7 1.9.0 2.1.1 2.15.8 2.15.9 2.11.0 2.15.10 2.15.11 2.15.12 2.15.13 2.15.14 1.8.2 2.15.5

详情介绍:

Cookie Rocket is a WordPress cookie consent banner that blocks Google Analytics, Meta Pixel, Hotjar and other third-party tracking scripts until the visitor consents, with Google Consent Mode v2, a cookie scanner and a consent log included in the free version. It is for any site that has to comply with GDPR, CCPA / CPRA, LGPD (Brazil) or LFPDPPP (Mexico), each with its own banner wording and consent rules, selectable per site. It is a fully self-hosted alternative to cloud cookie-consent services: no account, no monthly SaaS fee and no external calls. Real script blocking, Google Consent Mode v2 and on-demand cookie scanning are free here — features that comparable consent tools typically gate behind a paid plan or a remote service. Shortcodes

安装:

  1. Upload the cookie-rocket folder to the /wp-content/plugins/ directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Go to Cookie Rocket in the admin menu to configure the banner copy, colors and behavior.
  4. Optionally, place the [cookie-rocket-preferences] shortcode in your privacy policy page to let visitors update their choices at any time.

屏幕截图:

  • The consent banner on a live site. Google Analytics, Meta Pixel and Hotjar stay blocked until the visitor chooses; the reject button sits on the first layer, one click away.
  • Granular preferences: visitors allow or deny each category, with strictly-necessary always on.
  • The consent log, included in the free version: every decision, the categories accepted, and the visitor identified only by a one-way hash.
  • Status at a glance — blocking, Consent Mode v2, the law applied, and your consent numbers.

升级注意事项:

2.15.6 Thorough audit: keyboard-focus fixes, hardened consent-endpoint rate limiting, reliable recording behind full-page caches, embeds that restore after consent, a closed script-blocking gap, timezone-correct log stats, and complete Spanish/Portuguese. No settings change. 2.14.0 A cleaner four-section admin, a one-time setup guide, and a new option to match the banner to your site's own font — with no external fonts ever loaded. All your settings carry over. 2.13.0 Accessibility and design pass: zero automated WCAG AA violations across the admin, visible field borders, and a save that tells you when it fails instead of losing your changes silently. 2.12.1 Accessibility fix: the banner's Reject and Customize buttons are now clearly legible (WCAG AA), as visible as Accept all. 2.12.0 Pick your law (GDPR/LGPD/LFPDPPP) in Settings and the banner's default legal text follows it — new installs detect it from the site language. Also fixes the framework resetting to generic on save. 2.11.2 Polish & fixes from a full audit: correct consent-duration in the cookie policy, modal description now shows, working privacy-policy link, salted (irreversible) IP hashes, and broader WordPress compatibility. No settings change. 2.11.1 Fixes consent texts being cut off at 200 characters (the GDPR/LFPDPPP templates were truncated). After updating, re-pick your template or re-save to store the full message. 2.11.0 Adds an opt-in "Quick feedback" prompt on deactivation. Skipping sends nothing; no personal data is ever collected. Your settings and banner are unchanged. 2.1.4 Fixes button readability and form spacing in the admin. Native, clean WordPress styling. No changes to settings or the banner. 2.1.3 Cleaner Settings and Banner Design screens (sub-navigation + accordions) and a fully neutral monochrome admin. Your settings and banner are unchanged. 2.1.2 A calmer, neutral admin palette (standard WordPress blue and greys). No changes to settings or the banner. 2.1.1 A cleaner, guided dashboard that makes setup obvious. Your settings and banner are unchanged. 2.1.0 Adds a compliance health dashboard, a visual banner layout picker, neutral style presets, click-to-load embed placeholders and a refreshed cookie scanner. Your saved settings are unchanged. 1.9.1 Adds a Brazilian Portuguese translation, auto-applied on Portuguese-language sites. No other changes. 1.9.0 Internationalization: English is now the default language, with a bundled Spanish translation auto-applied on Spanish sites (all es_* locales). Your saved banner copy and categories are unchanged. 1.8.2 Documentation and listing copy only — no code changes. 1.8.1 Housekeeping only: removes an unused legacy stylesheet that was never loaded. No change to the banner. 1.8.0 The "Drawer" banner layout is now a distinct right-side panel (it previously matched the floating card). Only affects sites using the Drawer layout; other layouts are unchanged. 1.7.0 Adds a live banner preview on the Banner Design screen. Safe update; no change to the banner shown to visitors. 1.6.0 New Categories editor lets you rename, re-describe and reorder the cookie categories shown on the banner. Safe update; existing categories are unchanged until you edit them. 1.5.0 The admin screens are now fully translatable. No visible change; safe update. 1.4.0 New Consent Log viewer under Cookie Rocket → Consent Log shows recorded consents for compliance. Safe update; read-only, no change to the banner. 1.3.0 Translation readiness: the banner and modal strings are now fully translatable and a complete .pot is included. No visible change by default; translate via Loco Translate, WPML/Polylang or translate.wordpress.org. 1.2.0 New Cookie Scanner under Cookie Rocket → Scanner: detects known tracking services on your site on demand and shows what is being blocked. Safe update; no change to the banner or blocking behavior. 1.1.2 Robustness fix: default categories and settings now self-heal if missing, so the preferences modal and "Accept all" work even on installs where activation never ran. Recommended. 1.1.1 Important fix for 1.1.0: "Accept all" and the preferences modal now correctly enable the chosen categories, so scripts blocked before consent are re-activated when the visitor accepts. Recommended for everyone on 1.1.0. 1.1.0 Major update: Cookie Rocket now actually blocks common tracking scripts (Google Analytics, Meta Pixel, Hotjar and more) until consent, with Google Consent Mode v2 built in. Review Settings → Script Blocking after updating, especially if you use a caching plugin. 1.0.5 Correctness fixes: custom banner copy and consent duration set in Settings are now actually applied, and the consent audit log records events again. Recommended update; the banner looks the same by default. 1.0.4 Post-consent floating button now defaults to OFF for a cleaner site. Installs that explicitly enabled it keep it enabled; re-enable any time in Settings. The [cookie-rocket-preferences] shortcode is always available as alternative. 1.0.3 Important fix: the preferences modal can now be closed (X button) after consent, the title typography no longer inherits the theme's heading font, and the floating button can be hidden via a new setting. Recommended update. 1.0.2 Adds a Pro features showcase panel at the bottom of the Settings page. Safe to update — no functional changes to the cookie banner itself. 1.0.1 Visual refresh only. Brand-aligned colors in the preferences modal. Safe to update. 1.0.0 First public release.

常见问题:

Does this plugin send any data to external services?

No. Cookie Rocket stores consent entirely in the visitor's browser (cookie + localStorage) and logs events to your own WordPress database. Your visitors never generate a request to an external server: the plugin makes no third-party calls at runtime.

Is it compatible with caching plugins?

Yes. The banner state is read from a first-party cookie, so caching (page cache, object cache, CDN) does not interfere with consent storage or display.

Does it block third-party scripts automatically?

Yes. The free version automatically blocks the most common third-party tracking scripts — Google Analytics, Meta (Facebook) Pixel, Hotjar, Microsoft Clarity, LinkedIn, TikTok, Google Ads and more — until the visitor accepts the matching cookie category, and it ships Google Consent Mode v2 (default denied) out of the box. Enqueued scripts are blocked by default; an optional setting also blocks scripts pasted directly into your theme or header. Cookie Rocket Pro adds scheduled monthly re-scans that email you when a new tracker appears, plus Google Consent Mode advanced so your Google Ads and GA4 keep measuring while consent is denied.

Is it translation-ready?

Yes. The text domain is cookie-rocket and a complete .pot file is included under /languages/. All banner and modal strings are wrapped for translation. The plugin ships in English by default with Spanish (es_ES) and Brazilian Portuguese (pt_BR) translations bundled, applied automatically on matching locales. WordPress also loads community translations for plugins hosted on WordPress.org, and you can translate the banner yourself with Loco Translate or Poedit, or via WPML/Polylang.

Can it generate a cookie policy page?

Yes. Add the [cookie_rocket_policy] shortcode to any page, or go to Cookie Rocket → Cookie Policy and create the page in one click. It publishes a cookie declaration table — each cookie with its provider, purpose and duration, grouped by category — built from your latest scan plus a built-in catalog of the most common third-party cookies. Strictly-necessary cookies are always listed, and the table updates automatically as you re-scan.

Does it work on WordPress Multisite?

Yes. Each site stores its own settings. Activate per-site or network-activate from the network admin.

更新日志:

2.15.16 Fixed: plural sentences were left out of the translation fallback added in 2.15.15. That release made the plugin fall back to its own bundled translation for anything the language pack was missing, but only for ordinary strings — any sentence that changes with a number still came out in English. Plurals now use the same fallback. 2.15.15 Fixed: parts of the plugin appeared in English on sites whose translation is incomplete. WordPress loads the translation package from wordpress.org and stops there, so the complete catalogue shipped inside the plugin was never consulted. Where that package was missing strings, they fell back to English — including the name of a consent category, inside the consent dialog. The bundled catalogue is now used to fill those gaps, and never to replace a translation the site already has. 2.15.14 Fixed: a blocked embed kept its shape on sites with a strict Content-Security-Policy. The placeholder that stands in for a blocked video or map carries the aspect ratio of the embed it replaces, so the page does not jump when the visitor accepts. That ratio is different for every embed, so it travelled in a style attribute — which such a policy discards, leaving the placeholder with no height: the collapsed layout this placeholder exists to prevent. The ratio now travels in a data attribute and the script applies it. 2.15.13 Fixed: the plugin now behaves the same on sites that send a strict Content-Security-Policy. A CSP whose style-src and script-src do not allow 'unsafe-inline' makes the browser discard inline style attributes and inline event handlers. The banner and the dialog put some of their layout and behaviour there, so on those sites parts of the plugin silently stopped working. Everything moved to the stylesheet and to the script file, which the policy allows. 2.15.12 Fixed: four things in the preferences dialog that were harder to use than they looked. The category controls were a sliding switch with its rounded shape removed, which read as neither a switch nor a checkbox — a square knob in a square track, where the only clue to the state was the colour of the track. They are now plain checkboxes: an empty square for off, a filled square with a checkmark for on, and a greyed checked one for strictly-necessary. Same square, no-radius look; you can tell the state at a glance. 2.15.11 The plugin description and the feature list now say what the plugin does instead of promising an outcome. The description no longer guarantees a PageSpeed score, which depends on your site and host rather than on this plugin, and the framework line no longer claims to grant legal compliance, which no plugin can grant. What it does say is accurate: it ships banner wording and consent rules for GDPR, CCPA / CPRA, LGPD and LFPDPPP, and you pick the one that applies. No functional change. 2.15.10 The plugin header now carries the same name as the listing. 2.15.9 The plugin is now listed as what it does — a cookie consent banner and script blocker — instead of claiming compliance, which no plugin can grant. CCPA / CPRA joins the tags now that the framework is fully supported. Code hardening around the new visitor-country field. 2.15.8 New: the plugin now tells you what it found on your own site. Three notices that appear only when there is something real to say, and go away when you dismiss them or when the fact changes. 2.15.7 Fixed: the cookie bar took a third of a phone screen. On mobile the three buttons stacked one per row — 148px of controls on a 300px bar, tall enough to sit on top of a form's submit button. Accept now keeps its own full-width row and Customize and Reject share the next one: 282px instead of 300, in two rows instead of three. If your site turns off Customize or Reject, the remaining button grows into the whole row. Only the top and bottom bar layouts change; the popup, floating and drawer layouts are untouched. 2.15.6 New: declare your own services. Cookie Rocket recognizes nine common providers. Anything else on your site — a chat widget, a heatmap tool, a newsletter script — was neither blocked nor listed on your cookie policy. Blocking → Your own services lets you name it, give the script address so it gets blocked, and describe its cookies so they appear on your policy with a real purpose and duration. New: California. CCPA / CPRA joins GDPR, LGPD and LFPDPPP in the framework selector, with its own banner wording. New: the scanner sees your shop. On WooCommerce sites it now also reads the shop, cart, checkout and account pages — where conversion pixels usually live and where a homepage-only scan never looked. It also tells you which trackers are new since your last scan. Fixed: a failed scan no longer reads as a clean site. If a page could not be read, the result says so and lists which, instead of reporting zero trackers found. Fixed: the scanner reports Google Tag Manager. The container is deliberately not blocked — Consent Mode governs it — but staying silent made a site that loads everything through GTM read "no trackers found". It is now listed with its real status. Fixed: the blocking status tells the truth. A tracker pasted straight into your theme is not reached by script blocking unless raw-HTML blocking is on. That row used to claim it was blocked; it now says it is pasted directly into the HTML and links to the switch that handles it. New: consent-log retention is yours to set. Records were deleted after 90 days with no way to change it and nothing on screen saying so. There is now a field, and the log states how long it keeps records. Free: the Glass, Graphite and Branded banner themes, and the self-hosted font option. Updated design. Squared corners, no shadows, no transitions and no entrance animation, throughout the banner, the preferences dialog and the admin screens. If you are updating an existing site, the banner will lose its drop shadow and slide-in and gain a hairline border; your saved corner radius is untouched. Accessibility. The floating preferences button's focus ring is now visible on light backgrounds, and the category switches read clearly in both states. Polish, hardening & fixes from a thorough audit — functionality, security, accessibility, reliability and translations. Nothing to reconfigure; your settings, banner and consent log are unchanged. 2.15.5 On some themes the Reject button could render unfilled; its fill now holds up against theme button styles. 2.15.4 Default banner aligned to the common consent-tool convention: Reject filled with equal prominence, Customize outline, subtle 2px corners. 2.15.3 Banner button order follows the common convention on every layout, and no button is pre-focused when the banner appears. 2.15.2 Banner buttons always take the same corner radius as the banner on every layout. 2.15.1 Live-preview button labels, a clean preview without the admin bar, instant style presets, contextual help tooltips, and a 0px default corner radius. 2.15.0 One-click setup, a live banner editor, blocked-embed placeholders that keep your layout, and consent that persists across localStorage clears. 2.14.x and earlier Older release notes are available in the plugin’s development history on WordPress.org.