| 开发者 | sminec |
|---|---|
| 更新时间 | 2026年9月22日 21:35 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
{policy} and {privacy} placeholders in the description and the plugin turns them into real links right inside the sentence (if a placeholder is missing, links are appended after the text; if a URL is not set, the placeholder renders as plain text)type="text/plain" + data-cookiecategory, dynamic activation after choice without page reloadnymcs_is_category_allowed and nymcs_register_cookie, actions nymcs_after_consent_updated and nymcs_clear_cache, JS event nymcs:consent-updated. The action and the JS event fire on every frontend request that carries valid consent, not only when the choice changes — if you need one-time side effects, record the fact of processing yourself.nymcs_consent) + fallback cookie for 12 months.
Security note: the plugin never accepts, stores or outputs arbitrary CSS/JS/PHP entered by users. The Integrations tab is a form: you pick a supported service and enter its ID (counter number, Measurement ID, Pixel ID…), every value is validated against a strict whitelist format, and the counter snippet is generated by the plugin programmatically.
nymbl-cookie-sentinel folder to /wp-content/plugins/.<script type="text/plain" data-cookiecategory="statistics" src="..."></script>Not by itself. The plugin has no cloud service, no telemetry and no update server: it does not contact the plugin developer or anyone else. Only the counters and analytics that you enable yourself in the "Integrations" tab contact their services, and only after the visitor has consented to the category assigned to that integration. Before consent the snippet is printed blocked (type="text/plain") and never executed, so no request is made to the service's domain. The exact services, the data they receive and links to their terms and privacy policies are listed in the "External services" section.
Yes. The markup is rendered hidden, and visibility is managed by client-side JavaScript, so page caching does not break the consent logic. In addition, the plugin automatically purges the page cache whenever settings, the cookie registry, integrations or the consent version change. Supported out of the box: LiteSpeed Cache, WP Rocket, W3 Total Cache, WP Super Cache, WP Fastest Cache, Autoptimize, Hummingbird, Breeze, SiteGround Optimizer and Cache Enabler. For any other caching layer (CDN, server-side Varnish/nginx, Cloudflare) hook into the nymcs_clear_cache action or purge it on the hosting side.
Open the "Integrations" tab, select "Yandex.Metrika" and enter the counter number from your Metrika account settings (e.g. 12345678). The plugin generates the official counter code itself, prints it blocked (type="text/plain") and activates it after the visitor consents to the Statistics category. Alternatively, replace type="text/javascript" with type="text/plain" in your theme code and add the data-cookiecategory="statistics" attribute.
No. Following the WordPress.org plugin guidelines, the plugin does not accept, store or output arbitrary user code. The "Integrations" tab is a form: choose a supported service (Yandex.Metrika, GA4, GTM, VK Pixel, Top.Mail.ru, Facebook Pixel, Matomo) and enter its ID — the counter snippet is generated programmatically from validated values. For scripts outside this list, wrap them in your own theme/plugin code with type="text/plain" and data-cookiecategory="..."; the plugin activates such tags after consent as well.
Yandex.Metrika (with optional Webvisor), Google Analytics 4 (gtag.js), Google Tag Manager, VK Pixel (VK Ads), Top.Mail.ru, Facebook Pixel and self-hosted Matomo. Each integration accepts only the service ID, validated by a strict format (regex / integer / URL whitelist).
Use placeholders in the banner description (General Settings): {policy} is replaced with the cookie policy link and {privacy} with the privacy policy link — right inside the sentence, e.g. "Learn more: {policy}." If a page URL is not set, the placeholder is shown as plain text so the sentence stays readable. If the description contains no placeholders, the links are appended after the text automatically.
type="text/plain") until the visitor consents to the matching category.{policy} / {privacy} placeholders in the description; without placeholders the links are appended after the text, and with an empty URL a placeholder renders as plain text. Link URLs are validated server-side (esc_url_raw) and re-checked client-side (http/https/relative only) before they reach the DOM.aria-expanded), keeping the dialog compact while staying transparent.nymcs_clear_cache action for other caching layers; each purge call is guarded and cannot break saving.head, body or footer, and each entry has a category, a load priority and an on/off toggle.wp_insert_site hook.nymcs_consent cookie is read in a single place, NYMCS_Plugin::get_cookie_consent(), with size and JSON depth limits: categories are checked against a whitelist, version and timestamp are cast to integers, and consent stored for an older consent version is not accepted server-side.UPLOAD_ERR_*, is_uploaded_file(), 512 KB limit, .csv/.txt only) and parses it row by row with fgetcsv(); every cell is sanitized before it is stored.* (for example PHPSESSID / wordpress_logged_in_*, _ga_*, _pk_id.*).WP_List_Table is loaded only on the plugin's own admin screen.