Cookies and Content Security Policy icon

Cookies and Content Security Policy

by Johan Jonk Stenström

View on WordPress.org
80 Quality Score
Active Installs
18/30

With around 10,000 active installs, this plugin sits well below mainstream consent tools that exceed 100,000 installs, indicating a niche audience.

Update Freshness
25/25

The plugin was updated in May 2026 and is tested against WordPress 6.9.4, which is the strongest signal of active upkeep in the dataset.

User Rating
15/15

A 98 out of 100 score across 67 ratings suggests users are highly satisfied, though the smaller sample size makes the rating less statistically reliable than alternatives with thousands of reviews.

Support Health
8/15

There is only 1 support thread on record with a 0.0% resolution rate, which is a real concern given how tricky CSP misconfiguration can be.

WP Compatibility
15/15

It requires PHP 7.4 and WordPress 5.0 or newer, and is tested against the latest WordPress release, giving it a clean compatibility profile.

Scores higher than 79% of indexed plugins

About

Be fully GDPR and CCPA compliant through Content Security Policy. Blocks cookies and unwanted external content.

Active Installs 10k+
Rating ★★★★½ 4.9/5
Last Updated 2026-08-25 9:31am GMT
Requires WordPress 5.0+
Tested Up To 7.1
Requires PHP 7.4+

Security History

2 known vulnerabilities, all patched
2 Medium

Most recent: January 5, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Cookies and Content Security Policy uses HTTP Content Security Policy headers to block cookies and third-party resources from loading until the visitor consents. It combines a cookie consent banner with server-level blocking of external scripts, fonts, and trackers, aiming to satisfy GDPR and CCPA requirements at the header layer rather than relying on JavaScript-only suppression.

Who It's For

This plugin fits site owners who want technical, header-driven enforcement of cookie consent rather than a visual-only banner, particularly publishers loading third-party ads, European businesses serving international visitors, and privacy-focused operators comfortable editing CSP directives. It also suits small businesses that need legal compliance without paying for a premium consent management platform.

Who Should Skip It

Skip this plugin if you run a simple blog or brochure site with no third-party tracking, since CSP headers add complexity and potential breakage for negligible compliance gain. Users who need a polished, multi-language cookie banner with A/B testing or granular consent logging should look at Complianz or CookieYes instead.

The Bottom Line

Cookies and Content Security Policy earns a solid 80.11 out of 100 thanks to excellent maintenance, strong ratings, and broad compatibility, but its low install base and an unresolved support thread are real risks for users unfamiliar with CSP directives. It is a technically sharper option than most cookie banners, though anyone who needs hands-on help or a battle-tested user experience will be better served by Complianz or CookieYes.

Tags

CCPA content security policy cookie bar cookies GDPR