Cookies and Content Security Policy
by Johan Jonk Stenström 4.9 (67 reviews)

Cookies and Content Security Policy

Be fully GDPR and CCPA compliant through Content Security Policy. Blocks cookies and unwanted external content.

Cookies and Content Security Policy ranks #1,520 among WordPress.org plugins with 10,000+ active installations, a 4.9/5 rating from 67 reviews, and was last updated Aug 25, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v2.41 Current Version v2.41
Updated 3 weeks ago Last Update on 25 Aug, 2026
Refreshed 6 hours ago Last Refreshed on
Top 5% by installs Downloads -11.5% this week Actively maintained
View on WordPress.org
Rank
#1,520
-1 this week
Active Installs
10K+
-46.2%
KW Avg Position
41.6
No change
Downloads
471K
+151 today
Support Resolved
0%
No change
Rating
98%
Review 4.9 out of 5
4.9 (67 reviews)

Next Milestone 20K

Total Progress 87.6%
10K+ 20K+
99
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 1,236 more installs to reach 20K+

Rank Changes

1,442 1,481 1,520 1,558 1,597 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
1,441 1,480 1,520 1,559 1,598 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Current #1,520
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

50 100 150 200 250 300 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
50 100 150 200 250 300 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
67 reviews
Overall 98%
5
64 (96%)
4
1 (1%)
3
0 (0%)
2
0 (0%)
1
2 (3%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

3 known vulnerabilities on record · 2 in the last 24 months · checked 1 week ago

  1. Cookies and Content Security Policy [cookies-and-content-security-policy] < 2.35

    CVE-2025-63019 · Fixed in v2.35

  2. UNPATCHED

    Cookies and Content Security Policy [cookies-and-content-security-policy] <= 2.29 (unfixed)

    CVE-2025-51529 · No fix released

  3. Cookies and Content Security Policy [cookies-and-content-security-policy] < 2.16

    CVE-2023-40662 · Fixed in v2.16

Track This Plugin

Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.

Start Tracking Free

Plugin Details

Version
2.41
Last Updated
Aug 25, 2026
Requires WP
5.0+
Tested Up To
7.1
PHP Version
7.4 or higher
Author
Johan Jonk Stenström

Support & Rating

Rating
★ ★ ★ ★ ★ 4.9
Reviews
67
Support Threads
1
Resolved
0%

Keywords

Upgrade to Pro

Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.

Upgrade Now

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who need GDPR and CCPA compliance for cookies and external content. It solves this by using Content Security Policy to block unwanted cookies, iframes, scripts, and images, showing visitors a consent modal to choose what to accept.

  • Blocks cookies and external content
  • Sets Content Security Policy
  • Front-end consent modal for visitors
  • Blocks iframes, scripts, images from unknown domains
  • Multilingual support via WPML, Polylang
  • Quickstart list of common resources
  • Domains list auto-populated
  • Updated regularly

Frequently Asked Questions

Common questions about Cookies and Content Security Policy

Yes, if you set it up right.
Yes, if you set it up right.
After install, open a console (see screenshot 13) and see what is blocked by Content Security Policy. Then just go to WP Admin > Settings > Cookies and Content Security Policy > Domains and add the domains you want to allow. Or you can take a look at WP Admin > Settings > Cookies and Content Security Policy > Quickstart, and see if the resource you want to use is there.
After install, open a console (see screenshot 13) and see what is blocked by Content Security Policy. If you get the error message: Refused to load the script 'https://domain.com/some-script.js' because it violates the following Content Security Policy directive: "script-src [...] in the console, you should add https://domain.com/ to Script, since https://domain.com/ is the domain of the URL that caused the error, and script-src is the directive. If it is Always allow, Statistics, Experience or Marketing is up to you.
There are three scenarios where this can happen: In some cases cookies are cached. It could be your hosting (for example WP Engine does this), then just contact them and ask them to uncache the cookies_and_content_security_policy cookie, or you can check "WP Engine compatibility mode" under Settings. In other cases it could be your cache plugin (for example Litespeed cache does this), then just review your settings. Read more in the next question in the FAQ that is all about cache plugins. If you're using static page cache that doesn't go through php, go to Settings > Cookies and Content Security Policy > Settings and check Use meta under Advanced settings. I'm using a cache plugin, and it seems to be interfere with this plugin Review the settings of you cache plugin. Examples: Litespeed cache, go to WP Admin > LiteSpeed Cache > Advanced, scroll down to "Vary Cookies" and enter cookies_and_content_security_policy and save your changes. Hummingbird, go to WP Admin > Hummingbird > Caching, scroll down to "Exclusions" and in "Cookies" enter cookies_and_content_security_policy and save your changes. WP Fastest Cache, go to WP Admin > WP Fastest Cache > Exclude, scroll down to "Exclude Cookies" and click "Add New Rule" and enter cookies_and_content_security_policy and save.
In English https://crcom.se/ https://abliva.com/ - Transladed strings in Polylang, works in the same way with WPML https://www.ascelia.com/ - Transladed strings in Polylang, works in the same way with WPML https://alligatorbioscience.se/en/ - Transladed strings in Polylang, works in the same way with WPML https://oddoneout.se/en/ - Transladed strings in Polylang, works in the same way with WPML In Swedish https://studiocanalis.se/ https://yogajona.se/ https://handelskammaren.com/ https://akkafrakt.se/ https://mim.m.se/
Yes.
Yes, all texts are translatable. There are 10+ languages already translated. And if you want to contribute with a translation of your own language, please do! <3 All texts on the front end can be changed directly in the admin. And if you are using WPML, Polylang, or some other multilanguage plugin, there is also support for multilanguage translations.
Make sure you have "WPML String Translation" installed. Go to Settings > Cookies and Content Security Policy > Texts and save your texts. Go to WPML > String Translation. Search for "cacsp_" (without quotes). Click the plus sign to add translation. If you have a string named "cacsp_option_settings_policy_link", the value is a number. It is the ID of the Cookie policy page. Translate this by entering the ID of the cookie policy page in the language you are translating to.
Go to Settings > Cookies and Content Security Policy > Texts and save your texts. In the WordPress admin bar, choose "Show all languages". Go to Languages > Strings translations. In the "View all groups" dropdown, choose cookies-and-content-security-policy, and click "Filter". Translate your texts in the form. If you have a string named "cacsp_option_settings_policy_link", the value is a number. It is the ID of the Cookie policy page. Translate this by entering the ID of the cookie policy page in the language you are translating to.

Sign In / Register

You need to sign in or register to use this feature.