Description
Cookie Rocket is a WordPress cookie consent banner that blocks Google Analytics, Meta Pixel, Hotjar and other third-party tracking scripts until the visitor consents, with Google Consent Mode v2, a cookie scanner and a consent log included in the free version. It is for any site that has to comply with GDPR, CCPA / CPRA, LGPD (Brazil) or LFPDPPP (Mexico), each with its own banner wording and consent rules, selectable per site.
It is a fully self-hosted alternative to cloud cookie-consent services: no account, no monthly SaaS fee and no external calls. Real script blocking, Google Consent Mode v2 and on-demand cookie scanning are free here — features that comparable consent tools typically gate behind a paid plan or a remote service.
- Automatic script blocking: common third-party trackers (Google Analytics, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn, TikTok and more) are blocked until consent, with Google Consent Mode v2 built in.
- Built-in cookie scanner: detect on demand which known tracking services are present on your site and the cookies they set.
- Automatic cookie policy / cookie declaration: a single shortcode (or one-click page) publishes a table of every cookie your site uses — provider, purpose and duration — grouped by category and updated from your scans.
- Consent audit log with an admin viewer: every consent decision is recorded and browsable for compliance.
- Editable cookie categories: rename, re-describe and reorder the categories shown on the banner.
- Unified Cookie Banner editor: layout, content (text and labels) and colors, all in one place.
- Zero external scripts and zero CDN dependencies — everything is served from your own site.
- Framework selector: GDPR, CCPA / CPRA, LGPD (Brazil) and LFPDPPP (Mexico), each with its own banner wording and consent behavior.
- 100% local — no consent data is sent to third-party servers.
- WooCommerce aware: respects shop pages and checkout.
- Fully customizable colors, fonts sizes, copy and banner position.
- WCAG 2.1 AA accessible: keyboard navigation, focus states, ARIA labels.
- Multisite compatible.
- Five banner layouts: bottom bar, top bar, floating card, modal and drawer.
Shortcodes
[cookie-rocket-preferences]— renders a button that re-opens the cookie preferences modal.[cookie-rocket-withdraw]— renders a link that withdraws consent and clears stored preferences.[cookie_rocket_policy]— renders the automatic cookie declaration table (provider, purpose and duration per cookie, grouped by category).
Cookie Rocket Pro
Cookie Rocket Pro is a commercial extension built on top of the free plugin. It adds:
- A catalog of 76 recognized services covering 329 cookies. Every cookie comes with its purpose and duration already written, so the cookie declaration table fills itself in from a scan. The free version recognizes 34 services; anything else is described by hand under Your own services.
- Rules per region. Each visitor gets the law of their country, also behind page caching: GDPR in Europe, CCPA / CPRA in the United States, LFPDPPP in Mexico and LGPD in Brazil, each with its own consent model, Reject button, consent duration and banner text. Global Privacy Control is honored.
- Google Consent Mode advanced and Google Tag Manager. Google Ads and GA4 keep modeling conversions while consent is denied, and the Tag Manager container is added with consent already wired.
- A tamper-evident consent ledger. Every record is sealed and chained to the previous one, with CSV export and a one-click evidence report.
- A deeper scan, every month. The crawl goes beyond the key pages, and a monthly re-scan emails you when a new tracker appears.
- Premium styles and finishes. Glass, Branded and Frosted themes, a blurred backdrop, border color and thickness, shadow intensity, button text size and weight, spacing, and the position, color and label of the reopen button.
- Latin America pack. A generated privacy notice for Mexico and Brazil and a self-hosted ARCO / DSAR rights request channel.
Cookie Rocket Pro is available at templatesrocket.com. The free version published here is fully functional and does not require the Pro plugin to work.
Screenshots





Installation
- Upload the
cookie-rocketfolder to the/wp-content/plugins/directory, or install the plugin through the WordPress plugins screen directly. - Activate the plugin through the Plugins screen in WordPress.
- Go to Cookie Rocket in the admin menu to configure the banner copy, colors and behavior.
- Optionally, place the
[cookie-rocket-preferences]shortcode in your privacy policy page to let visitors update their choices at any time.
FAQ
-
Does this plugin send any data to external services?
-
No. Cookie Rocket stores consent entirely in the visitor’s browser (cookie + localStorage) and logs events to your own WordPress database. Your visitors never generate a request to an external server: the plugin makes no third-party calls at runtime.
-
Is it compatible with caching plugins?
-
Yes. The banner state is read from a first-party cookie, so caching (page cache, object cache, CDN) does not interfere with consent storage or display.
-
Does it block third-party scripts automatically?
-
Yes. The free version automatically blocks the most common third-party tracking scripts — Google Analytics, Meta (Facebook) Pixel, Hotjar, Microsoft Clarity, LinkedIn, TikTok, Google Ads and more — until the visitor accepts the matching cookie category, and it ships Google Consent Mode v2 (default denied) out of the box. Enqueued scripts are blocked by default; an optional setting also blocks scripts pasted directly into your theme or header. Cookie Rocket Pro adds scheduled monthly re-scans that email you when a new tracker appears, plus Google Consent Mode advanced so your Google Ads and GA4 keep measuring while consent is denied.
-
Is it translation-ready?
-
Yes. The text domain is
cookie-rocketand a complete.potfile is included under/languages/. All banner and modal strings are wrapped for translation. The plugin ships in English by default with Spanish (es_ES) and Brazilian Portuguese (pt_BR) translations bundled, applied automatically on matching locales. WordPress also loads community translations for plugins hosted on WordPress.org, and you can translate the banner yourself with Loco Translate or Poedit, or via WPML/Polylang. -
Yes. Add the
[cookie_rocket_policy]shortcode to any page, or go to Cookie Rocket Cookie Policy and create the page in one click. It publishes a cookie declaration table — each cookie with its provider, purpose and duration, grouped by category — built from your latest scan plus a built-in catalog of the most common third-party cookies. Strictly-necessary cookies are always listed, and the table updates automatically as you re-scan. -
Does it work on WordPress Multisite?
-
Yes. Each site stores its own settings. Activate per-site or network-activate from the network admin.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Cookie Rocket, Cookie Consent Banner and Script Blocker for GDPR, CCPA and LGPD” is open source software. The following people have contributed to this plugin.
Contributors“Cookie Rocket, Cookie Consent Banner and Script Blocker for GDPR, CCPA and LGPD” has been translated into 3 locales. Thank you to the translators for their contributions.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.16.4
Script blocking holds the whole script. When a plugin added a tracker together with a piece of inline code placed before it, only that inline code was held and the tracker itself could load before consent. Now every part is held, and once the visitor accepts they run once, in their original order. Held scripts no longer keep their address in an attribute that made the page’s HTML invalid.
* Rejecting now clears the cookies of every recognized service in the rejected categories, including social and functional ones, not only the main analytics and advertising cookies.
* The checkboxes in the preferences dialog stay visible on dark banners; before, light text colors made them white on white.
* Turning off Google Consent Mode in Settings now also stops the banner from sending consent updates.
* Under the GDPR, consent now lasts 13 months at most, as the CNIL recommends.
* The LGPD and LFPDPPP banner texts now follow your site’s language, like the buttons around them.
* The cookie policy now lists Cookie Rocket’s own session cookie, and the durations of the MUID, IDE and test_cookie cookies are corrected.
* Long category names with accented letters are no longer erased when saved.
* The setup summary and Status now show your real framework and settings, and the consent log shows the retention the cleanup actually applies.
* Banner font, text sizes and typography now live together in Banner Content. The corners offer more room for their names, and the preferences dialog has its title in the page’s HTML.
* The admin sits inside WordPress’s own spacing, exactly as wide as the notices above it, with one spacing scale on every screen and button icons in the button’s own color.
* Notices from other plugins and from WordPress sit above the whole Cookie Rocket screen, full width.
* The United States (CCPA / CPRA) text template is back in Banner Content, and every list names the frameworks the same way, in the same order.
2.16.3
- A new admin, redesigned from the ground up: one side menu with every screen a click away, clearer settings in tabs, a banner editor with the controls on the left and a live preview on the right in desktop, tablet and phone sizes, and every screen reworked for phones and tablets.
The banner no longer stops page caches from storing your pages. It wrote a security token into every page that changed every 12 hours, so strict page caches refused to store any page with the banner, and the others served a token that protected nothing. Your pages are now the same for every visitor at every hour, and every decision is still recorded: the consent endpoint accepts only real decisions and your own categories, with the same flood limit. - Reject and Accept now have the same size and the same level on every layout and screen width, as EU regulators ask. On phones they share a row, with Customize above; before, Accept took the whole row and Reject half of the next one. The keyboard order now matches what you see.
- The opt-out consent model now works. Under CCPA / CPRA or Generic you can let optional cookies run until the visitor rejects (Compliance Advanced — legal defaults). Under the GDPR, the LGPD and the LFPDPPP the banner always asks first, whatever the setting.
- The consent log never deletes a record while the consent it proves is still valid, whatever retention you set.
- New installs keep consent records for a year, keep consent for 6 months under the GDPR (the CNIL’s recommendation) and 12 months elsewhere, and show the button to change or withdraw consent.
- Fixed: the cookie policy listed Pinterest’s _routing_id cookie under X / Twitter. It belongs to Pinterest, and so does _epik, now listed too.
- The style presets now show each one as your visitors will see it, with its three buttons and a line on what it is for. Contrast was removed: it looked the same as Light. Glass, Branded and the new Frosted style are part of Cookie Rocket Pro; a site already using one of them, or Contrast, keeps its colors.
- The Colors section is organized by what each color paints (banner, Accept and Reject, Customize), with a hex field next to every color and the live contrast of each pair. A text that would be hard to read turns red with a one-click fix; it never blocks saving. The “?” tips are gone: every control says what it does.
- “Advanced” in Style & colors is now “Corners”: four shapes to choose from (square, subtle, soft, rounded), drawn as they will look.
- New in Style & colors: Border. Keep the line around the banner or remove it; every banner keeps its line until you change it. With the side panel on the left, the line now sits on the page side instead of against the screen edge.
- New in Style & colors: Shadow. Give the banner a soft shadow that lifts it off the page, or keep it flat as before.
- Title size and Text size (Content) now apply to every layout. Before, the pop-up, the floating box and the side panel kept fixed sizes; with the standard sizes they look exactly as they did.
- The time-zone fallback now recognizes 15 more EU and EEA countries and more zones in Mexico and Brazil, so your visitor breakdown by law is more complete.
Your current settings are unchanged: the new defaults apply to new installs.
2.16.2
Fixed: on phones and tablets the preferences dialog sat on top of the banner, showing two “Accept All” buttons. The banner and its backdrop now step aside while the dialog is open and come back if the visitor closes it without choosing. Pop-up layouts no longer dim the page twice.
* The dialog’s buttons are always whole on phones: when the categories do not fit, the list scrolls under a fixed footer instead of cutting “Save preferences” and “Accept All” in half.
* Checkmarks sit exactly in the center of their boxes on every screen density, whatever box model your theme uses.
* “Customize” is now spelled the same way as the rest of the banner, and the admin uses US spelling throughout (Style & colors, Text color). Spanish and Portuguese sites are unchanged.
* The Banner editor no longer scrolls sideways on phones, the consent log and scanner tables can be scrolled with the keyboard on small screens, and the service category menu is announced correctly to screen readers.
* The plugin’s hidden screens no longer write a PHP deprecation notice to your debug log on every visit.
No change to your settings, consent records or blocking.
2.16.1
Fixed: an em dash in the consent log, the one that means “no categories recorded”, was drawn at a contrast of 1.97:1. WCAG AA asks for 4.5:1 on text that carries meaning, and that dash carries meaning: it is how the log says a visitor accepted nothing. It now sits at 4.83:1 — still clearly muted, but readable.
* The admin stylesheet’s colors are now a system rather than a habit. Fifty-six colors were written by hand across the file, among them five near-whites and four light grays separated by differences no eye can see, with nothing to say which to reach for. They are now twenty-eight named values, and no color is written by hand anywhere else.
* Five of those near-identical grays were merged into the two they were already imitating. The change is real but slight — the largest is a background moving by 2%% of its lightness — and it affects a code block, a diagram, a nav strip, a panel and a notice.
* The colors borrowed from the WordPress admin itself are now named as such, so it is clear they are deliberate and that changing them would mean no longer matching the dashboard around them.
Nothing else changed: same rules, same values, same layout. No change to your banner, your settings or your consent records.
2.16.0
The scanner now recognizes 34 third-party services instead of 9. Until now it knew the large advertising and analytics platforms — Google Analytics, Meta, LinkedIn, TikTok and a few more — and everything else on your site was invisible to it: neither blocked, nor listed on your cookie policy, with nothing on screen to say so. Twenty-five services have been added, chosen for what a WordPress site actually runs rather than for what looks impressive in a list.
* Forms and anti-spam: Google reCAPTCHA, hCaptcha, Cloudflare Turnstile and CleanTalk. A contact form is the most common third party on a WordPress site and it was the one the scanner never saw.
* WordPress.com and Automattic: Jetpack Stats, WooCommerce Analytics, Gravatar hovercards and Crowdsignal.
* Embedded content and social: Instagram, Twitch, Spotify, SoundCloud, Dailymotion, Disqus, the Facebook SDK used by like buttons and comments (which is not the advertising pixel), and X/Twitter widgets.
* Live chat and share buttons: Tidio, LiveChat, Smartsupp, JivoChat, Chatra, ShareThis, AddToAny, Hello Bar and BDOW!/Sumo.
* Fixed: a site using the Facebook SDK for like buttons or comments was reported as running the Meta advertising pixel, so the cookie policy listed advertising cookies the site did not set. The two are told apart now.
* Every signature names a full domain and path, so it cannot match an unrelated script and break your site; every cookie listed comes from the service’s own published documentation. AddThis was considered and left out: it was shut down in 2023.
No change to your banner, your settings or your existing consent records. Run the scanner again to pick up whatever is new on your site.
2.15.17
Fixed, and this one made an unreadable site look like a clean one: the scanner never checked whether it had actually loaded your page. When a page answered with an error — a server error, a login wall, a firewall block, a site behind a password — the scanner parsed the error page as if it were your site, found no trackers in it, and reported zero. “0 trackers detected” is the most reassuring thing this plugin can tell you, and it was being shown to sites it had never managed to read even once. The scanner now checks the response before reading it, and your dashboard says plainly that nothing could be read instead of showing a zero.
* Fixed, and this one could empty a published Cookie Policy: a scan that read nothing was still saved as the result. If a firewall answered a scan with a block on every page, the empty result replaced your cookie inventory — and the Cookie Policy is generated from that inventory, so the declaration your visitors read would quietly go blank. A scan that could not read a single page now keeps the last good inventory and its date, and records only the failed attempt.
* Fixed: pages that could not be read were only reported when the scan found nothing at all. One tracker on your home page was enough for four blocked pages to vanish from the report while the screen claimed it had read them. They are now listed either way, and the page count only counts pages actually read.
* Fixed: with Cookie Rocket Pro installed alongside this plugin, eight PHP notices were written on every request because both editions define the same constants. They are guarded now.
No change to your banner, your settings or your existing consent records.
2.15.16
Fixed: plural sentences were left out of the translation fallback added in 2.15.15. That release made the plugin fall back to its own bundled translation for anything the language pack was missing, but only for ordinary strings — any sentence that changes with a number still came out in English. Plurals now use the same fallback.
* Fixed: three settings were left behind when the plugin was uninstalled, including the list of services you had declared yourself.
* The translation template shipped with the blank header that the extraction tool leaves behind, so a translator opening it saw placeholders instead of the plugin’s name and license. It is filled in now.
* Added an extension point so Cookie Rocket Pro can hide the notice that suggests routing the law per visitor — Pro already does that, and was recommending itself to people who had bought it.
No change to settings, consent records or blocking behavior.
2.15.15
Fixed: parts of the plugin appeared in English on sites whose translation is incomplete. WordPress loads the translation package from wordpress.org and stops there, so the complete catalog shipped inside the plugin was never consulted. Where that package was missing strings, they fell back to English — including the name of a consent category, inside the consent dialog. The bundled catalog is now used to fill those gaps, and never to replace a translation the site already has.
* Fixed: a malformed country value reaching the consent endpoint was trimmed to two letters instead of being rejected, so it could enter the consent record as a real country code. It is now discarded unless it is exactly an ISO-3166 alpha-2 code.
* Fixed: when neutralising a script whose type attribute was unquoted, spaced or module, the original attribute was left in place next to the new one. Blocking was unaffected — browsers keep the first attribute — but the markup was invalid. The attribute is now removed in all three forms.
No change to settings, consent records or blocking behavior.
2.15.14
Fixed: a blocked embed kept its shape on sites with a strict Content-Security-Policy. The placeholder that stands in for a blocked video or map carries the aspect ratio of the embed it replaces, so the page does not jump when the visitor accepts. That ratio is different for every embed, so it travelled in a style attribute — which such a policy discards, leaving the placeholder with no height: the collapsed layout this placeholder exists to prevent. The ratio now travels in a data attribute and the script applies it.
2.15.13
Fixed: the plugin now behaves the same on sites that send a strict Content-Security-Policy. A CSP whose style-src and script-src do not allow ‘unsafe-inline’ makes the browser discard inline style attributes and inline event handlers. The banner and the dialog put some of their layout and behavior there, so on those sites parts of the plugin silently stopped working. Everything moved to the stylesheet and to the script file, which the policy allows.
* Fixed: the [cookie-rocket-preferences] and [cookie-rocket-withdraw] shortcodes did nothing under such a policy. They carried their call in an onclick attribute, which the browser refuses to execute, so a visitor could not reopen their choices or withdraw consent from the page where you had placed the button. The script now listens for them by class.
* Fixed: in the preferences dialog each category’s control fell below its label instead of sitting on the right, because the row built its columns with a style attribute.
* Fixed: your Accept button text color, your solid secondary-button colors and the dialog’s fixed footer colors were only ever applied through style attributes, so a strict policy dropped them and the same settings rendered differently from one site to the next. They are part of the stylesheet now.
* The banner-layout thumbnails in the editor drew “floating” and “modal” as wide bars, when both stack their buttons and render as tall cards. They now match what applying them produces.
* The live preview was shorter than a floating banner, so the banner started above the frame and covered the previewed page. The preview is taller.
Style and markup only; no change to settings, consent records or blocking behavior.
2.15.12
Fixed: four things in the preferences dialog that were harder to use than they looked. The category controls were a sliding switch with its rounded shape removed, which read as neither a switch nor a checkbox — a square knob in a square track, where the only clue to the state was the color of the track. They are now plain checkboxes: an empty square for off, a filled square with a checkmark for on, and a greyed checked one for strictly-necessary. Same square, no-radius look; you can tell the state at a glance.
* The close button sat in the header at the same height as the title. It now sits anchored in the top-right corner of the dialog, which is where it is looked for, and it measures 28×28 instead of 13×22 — its width used to come from the width of the glyph itself, below the 24×24 minimum recommended by WCAG 2.5.8 and awkward to hit with a thumb.
* Each category’s description ran the full width and passed under the column of controls. On a phone the text reached the edge while the title above it stopped short, leaving a ragged right margin. Both now break on the same line.
* Hardening: the dialog sets its own box-sizing instead of relying on the theme to set it globally.
Style only. Your settings, banner and consent log are unchanged.
2.15.11
The plugin description and the feature list now say what the plugin does instead of promising an outcome. The description no longer guarantees a PageSpeed score, which depends on your site and host rather than on this plugin, and the framework line no longer claims to grant legal compliance, which no plugin can grant. What it does say is accurate: it ships banner wording and consent rules for GDPR, CCPA / CPRA, LGPD and LFPDPPP, and you pick the one that applies. No functional change.
2.15.10
The plugin header now carries the same name as the listing.
2.15.9
The plugin is now listed as what it does — a cookie consent banner and script blocker — instead of claiming compliance, which no plugin can grant. CCPA / CPRA joins the tags now that the framework is fully supported. Code hardening around the new visitor-country field.
2.15.8
New: the plugin now tells you what it found on your own site. Three notices that appear only when there is something real to say, and go away when you dismiss them or when the fact changes.
* Your visitors’ country is now recorded with each consent decision. It was already resolved in the browser by timezone and then thrown away. No IP, no external service, no new personal data.
* If a meaningful share of your visitors comes from a region under a different framework than the one your banner applies, the plugin says so, with the percentage.
* If a quarter or more of your visitors reject cookies, the plugin says so — and tells you whether Consent Mode v2 is on, which decides whether those visitors are measurable at all.
* The review request now waits until Cookie Rocket has actually done something countable on your site, and says what it did, instead of appearing on a 14-day timer.
2.15.7
Fixed: the cookie bar took a third of a phone screen. On mobile the three buttons stacked one per row — 148px of controls on a 300px bar, tall enough to sit on top of a form’s submit button. Accept now keeps its own full-width row and Customize and Reject share the next one: 282px instead of 300, in two rows instead of three. If your site turns off Customize or Reject, the remaining button grows into the whole row. Only the top and bottom bar layouts change; the popup, floating and drawer layouts are untouched.
* Translations: removed a leftover string and refreshed the template.
2.15.6
New: declare your own services. Cookie Rocket recognizes nine common providers. Anything else on your site — a chat widget, a heatmap tool, a newsletter script — was neither blocked nor listed on your cookie policy. Blocking Your own services lets you name it, give the script address so it gets blocked, and describe its cookies so they appear on your policy with a real purpose and duration.
New: California. CCPA / CPRA joins GDPR, LGPD and LFPDPPP in the framework selector, with its own banner wording.
New: the scanner sees your shop. On WooCommerce sites it now also reads the shop, cart, checkout and account pages — where conversion pixels usually live and where a homepage-only scan never looked. It also tells you which trackers are new since your last scan.
Fixed: a failed scan no longer reads as a clean site. If a page could not be read, the result says so and lists which, instead of reporting zero trackers found.
Fixed: the scanner reports Google Tag Manager. The container is deliberately not blocked — Consent Mode governs it — but staying silent made a site that loads everything through GTM read “no trackers found”. It is now listed with its real status.
Fixed: the blocking status tells the truth. A tracker pasted straight into your theme is not reached by script blocking unless raw-HTML blocking is on. That row used to claim it was blocked; it now says it is pasted directly into the HTML and links to the switch that handles it.
New: consent-log retention is yours to set. Records were deleted after 90 days with no way to change it and nothing on screen saying so. There is now a field, and the log states how long it keeps records.
Free: the Glass, Graphite and Branded banner themes, and the self-hosted font option.
Updated design. Squared corners, no shadows, no transitions and no entrance animation, throughout the banner, the preferences dialog and the admin screens. If you are updating an existing site, the banner will lose its drop shadow and slide-in and gain a hairline border; your saved corner radius is untouched.
Accessibility. The floating preferences button’s focus ring is now visible on light backgrounds, and the category switches read clearly in both states.
Polish, hardening & fixes from a thorough audit — functionality, security, accessibility, reliability and translations. Nothing to reconfigure; your settings, banner and consent log are unchanged.
* Fixed (accessibility): the banner no longer traps keyboard focus in the bar layout (you can Tab past it), while the popup, side panel and drawer still contain focus while open. The preferences dialog is announced by its title, traps focus even for a returning visitor who opens it from the floating button, returns focus to the control that opened it, and its cookie-category switches carry accessible names (WCAG 2.1.2 / 2.4.3).
* Fixed (reliability): behind a full-page cache, a visitor’s consent could go unrecorded when the cached page carried an expired security token — recording no longer depends on it. The consent-endpoint rate limit is now keyed on the real connection IP with a fixed one-minute window, so it cannot be side-stepped with spoofed headers or become a permanent block.
* Fixed (privacy): blocked social/media embeds (X, Instagram, TikTok, Facebook and similar) fully restore after consent, including embeds that load their own script; and the raw-HTML script blocker now also catches trackers whose src/type attributes are unquoted.
* Fixed (Consent Mode): the “functionality_storage” signal now follows the visitor’s functional-cookie choice instead of always reporting granted.
* Fixed: “Save text” and the Layout / position / width / backdrop controls now report or roll back a failed save instead of showing an unsaved change as applied; consent-log stats and retention compute their window in the site’s own timezone; the preferences close button meets contrast; and the cookie-category grid no longer overflows on narrow phones.
* Improved (translations): the whole interface, the cookie-declaration table (each cookie’s purpose and duration) and the cleanup-schedule label are now complete in Spanish and Portuguese.
2.15.5
On some themes the Reject button could render unfilled; its fill now holds up against theme button styles.
2.15.4
Default banner aligned to the common consent-tool convention: Reject filled with equal prominence, Customize outline, subtle 2px corners.
2.15.3
Banner button order follows the common convention on every layout, and no button is pre-focused when the banner appears.
2.15.2
Banner buttons always take the same corner radius as the banner on every layout.
2.15.1
Live-preview button labels, a clean preview without the admin bar, instant style presets, contextual help tooltips, and a 0px default corner radius.
2.15.0
One-click setup, a live banner editor, blocked-embed placeholders that keep your layout, and consent that persists across localStorage clears.
2.14.x and earlier
Older release notes are available in the plugin’s development history on WordPress.org.
