{"id":333952,"date":"2026-09-13T21:14:48","date_gmt":"2026-09-13T21:14:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cookiehug\/"},"modified":"2026-09-13T21:14:12","modified_gmt":"2026-09-13T21:14:12","slug":"cookiehug","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/cookiehug\/","author":23525172,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.2.6","stable_tag":"0.2.6","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"CookieHug","header_author":"CookieHug","header_description":"Connects your WordPress site to the CookieHug consent platform. The plugin itself is a thin connector \u2014 all configuration (banner, categories, scripts) lives in the CookieHug dashboard.","assets_banners_color":"070809","last_updated":"2026-09-13 21:14:12","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/cookiehug.com\/developer#wordpress-plugin","header_author_uri":"https:\/\/cookiehug.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":44,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.2.6":{"tag":"0.2.6","author":"cookiehug","date":"2026-09-13 21:14:12","revision":3694191}},"upgrade_notice":{"0.2.5":"<p>Version bump only; identical code to 0.2.4.<\/p>","0.2.4":"<p>Maintenance release: WordPress 7.1 compatibility and documentation updates. No change to the banner or the connection.<\/p>","0.2.2":"<p>Adds an Updates diagnostics panel so you can see at a glance why an update is or isn&#039;t showing up.<\/p>","0.2.1":"<p>Adds a WP Consent API status panel to the settings screen so you can confirm the integration at a glance.<\/p>","0.2.0":"<p>Adds WP Consent API integration (required for Google&#039;s CMP Partner Program) and WordPress.org compliance fixes.<\/p>","0.1.1":"<p>Adds a liveness heartbeat and enables in-dashboard update notifications.<\/p>","0.1.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3694189,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3694189,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3694189,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500-pl_PL.png":{"filename":"banner-1544x500-pl_PL.png","revision":3694189,"resolution":"1544x500","location":"assets","locale":"pl_PL","width":1544,"height":500},"banner-772x250-pl_PL.png":{"filename":"banner-772x250-pl_PL.png","revision":3694189,"resolution":"772x250","location":"assets","locale":"pl_PL","width":800,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.2.6"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3694189,"resolution":"1","location":"assets","locale":"","width":896,"height":895}},"screenshots":{"1":"Plugin settings page with an active connection."}},"plugin_section":[],"plugin_tags":[20011,223629,389,131785,396],"plugin_category":[54],"plugin_contributors":[280529],"plugin_business_model":[],"class_list":["post-333952","plugin","type-plugin","status-publish","hentry","plugin_tags-consent","plugin_tags-consent-mode","plugin_tags-cookies","plugin_tags-gdpr","plugin_tags-privacy","plugin_category-security-and-spam-protection","plugin_contributors-cookiehug","plugin_committers-cookiehug"],"banners":{"banner":"https:\/\/ps.w.org\/cookiehug\/assets\/banner-772x250-pl_PL.png?rev=3694189","banner_2x":"https:\/\/ps.w.org\/cookiehug\/assets\/banner-1544x500-pl_PL.png?rev=3694189","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/cookiehug\/assets\/icon.svg?rev=3694189","icon":"https:\/\/ps.w.org\/cookiehug\/assets\/icon.svg?rev=3694189","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/cookiehug\/assets\/screenshot-1.png?rev=3694189","caption":"Plugin settings page with an active connection."}],"raw_content":"<!--section=description-->\n<p><strong>CookieHug is a platform-first cookie consent solution.<\/strong> The WordPress plugin does three things and nothing more:<\/p>\n\n<ol>\n<li>Pairs your site with a CookieHug account via a one-time handshake.<\/li>\n<li>Injects the consent banner snippet into <code>&lt;head&gt;<\/code> on every page.<\/li>\n<li>Gives you a one-click link back to the CookieHug dashboard where you actually configure things.<\/li>\n<\/ol>\n\n<p><strong>Everything else \u2014 banner texts, colours, categories, Google Consent Mode v2, cookie scan results, translations \u2014 is managed in the CookieHug dashboard, not in WordPress.<\/strong> This is by design. It means:<\/p>\n\n<ul>\n<li>Config changes propagate instantly without touching the site.<\/li>\n<li>Upgrades to the consent logic happen on the platform side \u2014 no plugin update required for most fixes.<\/li>\n<li>The plugin surface area stays tiny, which is what you want from something that runs on every request.<\/li>\n<\/ul>\n\n<p>If you're looking for a plugin where you edit banner text in the WP admin, this isn't it. Use the CookieHug dashboard.<\/p>\n\n<h3>WP Consent API<\/h3>\n\n<p>CookieHug integrates with the <a href=\"https:\/\/wordpress.org\/plugins\/wp-consent-api\/\">WP Consent API<\/a>. When that plugin is active, every choice a visitor makes in the CookieHug banner is mirrored into the shared Consent API, so any other plugin on your site can gate its own cookies and scripts with <code>wp_has_consent()<\/code>. CookieHug registers as the site's consent management plugin and sets the consent type to opt-in (non-essential categories denied until the visitor consents).<\/p>\n\n<p>Category mapping (CookieHug \u2192 WP Consent API):<\/p>\n\n<ul>\n<li>necessary \u2192 functional (always allowed)<\/li>\n<li>preferences \u2192 preferences<\/li>\n<li>statistics \u2192 statistics, statistics-anonymous<\/li>\n<li>marketing \u2192 marketing<\/li>\n<\/ul>\n\n<p>This is required for, and verified by, Google's CMP Partner Program: it is not enough to support Consent Mode \u2014 a WordPress plugin must also use the WP Consent API.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects your site to <strong>CookieHug<\/strong>, a hosted consent-management service operated at https:\/\/cookiehug.com. The plugin is a connector \u2014 the consent banner, cookie scanning, and all configuration run on the CookieHug platform \u2014 so it has to communicate with that service to function. Nothing is sent until you click <strong>Connect with CookieHug<\/strong> and complete the handshake; an unconnected plugin makes no external requests.<\/p>\n\n<p>What is sent to cookiehug.com, and when:<\/p>\n\n<ul>\n<li><strong>During connection (one-time handshake):<\/strong> your site URL, site name, WordPress version, PHP version, and the plugin version, so the dashboard can register and identify the site.<\/li>\n<li><strong>Periodic heartbeat (about once a day, and when you open the plugin's settings page):<\/strong> the connection key, the current plugin \/ WordPress \/ PHP versions, and a software freshness report: the newest WordPress core version your site already knows about, plus the list of installed plugins (slug, name, version, whether it is active, and the newest version WordPress has already detected for it). Only component names and version numbers are sent, never content or user data. The dashboard uses this to show the site as active and to warn you about outdated software. This runs only while the site is connected.<\/li>\n<li><strong>Status checks (from wp-admin):<\/strong> the connection key, to retrieve the account\/plan\/license state shown on the settings page.<\/li>\n<li><strong>Consent banner script (on every front-end page view):<\/strong> visitors' browsers load <code>https:\/\/cookiehug.com\/api\/script\/&lt;key&gt;.js<\/code>. Standard web-request metadata (IP address, user agent) reaches CookieHug as part of serving that script, exactly as it would for any third-party script. The banner's consent logic and the choices visitors make are handled by the CookieHug platform.<\/li>\n<\/ul>\n\n<p>Use of the CookieHug service is governed by its Terms of Service and Privacy Policy:<\/p>\n\n<ul>\n<li>Terms of Service: https:\/\/cookiehug.com\/terms<\/li>\n<li>Privacy Policy: https:\/\/cookiehug.com\/privacy<\/li>\n<\/ul>\n\n<p>A CookieHug account is required. The service is provided by CookieHug and is not affiliated with WordPress.org.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, or extract into <code>wp-content\/plugins\/cookiehug\/<\/code>.<\/li>\n<li>Activate via <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/li>\n<li>Go to <strong>CookieHug<\/strong> in the admin menu and click <strong>Connect with CookieHug<\/strong>.<\/li>\n<li>Confirm the connection on the CookieHug dashboard. You'll be bounced back to WordPress with the connection saved.<\/li>\n<li>The banner starts appearing on the frontend automatically.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20change%20the%20banner%20colours%20%2F%20text%20%2F%20categories%3F\"><h3>How do I change the banner colours \/ text \/ categories?<\/h3><\/dt>\n<dd><p>Click <strong>Open CookieHug dashboard<\/strong> on the plugin settings page. Everything is configured there. The plugin never exposes those controls locally \u2014 that's intentional.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20store%20any%20personal%20data%3F\"><h3>Does the plugin store any personal data?<\/h3><\/dt>\n<dd><p>No. The plugin stores a license key, a connection key (hashed on the server), and a domain ID. No visitor data ever touches the plugin \u2014 consent events go directly from the banner script to the CookieHug backend.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20%2F%20uninstall%3F\"><h3>What happens when I deactivate \/ uninstall?<\/h3><\/dt>\n<dd><p>Deactivation stops the snippet from loading. Uninstall (Plugins \u2192 Delete) removes all <code>cookiehug_*<\/code> options and transients. The remote connection is <em>not<\/em> revoked automatically on uninstall \u2014 do that from the plugin's settings page before deleting, or from the CookieHug dashboard.<\/p><\/dd>\n<dt id=\"can%20i%20self-host%20or%20point%20the%20plugin%20at%20a%20staging%20cookiehug%20instance%3F\"><h3>Can I self-host or point the plugin at a staging CookieHug instance?<\/h3><\/dt>\n<dd><p>Yes \u2014 add to <code>wp-config.php<\/code>:<\/p>\n\n<pre><code>add_filter( 'cookiehug_api_base', function() { return 'https:\/\/cookiehug.test'; } );\n<\/code><\/pre><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.2.6<\/h4>\n\n<ul>\n<li>New <code>[cookiehug_declaration]<\/code> shortcode: renders the cookie declaration table on any page or post (the loader is enqueued only where the shortcode is used).<\/li>\n<\/ul>\n\n<h4>0.2.5<\/h4>\n\n<ul>\n<li>Resubmission build for the WordPress.org review. No code changes compared with 0.2.4: every PHP class already carries the CookieHug_ prefix; the version number is bumped only so this build is distinguishable from the earlier 0.2.4 upload.<\/li>\n<\/ul>\n\n<h4>0.2.4<\/h4>\n\n<ul>\n<li>Declare compatibility with WordPress 7.1.<\/li>\n<li>readme: the External services section now spells out the software freshness report sent with the daily heartbeat (installed plugins with their versions and update state).<\/li>\n<li>Admin: the Disconnect confirmation labels are passed through wp_localize_script(), so they can be translated like the rest of the plugin.<\/li>\n<li>Internal: all PHP classes are renamed from CH_* to CookieHug_* so every global symbol carries the plugin prefix (WordPress.org naming rule). No functional change.<\/li>\n<\/ul>\n\n<h4>0.2.3<\/h4>\n\n<ul>\n<li>The daily heartbeat now includes a software freshness report: WordPress core version, the list of installed plugins with their versions, and which updates WordPress has already queued. The CookieHug dashboard uses it to warn the site administrator about outdated software before it becomes a security problem. No content or personal data is sent \u2014 only component names and version numbers.<\/li>\n<\/ul>\n\n<h4>0.2.2<\/h4>\n\n<ul>\n<li>Add an \"Updates\" diagnostics panel to the settings screen: shows the installed version, a live check against the CookieHug update server (with the exact HTTP result), whether a newer version is available, and whether WordPress has queued the update. Includes a one-click \"Force update check\". Helps pinpoint why an update might not appear (server firewall \/ caching plugin) without touching the server.<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Add a \"WP Consent API\" status panel on the CookieHug settings screen: shows whether the WP Consent API plugin is active and confirms CookieHug is registered as the consent manager (consent type opt-in). Offers a one-click install link when the API is missing.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Integrate with the WP Consent API: visitor choices in the CookieHug banner are mirrored into the shared consent bus (wp_set_consent), so other plugins can read consent via wp_has_consent(). Required for Google's CMP Partner Program.<\/li>\n<li>Load the consent banner via wp_enqueue_script() instead of a raw printed tag (WordPress.org compliance).<\/li>\n<li>Use wp_safe_redirect() with the platform host allow-listed for the connect\/SSO hops.<\/li>\n<li>Drop the manual load_plugin_textdomain() call (translations load just-in-time since WP 4.6).<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Add a periodic heartbeat (daily, plus when opening the settings page) so the dashboard shows an accurate \"last seen\" and current WP\/PHP\/plugin versions.<\/li>\n<li>Ship the self-updater so future versions surface as a normal WordPress update.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial public release. Connect flow, dashboard passthrough, banner snippet injection.<\/li>\n<\/ul>","raw_excerpt":"Connect WordPress to CookieHug, a hosted cookie-consent platform with WP Consent API support. Configure everything in the dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/333952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=333952"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cookiehug"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=333952"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=333952"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=333952"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=333952"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=333952"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=333952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}