{"id":351571,"date":"2026-08-29T09:21:48","date_gmt":"2026-08-29T09:21:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/consenso-cookie-conforme-italia\/"},"modified":"2026-08-29T09:21:32","modified_gmt":"2026-08-29T09:21:32","slug":"onidea-consenso-cookie-conforme-italia","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/onidea-consenso-cookie-conforme-italia\/","author":23546008,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.6.2","stable_tag":"1.6.2","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"ONiDEA Consenso Cookie Conforme Italia","header_author":"ONiDEA adv","header_description":"Banner di consenso cookie GDPR (necessari \/ analytics \/ marketing \/ funzionali), blocco script fino al consenso, Google Consent Mode v2 e registro prova di consenso. Motore basato sulla libreria open source \"CookieConsent\" (MIT) di Orest Bida, self-hosted: nessun abbonamento, nessuna chiamata a servizi terzi a runtime.","assets_banners_color":"2456bb","last_updated":"2026-08-29 09:21:32","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/onidea.it\/agenzia-web-milano\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":46,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.6.2":{"tag":"1.6.2","author":"onideaadv","date":"2026-08-29 09:21:32","revision":3671293}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3671293,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3671293,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3671293,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3671293,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.6.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3671293,"resolution":"1","location":"assets","locale":"","width":1568,"height":747},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3671293,"resolution":"2","location":"assets","locale":"","width":1568,"height":747},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3671293,"resolution":"3","location":"assets","locale":"","width":1376,"height":752},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3671293,"resolution":"4","location":"assets","locale":"","width":1376,"height":752}},"screenshots":{"1":"The banner on the frontend, with \"Accept all\" and \"Reject all\" buttons of equal visual prominence, as required by the Italian Data Protection Authority's guidelines.","2":"The \"Customize\" panel, with cookie categories (Necessary, Statistics, Marketing, Functional) toggled individually.","3":"The Settings page: categories active on the site, Google Consent Mode v2, banner text.","4":"The Dashboard: banner status, consent breakdown, and the last-7-days trend."}},"plugin_section":[],"plugin_tags":[20011,223629,388,131785,396],"plugin_category":[54],"plugin_contributors":[278165],"plugin_business_model":[],"class_list":["post-351571","plugin","type-plugin","status-publish","hentry","plugin_tags-consent","plugin_tags-consent-mode","plugin_tags-cookie","plugin_tags-gdpr","plugin_tags-privacy","plugin_category-security-and-spam-protection","plugin_contributors-onideaadv","plugin_committers-onideaadv"],"banners":{"banner":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/banner-772x250.png?rev=3671293","banner_2x":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/banner-1544x500.png?rev=3671293","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/icon-128x128.png?rev=3671293","icon_2x":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/icon-256x256.png?rev=3671293","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/screenshot-1.png?rev=3671293","caption":"The banner on the frontend, with \"Accept all\" and \"Reject all\" buttons of equal visual prominence, as required by the Italian Data Protection Authority's guidelines."},{"src":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/screenshot-2.png?rev=3671293","caption":"The \"Customize\" panel, with cookie categories (Necessary, Statistics, Marketing, Functional) toggled individually."},{"src":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/screenshot-3.png?rev=3671293","caption":"The Settings page: categories active on the site, Google Consent Mode v2, banner text."},{"src":"https:\/\/ps.w.org\/onidea-consenso-cookie-conforme-italia\/assets\/screenshot-4.png?rev=3671293","caption":"The Dashboard: banner status, consent breakdown, and the last-7-days trend."}],"raw_content":"<!--section=description-->\n<p>ONiDEA Consenso Cookie Conforme Italia is a free, self-hosted alternative to subscription services like CookieYes or Cookiebot, covering the essential cookie consent features for WordPress sites:<\/p>\n\n<ul>\n<li>Consent banner with \"Accept all\" \/ \"Reject all\" buttons of equal visual prominence (as required by the Italian Data Protection Authority's \u2014 Garante Privacy \u2014 guidelines) plus a \"Customize\" option.<\/li>\n<li>Preferences panel with categories: Necessary (always on), Statistics, Marketing, Functional \u2014 enabled individually per site.<\/li>\n<li>Automatic blocking of scripts marked as non-essential until the user gives consent.<\/li>\n<li>Google Consent Mode v2: sets consent signals for Google Analytics 4 \/ Google Ads \/ AdSense before their scripts load, so they automatically honor the user's choice (only needs enabling where relevant).<\/li>\n<li>Server-side consent log (date, chosen categories, page, hashed IP \u2014 never stored in the clear) for the accountability record required by the GDPR, with CSV export.<\/li>\n<li>Engine built on the open-source \"CookieConsent\" library by Orest Bida (MIT license), served from your own site: no third-party calls, no subscription fee.<\/li>\n<\/ul>\n\n<h4>What it does NOT do (unlike paid services)<\/h4>\n\n<ul>\n<li>No automatic recurring scan of the site's cookies: categories and the scripts to block are configured manually (see GUIDA-RAPIDA.md, in Italian, in the plugin folder).<\/li>\n<li>Not IAB TCF certified: suited to Google AdSense\/Ads\/GA4 (via Consent Mode) and to the general run of editorial\/business\/e-commerce sites, not to publishers selling ad inventory through multiple ad exchanges\/SSPs that require IAB certification.<\/li>\n<li>Does not provide legal privacy\/cookie policy text: that remains your responsibility or your legal counsel's.<\/li>\n<\/ul>\n\n<h3>Included features<\/h3>\n\n<p>Every feature of the plugin \u2014 banner, categories, script blocking, Google Consent Mode v2, proof-of-consent log with CSV export, and the Dashboard with consent reporting\/trends (accepted\/rejected\/partial breakdown, last-7-days chart) \u2014 is included and active for anyone who installs the plugin, with no distinctions. The \"Powered by ONiDEA adv\" credit at the bottom of the banner is disabled by default and can be turned on by anyone from Settings.<\/p>\n\n<p>Any future premium extensions (if and when they arrive) will be a separate, independently distributed add-on \u2014 never functionality hidden inside this same package.<\/p>\n\n<h3>Credits and licenses<\/h3>\n\n<p>The banner engine is the open-source <strong>CookieConsent<\/strong> library by Orest Bida (https:\/\/github.com\/orestbida\/cookieconsent), released under the MIT license \u2014 fully compatible with this plugin's GPLv2+ license. The library's code is bundled unmodified in <code>assets\/js\/cookieconsent.umd.js<\/code> and <code>assets\/css\/cookieconsent*.css<\/code>; the original MIT license text is available at the repository above.<\/p>\n\n<p>Plugin developed and maintained by <a href=\"https:\/\/onidea.it\/agenzia-web-milano\/\">ONiDEA adv<\/a>, a web agency based in Milan, Italy.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>onidea-cookie-consent<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin from the WordPress Plugins screen.<\/li>\n<li>In the admin sidebar, open \"Consenso Cookie\" and configure categories, banner text, and links to your privacy\/cookie policy (under the \"Settings\" entry of the new menu).<\/li>\n<li>If the site uses AdSense\/Google Ads\/GA4, enable \"Google Consent Mode\".<\/li>\n<li>See GUIDA-RAPIDA.md (Italian-language guide, included in the plugin folder) for how to tag third-party scripts that need blocking.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"why%20doesn%27t%20the%20rest%20endpoint%20that%20logs%20consent%20use%20a%20nonce%3F\"><h3>Why doesn't the REST endpoint that logs consent use a nonce?<\/h3><\/dt>\n<dd><p>Deliberate choice, not an oversight. A WordPress nonce is generated when the page is rendered: on a site with page caching (practically all of them, in production) it ends up baked into the cached HTML and is replayed identically by every visitor for as long as that cache lives \u2014 often longer than the nonce's own lifetime. The practical result, observed during development: consents silently rejected by the endpoint (a <code>200<\/code> response with <code>{\"logged\":false}<\/code>, no visible error) for the entire lifetime of the cache.<\/p>\n\n<p>A nonce, in this specific case, does not protect anything worth protecting: the route is public by design (<code>permission_callback<\/code> is <code>__return_true<\/code>, deliberately \u2014 it must be callable by an anonymous visitor who has no account yet), it doesn't write anything privileged (only a row in an accountability-only log), and for a logged-out visitor the token is identical for everyone anyway. In its place: strict per-argument validation (type, length, and a category whitelist, so only well-formed rows can ever be written), a same-origin check on the request, and a 20-calls-per-hour-per-IP limit against abuse \u2014 computed from <code>REMOTE_ADDR<\/code> only by default, since request headers like <code>X-Forwarded-For<\/code> are attacker-controllable and are not trusted unless a site explicitly opts in via the <code>occit_trust_proxy_ip_headers<\/code> filter (for sites that know they sit behind a proxy\/CDN they control). None of this is a substitute for authentication; it bounds the worst case to \"some extra rows in a low-sensitivity accountability log,\" which is the actual risk on this endpoint. Details in the code, in <code>class-occ-frontend.php<\/code> and the REST handler.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20data%20to%20external%20services%3F\"><h3>Does the plugin send data to external services?<\/h3><\/dt>\n<dd><p>No. The banner engine (the \"CookieConsent\" library by Orest Bida) is downloaded once during development and distributed inside the plugin itself: it runs entirely on your own site, with no call to any third-party service either at runtime or during configuration. The consent log is a table in your own database.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.6.2<\/h4>\n\n<p>Second round of wordpress.org review fixes. The <code>tools\/<\/code> folder (developer-only scripts, <code>.py<\/code>\/<code>.mjs<\/code>, not needed at runtime) is no longer included in the distributed package \u2014 it stays in the source repository for internal use. Hardened the unauthenticated consent-log REST endpoint: added strict per-argument validation (type, length, a whitelist of the four known category keys) so the log table can only ever receive well-formed rows, and the per-IP rate limit now reads only <code>REMOTE_ADDR<\/code> by default instead of also trusting the attacker-controllable <code>X-Forwarded-For<\/code>\/<code>CF-Connecting-IP<\/code> headers (opt-in via the new <code>occit_trust_proxy_ip_headers<\/code> filter for sites that know they sit behind a trusted proxy\/CDN). The endpoint remains intentionally public (no user account exists to authenticate against) \u2014 see the FAQ below for the full rationale. No visible change for site visitors.<\/p>\n\n<h4>1.6.1<\/h4>\n\n<p>Updated the \"Tested up to\" header to 7.1, per wordpress.org's automated submission scan (the previous 7.0 value was flagged as outdated). No functional change.<\/p>\n\n<h4>1.6.0<\/h4>\n\n<p>Renamed the plugin to \"ONiDEA Consenso Cookie Conforme Italia\" (previously \"Consenso Cookie Conforme Italia\"), per wordpress.org directory guideline 17 (distinctive naming) \u2014 the previous name was too close to the generic pattern used by many other cookie-consent plugins. Internal function\/class\/option\/hook names were also renamed from the \"occ_\" prefix (3 characters) to \"occit_\", meeting the directory's minimum prefix length; existing settings and the consent-log table are migrated automatically and transparently on upgrade, no data is lost. The Dashboard page's CSS moved from an inline <code>&amp;lt;style&amp;gt;<\/code> block to a properly enqueued stylesheet. No visible change for site visitors; wp-admin menu URLs change (occ-dashboard \u2192 occit-dashboard, etc.) and any old bookmarks to them will need updating.<\/p>\n\n<h4>1.5.5<\/h4>\n\n<p>Text Domain header updated to match the wordpress.org-assigned slug (consenso-cookie-conforme-italia), fixing a textdomain_mismatch warning raised by the automated submission scan. No functional change.<\/p>\n\n<h4>1.5.4<\/h4>\n\n<p>Removed the Plugin URI header (it was identical to the Author URI, which wordpress.org's submission form does not allow \u2014 the two must point to different pages). Kept the Author URI pointing to the agency site, since there is no dedicated page for this specific plugin yet. No functional change.<\/p>\n\n<h4>1.5.3<\/h4>\n\n<p>Translated readme.txt into English, per wordpress.org's directory-listing language policy (July 2025): the readme is now the base language for community translations via translate.wordpress.org. The plugin itself \u2014 admin screens, banner text, settings, GUIDA-RAPIDA.md \u2014 remains entirely in Italian, as intended for its target audience. No functional change.<\/p>\n\n<h4>1.5.2<\/h4>\n\n<p>Fixed the findings from wordpress.org's official Plugin Check: prepared direct database queries are now documented with the matching phpcs exemption instead of being left unannotated; the CSV export's write to <code>php:\/\/output<\/code> (the HTTP response stream, not a real file \u2014 WP_Filesystem doesn't apply here) is documented the same way; removed GUIDA-RAPIDA.md from the distributed package (an internal guide for the agency, not required for the plugin to work \u2014 still available in the source repository). No functional change for site visitors.<\/p>\n\n<h4>1.5.1<\/h4>\n\n<p>Added a reference to the agency's site (ONiDEA adv, web agency in Milan) in the plugin header (Plugin URI\/Author URI) and in the readme's Credits section. No functional change for site visitors.<\/p>\n\n<h4>1.5.0<\/h4>\n\n<p>Removed the Free\/Pro distinction: the Dashboard with consent reporting and trends, previously reserved for the Pro tier, is now included and active for everyone. The wordpress.org directory guidelines (guideline 5, \"trialware\") do not allow functionality that already exists in the code but is disabled behind a license flag \u2014 this removal brings the plugin in line with that requirement ahead of submission. Any future premium extensions will be a separate add-on, never a hidden switch inside this same package.<\/p>\n\n<h4>1.4.1<\/h4>\n\n<p>Renamed the plugin to \"Consenso Cookie Conforme Italia\" (previously \"Cookie Consent - by ONiDEA\"), ahead of a future submission to the official wordpress.org repository \u2014 the previous name remains as the author\/agency name, no longer as the plugin name. No change to how the plugin behaves for site visitors. Internal cleanup: code brought in line with the WordPress Coding Standards (complete docblocks, style conventions), added an FAQ section (justification for the log endpoint's nonce-free design, confirmation of no calls to external services), a Credits and licenses section for the bundled CookieConsent library, and a Screenshots section.<\/p>\n\n<h4>1.4.0<\/h4>\n\n<p>The \"Powered by ONiDEA adv\" credit is now disabled by default at every tier (previously always on in Free, only removable in Pro) and is a free-standing Settings option independent of tier. Also fixed the \"|\" divider between the banner footer links, which stayed stuck to the first link when only two remained (e.g. Privacy Policy and Cookie Policy with the credit off): spacing is now symmetric regardless of how many links are present.<\/p>\n\n<h4>1.3.2<\/h4>\n\n<p>The \"Manage cookie preferences\" button now works even where <code>wp_kses_post()<\/code> strips its inline <code>onclick<\/code> \u2014 i.e. in widgets, filtered content, and many theme templates, where it used to stay visible but inert. The click is now captured via delegation in occ-init.js, so the button no longer depends on an inline attribute (also useful under a Content-Security-Policy).<\/p>\n\n<h4>1.3.1<\/h4>\n\n<p>The banner's two JavaScript files now load with <code>defer<\/code>. Without it, they blocked the parser and the browser fetched them at high priority, taking bandwidth away from the render-blocking CSS: the banner can never appear before the page itself, so that priority bought nothing and cost something.<\/p>\n\n<h4>1.3.0<\/h4>\n\n<p>The preferences-panel stylesheet (roughly 41% of the library's CSS) is no longer loaded with the page: it's only fetched by visitors who actually open the panel. Everyone else never downloads it. The split is regenerated with <code>tools\/split-modal-css.py<\/code> after a library update.<\/p>\n\n<h4>1.2.0<\/h4>\n\n<p>Banner settings now travel in a <code>&lt;script type=\"application\/json\"&gt;<\/code> block instead of via wp_localize_script: optimization plugins that combine JavaScript also swallow inline scripts, so excluding the banner script from the bundle (to make it appear earlier) left it without its settings and the banner failed to appear at all.\nThe consent log no longer requires a nonce: it used to get baked into the HTML when the page cache was written and expired before that cache did, silently losing consents on every cached site. In its place: a same-origin check and a per-IP hourly limit.<\/p>\n\n<h4>1.1.0<\/h4>\n\n<p>Added the \"Powered by ONiDEA adv\" credit to the banner (removable in the Pro version) and a Free\/Pro distinction (dashboard reporting reserved for the Pro version).<\/p>\n\n<h4>1.0.0<\/h4>\n\n<p>First release.<\/p>","raw_excerpt":"Self-hosted GDPR cookie consent banner: category-based blocking, Google Consent Mode v2, and a server-side proof-of-consent log.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/351571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=351571"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/onideaadv"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=351571"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=351571"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=351571"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=351571"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=351571"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=351571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}