{"id":371529,"date":"2026-09-28T13:55:31","date_gmt":"2026-09-28T13:55:31","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/152-fz-local-consent\/"},"modified":"2026-09-28T13:36:22","modified_gmt":"2026-09-28T13:36:22","slug":"xprttudio-local-consent-152-fz","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/xprttudio-local-consent-152-fz\/","author":23568481,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.2","stable_tag":"1.2.2","tested":"7.1.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"xprttudio Local Consent for 152-FZ","header_author":"xprttudio","header_description":"\u0411\u0430\u043d\u043d\u0435\u0440 \u0441\u043e\u0433\u043b\u0430\u0441\u0438\u044f \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 cookie \u0438 \u0447\u0435\u043a\u0431\u043e\u043a\u0441\u044b \u0441\u043e\u0433\u043b\u0430\u0441\u0438\u044f \u043d\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u043f\u0435\u0440\u0441\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 (152-\u0424\u0417) \u0432 \u0444\u043e\u0440\u043c\u0430\u0445 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0435\u0432 \u0438 \u0432 \u0447\u0435\u043a\u0430\u0443\u0442\u0435 WooCommerce. \u0412\u0441\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u2014 \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432\u0430\u0448\u0435\u0433\u043e \u0441\u0430\u0439\u0442\u0430, \u0431\u0435\u0437 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432. \u0412\u0435\u0434\u0451\u0442 \u0436\u0443\u0440\u043d\u0430\u043b \u0441\u043e\u0433\u043b\u0430\u0441\u0438\u0439.","assets_banners_color":"222222","last_updated":"2026-09-28 13:36:22","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/xprttudio\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":62,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.2":{"tag":"1.2.2","author":"xprttudio","date":"2026-09-28 13:36:22","revision":3717267}},"upgrade_notice":{"1.2.2":"<p>Fixes the WooCommerce checkout consent checkbox not rendering. Update recommended if you use the WooCommerce integration.<\/p>","1.2.1":"<p>Plugin renamed to xprttudio Local Consent for 152-FZ (slug: xprttudio-local-consent-152-fz). No functional changes.<\/p>","1.2.0":"<p>Fixes a critical PHP 8 crash and a Contact Form 7 validation bypass. Banner now has Accept\/Reject\/Settings buttons, policy versioning, and CSV export. Update recommended.<\/p>","1.1.0":"<p>Added button color setting and optional Contact Form 7 support (whitelist-based, disabled by default).<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3717267,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3717267,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3717267,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3717267,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Plugin settings page.","2":"Cookie banner on the site.","3":"Consent checkbox in the comment form."}},"plugin_section":[],"plugin_tags":[146881,145809,16626,131785,152263],"plugin_category":[],"plugin_contributors":[283191],"plugin_business_model":[],"class_list":["post-371529","plugin","type-plugin","status-publish","hentry","plugin_tags-152-","plugin_tags-152-fz","plugin_tags-cookie-consent","plugin_tags-gdpr","plugin_tags-personal-data","plugin_contributors-xprttudio","plugin_committers-xprttudio"],"banners":{"banner":"https:\/\/ps.w.org\/xprttudio-local-consent-152-fz\/assets\/banner-772x250.png?rev=3717267","banner_2x":"https:\/\/ps.w.org\/xprttudio-local-consent-152-fz\/assets\/banner-1544x500.png?rev=3717267","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/xprttudio-local-consent-152-fz\/assets\/icon-128x128.png?rev=3717267","icon_2x":"https:\/\/ps.w.org\/xprttudio-local-consent-152-fz\/assets\/icon-256x256.png?rev=3717267","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>This plugin helps bring a site in line with the requirements of Russian Federal Law No. 152-FZ \"On Personal Data\":<\/p>\n\n<ul>\n<li>Shows a 152-FZ checklist on the settings page: which items the plugin already covers (based on current settings) and what needs to be done separately \u2014 a policy link in the footer, a Roskomnadzor notice, hosting the server in Russia.<\/li>\n<li>Displays a cookie consent banner with three buttons \u2014 Accept, Reject, and Settings (expands an explanation and a link to the cookie policy).<\/li>\n<li>Adds a required consent checkbox to the WordPress comment form.<\/li>\n<li>Adds a required consent checkbox to the WooCommerce checkout page.<\/li>\n<li>Can optionally auto-add a required checkbox to specific Contact Form 7 forms, via a whitelist of form IDs; disabled for all forms by default.<\/li>\n<li>The Accept button color is customizable via the standard WordPress color picker.<\/li>\n<li>Supports policy versioning: bumping the version in settings shows the banner again to visitors who already consented to an earlier version.<\/li>\n<li>Keeps a consent log (date, type, policy version, hashed IP) to help confirm that consent was given.<\/li>\n<li>Lets you export the consent log to CSV.<\/li>\n<li>Configurable log retention period, with automatic cleanup.<\/li>\n<\/ul>\n\n<p>The plugin does not send any data to external servers. All data is stored in your site's own database.<\/p>\n\n<h4>Limitations<\/h4>\n\n<p>This plugin is a technical tool for collecting consent and does not replace legal advice. The personal data processing policy and consent texts must be prepared separately and must match your actual data processing practices.<\/p>\n\n<p>The plugin author is not responsible for whether your site actually complies with 152-FZ. Achieving and maintaining compliance \u2014 including the accuracy of your policy text, notifying Roskomnadzor, and the physical location of your hosting \u2014 is entirely the responsibility of the site owner. The plugin is provided \"as is\", without warranty of any kind, as permitted by the GPL license it is distributed under.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the \"Plugins\" menu in WordPress.<\/li>\n<li>Go to \"Settings \u2192 152-FZ: Consent\" and configure the banner text and checkboxes, and select the policy page.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20replace%20a%20legal%20privacy%20policy%3F\"><h3>Does the plugin replace a legal privacy policy?<\/h3><\/dt>\n<dd><p>No. The plugin is a technical tool for showing the banner and collecting consent. The personal data processing policy text must be prepared separately and linked in the settings.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20data%20to%20third-party%20services%3F\"><h3>Does the plugin send data to third-party services?<\/h3><\/dt>\n<dd><p>No, the plugin does not connect to any external services and does not share data with third parties.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20author%20responsible%20for%20my%20site%27s%20compliance%20with%20152-fz%3F\"><h3>Is the plugin author responsible for my site's compliance with 152-FZ?<\/h3><\/dt>\n<dd><p>No. The plugin is a technical tool only, not a legal service. Whether your site actually complies with 152-FZ \u2014 including the wording of your policy, notifying Roskomnadzor, and where your data is hosted \u2014 is the responsibility of the site owner, not the plugin author.<\/p><\/dd>\n<dt id=\"can%20i%20add%20the%20checkbox%20to%20my%20own%20form%20%28not%20comments%2C%20woocommerce%2C%20or%20contact%20form%207%29%3F\"><h3>Can I add the checkbox to my own form (not comments, WooCommerce, or Contact Form 7)?<\/h3><\/dt>\n<dd><p>Not yet. The plugin intentionally supports only the forms where it can reliably block submission without the checkbox and log the consent: WordPress comments, WooCommerce checkout, and whitelisted Contact Form 7 forms. There used to be a shortcode for adding the checkbox to any form, but it only rendered a checkbox with the HTML <code>required<\/code> attribute, without real server-side blocking or logging, which was misleading \u2014 so it was removed in 1.2.0.<\/p><\/dd>\n<dt id=\"what%20data%20is%20stored%20in%20the%20consent%20log%3F\"><h3>What data is stored in the consent log?<\/h3><\/dt>\n<dd><p>Date and time, form type, the policy version in effect at the time of consent, a hash of the IP address (not the IP address itself), and the browser user agent. This lets you confirm that consent was given without storing the IP address in plain text.<\/p><\/dd>\n<dt id=\"what%20does%20the%20%22reject%22%20button%20in%20the%20cookie%20banner%20do%3F\"><h3>What does the \"Reject\" button in the cookie banner do?<\/h3><\/dt>\n<dd><p>It hides the banner and logs the rejection. 152-FZ does not formally require an opt-out button in the banner, but many sites add one for transparency. The plugin does not control the loading of third-party scripts (analytics, ads, etc.) \u2014 if such scripts are added to the site outside of this plugin, rejecting in the banner will not disable them.<\/p><\/dd>\n<dt id=\"can%20i%20export%20the%20consent%20log%3F\"><h3>Can I export the consent log?<\/h3><\/dt>\n<dd><p>Yes, the settings page has an \"Export log to CSV\" button.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20affiliated%20with%20woocommerce%20or%20contact%20form%207%3F\"><h3>Is this plugin affiliated with WooCommerce or Contact Form 7?<\/h3><\/dt>\n<dd><p>No. This plugin integrates with WooCommerce and Contact Form 7 if they are installed, but it is not developed, owned, or endorsed by their respective teams.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Fixed: the WooCommerce checkout consent checkbox was wrapped in an extra wp_kses_post() call that silently stripped the <code>&lt;input&gt;<\/code> element (not in its default allow-list), so the checkbox never rendered while submission still required it. Replaced with wp_kses() using an explicit allow-list.<\/li>\n<li>Changed: the settings page's inline SVG icons are now escaped with wp_kses() and an explicit allow-list on output, instead of a phpcs:ignore comment.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Changed: renamed the plugin (display name and slug) to xprttudio Local Consent for 152-FZ \/ xprttudio-local-consent-152-fz, at the request of the WordPress.org Plugins Team during review.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Changed: clarified in the readme, FAQ, and the settings page checklist that the plugin is a technical tool only \u2014 the site owner, not the plugin author, is responsible for the site's actual compliance with 152-FZ.<\/li>\n<li>Fixed (critical): banner text, the \"Settings\" button explanation, and the checkbox text \u2014 free-form admin input \u2014 were passed to sprintf() as a format string. On PHP 8.0+, sprintf() throws a ValueError on any string with a stray % character (e.g. \"20% off\"), crashing the banner render with a fatal error on every page. Replaced with str_replace(), which doesn't parse the content as a format string and never fails.<\/li>\n<li>Fixed: the banner cookie now gets the Secure attribute on HTTPS sites.<\/li>\n<li>Fixed: the \"Keep records for, days\" setting did nothing \u2014 purge_old_records() existed but was never called. Added a daily WP-Cron job, unscheduled on deactivation.<\/li>\n<li>Changed: the settings page redesigned as cards instead of a flat table \u2014 a dedicated stylesheet instead of default WordPress styling, toggles for boolean settings, clear selectable rows for forms, a grid-based log table with a colored badge for the record type.<\/li>\n<li>Fixed (important): consent checkbox validation for whitelisted Contact Form 7 forms did not actually block submission \u2014 WPCF7_Validation::invalidate() silently does nothing when given a field name string that isn't a real CF7 tag declared in the form editor. Now a properly built WPCF7_FormTag object is used, and submission without the checkbox is blocked server-side as intended. Updating is required if you use the CF7 integration.<\/li>\n<li>Added: a 152-FZ checklist on the settings page \u2014 live status for items the plugin can verify (banner, checkbox, policy page), plus reminders for items outside its scope (footer link, Roskomnadzor notice, hosting location).<\/li>\n<li>Added: the cookie banner now has three buttons \u2014 Accept, Reject, and Settings (expands an explanation and policy link) \u2014 instead of a single \"I agree\" button.<\/li>\n<li>Added: banner text supports the %s placeholder, replaced with a link to the selected policy page, same as the checkbox text.<\/li>\n<li>Added: policy version (set under \"Cookie banner \u2192 Policy version\"). Bumping the version shows the banner again to visitors who already consented; the version is stored with every consent log record.<\/li>\n<li>Added: export the consent log to CSV.<\/li>\n<li>Changed: the consent log now stores the policy version in effect at the time of consent.<\/li>\n<li>Fixed: banner text, the \"Settings\" button explanation, and the checkbox text were saved through sanitize_textarea_field(), which stripped all HTML \u2014 manually added <code>&lt;a&gt;<\/code> links disappeared after saving. These fields now save through wp_kses_post(), as intended.<\/li>\n<li>Removed: the <code>[xprttudio_152fz_consent]<\/code> shortcode for arbitrary forms. It only rendered a checkbox with the <code>required<\/code> attribute but didn't block submission server-side or log consent \u2014 it didn't offer the same guarantees as the rest of the plugin. Use your form builder's own validation for forms this plugin doesn't integrate with directly.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added a banner button color setting (background, hover background, text) via the standard WordPress color picker.<\/li>\n<li>Added optional auto-insertion of the checkbox into Contact Form 7 forms \u2014 strictly via a whitelist of form IDs; empty by default, so the checkbox doesn't appear anywhere automatically.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Cookie consent banner and personal data consent checkboxes for Russian 152-FZ \u2014 comments, WooCommerce, Contact Form 7.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/371529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=371529"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/xprttudio"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=371529"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=371529"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=371529"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=371529"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=371529"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=371529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}