v1.0.0
12 Sep 2026First release.
Added
- Blocking for enqueued scripts (
script_loader_tag), the inline code attached to them (wp_inline_script_attributes), oEmbed and hand-pasted iframes — plus an optional whole-page scan for snippets pasted into a theme. - Default rules that recognise Google Analytics, Tag Manager, Site Kit, the Meta pixel, Hotjar, Clarity, Matomo, Plausible, Segment, Mixpanel, TikTok, LinkedIn, Google Ads, X and HubSpot by handle or URL, and YouTube, Vimeo, Dailymotion, Facebook, Instagram, TikTok and Google Maps as embeds.
- Google Consent Mode v2 defaults printed before any Google tag, with
ads_data_redactionandwait_for_update, and the update sent when a decision is made. - A tag whose category the visitor has already allowed is printed as itself — the cookie is read on the server, so there is no round trip through the blocker at all.
- The proof-of-consent log: a table in your own database, a REST route, daily pruning on a schedule you set, and the recent decisions listed in the settings screen. The IP is stored as an HMAC.
- Settings → Cookie Consent: layout, position, theme, policy page, policy version, what is blocked, the rule lists, Consent Mode and the log.
[devix_cookie_settings]shortcode, anddata-cc-openon any element, to reopen the choices.devix_cookie_consent_config,devix_cookie_consent_blocked_script,devix_cookie_consent_cookie_namefilters and adevix_cookie_consent_recordedaction.- The widget is bundled with the plugin: no third-party requests, and no account anywhere.