{"id":364960,"date":"2026-09-14T09:49:48","date_gmt":"2026-09-14T09:49:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/lean-cookie-consent\/"},"modified":"2026-09-16T09:33:09","modified_gmt":"2026-09-16T09:33:09","slug":"lean-cookie-consent","status":"publish","type":"plugin","link":"https:\/\/hy.wordpress.org\/plugins\/lean-cookie-consent\/","author":17825548,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.1.7","stable_tag":"2.1.7","tested":"7.1.1","requires":"5.1","requires_php":"7.1","requires_plugins":null,"header_name":"Lean Cookie Consent","header_author":"Alessandro Romani","header_description":"Minimal WordPress connector for the Lean Cookie Consent SaaS. Configure a Site Key in the admin area; the plugin enqueues a bundled local runtime that fetches site configuration from the SaaS. The plugin does not store custom consent logs and does not allow arbitrary script insertion.","assets_banners_color":"c4ccda","last_updated":"2026-09-16 09:33:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/maildihooz-lgtm\/lean-cookie-consent-wordpress","header_author_uri":"https:\/\/www.blacklotus.eu","rating":0,"author_block_rating":0,"active_installs":0,"downloads":94,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.0.4":{"tag":"2.0.4","author":"blacklotusconsulting","date":"2026-09-14 09:49:34","revision":3694914},"2.1.7":{"tag":"2.1.7","author":"blacklotusconsulting","date":"2026-09-16 09:33:09","revision":3698277}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3694874,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3694875,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3694873,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3694872,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.0.4","2.1.7"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[20011,20272,16626,131785,396],"plugin_category":[54],"plugin_contributors":[213309],"plugin_business_model":[],"class_list":["post-364960","plugin","type-plugin","status-publish","hentry","plugin_tags-consent","plugin_tags-cookie-banner","plugin_tags-cookie-consent","plugin_tags-gdpr","plugin_tags-privacy","plugin_category-security-and-spam-protection","plugin_contributors-blacklotusconsulting","plugin_committers-blacklotusconsulting"],"banners":{"banner":"https:\/\/ps.w.org\/lean-cookie-consent\/assets\/banner-772x250.png?rev=3694872","banner_2x":"https:\/\/ps.w.org\/lean-cookie-consent\/assets\/banner-1544x500.png?rev=3694873","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lean-cookie-consent\/assets\/icon-128x128.png?rev=3694874","icon_2x":"https:\/\/ps.w.org\/lean-cookie-consent\/assets\/icon-256x256.png?rev=3694875","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Lean Cookie Consent is a minimal WordPress connector for the Lean Cookie Consent SaaS platform. The plugin stores a single Site Key in the WordPress options table and enqueues a bundled local runtime on every frontend page. The runtime fetches public site configuration from <code>https:\/\/api.leancookieconsent.com\/v1\/config?site=YOUR_SITE_KEY<\/code>.<\/p>\n\n<p>Banner copy, layout, colors, cookie categories, services, languages, policy links and consent records are all managed inside the Lean Cookie Consent dashboard. The WordPress plugin bundles only the static SaaS runtime and optional local demo assets, does not keep a custom consent log table, does not set any first-party consent cookies of its own and does not expose any way to insert or execute arbitrary JavaScript.<\/p>\n\n<p>The plugin is a SaaS connector only. A Lean Cookie Consent account and a valid Site Key are required.<\/p>\n\n<p>When no Site Key is configured yet, the settings page shows a local demo preview and short setup steps. Site owners can also enable an optional frontend demo banner for testing and visual preview only. Demo mode is local only: it does not call the SaaS, does not store consent records, does not send events, does not run analytics or marketing scripts and does not provide compliance evidence.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the Lean Cookie Consent SaaS platform to fetch public banner configuration and to record visitor consent choices only when a valid Site Key is configured. Demo mode is local preview only and does not use these external services.<\/p>\n\n<p>Service: Lean Cookie Consent configuration API\nURL: https:\/\/api.leancookieconsent.com\/v1\/config\nWhen: On every frontend page load when a Site Key is configured in Settings \u2192 Lean Cookie Consent.\nWhat is sent: The configured Site Key (passed as a <code>site<\/code> URL query parameter, character-whitelist <code>[a-z0-9_-]<\/code>, max 64 chars), and the visitor's browser context (User-Agent, Accept-Language, current URL) needed by the SaaS to return the correct public configuration.\nWhat is received: A JSON configuration payload used by the bundled local runtime to render the cookie banner, preference center and consent-mode signaling on the visitor's browser. The payload also includes the consent record API endpoint used by the banner.\nWhy: To display the cookie banner and record consent choices that match the configuration you set up in your Lean Cookie Consent dashboard.\nAccount: A Lean Cookie Consent account and Site Key are required. The Site Key is entered manually in Settings \u2192 Lean Cookie Consent.\nService provider: Black Lotus Consulting Srl (https:\/\/leancookieconsent.com\/)\nPrivacy Policy: https:\/\/leancookieconsent.com\/privacy-policy\nTerms of Service: https:\/\/leancookieconsent.com\/terms<\/p>\n\n<p>Service: Lean Cookie Consent consent API\nURL: https:\/\/api.leancookieconsent.com\/api\/consent\nWhen: Only when a visitor interacts with the bundled local banner and saves, denies or accepts consent choices.\nWhat is sent: The configured Site Key, the visitor's selected consent categories\/action, banner\/policy metadata from the SaaS configuration and technical browser request metadata needed to store the consent evidence.\nWhat is received: A JSON response confirming whether the consent event was stored.\nWhy: To keep an auditable consent record for the site configuration managed in Lean Cookie Consent.<\/p>\n\n<p>The WordPress plugin itself does not send any other data to any other service. The only data stored by this plugin is the Site Key, kept in the WordPress <code>wp_options<\/code> table under the option name <code>lean_cookie_consent_site_key<\/code>, plus the optional demo-mode setting <code>lean_cookie_consent_demo_enabled<\/code>. The plugin does not set any first-party consent cookies, does not keep any custom database tables and does not record consent locally. Demo mode does not use the configuration API or consent API.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin does not collect, store or transmit visitor data on its own. The only data it stores in WordPress is the Site Key configured by the site owner and the optional demo-mode setting. The optional demo banner does not persist browser dismissal state and is not a consent record.<\/p>\n\n<p>The cookie consent banner, preference collection and consent records are handled by the Lean Cookie Consent SaaS. Please review the Lean Cookie Consent Privacy Policy (https:\/\/leancookieconsent.com\/privacy-policy) for details on what the SaaS collects and how it is processed.<\/p>\n\n<p>This plugin adds a short suggested text to the WordPress Privacy Policy Guide describing the SaaS integration and the data handled by the SaaS.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Sign up for a Lean Cookie Consent account at https:\/\/leancookieconsent.com\/ and create a site. Copy the Site Key shown in your site configuration.<\/li>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/lean-cookie-consent<\/code> directory, or install the plugin through the WordPress plugins screen.<\/li>\n<li>Activate the plugin through the Plugins screen in WordPress.<\/li>\n<li>Go to Settings -&gt; Lean Cookie Consent and paste your Site Key. Save \/ Connect.<\/li>\n<li>Open your site in a private browsing window to verify the banner appears.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20require%20an%20external%20account%3F\"><h3>Does it require an external account?<\/h3><\/dt>\n<dd><p>Yes. A Lean Cookie Consent account and a Site Key are required for the real banner and consent records. The SaaS runtime will not load until a valid Site Key is configured. Site owners can enable a local demo banner for testing only; while enabled, the demo banner is shown instead of the SaaS runtime.<\/p><\/dd>\n<dt id=\"what%20is%20demo%20mode%3F\"><h3>What is demo mode?<\/h3><\/dt>\n<dd><p>Demo mode is an optional local preview for testing what the banner will look like. It is not the real consent workflow. It does not call Lean Cookie Consent services, does not store consent records, does not send events, does not run analytics or marketing scripts and does not provide compliance evidence. If dismissed, it only hides the preview for the current page view. While demo mode is enabled, it takes precedence over the normal SaaS runtime.<\/p><\/dd>\n<dt id=\"can%20demo%20mode%20record%20consent%20or%20prove%20compliance%3F\"><h3>Can demo mode record consent or prove compliance?<\/h3><\/dt>\n<dd><p>No. Demo mode is only for testing and preview. It does not record consent, does not create consent evidence, does not version policies, does not export consent logs and does not provide an audit trail.<\/p>\n\n<p>To record consent choices, manage the real banner configuration, track policy versions, export consent records or keep audit evidence, you need a Lean Cookie Consent account and a valid Site Key configured in Settings -&gt; Lean Cookie Consent.<\/p><\/dd>\n<dt id=\"does%20it%20load%20external%20javascript%3F\"><h3>Does it load external JavaScript?<\/h3><\/dt>\n<dd><p>No remote executable JavaScript is loaded by version 2.0.0 and later. When a Site Key is configured, the plugin enqueues its bundled local runtime and the runtime fetches JSON configuration from the Lean Cookie Consent SaaS. The Site Key is passed as a <code>site<\/code> URL query parameter. See the \"External services\" section below for full details.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20allow%20inserting%20or%20executing%20arbitrary%20javascript%3F\"><h3>Does the plugin allow inserting or executing arbitrary JavaScript?<\/h3><\/dt>\n<dd><p>No. The plugin does not expose any script field, custom HTML, custom CSS, textarea, custom URL or other input that could be used to insert or execute arbitrary JavaScript. Frontend scripts are limited to the bundled local SaaS runtime and, when explicitly enabled without a Site Key, the bundled local demo script included in the plugin package.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20keep%20a%20local%20consent%20log%3F\"><h3>Does the plugin keep a local consent log?<\/h3><\/dt>\n<dd><p>No. Consent records are stored and managed entirely by the Lean Cookie Consent SaaS when a valid Site Key is configured. Demo mode does not create consent records. The WordPress plugin does not create or use any custom database table for consent logging.<\/p><\/dd>\n<dt id=\"where%20do%20i%20find%20my%20site%20key%3F\"><h3>Where do I find my Site Key?<\/h3><\/dt>\n<dd><p>Sign in to https:\/\/app.leancookieconsent.com\/admin, open your site configuration and copy the Site Key shown there.<\/p><\/dd>\n<dt id=\"is%20this%20trialware%3F\"><h3>Is this trialware?<\/h3><\/dt>\n<dd><p>No. Lean Cookie Consent is a paid SaaS service. A Lean Cookie Consent account and valid Site Key are required for the real consent workflow, including banner configuration, consent record storage, policy versioning, exports and audit evidence.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.1.7<\/h4>\n\n<ul>\n<li>Fix the demo banner close button and persist demo preferences (analytics\/marketing\/dismissed) in the technical cookie <code>lean_cookie_consent_demo<\/code> so reopening the demo restores the last selection.<\/li>\n<\/ul>\n\n<h4>2.1.6<\/h4>\n\n<ul>\n<li>Make demo banner actions update the analytics and marketing toggles before closing the preview.<\/li>\n<\/ul>\n\n<h4>2.1.5<\/h4>\n\n<ul>\n<li>Add a floating cookie settings button to reopen the frontend demo banner after closing it.<\/li>\n<\/ul>\n\n<h4>2.1.4<\/h4>\n\n<ul>\n<li>Refine demo banner copy and move the powered-by link below the action buttons.<\/li>\n<\/ul>\n\n<h4>2.1.3<\/h4>\n\n<ul>\n<li>Ensure the frontend demo banner is rendered before footer scripts and initialize it safely after DOMContentLoaded if needed.<\/li>\n<\/ul>\n\n<h4>2.1.2<\/h4>\n\n<ul>\n<li>Let demo mode take precedence over the SaaS runtime whenever the frontend demo option is enabled.<\/li>\n<li>Widen the admin preview so action buttons stay on one row on desktop.<\/li>\n<li>Add a powered-by link to the demo banner and admin preview.<\/li>\n<\/ul>\n\n<h4>2.1.1<\/h4>\n\n<ul>\n<li>Make the local demo banner visible whenever demo mode is enabled, without persisting a browser dismissal flag.<\/li>\n<li>Align the frontend demo banner and admin preview with the bundled Lean Cookie Consent runtime layout.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added an admin banner preview when no Site Key is configured.<\/li>\n<li>Added optional frontend demo mode for testing without storing consent records.<\/li>\n<li>Improved onboarding from plugin settings to Lean Cookie Consent dashboard.<\/li>\n<\/ul>\n\n<h4>2.0.4<\/h4>\n\n<ul>\n<li>Keep the bundled frontend runtime human-readable for WordPress.org review.<\/li>\n<li>Remove the public powered-by credit link from the bundled WordPress runtime.<\/li>\n<\/ul>\n\n<h4>2.0.3<\/h4>\n\n<ul>\n<li>Correct the WordPress readme \"Tested up to\" value for repository validation.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Add idempotent upgrade handling for legacy installs, including plugin version storage, legacy Site Key preservation when available and an admin notice when a SaaS Site Key must be configured.<\/li>\n<\/ul>\n\n<h4>2.0.1<\/h4>\n\n<ul>\n<li>Point the WordPress settings page dashboard button directly to the Lean Cookie Consent admin area.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Plugin rebuilt as a minimal SaaS connector. Removed the entire local consent management platform: banner HTML, preference panel, consent logging, CSV export, search, delete, retention cleanup, pseudonymization, category descriptions, color picker, font picker, layout picker, position picker, consent expiration, privacy policy guide for local CMP, custom consent table.<\/li>\n<li>The plugin now stores a single Site Key and enqueues a bundled local runtime on the frontend. Banner configuration is fully managed in the Lean Cookie Consent dashboard and fetched as JSON.<\/li>\n<li>Removed arbitrary script insertion completely. The plugin does not provide custom script, custom HTML, custom CSS, account registration, automatic onboarding or account-linking features in version 2.0.0.<\/li>\n<li>Added the External Services disclosure required by WordPress.org guidelines.<\/li>\n<li>Added uninstall cleanup that removes the legacy local CMP options and drops the legacy <code>wp_lean_cookie_consent<\/code> table.<\/li>\n<\/ul>\n\n<h4>1.3.8<\/h4>\n\n<ul>\n<li>Added pseudonymous consent IDs, action\/event metadata, site URL, banner language and CSV export fields to the Free consent log.<\/li>\n<li>Replaced raw IP display\/storage for new consent records with a one-way hash and a 12-month cleanup baseline.<\/li>\n<\/ul>\n\n<h4>1.3.7<\/h4>\n\n<ul>\n<li>Fixed Plugin Check findings for the standalone package.<\/li>\n<li>Replaced wp_date() with a WordPress 5.1-compatible date helper.<\/li>\n<li>Tightened uninstall cleanup naming and database-safety annotations.<\/li>\n<\/ul>\n\n<h4>1.3.6<\/h4>\n\n<ul>\n<li>Updated the frontend cookie banner to match the hosted Lean Cookie Consent layout.<\/li>\n<li>Made preferences visible in the banner by default, with SaaS-style panel, overlay, two-column desktop layout and compact mobile layout.<\/li>\n<\/ul>\n\n<h4>1.3.5<\/h4>\n\n<ul>\n<li>Reset legacy banner settings on upgrade to the standalone profile.<\/li>\n<li>Updated the default first-run banner layout to a compact bottom-right box.<\/li>\n<\/ul>\n\n<h4>1.3.4<\/h4>\n\n<ul>\n<li>Fixed frontend banner rendering by avoiding an admin-only WordPress helper.<\/li>\n<\/ul>\n\n<h4>1.3.3<\/h4>\n\n<ul>\n<li>Removed third-party consent helper output and related settings from the standalone plugin.<\/li>\n<li>Simplified plugin copy and documentation around the standalone local workflow.<\/li>\n<li>Added suggested Privacy Policy Guide text for the plugin local cookies and consent records.<\/li>\n<li>Added uninstall cleanup for plugin options and custom consent log tables.<\/li>\n<li>Kept the plugin focused on local banner display, preference collection and consent records.<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>Strengthened WCAG 2.1 A\/AA support for the frontend banner and preference panel.<\/li>\n<li>Added dialog description\/status semantics, visible focus styles, focus restoration and improved keyboard handling.<\/li>\n<li>Improved default contrast and mobile\/text-spacing resilience.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added policy page selector and policy version tracking.<\/li>\n<li>Stored policy\/plugin version metadata with consent records.<\/li>\n<li>Added editable category descriptions.<\/li>\n<li>Improved admin consent record visibility for policy versions.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Renamed product and slug to Lean Cookie Consent.<\/li>\n<li>Added preference panel with technical, analytics and marketing categories.<\/li>\n<li>Added configurable consent expiration.<\/li>\n<li>Added layout and position presets.<\/li>\n<li>Improved frontend footprint for visitors with saved consent.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Security and WordPress.org review remediation pass.<\/li>\n<li>Added nonces and capability checks for admin actions.<\/li>\n<li>Added AJAX nonce verification for consent logging.<\/li>\n<li>Replaced deprecated multisite activation code.<\/li>\n<li>Removed timezone override.<\/li>\n<li>Improved sanitization, validation and escaping.<\/li>\n<li>Aligned text domain with the plugin slug.<\/li>\n<\/ul>\n\n<h4>1.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Minimal SaaS connector with manual Site Key setup and a bundled local cookie consent runtime.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364960"}],"author":[{"embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/blacklotusconsulting"}],"wp:attachment":[{"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364960"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364960"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364960"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364960"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364960"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/hy.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}