{"id":301130,"date":"2026-05-30T22:07:13","date_gmt":"2026-05-30T22:07:13","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/okito-cookie-consent\/"},"modified":"2026-09-25T18:05:17","modified_gmt":"2026-09-25T18:05:17","slug":"okito-cookie-consent","status":"publish","type":"plugin","link":"https:\/\/es-ec.wordpress.org\/plugins\/okito-cookie-consent\/","author":23481969,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.3","stable_tag":"1.1.3","tested":"7.1.2","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Okito Cookie Consent","header_author":"Okito","header_description":"Professional cookie consent management and GDPR\/CCPA\/LGPD compliance. Integrates with the Okito SaaS platform for enterprise-grade cookie banner management.","assets_banners_color":"","last_updated":"2026-09-25 18:05:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/app.okito.com","header_author_uri":"https:\/\/okito.com","rating":4.9,"author_block_rating":0,"active_installs":0,"downloads":333,"num_ratings":10,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"okitoapp","date":"2026-06-03 08:46:10","revision":3559035},"1.1.0":{"tag":"1.1.0","author":"okitoapp","date":"2026-09-25 11:45:11","revision":3712976},"1.1.1":{"tag":"1.1.1","author":"okitoapp","date":"2026-09-25 14:40:20","revision":3713197},"1.1.2":{"tag":"1.1.2","author":"okitoapp","date":"2026-09-25 17:23:23","revision":3713376},"1.1.3":{"tag":"1.1.3","author":"okitoapp","date":"2026-09-25 18:05:17","revision":3713412}},"upgrade_notice":{"1.1.3":"<p>Adds a filter to switch the page-head Consent Mode defaults off for basic Consent Mode.<\/p>","1.1.2":"<p>Recommended for IAB TCF sites: Google tags find the TCF API from the first moment.<\/p>","1.1.1":"<p>Recommended for sites using WP Rocket together with Site Kit and the WP Consent API.<\/p>","1.1.0":"<p>WordPress 7.1 support, one-click connection and WP Consent API integration for Site Kit.<\/p>","1.0.2":"<p>Important fix for PHP 8 sites when enabling the cookie banner.<\/p>","1.0.1":"<p>Maintenance and compatibility update.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":1,"5":9},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3557673,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3557673,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2","1.1.0","1.1.1","1.1.2","1.1.3"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"WordPress admin dashboard with status and quick actions","2":"Settings page with Connect with Okito and the Website Key field","3":"Cookie banner and related tools in the Okito web application"}},"plugin_section":[],"plugin_tags":[166295,20272,16626,131785,234433],"plugin_category":[54],"plugin_contributors":[265097],"plugin_business_model":[],"class_list":["post-301130","plugin","type-plugin","status-publish","hentry","plugin_tags-ccpa","plugin_tags-cookie-banner","plugin_tags-cookie-consent","plugin_tags-gdpr","plugin_tags-google-consent-mode","plugin_category-security-and-spam-protection","plugin_contributors-okitoapp","plugin_committers-okitoapp"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/okito-cookie-consent\/assets\/icon-128x128.png?rev=3557673","icon_2x":"https:\/\/ps.w.org\/okito-cookie-consent\/assets\/icon-256x256.png?rev=3557673","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Okito Cookie Consent<\/strong> adds a customizable cookie consent banner to your WordPress site and keeps Google Analytics, Google Ads and your other tags in line with each visitor's choice. It helps you meet the GDPR, UK GDPR, ePrivacy, CCPA\/CPRA and other US state privacy laws, Brazil's LGPD and T\u00fcrkiye's KVKK.<\/p>\n\n<p>You design the banner in the Okito dashboard; the plugin connects your site with one click and loads a single asynchronous script. No coding and no theme changes are needed.<\/p>\n\n<h4>Why Okito<\/h4>\n\n<ul>\n<li><strong>Google Consent Mode v2<\/strong> \u2014 ad_storage, analytics_storage, ad_user_data and ad_personalization are set before your Google tags run and updated the moment a visitor decides. Works with Google Analytics 4, Google Ads, Google Tag Manager and Site Kit by Google.<\/li>\n<li><strong>IAB TCF v2.3<\/strong> \u2014 registered IAB Europe CMP (ID 508) with the full <code>__tcfapi<\/code>, Google Additional Consent (AC string) and Google's <code>enableAdvertiserConsentMode<\/code>, for sites that run AdSense, Ad Manager or programmatic ads.<\/li>\n<li><strong>WP Consent API<\/strong> \u2014 every choice is passed to the WP Consent API, so Site Kit and other compatible plugins follow it automatically.<\/li>\n<li><strong>Geo-targeting by privacy law<\/strong> \u2014 show the banner only where consent is required (EEA, UK, Switzerland, T\u00fcrkiye, Brazil and similar) and keep measurement on elsewhere.<\/li>\n<li><strong>US privacy<\/strong> \u2014 opt-out notice with a \"Do Not Sell or Share My Personal Information\" link, the IAB US Privacy API (<code>__uspapi<\/code>) and Global Privacy Control (GPC) support.<\/li>\n<li><strong>Automatic script blocking<\/strong> \u2014 tracking scripts wait until the visitor consents to their category.<\/li>\n<li><strong>Cookie scanner<\/strong> \u2014 Okito scans your site and sorts cookies into categories for your cookie policy.<\/li>\n<li><strong>Consent records<\/strong> \u2014 every decision is logged as proof of consent.<\/li>\n<li><strong>50+ languages<\/strong> \u2014 the banner speaks your visitor's language automatically.<\/li>\n<\/ul>\n\n<h4>Built for WordPress<\/h4>\n\n<ul>\n<li><strong>Connect with Okito<\/strong> \u2014 sign in, pick your site and the banner is live. No key to copy.<\/li>\n<li><strong>Fast<\/strong> \u2014 one small asynchronous script. Nothing is rendered by PHP, so your pages stay light.<\/li>\n<li><strong>Caching and optimization friendly<\/strong> \u2014 works with WP Rocket, LiteSpeed Cache, Autoptimize, SiteGround Optimizer, W3 Total Cache and Cloudflare; the consent scripts are never delayed, combined or deferred.<\/li>\n<li><strong>Site Health checks<\/strong> \u2014 Tools \u2192 Site Health warns you about a second cookie plugin, a missing WP Consent API, Site Kit's Consent Mode setting and Google tags that load before your consent defaults.<\/li>\n<li><strong>Debug mode<\/strong> \u2014 add <code>?okito_debug=1<\/code> to any URL to see whether the consent defaults load before your Google tags.<\/li>\n<\/ul>\n\n<h4>Free plan<\/h4>\n\n<p>Start free and upgrade when you need more websites or advanced features. See <a href=\"https:\/\/app.okito.com\/pricing\">Okito pricing<\/a>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin relies on Okito, a third-party cookie consent and compliance platform operated by Okito (https:\/\/okito.com). It is required for the plugin to function: the banner, consent storage, IAB TCF v2.3 signals, Google Consent Mode v2 and the cookie scanner are all delivered by Okito's service. A free plan is available.<\/p>\n\n<p>The plugin contacts the Okito service in three ways:<\/p>\n\n<ol>\n<li><strong>CDN script load (visitor's browser, public pages only when the banner is enabled)<\/strong><\/li>\n<\/ol>\n\n<ul>\n<li><strong>Endpoint:<\/strong> <code>https:\/\/cdn.okito.com\/js\/{WEBSITE_KEY}<\/code><\/li>\n<li><strong>When:<\/strong> On every public page view in the visitor's browser, after the plugin is enabled and a Website Key is configured.<\/li>\n<li><strong>What is sent:<\/strong> The visitor's browser performs a standard HTTPS request for the script file. This means Okito receives the Website Key (as part of the URL), the visitor's IP address, User-Agent and the standard <code>Referer<\/code> header sent by the browser. While the banner is displayed, it stores the visitor's consent choices in the browser (cookies \/ local storage) and reports anonymized consent metrics to Okito so they can be shown in your Okito dashboard.<\/li>\n<li><strong>Why:<\/strong> This is what renders the cookie consent banner, captures the visitor's choice, blocks\/unblocks tagged third-party scripts and feeds the Okito analytics for that website.<\/li>\n<\/ul>\n\n<ol>\n<li><strong>Admin \"Test Connection\" request (server-side, WordPress admin only)<\/strong><\/li>\n<\/ol>\n\n<ul>\n<li><strong>Endpoint:<\/strong> <code>https:\/\/cdn.okito.com\/js\/{WEBSITE_KEY}<\/code><\/li>\n<li><strong>When:<\/strong> Only when an administrator clicks the \"Test Connection\" button on the Okito \u2192 Settings page.<\/li>\n<li><strong>What is sent:<\/strong> A standard HTTPS GET request from your server containing only the Website Key entered in the form. No visitor data, posts or user information is transmitted.<\/li>\n<li><strong>Why:<\/strong> To verify that the Website Key is valid against the Okito CDN.<\/li>\n<\/ul>\n\n<ol>\n<li><strong>\"Connect with Okito\" (administrator's browser, WordPress admin only)<\/strong><\/li>\n<\/ol>\n\n<ul>\n<li><strong>Endpoint:<\/strong> <code>https:\/\/app.okito.com\/integrations\/wordpress\/connect<\/code><\/li>\n<li><strong>When:<\/strong> Only when an administrator clicks \"Connect with Okito\".<\/li>\n<li><strong>What is sent:<\/strong> The site's home URL, the URL of the plugin settings page and a random one-time code. After the administrator signs in to Okito and chooses a website, Okito sends the browser back to the settings page with the Website Key and the same code, which the plugin checks before saving the key.<\/li>\n<li><strong>Why:<\/strong> To connect the site to an Okito account without copying the Website Key by hand.<\/li>\n<\/ul>\n\n<p>The plugin does not send any other data to Okito or any other third party. No personal data of WordPress visitors is transmitted by PHP code in this plugin.<\/p>\n\n<p>Use of the Okito service is subject to:<\/p>\n\n<ul>\n<li>Okito Terms of Service: https:\/\/okito.com\/terms-of-service\/<\/li>\n<li>Okito Privacy Policy: https:\/\/okito.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<p>Site administrators are responsible for ensuring their own privacy policy describes the use of Okito where required by law. Suggested wording is registered with WordPress and visible under <strong>Settings \u2192 Privacy<\/strong> after this plugin is active.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin:<\/p>\n\n<ul>\n<li>Saves your <strong>Okito Website Key<\/strong> and an <strong>enabled\/disabled<\/strong> flag in the WordPress options table.<\/li>\n<li>When enabled, loads the script described in <strong>External services<\/strong> on public pages so visitors see the cookie banner and consent features.<\/li>\n<\/ul>\n\n<p>Suggested wording for your Privacy Policy is available in WordPress under <strong>Settings \u2192 Privacy<\/strong> after this plugin is active.<\/p>\n\n<!--section=installation-->\n<h4>Install<\/h4>\n\n<ol>\n<li>In WordPress, go to <strong>Plugins \u2192 Add New<\/strong>, search for <strong>Okito Cookie Consent<\/strong>, then click <strong>Install Now<\/strong> and <strong>Activate<\/strong>.<\/li>\n<li>Or upload the ZIP under <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<\/ol>\n\n<h4>Connect your site<\/h4>\n\n<ol>\n<li>Go to <strong>Okito \u2192 Settings<\/strong>.<\/li>\n<li>Click <strong>Connect with Okito<\/strong>, sign in (or create a free account) and choose your website.<\/li>\n<li>You are sent back to WordPress with the cookie banner enabled.<\/li>\n<\/ol>\n\n<p>Prefer to do it by hand? Copy the Website Key from the Okito dashboard, paste it into <strong>Okito \u2192 Settings<\/strong>, enable the banner and save.<\/p>\n\n<h4>Recommended<\/h4>\n\n<ul>\n<li>Install the <strong>WP Consent API<\/strong> plugin so other plugins follow the visitor's choice.<\/li>\n<li>Using Site Kit by Google? Turn on <strong>Consent Mode<\/strong> under Site Kit \u2192 Settings \u2192 Admin Settings.<\/li>\n<li>Check <strong>Tools \u2192 Site Health<\/strong> for Okito's setup checks.<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20add%20a%20cookie%20consent%20banner%20to%20wordpress%3F\"><h3>How do I add a cookie consent banner to WordPress?<\/h3><\/dt>\n<dd><p>Install Okito Cookie Consent, click <strong>Connect with Okito<\/strong> in Okito \u2192 Settings and choose your website. The banner appears on your site right away; change its design, texts and languages in the Okito dashboard.<\/p><\/dd>\n<dt id=\"does%20okito%20support%20google%20consent%20mode%20v2%3F\"><h3>Does Okito support Google Consent Mode v2?<\/h3><\/dt>\n<dd><p>Yes. Consent Mode v2 defaults (ad_storage, analytics_storage, ad_user_data, ad_personalization) are set before your Google tags load and updated as soon as the visitor makes a choice (advanced Consent Mode). For basic Consent Mode, choose Google tags \u2192 Basic in the Okito Banner Builder and add <code>add_filter( 'okito_print_consent_mode_defaults', '__return_false' );<\/code> to your theme or a small plugin: Okito then sends no Consent Mode commands and keeps Google tags blocked until the visitor consents.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20google%20tag%20manager%20and%20site%20kit%3F\"><h3>Does it work with Google Tag Manager and Site Kit?<\/h3><\/dt>\n<dd><p>Yes. Keep your Google Tag Manager container or Site Kit as it is: Okito's defaults load first in the page head. Site Kit also reads the visitor's choice through the WP Consent API.<\/p><\/dd>\n<dt id=\"is%20okito%20an%20iab%20tcf%20cmp%3F\"><h3>Is Okito an IAB TCF CMP?<\/h3><\/dt>\n<dd><p>Yes. Okito is registered with IAB Europe as CMP ID 508 and supports TCF v2.3, including the Google Additional Consent string.<\/p><\/dd>\n<dt id=\"can%20i%20show%20the%20banner%20only%20in%20the%20eu%3F\"><h3>Can I show the banner only in the EU?<\/h3><\/dt>\n<dd><p>Yes. With geo-targeting the banner opens only where a consent law requires it, and measurement stays on for visitors from other regions.<\/p><\/dd>\n<dt id=\"will%20the%20plugin%20slow%20down%20my%20website%3F\"><h3>Will the plugin slow down my website?<\/h3><\/dt>\n<dd><p>No. It loads one asynchronous script; the banner is rendered in the visitor's browser, not by PHP on your server.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20caching%20plugins%3F\"><h3>Is it compatible with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. Okito tells WP Rocket, LiteSpeed Cache, Autoptimize, SiteGround Optimizer, W3 Total Cache and Cloudflare Rocket Loader to leave its consent scripts alone, so they are never delayed, combined or deferred.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20okito%20account%3F%20is%20there%20a%20free%20plan%3F\"><h3>Do I need an Okito account? Is there a free plan?<\/h3><\/dt>\n<dd><p>Yes, the banner is managed in an Okito account. You can create one for free while connecting the plugin.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20add%20links%20or%20branding%20to%20my%20site%3F\"><h3>Does the plugin add links or branding to my site?<\/h3><\/dt>\n<dd><p>The plugin only adds the consent script. What appears inside the banner is set in your Okito dashboard.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>New <code>okito_print_consent_mode_defaults<\/code> filter: return false to skip the Consent Mode defaults printed in the page head (basic Consent Mode, where Google tags stay blocked until consent)<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>IAB TCF stub in the page head: the TCF API (__tcfapi) is available before Google tags run, even when they load before the Okito banner script<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>WP Rocket \"Delay JavaScript\": the WP Consent API and Site Kit's Consent Mode script are no longer delayed until the first interaction, so Site Kit receives the visitor's choice right away<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Tested with WordPress 7.1<\/li>\n<li>One-click \"Connect with Okito\": sign in, pick the site and the banner is enabled, no key copying<\/li>\n<li>WP Consent API integration: visitor choices are passed to the WP Consent API (functional, preferences, statistics, marketing), so Site Kit and other compatible plugins follow them<\/li>\n<li>Google Consent Mode v2 defaults printed early in the page: region-aware, Global Privacy Control support and Okito's Google developer ID<\/li>\n<li>Compatibility with caching and optimization plugins (WP Rocket, LiteSpeed Cache, Autoptimize, SiteGround Optimizer, W3 Total Cache, Cloudflare Rocket Loader): Okito's scripts are never delayed, deferred or combined<\/li>\n<li>Site Health checks: banner setup, other active consent plugins, WP Consent API, Site Kit Consent Mode and whether Google tags load before the consent defaults<\/li>\n<li>Escaped all admin output, prepared database queries and other WordPress Plugin Check fixes<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fixed a PHP 8+ fatal error when the cookie banner was enabled (script tag filter)<\/li>\n<li>Improved banner enable flag handling and WordPress 6.3+ async script loading<\/li>\n<li>Added compatibility helpers for WordPress 6.4\u20137.0 and PHP 7.4\u20138.x<\/li>\n<li>Script loading uses native <code>async<\/code> strategy on WordPress 6.3+ and a safe fallback on older supported versions<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Updated IAB TCF references to v2.3 in plugin UI and documentation<\/li>\n<li>Switched script delivery and connection checks to cdn.okito.com<\/li>\n<li>Improved script connection verification logic for CDN responses<\/li>\n<li>Added custom Okito admin menu icon<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>CDN script injection in <code>wp_head<\/code><\/li>\n<li>Settings for Website Key and enable\/disable<\/li>\n<li>Connection test from WordPress admin<\/li>\n<li>Suggested privacy policy text for the site Privacy Policy page<\/li>\n<\/ul>","raw_excerpt":"Cookie consent banner for GDPR, CCPA, KVKK and LGPD with Google Consent Mode v2, IAB TCF v2.3, WP Consent API and geo-targeting. Free plan.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/301130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=301130"}],"author":[{"embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/okitoapp"}],"wp:attachment":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=301130"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=301130"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=301130"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=301130"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=301130"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=301130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}