Kookies Consent Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Kookies Consent helps site owners manage consent for optional services in a clear and auditable way. Configuration and consent records remain in WordPress. The plugin does not require a cloud service, telemetry, or external frontend libraries.
Features include:
- A consent banner with accept, reject, granular selection, and later withdrawal.
- Fail-closed blocking of external content that has not been approved, including dynamically inserted resources. Visible embeds are replaced by a placeholder exactly where the content stands; blocked scripts and resources in the document head are neutralised silently, because there is no visible place for a consent box.
- A local service registry with purpose, provider, origins, data categories, international-transfer information, and storage details.
- Signed, pseudonymous records of consent decisions.
- A guided Borlabs Cookie migration with read-only analysis, quarantine, review, snapshot, automatic browser testing, cutover, and rollback.
- Diagnostic and Content Security Policy features for testing the configured site.
- Local placeholders that remain keyboard accessible and a settings view that can be reopened at any time.
- Site-wide consent for recognized embedded services, with an optional one-time alternative and downloadable signed TXT and JSON selection receipts.
- An administrator-only technical evidence package containing configuration checks and aggregate proof counts, but no individual consent IDs, IP addresses, email addresses, user agents, or cookie values.
Important when using cache plugins: A full-page cache stores one rendered copy of a page and serves it to every visitor — including the consent state of whoever happened to fill the cache. Consent-dependent pages must never be stored that way. Kookies Consent therefore detects the common page-cache plugins by name, measures before every browser check whether the site really serves fresh pages, and offers to switch a blocking cache off with one click — remembering exactly what it touched so it can be switched back on. A cache run by your hoster or CDN is named with concrete header evidence, but can only be switched off by the hoster.
Kookies Consent supports the technical implementation of privacy requirements. Legal assessment, service selection, and site-specific configuration remain the site owner’s responsibility. The plugin does not provide legal advice or guarantee compliance with any specific law.
Borlabs Cookie® is a registered trademark of its respective owner. Kookies Consent is an independent product and has no commercial affiliation with the provider of Borlabs Cookie. It is neither operated nor endorsed by that provider. The name “Borlabs Cookie” is used solely to describe compatibility and migration options.
Borlabs migration
The guided assistant runs as one continuous operation with visible progress across six phases. You start it once; read-only analysis, quarantined import and the completeness check then run without further clicks. The assistant stops at exactly two points: once for the answers only the site owner can give, and once before the irreversible cutover. That is four clicks in total.
Detected configuration is imported into quarantine, where services can be reviewed without executing imported scripts, CSS, regular expressions, or shortcodes. Everything the operator must answer — missing mandatory provider details and the explicit confirmation that the imported service data is correct — is collected on a single screen. After that confirmation, Kookies Consent creates a snapshot, applies the reviewed service list and runs an automatic browser test for first visit, rejection, granular consent, and withdrawal. The final cutover is available only after those checks pass. The saved snapshot can restore the previous configuration and reactivate Borlabs.
The progress state is derived from signed facts on the server, never from the browser, so a page reload, a request timeout or a closed browser resumes exactly where the run stopped. Large installations are imported in resumable batches. Everything except the browser test itself works without JavaScript.
Historical Borlabs consent cookies, TCF data, logs, statistics, license information, and account data are never converted into new Kookies Consent consent.
External services
Kookies Consent itself does not require or contact a cloud service, does not send telemetry, and does not automatically enable any provider listed below. It contains a local catalogue so a site owner can identify and configure services already used by that WordPress site. A catalogue entry alone creates no external connection.
An external connection occurs only when the site owner has configured the corresponding service and a visitor has granted the required consent (or deliberately requests a one-time load). The visitor’s browser then connects directly to that provider to load the selected map, media, font, form protection, analytics, marketing, payment, booking, review or chat content. Depending on the provider and configured content, the provider receives the visitor’s IP address, ordinary HTTP request and device/browser data, the referring page and the requested content identifier; the provider may also use cookies or similar browser storage. Exact processing and retention are controlled by the site owner and provider, not by Kookies Consent. Without the required consent, Kookies Consent keeps these resources blocked.
The local catalogue currently recognises these optional providers. The links below are supplied so operators can review the applicable terms and privacy information before enabling a service:
- Google (YouTube, Google Maps, Google Analytics, Google Ads/DoubleClick, reCAPTCHA, Google Tag Manager and Google Fonts): Terms, Privacy.
- Meta (Facebook, Instagram and Meta Pixel): Terms, Privacy.
- Vimeo: Terms, Privacy.
- hCaptcha / Intuition Machines: Terms, Privacy.
- Matomo Cloud: Terms, Privacy. For a self-hosted Matomo installation, the site operator’s own terms and privacy notice apply instead.
- OpenStreetMap Foundation: Terms, Privacy.
- X/Twitter: Terms, Privacy.
- Cloudflare Turnstile: Terms, Privacy.
- TikTok (embeds and Pixel): Terms, Privacy.
- LinkedIn Insight Tag: Terms, Privacy.
- Pinterest Tag: Terms, Privacy.
- Microsoft Clarity and Microsoft Advertising (UET): Terms, Privacy.
- Hotjar: Terms, Privacy.
- Calendly: Terms, Privacy.
- Doctify: Terms, Privacy.
- HubSpot: Terms, Privacy.
- Intercom: Terms, Privacy.
- Mapbox: Terms, Privacy.
- Adobe Fonts: Terms, Privacy.
- Spotify: Terms, Privacy.
- SoundCloud: Terms, Privacy.
- Dailymotion: Terms, Privacy.
- Twitch: Terms, Privacy.
- Stripe: Terms, Privacy.
- PayPal: Terms, Privacy.
- Yumpu / i-Magazine: Terms, Privacy.
Site owners can also configure a custom provider or a self-hosted service. In that case Kookies Consent connects only to the domains entered by the operator after the configured consent, and the operator must supply and review that provider’s purpose, data, terms and privacy information.
The plugin also contains an optional connection test. Only a logged-in administrator holding the plugin’s own capability can run it, and only from the plugin’s settings screen — either by pressing the test button there, or as one step of the guided migration that administrator is already working through. It never runs for visitors, and it never starts unless an administrator has that screen open. The test opens a preview of the site’s own pages inside that administrator’s browser and deliberately attempts to load small probe resources from the hosts of the services configured on that site: providers from the list above, hosts the operator entered for a custom service, and hosts carried over from a previous consent plugin during migration. The purpose is the opposite of loading them: every attempt is expected to be refused by the plugin’s own blocking layer, and the resulting report lists which attempts were refused and which were not. Thirteen of the fourteen probe types are stopped inside the browser before a request leaves it. The fourteenth is a dynamic JavaScript import(), which JavaScript cannot intercept; it is stopped by the enforced Content-Security-Policy the plugin sends on those pages instead. That header is absent when the operator has switched strict blocking off, when only a report-only policy is in place, or when a server or another plugin replaces it — in each of those cases this one probe does reach the provider, and the report says so. A probe address carries no payload, no site identifier and no visitor data; for that one probe the provider sees the ordinary data of a single request, which includes the administrator’s IP address and the address of the site. No result is transmitted anywhere: the report is stored in the site’s own database and shown only in the administration area.
Privacy
Kookies Consent stores the configured service registry and, when enabled, pseudonymous signed consent records in the WordPress database. A record contains its consent ID, decision, selected optional service IDs, configuration hash, language, expiry time, and integrity hashes/signature; it does not contain a full IP address, email address, full user agent, or raw cookie value. Records are deliberately not linked to an email address; WordPress privacy export and erasure requests therefore never guess an identity association. Visitors can instead download the signed choice stored in their current browser. The administrator evidence package reports verified, invalid, and legacy records separately without exporting individual consent IDs. The plugin does not send usage or diagnostic data to Kookies Consent. Provider and privacy-policy links entered by the site owner are used only in the local site configuration.
Screenshots
Consent banner with clear primary actions and direct access to granular settings.
Guided Borlabs migration with understandable steps, results, and status indicators.

