=== NOP Cookie Consent ===
Contributors: nopdigital
Tags: cookies, gdpr, consent, ccpa, privacy
Requires at least: 6.2
Tested up to: 6.8
Requires PHP: 7.4
Stable tag: 1.1.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Cookie consent that blocks third-party scripts before consent, as the law actually requires. No ads, no upsell banners, no branding in your visitors' faces.

== Description ==

Most cookie plugins show a banner and let the tracking run anyway. The banner then collects a signature on something that already happened, which is not what GDPR, DSGVO, AVG or the UK rules ask for. This plugin starts from the other end: it looks at the HTML your site is about to send and disarms the third-party scripts, embeds, stylesheets and tracking pixels until the visitor says yes.

**What it does**

* Blocks third-party scripts, iframes, stylesheets and tracking pixels until the matching category is allowed. Around fifty known services are recognised out of the box, and anything else can be marked by hand or added as a rule.
* Puts a box with the provider's name and a button where a blocked video, map or booking form was, so nothing disappears from the page without an explanation.
* Sends Google Consent Mode v2 signals, so the choice exists for Analytics, Ads and Tag Manager too and not only inside this panel.
* Honours Global Privacy Control, which has the force of law in California.
* Works on a site with page caching, because the blocking never depends on the visitor's cookie: the server always blocks, the browser restores.
* Four categories, the technical one with no switch because technical cookies are not consented to, they are disclosed.
* Colour, position, size, radius, shadow, buttons: all yours, including a live preview that is the real banner with the real stylesheet.
* Banner texts ready in English, Italian, French, Spanish and German, and rewritable.
* A cookie policy page generated from the list of third parties your site actually uses.
* Keeps a record of the choices made, without storing IP addresses or user agents.

**What it does not do**

* It does not claim the list of recognised services is complete. It never will be: that is why there is a scan that tells you what is getting through, and a way to add your own rules.
* It does not publish a table of cookie names and durations. Those are decided by the providers, changed without notice, and a table that says "two years" because it was true in 2021 is a confident false statement, which in an inspection is worse than a missing one.
* It does not let you hide the reject button. A banner with only "Accept all" does not collect a free consent, and a plugin that let you configure it that way would be selling you the belief that you are covered.

**Free and Pro**

Compliance is in the free version: the banner, the blocking before consent, the categories, a reject button with the same visual weight as accept, the right to change your mind, the policy, Consent Mode, the colours and the position. Making people pay for compliance would mean leaving the ones who do not pay exposed, and the ones who do not pay are usually the ones who do not know they are exposed.

A licence adds the consent log and its export, the site scan, your own blocking rules, more than one language, the logo and extra CSS.

== Installation ==

1. Upload the plugin and activate it.
2. Open Cookie Consent in the admin menu. The Banner tab opens first: the banner is already on, with safe defaults.
3. Choose position, colours and buttons. The preview on the right is the real banner and changes as you go.
4. In Settings, create the cookie policy page or choose the one you already have.
5. Put `[nopdcc_preferences]` in the footer, or keep the small round button, so visitors can change their mind.
6. With Pro, open Third parties and press Scan the site: the second list shows what nothing is blocking yet.

== Frequently Asked Questions ==

= Does it work with a caching plugin? =

Yes. The HTML never changes according to the visitor's cookie, so a page cached for someone who accepted is safe to serve to someone who has not. The restoring is done by the browser, which always has the cookie.

= Will it break my site? =

The blocking only touches tags that carry a third-party address. Scripts, stylesheets and images from your own domain are left exactly as they were, attribute by attribute. Payment and anti-spam services (Stripe, PayPal, reCAPTCHA, hCaptcha) are classified as technical and never blocked, because blocking them stops checkout and silently breaks contact forms.

= What about Google Tag Manager? =

By default the container is blocked, because from outside we cannot see what is inside it. If you have set up Consent Mode inside Tag Manager, switch the setting: the container then loads and receives the signals, denied until the visitor decides.

= Do you store IP addresses? =

No. The consent log holds a random identifier generated by the browser, the date, the categories, the revision and a one-way fingerprint that cannot be turned back into an address.

== Changelog ==

= 1.1.1 =
* "See plans and prices" in the Pro licence tab now opens the plans on the Cookie Consent page.

= 1.1.0 =
* New admin, in line with the other NOP Digital plugins: Banner, Texts, Third parties, Consent log, Settings, Pro licence.
* Banner tab with the on/off switch, visual position picker, colour presets and a live preview inside a mock site.
* Fixed: switches could not be turned off once saved.
* Fixed: the scan counted plain links as loaded services.
* Fixed: the font size variable overwrote the text colour of the banner.
* Italian translation of the admin.

= 1.0.0 =
* First release.
