=== CookiePile - Cookie Consent & Consent Mode v2 ===
Contributors: miotix
Tags: cookie consent, consent mode, gdpr, cookie banner, google tag manager
Requires at least: 6.3
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.11
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Cookie consent that reaches your tracking: Consent Mode v2, GTM, WP Consent API, script blocking and diagnostics that check it all works.

== Description ==

Most cookie banners stop at the banner. CookiePile also checks that your tags respect it.

**Tracking Diagnostics** loads any page of your site the way a visitor sees it (before a choice, after "Reject all", after "Accept all") and shows you, in plain language:

* tracking requests or cookies that happen before the visitor agrees,
* Google tags that report consent as granted when it was not,
* a consent default that loads after your tags, or that a speed plugin delays,
* duplicate GA4 ids, Tag Manager containers and Meta pixels,
* a second consent tool fighting the first one.

Everything runs on your own site and in your own browser. Nothing is sent to CookiePile or anyone else.

= Consent signals =

* **Google Consent Mode v2**, all seven consent types, printed at the very top of `<head>` before any Google tag. Basic or Advanced mode, `wait_for_update`, `ads_data_redaction`, `url_passthrough`.
* **Google Tag Manager**: a `cookiepile_consent_update` dataLayer event with the category choices, ready to use as a trigger.
* **WP Consent API**: when the free WP Consent API plugin is active, Site Kit, WooCommerce and other plugins that read it follow the visitor's choice automatically.
* **Microsoft Advertising (UET)** and **Microsoft Clarity (ConsentV2)** consent.

= Blocking =

* Known tracking scripts (about 45 services: Meta Pixel, TikTok, LinkedIn, Pinterest, Hotjar, HubSpot, X, Snap and more) wait until the visitor allows their category.
* Scripts added later by tag managers and page builders are caught too.
* YouTube, Vimeo, Google Maps and other embeds become a click-to-load placeholder.
* Add your own services through a simple form (a name, a category and part of the script address).

= Banner =

* Bar, corner box or center dialog. Colors, radius and font size from the settings, no code needed.
* "Reject all" has the same weight as "Accept all" by default.
* A small floating button (or the `[cookiepile_preferences]` shortcode) lets visitors change their mind.
* Keyboard and screen reader friendly.
* Full right-to-left support. Hebrew included.

= Also included =

* Cookie scanner and a `[cookiepile_cookie_list]` shortcode for your cookie policy page.
* Consent log on your own site: random consent ID, choice, version, date and a salted hash of a shortened IP address. Search by consent ID.
* Export and import settings.
* Works with page caching: the banner is decided in the browser.

CookiePile helps you work toward compliance. It is not legal advice, and no plugin can make a site compliant on its own.

= CookiePile Pro =

A separate paid version adds pixel consent APIs (Meta and TikTok load with consent revoked and switch on after consent), region rules with Global Privacy Control, weekly monitoring with email alerts and a client-ready report, consent log export and statistics, and your own image as the banner logo. Learn more at [cookiepile.com](https://cookiepile.com).

== Installation ==

1. Install and activate CookiePile.
2. Open **CookiePile** in the admin menu. The defaults are safe: opt-in, Advanced Consent Mode, blocking on.
3. Pick your cookie policy page on the **Banner** tab.
4. Open **Tracking Diagnostics** and run it on your home page.
5. Optional: install the free **WP Consent API** plugin if you use Site Kit or WooCommerce.

== Frequently Asked Questions ==

= Does this make my site GDPR compliant? =

No plugin can do that on its own. CookiePile gives you the technical parts (consent before tracking, signals your tags understand, a log, and a way to verify it). Your legal advisor can tell you what else your site needs.

= Basic or Advanced Consent Mode? =

Advanced lets Google tags load and send cookieless signals until the visitor chooses, which keeps modeled conversions in Google Ads and GA4. Basic blocks Google tags completely until consent. Both are supported; choose on the Consent signals tab.

= Does it work with Site Kit, GTM4WP and WooCommerce? =

Yes. The consent default prints before their tags. For Site Kit and WooCommerce, also install the WP Consent API plugin.

= My speed plugin delays JavaScript. =

Exclude `cookiepile-head` and `cookiepile.js` from delay, defer and combine features. Tracking Diagnostics tells you when this is needed.

= Can I add custom CSS? =

Use Appearance > Customize > Additional CSS. Every element has a `cookiepile-` class, for example `.cookiepile-banner` and `.cookiepile-btn-primary`.

= Does CookiePile contact external services? =

The plugin itself does not. See "External services" below for the one SDK it includes and for what the diagnostics screen does.

== External services ==

= Freemius (the only service this plugin connects to) =

This plugin includes the Freemius SDK (https://freemius.com), the service that handles licensing and updates for the paid version and, if you allow it, opt-in usage data.

What is sent and when: on activation the SDK shows an opt-in screen. If you say yes, it sends your site address, the WordPress and PHP versions, your active plugin and theme list, and your name and admin email address to Freemius, and it checks for plugin updates from there afterwards. If you skip the opt-in, none of that is sent. If you activate a paid license, the SDK sends the license key and your site address to Freemius so the license can be validated and renewed, and it checks for updates.

Freemius terms of service: https://freemius.com/terms/ Freemius privacy policy: https://freemius.com/privacy/

= What CookiePile itself does NOT send anywhere =

Nothing. The banner and the visitor's choice, script and embed blocking, the cookie scanner, the consent log and Tracking Diagnostics all run on your own site and in your own browser, and no part of them contacts CookiePile or any other server.

Tracking Diagnostics deserves a word, because it deals with third-party tags: it opens pages of YOUR OWN site in YOUR OWN browser (before a choice, after "Reject all", after "Accept all") and reports which requests those pages make. Any outside address it names is a request your own tags make, never one this plugin makes.

The plugin's code contains the addresses of about 45 tracking services (for example googletagmanager.com, google-analytics.com, clarity.ms, bat.bing.com, analytics.tiktok.com and connect.facebook.net). They are text patterns used to recognize those services in your own page and hold them back until the visitor allows their category, and to recognize them in a diagnostics run. CookiePile never requests them, and it does not load any script, font, image or stylesheet from an outside server.

== Screenshots ==

1. The consent banner on a live site, as a full-width bar at the bottom of the page.
2. The preferences dialog, with a switch for each category.
3. What CookiePile includes, listed on the plugin's own screen.
4. Banner settings: layout, position and every text a visitor reads.
5. Categories: rename the four categories and rewrite their descriptions.
6. Blocking: the known tracking services and how each one is handled.

== Changelog ==

= 0.1.11 =
* Button color source "Automatic" now finds your theme's color on far more sites. It was only looking at one place in the page, which missed Elementor and several block themes entirely, so those sites quietly fell back to the default green.
* The button color you choose is used exactly as you chose it. 0.1.10 lightened it for contrast on dark banners and showed the lightened version, so the buttons were never quite the color in the picker.
* Buttons are now protected from theme and page builder styles, the way the switches already were. On dark banners a theme's own button styling could repaint them, and the rollover left the label unreadable.
* The Preferences button reads as the quiet button again on a dark banner instead of looking like the Accept and Reject buttons.
* The switches in the preferences dialog were too close to the background to see, on light and dark alike. They now meet the contrast a control is supposed to have.

= 0.1.10 =
* Dark banners: the accent color, whether borrowed from your site or chosen on the Banner tab, is now checked against the banner background and lightened when it would be too dark to see. On dark sites this was leaving the cookie icon, the button outline and the switches close to invisible, and the Accept and Reject buttons sinking into the banner.
* The switches read correctly on a dark banner, and "Always on" no longer looks switched off.
* Banner tab: the Button color field is dimmed while Button color source is set to Automatic, with a line saying the color is coming from your theme. It used to look editable while having no effect.
* The translation files for Arabic, Russian, Polish, Czech and Romanian declared more plural forms than they carried, which stricter gettext tools reject.
* Arabic now covers the admin screens as well as the banner.

= 0.1.9 =
* Right to left fix: on an RTL site whose theme does not set the page direction, the small floating button stayed on the left while the banner correctly mirrored. It now follows the banner.
* Thirteen more visitor languages in the paid versions: Arabic, Russian, Polish, European Portuguese, Swedish, Danish, Finnish, Norwegian, Czech, Greek, Romanian, Hungarian and Turkish. Twenty languages in all. Arabic and Hebrew lay out right to left.
* The credit line is translated too, in every one of those languages.

= 0.1.8 =
* Fixed: the banner and dialog title was smaller and faded on sites that show a logo. The credit line added in 0.1.7 shared a style class with the logo row.
* The cookie icon is now the standard logo on the banner and in the preferences dialog, so the banner says "cookies" at a glance. Pick the site icon, the theme logo or no logo at all on the Banner tab whenever you prefer your own.
* The credit line, when you switch it on, now shows the cookie icon next to the text.

= 0.1.7 =
* The small floating button now shows a cookie icon instead of your site logo. On a button that stays on screen after the visitor has chosen, the site's own logo said nothing about what the button does. Your logo still appears on the banner and in the preferences dialog.
* New Button color source setting. On Automatic, the banner borrows your theme's own accent color (theme palette, then a button, then a link) and picks readable button text to match. Set it to use the button color below if you would rather choose it yourself.
* New optional line in the preferences dialog crediting CookiePile. Off unless you switch it on, and never shown on the banner itself.

= 0.1.6 =
* The admin menu icon style is enqueued instead of printed inline.
* The blocker now closes its own output buffer explicitly instead of leaving it to PHP.
* Asset versions are read without silencing errors.
* readme: the External services section documents exactly what the licensing SDK sends and when, and makes clear that the tracking addresses in the code are patterns for recognizing your own tags, not requests this plugin makes.

= 0.1.4 =
* Packaging only: each edition now ships just the screens and the documentation that belong to it. No change to the banner, the signals or the diagnostics.

= 0.1.3 =
* The admin menu shows the CookiePile icon in color.
* New Free vs Pro tab on the CookiePile screen.
* Preferences dialog: Save sits on the left, Reject and Accept on the right.
* The switches, the close button and the floating button keep their look on themes and page builders that style every input and button.

= 0.1.1 =
* The banner and the preferences dialog can show your logo (the site icon by default), and the floating button uses it too, in a quieter style.
* Colors: new Automatic mode picks a light or dark banner to match the page background. Light, Dark and Custom are also available.
* Banner texts you have not changed now follow the site language (and the page language on multilingual sites). Visitor-facing translations added for German, French, Spanish, Italian, Dutch and Brazilian Portuguese.
* Preferences dialog: Save, Reject and Accept sit on one row.
* Banner titles and buttons keep their look on themes with strong heading and button styles.

= 0.1.0 =
* First release: banner and preferences, Google Consent Mode v2, GTM dataLayer event, WP Consent API, Microsoft UET and Clarity consent, script and embed blocking, Tracking Diagnostics, cookie scanner and cookie list shortcode, consent log, settings export and import, Hebrew translation.

== Upgrade Notice ==

= 0.1.11 =
Fixes the automatic button color on Elementor and block themes, shows the color you picked exactly, and repairs the buttons and switches on dark banners.

= 0.1.10 =
Fixes a dark mode problem: on a dark site the cookie icon, the button outline and the switches could be almost invisible. Colors are now checked for contrast against the banner.

= 0.1.9 =
Right to left sites: the floating button now mirrors with the banner. Thirteen more languages in the paid versions, twenty in all.

= 0.1.8 =
Fixes a 0.1.7 bug that shrank and faded the banner title on sites with a logo. The cookie icon becomes the standard banner logo, and the Banner tab still lets you use your site icon or theme logo instead.

= 0.1.7 =
The floating button shows a cookie icon rather than your site logo, and the banner can now borrow your theme's accent color automatically.

= 0.1.6 =
Housekeeping for the WordPress.org review. No change to how the banner, the signals or the diagnostics work.

= 0.1.4 =
Packaging only. Nothing changes in how the banner, the signals or the diagnostics work.

= 0.1.3 =
The banner keeps its look on themes and page builders with strong form and button styles.

= 0.1.1 =
Logo on the banner, automatic light or dark colors, and banner texts that follow the site language.

= 0.1.0 =
First release.
