Free WordPress Plugin
Warder: a cookie banner that stays on your server
A free GDPR cookie consent banner for WordPress. It holds your analytics scripts until a visitor opts in, and it runs entirely from your own domain: no account, no external service, no paid tier.
Why another cookie banner
Most consent plugins are the front end of a paid service. The banner calls their servers, the free tier has a page or domain limit, and the features you need sit behind an upgrade.
Warder is built on the open-source CookieConsent v3 library and adds a WordPress settings screen, sensible defaults for WordPress and WooCommerce, and script blocking that stops cookies before they are set. It runs on imagewize.com and on every Imagewize theme demo.
What it does
Nothing leaves your server
No CDN, no consent API, no phone-home. The script is served from your own domain, and the visitor’s choice is stored in their own browser.
Scripts actually blocked
Known cookie-setting scripts are held before the browser can run them, rather than cleaned up afterwards. WooCommerce order attribution is blocked out of the box.
Opt in, not opt out
Every non-necessary category stays unticked until the visitor chooses. A floating cookie button lets them change their mind later.
Your own categories
Add, rename and describe cookie categories from the settings screen, each with its own cookie list. Cookies are cleared when a visitor withdraws consent.
Six languages
Interface strings in English, Dutch, German, French, Spanish and Italian. The banner text you write yourself is stored as you type it.
Small and cache-safe
One deferred script of about 18KB gzipped, no jQuery. Settings are versioned in the script URL, so cached pages always load the matching configuration.
What it does not do
So you can rule it out in thirty seconds rather than after installing it:
- No consent log. The choice is stored in the visitor’s browser, so there is no proof-of-consent export.
- No Google Consent Mode v2 signals.
- No automatic cookie scanner. You list the cookies you want managed.
- No CCPA “Do Not Sell” flow.
Warder gives you the mechanism: blocking before consent, granular categories and a choice the visitor controls. Whether a site is compliant depends on how it is configured and what it loads. It is a tool, not legal advice.
For the developers: blocking your own scripts
Warder needs WordPress 5.0 or later and PHP 8.0 or later, and is tested up to WordPress 7.1. Hold any script you embed yourself until its category is accepted by marking it:
<script type="text/plain" data-category="analytics" src="..."></script>
Or block a script another plugin registered, by its handle:
add_filter( 'warder_blocked_scripts', function ( $scripts ) {
$scripts['my-analytics-handle'] = 'analytics';
return $scripts;
} );
Frequently asked questions
- Is Warder free? Yes. Every feature is in the free plugin on WordPress.org. There is no pro tier, no per-domain limit and no trial.
- Does Warder make my site GDPR compliant? No plugin can promise that. Warder holds scripts until consent, lets visitors choose per category and change their choice later. Compliance still depends on configuring it for what your site actually loads.
- Does it block Google Analytics before consent? It clears Google Analytics cookies, and it holds the GA script once that script is marked with a category or its handle is registered through a filter. WooCommerce order attribution and SourceBuster are blocked automatically.
- Does the plugin send any data anywhere? No. It makes no external requests at all. The consent script is served from your own domain, and the visitor’s choice is stored in their browser.
- Can you set it up for me? Yes. I can configure the categories and cookie lists for what your site loads and hold your analytics scripts until consent, billed at the flat €65 per hour rate.
Related
- Aludra: the free block page builder, also on WordPress.org.
- Managed WordPress hosting: EU-hosted on Hetzner, the same stack this site runs on.
- All Imagewize plugins
Not sure what your site loads?
Tell me the site and what it runs. I will check which scripts set cookies before consent and set Warder up to hold them.