Set up Cookie Crumb

Cookie Crumb is the free plugin WorkMore Cookie Crumb: a consent banner that holds scripts, videos and pixels back until your visitors answer, a cookie scan, a consent log and a dashboard — all on your own site, complete on its own. WorkMore Cookie Crumb Pro, an add-on to it, is in development; this page will cover it when it is released.

The plugin is a tool, not legal advice: which cookies need consent, how to ask and how long to keep a record depend on the law that applies to your site.

What you need

1. Install the free plugin

  1. Plugins → Add New → Upload Plugin, choose the zip, Install Now, Activate.
  2. Open Settings → Cookie Crumb. A site that was never set up opens on Set up your cookie banner: four steps, and everything in them can be changed afterwards. Skip the setup takes you straight to the tabs.

Nothing changes for your visitors until you publish.

2. The four steps

  1. Look at the site. Press Scan the site. The screen opens a few of your pages in your own browser, the way a visitor who is not logged in gets them, and lists the cookies they set and what they load from other sites. It takes under a minute. While it runs, your pages' own trackers run once in your browser. Nothing is sent to an outside service.
  2. Sort what was found. Each cookie and script goes into a category or is left out. What the plugin recognises — Google Analytics, Tag Manager, Google Ads, YouTube, Google Maps, Meta Pixel, Facebook embeds, and the cookies of WordPress and WooCommerce — has its category already; choose one for the rest. A script in any category but the necessary one will be held back until a visitor allows that category.
  3. The banner. Choose how it asks — Ask first (recommended) holds scripts back until the answer; Notice only informs and holds nothing — and how it looks. Its words, its languages and the link to your policy are under Banner design afterwards.
  4. Publish. Publishing puts the banner on every page and holds the listed scripts back. The page caches of common caching plugins and hosts are cleared; if your host caches pages some other way, clear that cache after publishing.

3. Check what still loads before the answer

Open Cookie scan and press Scan again. Now that a banner is published, the scan also opens each page as a visitor who has not answered, and lists under Loaded before the visitor answered whatever still reached another site — with, for each, whether a rule can hold it:

A scan cannot see what loads only after a click or a purchase, or what an ad blocker in your browser stops.

4. Let visitors change their answer

By default a small round button stays in a corner of every page and opens the cookie settings window. Under Banner settings you can use your own link instead, or as well: any link to #cookie-settings opens the window — in a menu, a footer or a page — and so does the [wmcc_settings] shortcode. The window shows the visitor their consent ID.

5. Read the consent log

Consent log shows how visitors answered — by kind, by category, over time — and page views by month. Below it, every answer is one record: paste a visitor's consent ID to find theirs, and Export CSV takes the list with you. The log keeps the last 90 days. Settings → Privacy → Policy guide in WordPress has a paragraph about it that you can use in your privacy policy.

Changing the banner later

Everything is a draft until you publish it. Change the cookie list under Cookies, the words and the look under Banner design — beside a live preview of your real site at desktop, tablet and phone widths — then press Publish banner. Each publish is a version, and every record names the version the visitor answered. Visitors are asked again only when a category that needs consent was added.

If something goes wrong

Pro

Pro will be a separate plugin, WorkMore Cookie Crumb Pro, sold by Freemius; its price is on the pricing page, and its Buy button appears there the day it can be bought. It will install from the zip in your purchase email beside the free plugin, which must stay active. If a subscription lapses, nothing breaks: what you set up keeps running and stays editable.

Uninstall

Deactivating never deletes anything. Uninstalling removes the consent log, the statistics and the settings only if you ticked Settings → Delete the consent log, statistics and settings when the plugin is uninstalled; it is off by default, because a consent log is a record you may be asked for. Export it first.