Skip to content
Subset

User guide

Getting started

Put up a banner that actually blocks, categorise the scripts your site already loads, and keep the record of who consented to what.

Most consent banners ask politely and then load the tracker anyway. Cookie Manager holds scripts at the WordPress enqueue layer, which is why declining works rather than merely being recorded.

Install

wp plugin install subset-cookie-manager --activate

On activation the banner is off. That is deliberate: a consent banner that appears before you have categorised your scripts blocks nothing and annoys everyone, which is the worst of both outcomes.

Find out what your site actually loads

Settings → Cookie Manager → Scripts (placeholder — not final) lists every enqueued script and style handle the plugin can see. Open it before the banner goes up: that list is the inventory, and the banner is only as good as it.

Every handle starts unassigned. An unassigned non-essential script is blocked until you say otherwise, which is the right way round: the failure mode is “a script did not run” rather than “a tracker ran without consent”.

Categorise them

Four categories, which is the set nearly every regulator’s guidance converges on:

CategoryWhat belongs in itBlocked before consent
EssentialSession, cart, CSRF, the consent record itselfNo
PreferencesLanguage, theme, dismissed noticesYes
AnalyticsPage-view counting, heatmaps, session replayYes
MarketingAd pixels, remarketing, cross-site identifiersYes

“Essential” is narrower than people hope. A cookie is essential when the service the visitor asked for cannot work without it — a shopping cart, a login session. It is not essential because your analytics dashboard would look worse without it.

Turn the banner on

Once your scripts are categorised, switch the banner on. A visitor who declines is a visitor whose declined categories never enqueue.

Planned for 1.0.0Changelog

Categorised banner, blocking by handle, default-deny, and the consent log are all in the free version’s first release.

Keep the record

Each decision is stored with its timestamp, the categories chosen, and the version of the banner that was shown. That last field is the one people forget and the one a regulator asks about: “what exactly was this person agreeing to” is a question about the banner as it was that day, not as it is now.

What the law actually requires is the background, and is true regardless of which plugin you use. The developer reference covers intervening in the blocking decision from your own code.