WordPress & WooCommerce technical privacy

WordPress Privacy & Consent Audit

WordPress sites often combine consent plugins, analytics plugins, GTM, theme scripts and third-party embeds. PlainPrivacy tests how those pieces behave together in the browser and whether consent choices actually control the tracking they are meant to control.

Technical assessment and implementation support. PlainPrivacy does not provide legal advice.

Audit method
01

Observe the live implementation

02

Compare consent states

03

Document evidence and priorities

04

Implement and retest when requested

Scope

What we investigate on WordPress and WooCommerce

The review focuses on consent plugins, plugin/theme scripts, embedded services and the analytics or advertising tools connected to the site.

01

Consent plugin behavior

Review the configured consent plugin or CMP, its categories, banner behavior and the visitor's ability to reopen preferences.

02

Plugins, themes & embeds

Identify plugin, theme and embedded scripts that create cookies or third-party requests and check whether they bypass consent controls.

03

WooCommerce tracking

Where relevant, test ecommerce analytics, checkout-related tracking and marketing integrations across consent states.

04

GTM, GA4 & advertising

Review GTM, GA4, Google Ads, Meta Pixel and other relevant integrations for consent-aware behavior.

05

Consent withdrawal

Verify that visitors can change or withdraw preferences and that subsequent browser behavior reflects the new choice.

06

Duplicate or direct scripts

Identify duplicate tracking, hard-coded tags and scripts installed outside the primary consent or tag-management flow.

Evidence

What the review is based on

Findings are grounded in observable website behavior and the configuration available within the agreed scope.

  • Fresh-session tests before any choice
  • Accept, reject and preference-change tests
  • Cookies, local/session storage and network requests
  • Plugin/theme/embed behavior
  • GTM and analytics/advertising requests where present
  • Screenshots and reproducible technical findings

Deliverables

What you receive

The output is designed to be usable by business owners, developers, agencies and privacy advisers.

  • Prioritized technical findings
  • Observed cookie/tracker inventory
  • Consent and withdrawal behavior notes
  • Implementation recommendations
  • Optional implementation/remediation support
  • Post-fix verification and retesting

How it works

Investigate first. Change only what the evidence supports.

The initial review establishes the current behavior. Recommended changes are then scoped, implemented only when agreed, and retested afterward.

1

Review

Confirm the platform, regions, consent system and tracking stack that need to be tested.

2

Test

Run controlled browser journeys and inspect consent, storage, requests and tracking behavior.

3

Prioritize

Separate working controls from technical issues and identify the fixes that matter most.

4

Fix & verify

When implementation support is requested, apply agreed changes and repeat the relevant tests.

Request a technical review

Need evidence of what your website is actually doing?

Tell us about the website, platform, consent setup and current concern. We will suggest an appropriate technical scope.

Request Your Technical Audit