What you get
Everything Consentinel does, and where.
Consentinel comes in parts, and you do not need all of them. The WordPress plugin works on its own, for free, with no account. A free Cloud account works on any site you can edit. Paid plans add domains, depth, history and the reports you hand to someone else.
10 of the entries below are things we can't do. They're marked, and you can filter to just those. What Consentinel finds beyond blocking depends on your platform, not on what you pay.
The short version
The protection is free. Holding trackers until your visitor agrees, honoring the browser opt-out signal, Google's consent setting and your own per-tracker rules all work at full strength on the free plan. We don't charge for the thing that protects you.
You pay for four things: more websites, deeper checks, a longer record — 90 days becomes two years — and the reports you hand to a client or a lawyer.
If you're on WordPress, start with the plugin. It's free, it needs no account, and it does something no browser-based tool can: it stops tracking scripts on your server, before the page is sent.
Side by side
What Each Part Gives You.
The four ways to run Consentinel, compared on the things people actually choose between. Where a mark is qualified, the qualification is printed next to it rather than hidden in a footnote.
| What you get | Plugin OnlyFree | Plugin + CloudFree plugin + any plan | Cloud FreeFree | Cloud PaidFrom $19/mo |
|---|---|---|---|---|
| Holds trackers until your visitor agrees | Included | Included | Included | Included |
| Works with no Consentinel account | Included | Not includedneeds a Cloud account | Not included | Not included |
| Blocks on the server, before the page is sent | IncludedWordPress only | IncludedWordPress only | Not includedonly WordPress allows this | Partlyon WordPress, through the plugin |
| Honors the “don’t sell my data” browser setting | Included | Included | Included | Included |
| Google's own consent setting | Included | Included | Included | Included |
| Do Not Sell or Share control | Included | Included | Includedyou place it | Includedyou place it |
| Keeps a consent record | Includedin WordPress, up to 24 months | Includedin Cloud | Included90 days | Included24 months |
| Export the record as a spreadsheet | Included | Included | Included | Included |
| A settings history that can't be edited | Partlya dated snapshot you export | Included | Included | Included |
| Checks your installation | Includedreads your files | Included | Includedreads the page as delivered | Included |
| A real browser that visits twice | Not includedno JavaScript is run | Includedthrough Cloud | Included100 pages per domain | Included600, or 4,000 on Scale |
| How often it re-checks | Partlyweekly, on your own server | PartlyCloud's schedule | Partlymonthly | Includedweekly |
| The full findings, not the top three | Not included | Not included | Not includedverdict in full, 3 findings | Included |
| Which pages a tracker fired on | Not included | Not included | Not included | Included |
| Who actually set each cookie | Not included | Not included | Not included | Included |
| Cookie policy generated from a crawl | Not included | Not included | Not included | IncludedPro and up |
| The Privacy Defense Report | Not included | Not included | Not included | IncludedAgency and Scale |
| Your name on the report | Not included | Not included | Not included | IncludedAgency and Scale |
| Remove our branding | Includedour badge is off unless you turn it on | Partlyfollows your Cloud plan | Not includedbranding strip shown | Included |
| Legal hold | Partlychecked before deleting | Included | Includedsupport switches it on, free | Includedswitch it on yourself |
Things we have decided on but not shipped are not in this table. When one ships it gets a row, and not before. The detail behind every line is below.
The Detail
Showing 70 of 70.
The WordPress Plugin, on Its Own
Install it and it works. No Consentinel account, and it makes no outbound connection to us unless you connect one. Everything below runs on your own WordPress site.
Works with no account
The banner, the blocking, the scanner and the consent record all run inside WordPress. Your data stays on your site.
Set up to block from the start
A fresh install defaults to holding non-essential trackers until the visitor agrees. US visitors also get Do Not Sell or Share and browser-signal handling.
A banner people can actually refuse
Full-width bar or corner box, your own wording, your policy links, and Accept all, Reject all and Preferences. Refusing is exactly as easy as accepting.
A preferences window
Visitors can turn functional, analytics, marketing and social tracking on or off separately, see which trackers you run, reopen preferences later, or withdraw.
Full control of how it looks
Colors, type, shape, position and layout are all yours. The “Powered by Consentinel” strip is off when you install it — it is opt-in, not a paid unlock.
Readable on whatever colors you pick
The banner and the preferences window switch to dark or light text on their own, based on the background and button colors you set. Both are announced to screen readers as dialogs.
A rule for every tracker
Set each one to always block, block until your visitor agrees, or never block. The browser blocker catches known tracker domains however they try to load.
It tells you loudly when blocking is off
If the master blocking switch is off, your per-tracker rules are not being enforced — and the admin screen says so in plain sight. A saved setting is not the same as an active one.
Blocking on the server, before the page is sent
Tracker scripts your other plugins add the normal way are rewritten in PHP before your visitor's browser ever sees them. No other consent tool on WordPress reaches these.
Scripts a plugin writes straight into the page
These need one extra setting switched on. It's off when you install, because it checks every part of every page before sending it — and we'd rather you turn that on deliberately than find it running by surprise.
- A limit
Fonts and icons loaded by a style file
Some fonts arrive through a style file rather than the page itself. Those can only be stopped by setting them to “always block” — and then they're gone for everyone, including visitors who agreed. “Block until they agree” can't work on them, because once removed, a browser has no way to put a style file back.
- A limit
Scripts your host or CDN adds
Cloudflare and similar services inject scripts after WordPress has finished building the page. No WordPress plugin can reach those, ours included. Turn them off at the host if you need silence before consent.
A scanner that reads your site's files
It checks your theme, your plugins, your rendered pages and your published content, up to 25 pages per run, and flags known trackers.
- A limit
What the scanner cannot see
It does not run JavaScript, so a tracker that only appears once scripts execute will not show up here. That is what the Cloud crawler is for.
Runs weekly, or whenever you ask
It scans after you activate it and once a week after that. On a large site some pages will not fit the time budget — those pages are named, not quietly skipped.
A consent record you keep
Time, what they chose, a scrambled and shortened IP, a scrambled browser string, and detected region — stored in WordPress, exportable as a spreadsheet, kept up to 24 months.
A settings snapshot you can hand over
Exports a dated file of exactly how the plugin was set up, what it decided about each tracker, and what the last scan found, with a fingerprint proving nobody altered the file. It records your settings — not what your visitors' browsers actually did. For that, you need a Cloud crawl.
- A limit
Cookies cleared when someone says no
On reject, withdrawal, Do Not Sell or a browser opt-out signal, recognized first-party tracker cookies are cleared. This is hygiene after the fact — it does not undo tracking that already happened.
Honors the browser opt-out signal
If a visitor has turned on the browser setting that means “don't sell my data”, non-essential categories are switched off without them touching your banner, and it is recorded accurately.
Do Not Sell or Share links
Drop the required links into your footer, your privacy page or a page builder. The link shows for every visitor, so a cached page can never show the wrong version to the wrong region.
Google's own consent setting
Sends denied by default before Google's tags decide anything, then updates from what your visitor chose. Turn it off if another plugin already handles it.
Shortcodes, blocks and Elementor widgets
Put preferences, Do Not Sell and withdrawal controls wherever your layout needs them.
Multisite
Activate across a network and each subsite gets its own settings, its own log and its own consent state.
Health checks that catch silent failures
Warnings for consent records failing to save, every visitor collapsing to one IP behind a proxy, stale files served by a CDN, and caching interfering with server-side blocking.
A setting for sites behind a proxy or CDN
Tell it to trust your provider's real-visitor headers so your consent records and rate limits do not collapse into a single edge-server address.
The Plugin Connected to Consentinel Cloud
You connect the plugin to a Cloud account. Cloud manages what your visitors see across every site; WordPress keeps doing the server-side blocking only WordPress can do.
Connecting is your choice, and reversible
The plugin is complete without Cloud. You start the connection from the plugin's Cloud tab, and you can disconnect from the same place.
It proves the site is yours
Connecting checks domain control before it links anything, so nobody can attach your site to their account.
Your site asks Cloud, Cloud never pushes
The site fetches its settings from Cloud. Those requests carry no visitor data, no page content and no consent records.
One banner, managed centrally
Once you publish from Cloud, the plugin loads Cloud's banner as the first script on the page and consent choices are recorded in Cloud.
Nothing breaks before you publish
Connected but not published yet? The plugin keeps serving its own banner and blocker, and tells you Cloud has nothing to serve.
You keep the WordPress advantage
Cloud's blocking rules feed the plugin's server-side gating. Connecting does not downgrade you to browser-only blocking.
One record, not two
While connected and published, Cloud holds the consent records and the local WordPress log switches off — so there is one visitor experience and one current record, not two that disagree.
Cloud's scan results inside WordPress
The plugin shows Cloud's latest crawl result. The local file scan pauses, because Cloud's real-browser crawl is the better measurement.
A sync button that tells you what happened
“Sync config now” reports synced, nothing published, or couldn't reach Cloud. You never have to guess whether a click worked.
- A limit
Disconnecting restores everything
Disconnect and the local banner and log come straight back. Disconnecting in WordPress does not notify Cloud, so a disconnected site and an unreachable one look the same from the Cloud side.
Deleting a site checks for a legal hold first
If you delete a connected site and asked to remove local data, the plugin asks Cloud whether a legal hold is in place. If Cloud says yes — or cannot be reached — deletion is refused, erring toward keeping your records.
Consentinel Cloud, Free Plan
One script tag on any site you can edit. The protection is not the paid part — blocking, browser opt-out signals, Google's consent setting and per-tracker rules all run at full strength on the free plan.
The protection is not gated
Holding trackers until your visitor agrees, honoring the browser opt-out signal, Google's consent setting and your own per-tracker rules all work on the free plan. We charge for breadth, depth and workflow — not for the thing that protects you.
- A limit
The snippet has to go first
Our code has to be the first thing in the head of your page. That position is the whole thing that makes it work — a tag manager or a platform script above it will win the race, and then we can't help.
A banner your site's styling cannot break
The banner and preferences window are sealed off from your site's CSS, so a theme update cannot deform them.
Design it with a live preview
Wording, colors, layout, policy links and behavior, previewed with the real banner rather than a picture of one.
Readable on whatever colors you pick
Text switches to dark or light on its own against the background and button colors you choose, and the customizer flags any pairing that is hard to read and fixes it in one click. The banner and the preferences window are announced to screen readers as dialogs.
Published settings are frozen
Each published version is locked and linked to the consent records made while it was live, so you can answer what a visitor actually saw on a given day. Saved drafts protect nobody until you publish.
Your settings are baked into your own file
Publishing builds a file specific to your site. The browser does not have to fetch settings before blocking starts.
A consent record you cannot edit
Every choice is stored so that nothing can be changed or deleted afterwards, by us or by you — with what they chose, how, which banner version, the time, the region, and scrambled IP and browser strings.
90-day history
The free plan keeps consent records for 90 days, unless a legal hold is on. Paid plans keep 24 months.
Read and export the log
Review consent records in the dashboard or export them as a spreadsheet.
Organizations, sites and roles
The account structure is there from the start — you do not have to restructure anything to upgrade later. Free is capped at one domain, and there is no overage on it because there is no card on file.
A one-click check of your installation
Fetches your page, finds known trackers, works out which platform you are on and whether your snippet is in the right place.
- A limit
That check does not run JavaScript
It reads the page as delivered. A tracker that only appears once scripts run will not show up in it — the crawler below is what catches those.
A real browser that visits twice
We load your site in a real browser twice — once saying no to cookies, once saying yes — and compare the two. Free covers up to 100 pages per website, and it sees things a page script can't, including the cookies browsers hide from scripts.
Prove the domain is yours first
A deep crawl only runs after you add a short line of text to your domain settings. That gate is permanent — it is why we cannot be pointed at someone else's site, and why nobody can point us at yours.
Crawled every month
Verified free sites are crawled monthly. Running one by hand resets the clock. Unverified sites are not scheduled.
- A limit
The verdict in full, three findings shown
You always see the complete verdict and what to do about it. On the free plan the detail is capped at your 3 most severe findings — we cap the volume, never the conclusion.
What your visitors actually chose
Accept, decline, preferences, Do Not Sell and browser-signal rates, taken from your server-side records rather than guessed in the browser.
Documentation without a login
Install guide, what can and cannot be blocked, how to verify your install, and the developer reference — all public.
Legal hold, free
A hold stops us deleting anything and unlocks your full preserved history. On the free plan support switches it on the same day, at no charge. Clearing one is never gated.
Consentinel Cloud, Paid Plans
Everything on the free plan, plus more domains, deeper crawls, longer history, and the outputs you hand to a client or to counsel.
24-month history
Every paid plan keeps consent records for 24 months instead of 90 days. If you only take one thing from this column, take this one: keep your records.
More domains, and no wall when you pass the limit
Pro includes 2, Agency 25, Scale 100. Go over and you are billed at a published monthly rate per extra domain — your client sites never go dark.
Crawled every week
Paid sites are crawled weekly rather than monthly, so a tracker someone adds on a Tuesday does not wait a month to surface.
The full findings, not the top three
Every tracker that ran before consent, every tracker that was held, the cookies, and a bucket for companies we didn't recognize rather than quietly dropping them.
Which pages it fired on
Sample pages and request counts per tracker, so you fix the template that caused it rather than hunting page by page.
Who actually set each cookie
Most scanners treat “this cookie exists” as “the website placed this cookie.” They are not the same thing, and a demand letter that dumps a raw cookie list is relying on the confusion.
A cookie policy generated from what we saw
Pro and up. Built from your latest successful crawl — from observed browser behavior, not from a questionnaire you filled in.
Remove our branding
Paid Cloud drops the Consentinel strip from the banner.
Invite your team
Paid organizations can invite members and assign roles.
The Privacy Defense Report
Agency and Scale. A print-ready technical record from a completed crawl: what transmitted before consent, what was held, who set each cookie, your consent statistics, your settings history, and a plain statement of the method and its limits.
- A limit
Your name on the report
Agency and Scale. The report can carry your agency's name for client delivery. This is the report only — it is not full product white-labeling.
Turn on a legal hold yourself
Pro and up can switch a hold on from the dashboard. Free gets it same-day from support. Clearing one is never gated on any plan.
- A limit
Deeper crawls on Scale
Scale raises the depth to 4,000 pages per domain. Pro and Agency both sit at 600 — Agency's advantage is breadth, not depth.
Scale is sold by talking to us
Scale is not self-serve. Someone works through your domain count, platforms and crawl load with you and onboards in batches, because crawl capacity is the real constraint.
Start with the part you need. Add the rest when you need it.
What can be blocked depends on where your platform lets our script run, so read this alongside each platform's external exposure. Consentinel is compliance tooling, not legal advice.