Description
Bulgaro GDPR adds a GDPR cookie consent banner (cookie notice) to your WordPress site: it blocks analytics and marketing scripts until the visitor agrees, records every consent, and never breaks checkout.
The free plugin includes:
- A cookie consent banner with Accept, Necessary only, and category preferences — 14 languages or automatic browser detection
- Consent management with records stored as a pseudonymous SHA-256 id (no IP address) — GDPR and ePrivacy friendly
- Automatic blocking for known trackers (GA4, GTM, Meta Pixel, and others)
- Google Consent Mode v2
- A scanner that stays on your server
- Coverage for WordPress core cookies, WooCommerce, and payment providers
- A Consent Register showing how many consents were recorded and the most recent entries
Payment scripts are detected and never blocked, so checkout can finish. Covered providers include Stripe, PayPal, WooPayments, ePay.bg, BORICA, myPOS, EasyPay, Paysera, Revolut Pay, Mollie, Klarna, Adyen, Square, Braintree, Amazon Pay, Google Pay, Razorpay, PayU, 2Checkout, iCard, TBI Bank and NestPay virtual POS.
The admin screens are available in English and Bulgarian.
Bulgaro GDPR Pro
Bulgaro GDPR Pro is an optional paid add-on that adds:
- 10 extra banner color themes (15 in total) and 3 extra banner shapes
- Custom Scripts Manager — inject your own functional, analytics and marketing snippets, each fired only after the visitor consents to that category
- Consent Register audit tools — CSV export for audits and a configurable retention window
- A daily automatic website scan with an email alert when a new third-party tracking service appears
The free plugin is fully functional on its own; the add-on only adds the extras above. Learn more: https://supremecommerce.eu/bulgaro-gdpr/
External services
The core GDPR features — cookie banner, script blocker, scanner and payment coverage — work entirely on your own server and send no data anywhere. The only same-domain requests are from the built-in Website Scanner, which reads pages on your OWN site (same domain) with the user agent BulgaroGDPR-Scanner, and only when you start a scan from the admin. No visitor data is ever sent off your site.
Freemius (payments and licensing). The plugin uses the Freemius service to sell and manage the optional Pro upgrade: secure checkout, license activation, update delivery and (only if you opt in) anonymous usage diagnostics. On activation you are shown an opt-in screen that you can skip — the free plugin runs fully in anonymous mode and contacts Freemius only when you choose to connect, buy a license, activate one, or check for a Pro update. Data that may then be sent includes your site URL, WordPress/PHP versions, admin email and license key, used to deliver and validate your purchase. Freemius is operated by Freemius, Inc.
Terms: https://freemius.com/terms/ — Privacy policy: https://freemius.com/privacy/
The service and CDN domain names that appear inside the plugin code (for example Google Analytics, Stripe, jQuery/Swiper CDNs) are detection patterns only: they are text the scanner matches against the HTML of your own pages to recognise which third-party scripts a visitor’s browser would load. The plugin never loads, enqueues or connects to any of them.
Payment and captcha hosts (Stripe, PayPal, ePay.bg, BORICA, reCAPTCHA, and the rest of the catalog) are loaded by those providers when a visitor reaches a form or checkout. This plugin does not contact them itself.
Installation
- Upload the
bulgaro-gdprfolder to/wp-content/plugins/. - Activate Bulgaro GDPR from the Plugins screen.
- Open Bulgaro GDPR Settings and set the cookie policy URL.
- Open Bulgaro GDPR WordPress & Payments and confirm the shop’s payment gateways are in the catalog.
- Run Scan Website. Checkout, cart and a product page are included when WooCommerce is active.
Place [bulgaro_consent_settings] on the policy page so visitors can change their choice. Place [bulgaro_cookie_table] to list WordPress, WooCommerce and payment cookies. The “Create Cookie Policy page” button inserts both into a draft.
FAQ
-
Does this block card payments?
-
No. Payment providers are classified as necessary and the script blocker ignores their URLs. ePay.bg, BORICA and NestPay are usually a form post; the scanner reads form actions on the checkout page.
-
Does the plugin phone home?
-
No. There is no license server and no remote call except the scanner reading your own URLs.
-
Is the compliance score a legal guarantee?
-
No. It is a technical configuration score.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Bulgaro GDPR” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Bulgaro GDPR” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.3.0
- New: Pro upgrade powered by Freemius — secure checkout, license activation and automatic Pro-update delivery. The free plugin runs in anonymous mode; the opt-in on activation is optional and skippable.
- Security: premium theme and shape code is now a separate licensed build. The 10 premium themes and 3 premium shapes no longer ship in the free download at all, so there is nothing to unlock without a real license.
- All existing free features are unchanged (5 themes, 2 shapes, banner, script blocker, scanner, payment coverage, consent register).
- readme: documented the Freemius service under “External services”.
1.2.6
- Compliance: inline CSS is now enqueued via the WordPress functions (shared assets/css/public.css); the Google Consent Mode snippet is printed with wp_print_inline_script_tag(); load_plugin_textdomain() removed (WordPress.org auto-loads translations).
- The scanner’s internal catalog no longer stores CDN host names as contiguous strings (they are detection patterns, not loaded resources) to avoid false “remote file” flags. No functional change.
1.2.0
- The premium features (the extra banner themes and shapes, the Custom Scripts Manager, and the Consent Register audit tools) now live entirely in the separate Bulgaro GDPR Pro add-on. The free plugin no longer bundles any locked premium code — it exposes extension points the add-on hooks into. All existing free features are unchanged.
1.1.0
- New: Consent Register admin page — total consents, last-30-days count and the most recent entries (date, accepted categories, policy version). PRO unlocks a searchable log, CSV export for audits, and a configurable retention window.
- PRO: auto-scan alerts can now be sent to a custom list of email addresses (comma-separated); leave it empty to use the site admin email.
- Hardening: the public consent endpoint is now rate-limited per source, a returning visitor updates their own record instead of creating a new row, and a daily maintenance task prunes records past the retention window — the consent table can no longer grow without bound.
- Reliability: the script blocker never emits an empty page if the HTML rewrite hits a PCRE limit on a very large page (falls back to the original HTML).
- Payment safety: inline scripts are matched only by tracker function signatures, and any inline script that references a payment/captcha host is left untouched — a bank/3DS snippet can never be caught by a broad tracker id.
- New detections: Criteo, Adform and Smartlook added to the catalog and the blocking ruleset.
- Admin: minor output-escaping hardening on the settings screen.
1.00.11
- Bug fix: clicking “Create Cookie Policy page” on a site that already has a policy page (slug cookie-policy or politika-za-biskvitki, created by hand or by another tool) no longer creates a duplicate “cookie-policy-2” page — the existing page is found and linked into the banner instead.
1.00.10
- Plugin and author links now point to the real home of the project — supremecommerce.eu (plugin page + author URI), instead of the old placeholder domain.
1.00.09
- The PRO badges on premium themes, shapes and the Custom Scripts Manager now appear only while those features are locked — with an active PRO license (or the owner’s BGDPR_PRO_OWNER key) the settings screen looks native, without upsell labels.
1.00.08
- Scanner page polish: shorter title, last-scan time in a human format (“date, time — X ago”), a staleness hint when the scan is over 14 days old, a collapsible list of the exact scanned URLs, and an explicit green “Clean” state when nothing needs attention. Dashboard: the duplicated “Last scan” line was removed from the checklist (it lives in the score sidebar, now also in human format).
1.00.07
- The scanner now recognizes common UI libraries loaded from public CDNs (Slick Carousel, jQuery, Swiper, Owl Carousel 2) as necessary interface libraries — they no longer appear as unknown services needing manual review. Matching is path-qualified, so generic CDN hosts like cdn.jsdelivr.net are still flagged when they serve anything else.
1.00.06
- The example cookie table on the WordPress & Payments screen is now collapsible, same as the payment provider catalog — the page stays short and tidy.
1.00.05
- WordPress & Payments screen cleaned up: only active cache/optimization plugins are listed, inactive states are neutral gray instead of red, detected payment providers appear in a compact “On this site” block, and the full provider catalog moved into a collapsible section. Fixed the outdated cookie-table description.
1.00.04
- PRO split groundwork: the 10 premium themes, 3 premium shapes and the Custom Scripts Manager are now visible but locked in the free version (server-side enforced). Sites already using a premium shape/theme or saved script snippets keep them working (grandfathered). The future PRO add-on will unlock them via the new bgdpr_is_pro filter.
1.00.03
- Removed the premature “PRO” badges from Automatic Language Detection and Export/Import — both are full free features. PRO badges remain only on the premium themes, premium shapes and the upcoming Custom Scripts Manager.
1.00.02
- The Cookie Policy link now also appears in the Preferences view — after a visitor has consented, the page stays reachable via the floating “Cookies” button (previously the link existed only in the first banner view).
1.00.01
- First stable release — version numbering milestone; functionality identical to 0.10.10.
0.10.10
- Fix: the “Cookie settings” reopen link inside generated Cookie Policy pages now renders in the page’s own language (e.g. “Настройки на бисквитките” in Bulgarian pages) instead of always following the site locale.
0.10.9
- Cookie Policy generator: the technical cookie-inventory table is no longer inserted into the generated page — section 4 now explains the cookie categories in plain language (the [bulgaro_cookie_table] shortcode remains available for sites that want the full table).
- Clean page template: generated pages now render through the plugin’s own template — the site header and navigation stay, but theme footer widget areas and credits (“Archives”, “Categories”, “Designed by …”) never appear, on Divi, Elementor, block (FSE) and classic themes alike. Existing generated pages are migrated automatically.
0.10.8
- The Preferences view is now identical in every banner position on desktop and tablet: float-left and float-right cards widen to the bottom-bar width and show the same 2-column category grid (mobile keeps the single column everywhere).
0.10.7
- Fix: the Bulgarian admin translation file (.mo) was structurally rejected by WordPress’s MO reader (missing hash-table offset), so the BG/EN admin language switcher showed Bulgarian as selected but the panel stayed in English — rebuilt the translation file, Bulgarian now renders correctly.
- Live preview: desktop, tablet and mobile now share the same fixed-size preview window — the mobile view no longer looks cut off.
0.10.6
- Cookie Policy generator: the generated page now renders clean on any platform — no sidebar on Divi, Elementor’s header/footer template when Elementor is active, automatic full-width/no-sidebar template selection on classic and block themes, and comments/pingbacks disabled under the policy text.
0.10.5
- Cookie Policy generator: the page is now published immediately with a clean /cookie-policy/ URL (no more drafts with ?page_id= addresses), follows the clicking admin’s language, contains no guessed company data (clear placeholders instead), has no duplicated in-content title, and is created without a sidebar on Divi-based sites.
0.10.4
- Settings cleanup: the “Hidden” reopen-button option is removed (withdrawing consent must be as easy as giving it) — the “Cookies” pill is now the single, always-on revisit style.
- Settings cleanup: removed the “Cookie lifetime (days)” and “Policy version” fields (fixed 365-day lifetime, policy version is now managed internally; enabling “Require re-consent” bumps it automatically on save).
- Live preview: the Desktop tab now renders the true desktop layout (real 1200px viewport scaled to fit) instead of looking like the mobile view.
- Cookie Policy generator: the “Create Cookie Policy page” button now builds a complete, real policy page (9 sections, EN or BG depending on the site language, cookie table shortcode included), detects existing pages that already contain the consent shortcode, and shows a “View page” link when a policy URL is set.
0.10.3
- Polish: banner icon removed for a cleaner text-first layout; the whole category row in Preferences is clickable (bigger touch target); tighter row spacing; 38px button height; visible keyboard focus on buttons and toggles; mobile safe-area-inset support.
- Fix: an over-specific CSS reset (#bgdpr-banner *) was zeroing the designed paddings/margins inside the banner — the banner now renders with proper spacing on all pages; bottom/top bar widened to 720px so longer translations fit; float-card category list switches to one column to prevent text overlap.
- Removed the “Icon only” reopen-button style — the text pill (“Cookies”) is now the single revisit style, which is also the legally safest option.
0.10.2
- Reopen pill is now text-only (no icon) with a one-word label: “Cookies” translated into all 14 banner languages.
0.10.1
- New banner languages: French, Polish and Czech (14 languages in total).
0.10.0
- WordPress requirements: core and WooCommerce cookies, cache-plugin exclusions, HPOS and checkout blocks already declared.
- Payment coverage for Bulgarian and EU checkouts. Payment scripts are never blocked.
- Scanner reads checkout form actions (ePay.bg, BORICA, NestPay).
- Shortcode
[bulgaro_cookie_table]for the cookie policy page. - Uninstall removes scan data and the admin language preference.
- Tested on WordPress 7.1.
0.9.1
- Consent banner, script blocker, website scanner and compliance score.
