Title: Bulgaro GDPR
Author: supremecommerce
Published: <strong>October 7, 2026</strong>
Last modified: October 7, 2026

---

Search plugins

![](https://ps.w.org/bulgaro-gdpr/assets/banner-772x250.png?rev=3733015)

![](https://ps.w.org/bulgaro-gdpr/assets/icon-256x256.png?rev=3733015)

# Bulgaro GDPR

 By [supremecommerce](https://profiles.wordpress.org/supremecommerce/)

[Download](https://downloads.wordpress.org/plugin/bulgaro-gdpr.1.3.0.zip)

 * [Details](https://pcd.wordpress.org/plugins/bulgaro-gdpr/#description)
 * [Reviews](https://pcd.wordpress.org/plugins/bulgaro-gdpr/#reviews)
 *  [Installation](https://pcd.wordpress.org/plugins/bulgaro-gdpr/#installation)
 * [Development](https://pcd.wordpress.org/plugins/bulgaro-gdpr/#developers)

 [Support](https://wordpress.org/support/plugin/bulgaro-gdpr/)

## Description

Bulgaro GDPR adds a GDPR cookie consent banner (cookie notice) to your WordPress
site: it blocks analytics and marketing scripts until the visitor agrees, records
every consent, and never breaks checkout.

The free plugin includes:

 * A cookie consent banner with Accept, Necessary only, and category preferences—
   14 languages or automatic browser detection
 * Consent management with records stored as a pseudonymous SHA-256 id (no IP address)—
   GDPR and ePrivacy friendly
 * Automatic blocking for known trackers (GA4, GTM, Meta Pixel, and others)
 * Google Consent Mode v2
 * A scanner that stays on your server
 * Coverage for WordPress core cookies, WooCommerce, and payment providers
 * A Consent Register showing how many consents were recorded and the most recent
   entries

Payment scripts are detected and never blocked, so checkout can finish. Covered 
providers include Stripe, PayPal, WooPayments, ePay.bg, BORICA, myPOS, EasyPay, 
Paysera, Revolut Pay, Mollie, Klarna, Adyen, Square, Braintree, Amazon Pay, Google
Pay, Razorpay, PayU, 2Checkout, iCard, TBI Bank and NestPay virtual POS.

The admin screens are available in English and Bulgarian.

#### Bulgaro GDPR Pro

Bulgaro GDPR Pro is an optional paid add-on that adds:

 * 10 extra banner color themes (15 in total) and 3 extra banner shapes
 * Custom Scripts Manager — inject your own functional, analytics and marketing 
   snippets, each fired only after the visitor consents to that category
 * Consent Register audit tools — CSV export for audits and a configurable retention
   window
 * A daily automatic website scan with an email alert when a new third-party tracking
   service appears

The free plugin is fully functional on its own; the add-on only adds the extras 
above. Learn more: https://supremecommerce.eu/bulgaro-gdpr/

#### External services

The core GDPR features — cookie banner, script blocker, scanner and payment coverage—
work entirely on your own server and send no data anywhere. The only same-domain
requests are from the built-in Website Scanner, which reads pages on your OWN site(
same domain) with the user agent `BulgaroGDPR-Scanner`, and only when you start 
a scan from the admin. No visitor data is ever sent off your site.

Freemius (payments and licensing). The plugin uses the Freemius service to sell 
and manage the optional Pro upgrade: secure checkout, license activation, update
delivery and (only if you opt in) anonymous usage diagnostics. On activation you
are shown an opt-in screen that you can skip — the free plugin runs fully in anonymous
mode and contacts Freemius only when you choose to connect, buy a license, activate
one, or check for a Pro update. Data that may then be sent includes your site URL,
WordPress/PHP versions, admin email and license key, used to deliver and validate
your purchase. Freemius is operated by Freemius, Inc.
 Terms: https://freemius.com/
terms/ — Privacy policy: https://freemius.com/privacy/

The service and CDN domain names that appear inside the plugin code (for example
Google Analytics, Stripe, jQuery/Swiper CDNs) are detection patterns only: they 
are text the scanner matches against the HTML of your own pages to recognise which
third-party scripts a visitor’s browser would load. The plugin never loads, enqueues
or connects to any of them.

Payment and captcha hosts (Stripe, PayPal, ePay.bg, BORICA, reCAPTCHA, and the rest
of the catalog) are loaded by those providers when a visitor reaches a form or checkout.
This plugin does not contact them itself.

## Installation

 1. Upload the `bulgaro-gdpr` folder to `/wp-content/plugins/`.
 2. Activate Bulgaro GDPR from the Plugins screen.
 3. Open Bulgaro GDPR  Settings and set the cookie policy URL.
 4. Open Bulgaro GDPR  WordPress & Payments and confirm the shop’s payment gateways
    are in the catalog.
 5. Run Scan Website. Checkout, cart and a product page are included when WooCommerce
    is active.

Place `[bulgaro_consent_settings]` on the policy page so visitors can change their
choice. Place `[bulgaro_cookie_table]` to list WordPress, WooCommerce and payment
cookies. The “Create Cookie Policy page” button inserts both into a draft.

## FAQ

### Does this block card payments?

No. Payment providers are classified as necessary and the script blocker ignores
their URLs. ePay.bg, BORICA and NestPay are usually a form post; the scanner reads
form actions on the checkout page.

### Does the plugin phone home?

No. There is no license server and no remote call except the scanner reading your
own URLs.

### Is the compliance score a legal guarantee?

No. It is a technical configuration score.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Bulgaro GDPR” is open source software. The following people have contributed to
this plugin.

Contributors

 *   [ supremecommerce ](https://profiles.wordpress.org/supremecommerce/)
 *   [ Freemius ](https://profiles.wordpress.org/freemius/)

[Translate “Bulgaro GDPR” into your language.](https://translate.wordpress.org/projects/wp-plugins/bulgaro-gdpr)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/bulgaro-gdpr/), check
out the [SVN repository](https://plugins.svn.wordpress.org/bulgaro-gdpr/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/bulgaro-gdpr/) by
[RSS](https://plugins.trac.wordpress.org/log/bulgaro-gdpr/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.3.0

 * New: Pro upgrade powered by Freemius — secure checkout, license activation and
   automatic Pro-update delivery. The free plugin runs in anonymous mode; the opt-
   in on activation is optional and skippable.
 * Security: premium theme and shape code is now a separate licensed build. The 
   10 premium themes and 3 premium shapes no longer ship in the free download at
   all, so there is nothing to unlock without a real license.
 * All existing free features are unchanged (5 themes, 2 shapes, banner, script 
   blocker, scanner, payment coverage, consent register).
 * readme: documented the Freemius service under “External services”.

#### 1.2.6

 * Compliance: inline CSS is now enqueued via the WordPress functions (shared assets/
   css/public.css); the Google Consent Mode snippet is printed with wp_print_inline_script_tag();
   load_plugin_textdomain() removed (WordPress.org auto-loads translations).
 * The scanner’s internal catalog no longer stores CDN host names as contiguous 
   strings (they are detection patterns, not loaded resources) to avoid false “remote
   file” flags. No functional change.

#### 1.2.0

 * The premium features (the extra banner themes and shapes, the Custom Scripts 
   Manager, and the Consent Register audit tools) now live entirely in the separate
   Bulgaro GDPR Pro add-on. The free plugin no longer bundles any locked premium
   code — it exposes extension points the add-on hooks into. All existing free features
   are unchanged.

#### 1.1.0

 * New: Consent Register admin page — total consents, last-30-days count and the
   most recent entries (date, accepted categories, policy version). PRO unlocks 
   a searchable log, CSV export for audits, and a configurable retention window.
 * PRO: auto-scan alerts can now be sent to a custom list of email addresses (comma-
   separated); leave it empty to use the site admin email.
 * Hardening: the public consent endpoint is now rate-limited per source, a returning
   visitor updates their own record instead of creating a new row, and a daily maintenance
   task prunes records past the retention window — the consent table can no longer
   grow without bound.
 * Reliability: the script blocker never emits an empty page if the HTML rewrite
   hits a PCRE limit on a very large page (falls back to the original HTML).
 * Payment safety: inline scripts are matched only by tracker function signatures,
   and any inline script that references a payment/captcha host is left untouched—
   a bank/3DS snippet can never be caught by a broad tracker id.
 * New detections: Criteo, Adform and Smartlook added to the catalog and the blocking
   ruleset.
 * Admin: minor output-escaping hardening on the settings screen.

#### 1.00.11

 * Bug fix: clicking “Create Cookie Policy page” on a site that already has a policy
   page (slug cookie-policy or politika-za-biskvitki, created by hand or by another
   tool) no longer creates a duplicate “cookie-policy-2” page — the existing page
   is found and linked into the banner instead.

#### 1.00.10

 * Plugin and author links now point to the real home of the project — supremecommerce.
   eu (plugin page + author URI), instead of the old placeholder domain.

#### 1.00.09

 * The PRO badges on premium themes, shapes and the Custom Scripts Manager now appear
   only while those features are locked — with an active PRO license (or the owner’s
   BGDPR_PRO_OWNER key) the settings screen looks native, without upsell labels.

#### 1.00.08

 * Scanner page polish: shorter title, last-scan time in a human format (“date, 
   time — X ago”), a staleness hint when the scan is over 14 days old, a collapsible
   list of the exact scanned URLs, and an explicit green “Clean” state when nothing
   needs attention. Dashboard: the duplicated “Last scan” line was removed from 
   the checklist (it lives in the score sidebar, now also in human format).

#### 1.00.07

 * The scanner now recognizes common UI libraries loaded from public CDNs (Slick
   Carousel, jQuery, Swiper, Owl Carousel 2) as necessary interface libraries — 
   they no longer appear as unknown services needing manual review. Matching is 
   path-qualified, so generic CDN hosts like cdn.jsdelivr.net are still flagged 
   when they serve anything else.

#### 1.00.06

 * The example cookie table on the WordPress & Payments screen is now collapsible,
   same as the payment provider catalog — the page stays short and tidy.

#### 1.00.05

 * WordPress & Payments screen cleaned up: only active cache/optimization plugins
   are listed, inactive states are neutral gray instead of red, detected payment
   providers appear in a compact “On this site” block, and the full provider catalog
   moved into a collapsible section. Fixed the outdated cookie-table description.

#### 1.00.04

 * PRO split groundwork: the 10 premium themes, 3 premium shapes and the Custom 
   Scripts Manager are now visible but locked in the free version (server-side enforced).
   Sites already using a premium shape/theme or saved script snippets keep them 
   working (grandfathered). The future PRO add-on will unlock them via the new bgdpr_is_pro
   filter.

#### 1.00.03

 * Removed the premature “PRO” badges from Automatic Language Detection and Export/
   Import — both are full free features. PRO badges remain only on the premium themes,
   premium shapes and the upcoming Custom Scripts Manager.

#### 1.00.02

 * The Cookie Policy link now also appears in the Preferences view — after a visitor
   has consented, the page stays reachable via the floating “Cookies” button (previously
   the link existed only in the first banner view).

#### 1.00.01

 * First stable release — version numbering milestone; functionality identical to
   0.10.10.

#### 0.10.10

 * Fix: the “Cookie settings” reopen link inside generated Cookie Policy pages now
   renders in the page’s own language (e.g. “Настройки на бисквитките” in Bulgarian
   pages) instead of always following the site locale.

#### 0.10.9

 * Cookie Policy generator: the technical cookie-inventory table is no longer inserted
   into the generated page — section 4 now explains the cookie categories in plain
   language (the [bulgaro_cookie_table] shortcode remains available for sites that
   want the full table).
 * Clean page template: generated pages now render through the plugin’s own template—
   the site header and navigation stay, but theme footer widget areas and credits(“
   Archives”, “Categories”, “Designed by …”) never appear, on Divi, Elementor, block(
   FSE) and classic themes alike. Existing generated pages are migrated automatically.

#### 0.10.8

 * The Preferences view is now identical in every banner position on desktop and
   tablet: float-left and float-right cards widen to the bottom-bar width and show
   the same 2-column category grid (mobile keeps the single column everywhere).

#### 0.10.7

 * Fix: the Bulgarian admin translation file (.mo) was structurally rejected by 
   WordPress’s MO reader (missing hash-table offset), so the BG/EN admin language
   switcher showed Bulgarian as selected but the panel stayed in English — rebuilt
   the translation file, Bulgarian now renders correctly.
 * Live preview: desktop, tablet and mobile now share the same fixed-size preview
   window — the mobile view no longer looks cut off.

#### 0.10.6

 * Cookie Policy generator: the generated page now renders clean on any platform—
   no sidebar on Divi, Elementor’s header/footer template when Elementor is active,
   automatic full-width/no-sidebar template selection on classic and block themes,
   and comments/pingbacks disabled under the policy text.

#### 0.10.5

 * Cookie Policy generator: the page is now published immediately with a clean /
   cookie-policy/ URL (no more drafts with ?page_id= addresses), follows the clicking
   admin’s language, contains no guessed company data (clear placeholders instead),
   has no duplicated in-content title, and is created without a sidebar on Divi-
   based sites.

#### 0.10.4

 * Settings cleanup: the “Hidden” reopen-button option is removed (withdrawing consent
   must be as easy as giving it) — the “Cookies” pill is now the single, always-
   on revisit style.
 * Settings cleanup: removed the “Cookie lifetime (days)” and “Policy version” fields(
   fixed 365-day lifetime, policy version is now managed internally; enabling “Require
   re-consent” bumps it automatically on save).
 * Live preview: the Desktop tab now renders the true desktop layout (real 1200px
   viewport scaled to fit) instead of looking like the mobile view.
 * Cookie Policy generator: the “Create Cookie Policy page” button now builds a 
   complete, real policy page (9 sections, EN or BG depending on the site language,
   cookie table shortcode included), detects existing pages that already contain
   the consent shortcode, and shows a “View page” link when a policy URL is set.

#### 0.10.3

 * Polish: banner icon removed for a cleaner text-first layout; the whole category
   row in Preferences is clickable (bigger touch target); tighter row spacing; 38px
   button height; visible keyboard focus on buttons and toggles; mobile safe-area-
   inset support.
 * Fix: an over-specific CSS reset (#bgdpr-banner *) was zeroing the designed paddings/
   margins inside the banner — the banner now renders with proper spacing on all
   pages; bottom/top bar widened to 720px so longer translations fit; float-card
   category list switches to one column to prevent text overlap.
 * Removed the “Icon only” reopen-button style — the text pill (“Cookies”) is now
   the single revisit style, which is also the legally safest option.

#### 0.10.2

 * Reopen pill is now text-only (no icon) with a one-word label: “Cookies” translated
   into all 14 banner languages.

#### 0.10.1

 * New banner languages: French, Polish and Czech (14 languages in total).

#### 0.10.0

 * WordPress requirements: core and WooCommerce cookies, cache-plugin exclusions,
   HPOS and checkout blocks already declared.
 * Payment coverage for Bulgarian and EU checkouts. Payment scripts are never blocked.
 * Scanner reads checkout form actions (ePay.bg, BORICA, NestPay).
 * Shortcode `[bulgaro_cookie_table]` for the cookie policy page.
 * Uninstall removes scan data and the admin language preference.
 * Tested on WordPress 7.1.

#### 0.9.1

 * Consent banner, script blocker, website scanner and compliance score.

## Meta

 *  Version **1.3.0**
 *  Last updated **9 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/bulgaro-gdpr/)
 * Tags
 * [cookie banner](https://pcd.wordpress.org/plugins/tags/cookie-banner/)[cookie consent](https://pcd.wordpress.org/plugins/tags/cookie-consent/)
   [GDPR](https://pcd.wordpress.org/plugins/tags/gdpr/)[google consent mode](https://pcd.wordpress.org/plugins/tags/google-consent-mode/)
   [woocommerce](https://pcd.wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://pcd.wordpress.org/plugins/bulgaro-gdpr/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/bulgaro-gdpr/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/bulgaro-gdpr/reviews/)

## Contributors

 *   [ supremecommerce ](https://profiles.wordpress.org/supremecommerce/)
 *   [ Freemius ](https://profiles.wordpress.org/freemius/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/bulgaro-gdpr/)