Title: Privacy Drift
Author: Thomas
Published: <strong>September 1, 2026</strong>
Last modified: September 1, 2026

---

Search plugins

![](https://ps.w.org/privacy-drift/assets/banner-772x250.png?rev=3676322)

![](https://ps.w.org/privacy-drift/assets/icon.svg?rev=3676322)

# Privacy Drift

 By [Thomas](https://profiles.wordpress.org/stermole/)

[Download](https://downloads.wordpress.org/plugin/privacy-drift.0.13.10.zip)

 * [Details](https://mfe.wordpress.org/plugins/privacy-drift/#description)
 * [Reviews](https://mfe.wordpress.org/plugins/privacy-drift/#reviews)
 *  [Installation](https://mfe.wordpress.org/plugins/privacy-drift/#installation)
 * [Development](https://mfe.wordpress.org/plugins/privacy-drift/#developers)

 [Support](https://wordpress.org/support/plugin/privacy-drift/)

## Description

Privacy Drift monitors technical privacy changes on WordPress sites and explains
them in plain language.

It helps answer:

 1. Who does my website connect to right now?
 2. Where is that finding used?
 3. What changed since I last reviewed it?
 4. Could this change matter for privacy / GDPR?
 5. What should I do next?
 6. Does a supported cookie/consent banner actually reject optional-looking activity?
 7. Who reviewed or approved a finding, and when?

The browser scan observes runtime requests and browser-visible cookie/storage names
without collecting cookie or storage values. The first scan becomes a trusted baseline;
later scans show added and removed findings.

Privacy Drift is a technical monitoring aid. It is designed to help website administrators
identify privacy-relevant technical changes. It does not create, automate, certify
or guarantee legal compliance.

#### Key features

 * One-click browser scan with visible progress.
 * Trusted baseline and drift detection for added/removed external resources.
 * Plain-language privacy/GDPR risk signals with explicit coverage limits.
 * Consent rejection test for supported and safely detectable cookie banners.
 * Before/after Reject comparison of third-party resources and browser-visible cookie/
   storage names.
 * Known CMP selectors for Complianz, Cookiebot, OneTrust, CookieYes, Usercentrics,
   Real Cookie Banner and Borlabs Cookie, plus a conservative text fallback inside
   clearly identified cookie/consent containers.
 * Unknown or ambiguous banners are reported as unsupported rather than clicked 
   blindly.
 * Findings grouped by service/host and resource type.
 * Source locations for WordPress Pages, Posts and Products where WordPress can 
   resolve the URL.
 * Reversible Mark as Expected decisions.
 * Local Review & Audit Log for review decisions and trusted-baseline approvals.
 * Recent monitoring history with scan-to-scan Added/Removed details.
 * Optional host research with versioned, revocable permission for each administrator.
 * Privacy & Data Flows page with local storage and external-service disclosures.
 * No silent telemetry and no generic force-blocking of third-party resources.

#### Consent rejection test

The rejection test is a technical behaviour check. It loads a fresh page state in
a sandboxed same-site browser frame, searches for a supported or unambiguous consent-
banner Reject/Decline action, captures third-party activity before the choice, clicks
Reject, waits for the page to settle and captures the resulting resources plus browser-
visible cookie/storage names.

Results distinguish external resources observed before Reject, after Reject and 
newly appearing after Reject. Known analytics/advertising services and common analytics/
advertising cookie names receive higher attention.

If Privacy Drift cannot safely identify a Reject action, it reports that limitation
instead of guessing.

A successful rejection test is not a legal GDPR compliance verdict. It is technical
evidence that can reveal obvious consent regressions such as analytics or advertising
activity appearing before or remaining after a rejection action.

#### Privacy and data handling

Privacy Drift follows a local-first approach for its core monitoring features.

 * Scan results, trusted baselines, monitoring history, Expected classifications,
   host-intelligence cache and the review/audit trail are stored in the local WordPress
   database.
 * Each administrator’s first-use scope acknowledgement stores only the disclaimer
   version, activation identifier and acknowledgement timestamp as local WordPress
   user metadata. This acknowledgement is not sent to the Privacy Drift operator.
 * Privacy Drift does not collect or transmit cookie values or browser-storage values.
 * Privacy Drift does not silently send installation identifiers, site URLs, scan
   events, usage telemetry or analytics to the plugin operator.
 * Core scanning and review features do not require a Privacy Drift account or an
   external Privacy Drift service.
 * No host/network lookup is made automatically. Activation, dashboard use and local
   review do not initiate third-party service requests.
 * Server scans request only the configured WordPress site’s origin, including redirects.
   They inspect returned HTML without fetching the third-party resources found in
   it.
 * Browser and consent scans execute the site’s front end. External services already
   embedded by that website can therefore receive requests from the administrator’s
   browser; these are website-originated requests, not Privacy Drift telemetry.
 * Presentation assets are packaged locally. There are no remote fonts, scripts,
   styles, tracking pixels, remote logs or alternate update services supplied by
   Privacy Drift.
 * The Free plugin sends no automated monitoring email and contains no Premium early-
   access mail flow.

Administrators remain responsible for the privacy implications of the WordPress 
site being scanned, including third-party services already configured on that site.

Open Privacy Drift  Privacy & Data Flows for the full storage inventory and RDAP
permission controls. Baseline and latest scan are replaced when approved or scanned
respectively; history and audit log retain up to 100 entries each, Expected classifications
up to 250 entries, and host intelligence up to 100 hosts. The latest consent-test
result and local browser-scan counter are also retained. There is no automatic time-
based expiry. URLs, hostnames, resource types, cookie/storage names, timestamps 
and technical results can be stored; URLs may contain personal information already
present in the inspected website’s paths or query strings. Avoid testing pages containing
sensitive personal data unnecessarily.

Audit events associate actions with a WordPress user ID without copying the user’s
display name into new events. Administrator-linked acknowledgement, onboarding and
RDAP permission metadata are local. WordPress personal-data export includes this
metadata and that user’s audit entries. Erasure removes the metadata and anonymizes
their identity in retained technical audit events, including legacy copied names;
it does not erase unrelated site-wide technical findings. Privacy Drift also supplies
suggested text to the WordPress Privacy Policy Guide for the site operator to review
and adapt.

Temporary administrator view state (scroll position and expanded review/history 
details) uses the browser tab’s sessionStorage under privacyDriftExpectedViewportV1
and privacyDriftHistoryViewportV1. It is removed after restoring the view or when
the tab session ends. It is not telemetry; uninstall cannot clear storage in an 
already open browser tab.

#### External services and explicit data transfers

RDAP.org is the only third-party research service initiated by the Free plugin. 
A Research host action without current permission opens a disclosure before any 
external lookup:

 * RDAP.org provides bootstrap access to public domain and network registration 
   information. After “Allow external lookup”, Privacy Drift sends the selected 
   host’s derived root domain, or the selected IP address if the finding is already
   an IP address. It performs no separate DNS resolution or hidden IP enrichment.
   RDAP.org may redirect to the authoritative registry or regional Internet registry
   RDAP service. The HTTP request necessarily exposes the WordPress server’s public
   IP address and the Privacy Drift version in its User-Agent. Privacy Drift does
   not add the WordPress site URL, administrator identity, account details, scan
   history, page content, or cookie/storage values to the request. The selected 
   domain or IP itself may identify the inspected site or its provider. Official
   usage/rate-limit information: https://about.rdap.org/#how-to-use-rdaporg ; privacy
   considerations: https://about.rdap.org/#privacy-considerations . Authoritative
   RDAP services may have their own notices.
 * Permission is stored per administrator in local user metadata with a consent 
   version and approval timestamp. Cancel, including Escape, sends no RDAP request.
   Later Research host actions by that administrator may use the current permission;
   no background research is scheduled. Revoke permission on Privacy & Data Flows
   to require approval again. Material changes to the data flow require a new consent
   version and renewed approval.

Google, Meta, Stripe, Hotjar, HubSpot, YouTube, Maps and other service signatures
are local classification rules, not requests to those companies.

Automated external notifications and email alerts are not part of the Free version.

#### Security and scope

Administrative mutations use WordPress capability checks and nonces. Browser-scan
targets are restricted to the current WordPress site. Scan frames are sandboxed,
do not permit top-level navigation, and use a no-referrer policy. Host research 
uses WordPress safe HTTP requests and only runs on demand.

Because browser-grade inspection intentionally executes the site’s own front-end
JavaScript to observe runtime behaviour, administrators should only run browser/
consent scans on the WordPress site they intend to inspect. Privacy Drift does not
load arbitrary third-party scan targets in the admin frame.

Privacy Drift deliberately reports uncertainty where a technical result is not sufficient
for a legal conclusion.

#### First-use scope acknowledgement

The first time each WordPress administrator opens Privacy Drift after installation
or reactivation, the plugin displays a blocking scope modal explaining that findings
are technical indicators rather than legal conclusions and that Privacy Drift does
not guarantee regulatory compliance.

The administrator can acknowledge the notice with “Got it — continue”. The acknowledgement
stores only a disclaimer version, activation identifier and UTC timestamp as user
metadata in the local WordPress database. It does not transmit acceptance data, 
identity data or telemetry to the Privacy Drift operator, and it does not waive 
rights that cannot lawfully be waived.

Each activation starts a new local acknowledgement cycle, so every administrator
must review and acknowledge the scope again after the plugin is reactivated. Scan
results, trusted baselines and monitoring history are not removed by deactivation
or by this acknowledgement reset.

#### Support and security contact

For technical support, responsible security reports or questions about Privacy Drift
data handling, contact: wordpress@stermole.at

Security issues should not be published publicly before a reasonable opportunity
to investigate and provide a fix.

### Requirements

 * WordPress 6.4 or newer.
 * PHP 8.0 or newer.
 * A current browser with JavaScript enabled for browser-grade scans and the Consent
   rejection test.
 * WordPress administrator access (`manage_options`) to run scans and review findings.

Privacy Drift is currently tested against WordPress up to version 7.1. Older WordPress
or PHP versions are not supported.

### Uninstallation

Deactivating Privacy Drift stops the plugin but keeps its stored monitoring data
so it can be reactivated later.

To remove Privacy Drift completely:

 1. Go to Plugins  Installed Plugins.
 2. Deactivate Privacy Drift if it is active.
 3. Click Delete for Privacy Drift.

WordPress then runs the plugin’s uninstall routine. Privacy Drift clears its scheduled
monitoring hook and removes its stored baseline, latest scan, monitoring history,
audit log, Expected classifications, browser-scan count, host-intelligence cache,
latest consent-test result, activation-cycle identifier, legacy Premium-waitlist
state, and all plugin-specific first-use, onboarding and RDAP permission user metadata.
On multisite it cleans the options and scheduled hook for every site and removes
the shared plugin user metadata. Deactivation alone retains these records.

If you may want to keep the existing baseline and monitoring history, deactivate
the plugin instead of deleting it.

### Disclaimer

Privacy Drift is a technical monitoring and diagnostic tool intended to assist website
administrators in identifying privacy-relevant technical behaviour and changes. 
It is not legal advice, a legal audit, a certification service, a consent-management
platform, or a guarantee of GDPR, DSGVO, ePrivacy, cookie-consent or other regulatory
compliance.

No plugin can determine or provide complete legal compliance for a website. Legal
obligations depend on the website operator, applicable jurisdiction, purposes and
legal bases of processing, contracts, consent design, third-party services, organisational
measures and facts that a technical browser scan cannot determine.

Privacy Drift can only report technical activity it is able to observe in the tested
WordPress and browser state. Results can be affected by caching, consent-manager
configuration, browser behaviour, conditional loading, logged-in state, geolocation,
network conditions, A/B tests, third-party services and later site changes. A clear
result does not prove that no other privacy-relevant processing exists. A warning
or risk signal does not by itself establish a legal violation.

Website operators remain responsible for reviewing the results, configuring their
website and consent mechanisms correctly, maintaining appropriate privacy notices
and agreements, obtaining professional advice where appropriate, and determining
the legal requirements that apply to their specific website and organisation.

Privacy Drift does not accept responsibility for legal decisions made solely on 
the basis of plugin output. To the extent permitted by applicable law, the software
is provided under GPLv2-or-later without warranty; there is no warranty that the
software will be error-free, uninterrupted, suitable for a particular legal purpose,
or capable of detecting every privacy-relevant change.

The first-use acknowledgement documents that the scope notice was presented and 
acknowledged for that administrator account. It is not a contract replacing applicable
terms, does not constitute legal advice, and does not exclude or limit liability
or statutory rights where such exclusion or limitation is prohibited by applicable
law.

Nothing in this disclaimer excludes or limits liability where such exclusion or 
limitation is prohibited by applicable law.

Privacy Drift is an independent plugin and is not endorsed by, affiliated with, 
or sponsored by the WordPress Foundation or WordPress.org.

## Screenshots

[[

[[

[[

[[

[[

[[

## Installation

 1. In WordPress, go to Plugins  Add New.
 2. Install Privacy Drift from the WordPress Plugin Directory, or upload the `privacy-
    drift.zip` file via Plugins  Add New  Upload Plugin.
 3. Activate Privacy Drift.
 4. Open Privacy Drift from the WordPress admin menu.
 5. Review the first-use scope notice and select “Got it — continue” when you understand
    the stated limitations.
 6. Run the first browser scan. The first successful browser scan becomes the trusted
    baseline used for later drift comparisons.
 7. Review the detected third-party services, cookies/storage names and any technical
    privacy-risk signals.
 8. Run additional scans after relevant site, plugin, theme or consent-manager changes
    to see what changed.

Privacy Drift stores scan and review data locally in the WordPress database. No 
account or external Privacy Drift service is required for the core plugin.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Privacy Drift” is open source software. The following people have contributed to
this plugin.

Contributors

 *   [ Thomas ](https://profiles.wordpress.org/stermole/)

[Translate “Privacy Drift” into your language.](https://translate.wordpress.org/projects/wp-plugins/privacy-drift)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/privacy-drift/), check
out the [SVN repository](https://plugins.svn.wordpress.org/privacy-drift/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/privacy-drift/) 
by [RSS](https://plugins.trac.wordpress.org/log/privacy-drift/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.13.10

 * Removed automated monitoring mail and the Premium early-access mail flow from
   Free.
 * Added per-administrator, versioned and revocable RDAP permission before external
   host research; removed hidden DNS enrichment.
 * Added Privacy & Data Flows, WordPress privacy-policy guidance and administrator-
   data export/erasure, with complete multisite uninstall cleanup.
 * Removed inline presentation code and moved application state and local script
   translations to authenticated same-origin requests.
 * Hardened same-site redirects, response limits, input shapes, accessibility, keyboard
   focus and internationalization.
 * Added pinned coding/static-analysis gates, distributed-package egress checks 
   and observed runtime consent/egress tests.

#### 0.13.9

 * Replaced direct admin CSS and JavaScript output with screen-scoped enqueued assets.
 * Corrected WordPress.org contributor and RDAP service disclosures.
 * Added release-checker regression coverage for direct style and script output.

#### 0.13.8

 * Added CI coverage for the minimum supported WordPress and PHP versions.
 * Hardened WordPress.org release-package validation and RDAP regression tests.

#### 0.13.7

 * Fixed PHP 8.5 deprecation notices in development regression tests while retaining
   PHP 8.0 compatibility.

#### 0.13.6

 * Removed the WordPress site URL from on-demand RDAP request User-Agents.
 * Consolidated host research into a single implementation using the distributed
   plugin version.

#### 0.13.5

 * Removed GET-based first-use acknowledgement status handling to satisfy WordPress
   Plugin Check.
 * Replaced the first-use notice with a local-only blocking modal that matches the
   Privacy Drift dashboard.
 * Required every administrator to acknowledge the scope again after plugin reactivation
   without removing scan or baseline data.
 * Finalized WordPress.org release hardening and package-only Plugin Check validation.

#### 0.13.4

 * Finalized WordPress.org release disclosures, minimum requirements, installation/
   uninstallation guidance and compliance disclaimer.
 * Added a per-administrator first-use scope acknowledgement that is stored only
   in local WordPress user metadata and does not block plugin use or transmit data.
 * Clarified the local-first data model, absence of silent telemetry, on-demand 
   RDAP.org transfer and explicit Premium early-access email data flow.
 * Added a support/security contact and GPL license URI to the plugin metadata.
 * Hardened the WordPress Plugin Check CI path to run the official Plugin Check 
   plugin in a pinned, reproducible Docker environment.

#### 0.13.3

 * Redesigned the dashboard information architecture so actions, informational guidance
   and scan results are visually distinct.
 * Reworked the Consent rejection test into a clearer Test & Protect card with plain-
   language purpose, current status and a visual explanation of why the check matters.
 * Added clearer result/review labels and a direct Review changes action for non-
   clear baseline states.
 * Kept the redesign presentation-only so scan, consent, nonce, capability and persistence
   logic remain unchanged.

#### 0.13.2

 * Prepared the plugin for WordPress.org review with aligned release metadata and
   Tested up to information.
 * Added explicit in-product and readme disclosures for on-demand RDAP.org host 
   research and Premium early-access email submission.
 * Added stricter browser-frame referrer handling and release UI/version cleanup.
 * Added an official WordPress Plugin Check CI gate and marketplace distribution
   exclusions.
 * Expanded release acceptance to lint all PHP/INC files, validate the clean ZIP
   layout and test the current WordPress 7.1 release line.

#### 0.13.1

 * Made GDPR/consent technical risk signals more prominent in the plain-English 
   result summary.
 * Integrated Consent rejection-test outcomes into the risk explanation while retaining
   a clear non-legal disclaimer.

#### 0.13.0

 * Added an automated Consent rejection test for supported and safely detectable
   cookie banners.
 * Added CMP detection for common WordPress/enterprise consent platforms plus a 
   conservative generic Reject/Decline fallback.
 * Added before/after Reject resource comparison and post-Reject cookie/storage-
   name inspection.
 * Added plain-language results for clear, review, unsupported-banner and no-banner
   states.
 * Added a deliberately leaky test CMP fixture and Playwright regression coverage
   proving that analytics cookies remaining after Reject are flagged.

#### 0.12.0

 * Added single-page wp-admin interactions for browser scans, review actions, baseline
   approval, host research, waitlist signup and monitoring pagination.

## Meta

 *  Version **0.13.10**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/privacy-drift/)
 * Tags
 * [analytics](https://mfe.wordpress.org/plugins/tags/analytics/)[GDPR](https://mfe.wordpress.org/plugins/tags/gdpr/)
   [monitoring](https://mfe.wordpress.org/plugins/tags/monitoring/)[privacy](https://mfe.wordpress.org/plugins/tags/privacy/)
 *  [Advanced View](https://mfe.wordpress.org/plugins/privacy-drift/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/privacy-drift/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/privacy-drift/reviews/)

## Contributors

 *   [ Thomas ](https://profiles.wordpress.org/stermole/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/privacy-drift/)