{"id":359921,"date":"2026-09-01T14:31:47","date_gmt":"2026-09-01T14:31:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/privacy-drift\/"},"modified":"2026-09-01T14:31:22","modified_gmt":"2026-09-01T14:31:22","slug":"privacy-drift","status":"publish","type":"plugin","link":"https:\/\/mfe.wordpress.org\/plugins\/privacy-drift\/","author":23554661,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.13.10","stable_tag":"0.13.10","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"Privacy Drift","header_author":"Thomas Stermole","header_description":"See which third-party services your WordPress site loads, spot new ones automatically, and know what changed.","assets_banners_color":"385060","last_updated":"2026-09-01 14:31:22","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":28,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"0.13.10":{"tag":"0.13.10","author":"stermole","date":"2026-09-01 14:31:22","revision":3676322}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3676322,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3676322,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3676322,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3676322,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3676322,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.13.10"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3676322,"resolution":"1","location":"assets","locale":"","width":1440,"height":1000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3676322,"resolution":"2","location":"assets","locale":"","width":1440,"height":1000},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3676322,"resolution":"3","location":"assets","locale":"","width":1440,"height":1000},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3676322,"resolution":"4","location":"assets","locale":"","width":1440,"height":1000},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3676322,"resolution":"5","location":"assets","locale":"","width":1440,"height":1000},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3676322,"resolution":"6","location":"assets","locale":"","width":1440,"height":1000}},"screenshots":[]},"plugin_section":[],"plugin_tags":[232,131785,5603,396,278672],"plugin_category":[36,54],"plugin_contributors":[278673],"plugin_business_model":[],"class_list":["post-359921","plugin","type-plugin","status-publish","hentry","plugin_tags-analytics","plugin_tags-gdpr","plugin_tags-monitoring","plugin_tags-privacy","plugin_tags-third-party-scripts","plugin_category-analytics","plugin_category-security-and-spam-protection","plugin_contributors-stermole","plugin_committers-stermole"],"banners":{"banner":"https:\/\/ps.w.org\/privacy-drift\/assets\/banner-772x250.png?rev=3676322","banner_2x":"https:\/\/ps.w.org\/privacy-drift\/assets\/banner-1544x500.png?rev=3676322","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/privacy-drift\/assets\/icon.svg?rev=3676322","icon":"https:\/\/ps.w.org\/privacy-drift\/assets\/icon.svg?rev=3676322","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-1.png?rev=3676322","caption":""},{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-2.png?rev=3676322","caption":""},{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-3.png?rev=3676322","caption":""},{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-4.png?rev=3676322","caption":""},{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-5.png?rev=3676322","caption":""},{"src":"https:\/\/ps.w.org\/privacy-drift\/assets\/screenshot-6.png?rev=3676322","caption":""}],"raw_content":"<!--section=description-->\n<p>Privacy Drift monitors technical privacy changes on WordPress sites and explains them in plain language.<\/p>\n\n<p>It helps answer:<\/p>\n\n<ol>\n<li>Who does my website connect to right now?<\/li>\n<li>Where is that finding used?<\/li>\n<li>What changed since I last reviewed it?<\/li>\n<li>Could this change matter for privacy \/ GDPR?<\/li>\n<li>What should I do next?<\/li>\n<li>Does a supported cookie\/consent banner actually reject optional-looking activity?<\/li>\n<li>Who reviewed or approved a finding, and when?<\/li>\n<\/ol>\n\n<p>The browser scan observes runtime requests and browser-visible cookie\/storage names without collecting cookie or storage values. The first scan becomes a trusted baseline; later scans show added and removed findings.<\/p>\n\n<p>Privacy Drift is a technical monitoring aid. It is designed to help website administrators identify privacy-relevant technical changes. It does not create, automate, certify or guarantee legal compliance.<\/p>\n\n<h4>Key features<\/h4>\n\n<ul>\n<li>One-click browser scan with visible progress.<\/li>\n<li>Trusted baseline and drift detection for added\/removed external resources.<\/li>\n<li>Plain-language privacy\/GDPR risk signals with explicit coverage limits.<\/li>\n<li>Consent rejection test for supported and safely detectable cookie banners.<\/li>\n<li>Before\/after Reject comparison of third-party resources and browser-visible cookie\/storage names.<\/li>\n<li>Known CMP selectors for Complianz, Cookiebot, OneTrust, CookieYes, Usercentrics, Real Cookie Banner and Borlabs Cookie, plus a conservative text fallback inside clearly identified cookie\/consent containers.<\/li>\n<li>Unknown or ambiguous banners are reported as unsupported rather than clicked blindly.<\/li>\n<li>Findings grouped by service\/host and resource type.<\/li>\n<li>Source locations for WordPress Pages, Posts and Products where WordPress can resolve the URL.<\/li>\n<li>Reversible Mark as Expected decisions.<\/li>\n<li>Local Review &amp; Audit Log for review decisions and trusted-baseline approvals.<\/li>\n<li>Recent monitoring history with scan-to-scan Added\/Removed details.<\/li>\n<li>Optional host research with versioned, revocable permission for each administrator.<\/li>\n<li>Privacy &amp; Data Flows page with local storage and external-service disclosures.<\/li>\n<li>No silent telemetry and no generic force-blocking of third-party resources.<\/li>\n<\/ul>\n\n<h4>Consent rejection test<\/h4>\n\n<p>The rejection test is a technical behaviour check. It loads a fresh page state in a sandboxed same-site browser frame, searches for a supported or unambiguous consent-banner Reject\/Decline action, captures third-party activity before the choice, clicks Reject, waits for the page to settle and captures the resulting resources plus browser-visible cookie\/storage names.<\/p>\n\n<p>Results distinguish external resources observed before Reject, after Reject and newly appearing after Reject. Known analytics\/advertising services and common analytics\/advertising cookie names receive higher attention.<\/p>\n\n<p>If Privacy Drift cannot safely identify a Reject action, it reports that limitation instead of guessing.<\/p>\n\n<p>A successful rejection test is not a legal GDPR compliance verdict. It is technical evidence that can reveal obvious consent regressions such as analytics or advertising activity appearing before or remaining after a rejection action.<\/p>\n\n<h4>Privacy and data handling<\/h4>\n\n<p>Privacy Drift follows a local-first approach for its core monitoring features.<\/p>\n\n<ul>\n<li>Scan results, trusted baselines, monitoring history, Expected classifications, host-intelligence cache and the review\/audit trail are stored in the local WordPress database.<\/li>\n<li>Each administrator's first-use scope acknowledgement stores only the disclaimer version, activation identifier and acknowledgement timestamp as local WordPress user metadata. This acknowledgement is not sent to the Privacy Drift operator.<\/li>\n<li>Privacy Drift does not collect or transmit cookie values or browser-storage values.<\/li>\n<li>Privacy Drift does not silently send installation identifiers, site URLs, scan events, usage telemetry or analytics to the plugin operator.<\/li>\n<li>Core scanning and review features do not require a Privacy Drift account or an external Privacy Drift service.<\/li>\n<li>No host\/network lookup is made automatically. Activation, dashboard use and local review do not initiate third-party service requests.<\/li>\n<li>Server scans request only the configured WordPress site's origin, including redirects. They inspect returned HTML without fetching the third-party resources found in it.<\/li>\n<li>Browser and consent scans execute the site's front end. External services already embedded by that website can therefore receive requests from the administrator's browser; these are website-originated requests, not Privacy Drift telemetry.<\/li>\n<li>Presentation assets are packaged locally. There are no remote fonts, scripts, styles, tracking pixels, remote logs or alternate update services supplied by Privacy Drift.<\/li>\n<li>The Free plugin sends no automated monitoring email and contains no Premium early-access mail flow.<\/li>\n<\/ul>\n\n<p>Administrators remain responsible for the privacy implications of the WordPress site being scanned, including third-party services already configured on that site.<\/p>\n\n<p>Open Privacy Drift \u2192 Privacy &amp; Data Flows for the full storage inventory and RDAP permission controls. Baseline and latest scan are replaced when approved or scanned respectively; history and audit log retain up to 100 entries each, Expected classifications up to 250 entries, and host intelligence up to 100 hosts. The latest consent-test result and local browser-scan counter are also retained. There is no automatic time-based expiry. URLs, hostnames, resource types, cookie\/storage names, timestamps and technical results can be stored; URLs may contain personal information already present in the inspected website's paths or query strings. Avoid testing pages containing sensitive personal data unnecessarily.<\/p>\n\n<p>Audit events associate actions with a WordPress user ID without copying the user's display name into new events. Administrator-linked acknowledgement, onboarding and RDAP permission metadata are local. WordPress personal-data export includes this metadata and that user's audit entries. Erasure removes the metadata and anonymizes their identity in retained technical audit events, including legacy copied names; it does not erase unrelated site-wide technical findings. Privacy Drift also supplies suggested text to the WordPress Privacy Policy Guide for the site operator to review and adapt.<\/p>\n\n<p>Temporary administrator view state (scroll position and expanded review\/history details) uses the browser tab's sessionStorage under privacyDriftExpectedViewportV1 and privacyDriftHistoryViewportV1. It is removed after restoring the view or when the tab session ends. It is not telemetry; uninstall cannot clear storage in an already open browser tab.<\/p>\n\n<h4>External services and explicit data transfers<\/h4>\n\n<p>RDAP.org is the only third-party research service initiated by the Free plugin. A Research host action without current permission opens a disclosure before any external lookup:<\/p>\n\n<ul>\n<li>RDAP.org provides bootstrap access to public domain and network registration information. After \u201cAllow external lookup\u201d, Privacy Drift sends the selected host's derived root domain, or the selected IP address if the finding is already an IP address. It performs no separate DNS resolution or hidden IP enrichment. RDAP.org may redirect to the authoritative registry or regional Internet registry RDAP service. The HTTP request necessarily exposes the WordPress server's public IP address and the Privacy Drift version in its User-Agent. Privacy Drift does not add the WordPress site URL, administrator identity, account details, scan history, page content, or cookie\/storage values to the request. The selected domain or IP itself may identify the inspected site or its provider. Official usage\/rate-limit information: https:\/\/about.rdap.org\/#how-to-use-rdaporg ; privacy considerations: https:\/\/about.rdap.org\/#privacy-considerations . Authoritative RDAP services may have their own notices.<\/li>\n<li>Permission is stored per administrator in local user metadata with a consent version and approval timestamp. Cancel, including Escape, sends no RDAP request. Later Research host actions by that administrator may use the current permission; no background research is scheduled. Revoke permission on Privacy &amp; Data Flows to require approval again. Material changes to the data flow require a new consent version and renewed approval.<\/li>\n<\/ul>\n\n<p>Google, Meta, Stripe, Hotjar, HubSpot, YouTube, Maps and other service signatures are local classification rules, not requests to those companies.<\/p>\n\n<p>Automated external notifications and email alerts are not part of the Free version.<\/p>\n\n<h4>Security and scope<\/h4>\n\n<p>Administrative mutations use WordPress capability checks and nonces. Browser-scan targets are restricted to the current WordPress site. Scan frames are sandboxed, do not permit top-level navigation, and use a no-referrer policy. Host research uses WordPress safe HTTP requests and only runs on demand.<\/p>\n\n<p>Because browser-grade inspection intentionally executes the site's own front-end JavaScript to observe runtime behaviour, administrators should only run browser\/consent scans on the WordPress site they intend to inspect. Privacy Drift does not load arbitrary third-party scan targets in the admin frame.<\/p>\n\n<p>Privacy Drift deliberately reports uncertainty where a technical result is not sufficient for a legal conclusion.<\/p>\n\n<h4>First-use scope acknowledgement<\/h4>\n\n<p>The first time each WordPress administrator opens Privacy Drift after installation or reactivation, the plugin displays a blocking scope modal explaining that findings are technical indicators rather than legal conclusions and that Privacy Drift does not guarantee regulatory compliance.<\/p>\n\n<p>The administrator can acknowledge the notice with \u201cGot it \u2014 continue\u201d. The acknowledgement stores only a disclaimer version, activation identifier and UTC timestamp as user metadata in the local WordPress database. It does not transmit acceptance data, identity data or telemetry to the Privacy Drift operator, and it does not waive rights that cannot lawfully be waived.<\/p>\n\n<p>Each activation starts a new local acknowledgement cycle, so every administrator must review and acknowledge the scope again after the plugin is reactivated. Scan results, trusted baselines and monitoring history are not removed by deactivation or by this acknowledgement reset.<\/p>\n\n<h4>Support and security contact<\/h4>\n\n<p>For technical support, responsible security reports or questions about Privacy Drift data handling, contact: wordpress@stermole.at<\/p>\n\n<p>Security issues should not be published publicly before a reasonable opportunity to investigate and provide a fix.<\/p>\n\n<h3>Requirements<\/h3>\n\n<ul>\n<li>WordPress 6.4 or newer.<\/li>\n<li>PHP 8.0 or newer.<\/li>\n<li>A current browser with JavaScript enabled for browser-grade scans and the Consent rejection test.<\/li>\n<li>WordPress administrator access (<code>manage_options<\/code>) to run scans and review findings.<\/li>\n<\/ul>\n\n<p>Privacy Drift is currently tested against WordPress up to version 7.1. Older WordPress or PHP versions are not supported.<\/p>\n\n<h3>Uninstallation<\/h3>\n\n<p>Deactivating Privacy Drift stops the plugin but keeps its stored monitoring data so it can be reactivated later.<\/p>\n\n<p>To remove Privacy Drift completely:<\/p>\n\n<ol>\n<li>Go to Plugins \u2192 Installed Plugins.<\/li>\n<li>Deactivate Privacy Drift if it is active.<\/li>\n<li>Click Delete for Privacy Drift.<\/li>\n<\/ol>\n\n<p>WordPress then runs the plugin's uninstall routine. Privacy Drift clears its scheduled monitoring hook and removes its stored baseline, latest scan, monitoring history, audit log, Expected classifications, browser-scan count, host-intelligence cache, latest consent-test result, activation-cycle identifier, legacy Premium-waitlist state, and all plugin-specific first-use, onboarding and RDAP permission user metadata. On multisite it cleans the options and scheduled hook for every site and removes the shared plugin user metadata. Deactivation alone retains these records.<\/p>\n\n<p>If you may want to keep the existing baseline and monitoring history, deactivate the plugin instead of deleting it.<\/p>\n\n<h3>Disclaimer<\/h3>\n\n<p>Privacy Drift is a technical monitoring and diagnostic tool intended to assist website administrators in identifying privacy-relevant technical behaviour and changes. It is not legal advice, a legal audit, a certification service, a consent-management platform, or a guarantee of GDPR, DSGVO, ePrivacy, cookie-consent or other regulatory compliance.<\/p>\n\n<p>No plugin can determine or provide complete legal compliance for a website. Legal obligations depend on the website operator, applicable jurisdiction, purposes and legal bases of processing, contracts, consent design, third-party services, organisational measures and facts that a technical browser scan cannot determine.<\/p>\n\n<p>Privacy Drift can only report technical activity it is able to observe in the tested WordPress and browser state. Results can be affected by caching, consent-manager configuration, browser behaviour, conditional loading, logged-in state, geolocation, network conditions, A\/B tests, third-party services and later site changes. A clear result does not prove that no other privacy-relevant processing exists. A warning or risk signal does not by itself establish a legal violation.<\/p>\n\n<p>Website operators remain responsible for reviewing the results, configuring their website and consent mechanisms correctly, maintaining appropriate privacy notices and agreements, obtaining professional advice where appropriate, and determining the legal requirements that apply to their specific website and organisation.<\/p>\n\n<p>Privacy Drift does not accept responsibility for legal decisions made solely on the basis of plugin output. To the extent permitted by applicable law, the software is provided under GPLv2-or-later without warranty; there is no warranty that the software will be error-free, uninterrupted, suitable for a particular legal purpose, or capable of detecting every privacy-relevant change.<\/p>\n\n<p>The first-use acknowledgement documents that the scope notice was presented and acknowledged for that administrator account. It is not a contract replacing applicable terms, does not constitute legal advice, and does not exclude or limit liability or statutory rights where such exclusion or limitation is prohibited by applicable law.<\/p>\n\n<p>Nothing in this disclaimer excludes or limits liability where such exclusion or limitation is prohibited by applicable law.<\/p>\n\n<p>Privacy Drift is an independent plugin and is not endorsed by, affiliated with, or sponsored by the WordPress Foundation or WordPress.org.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In WordPress, go to Plugins \u2192 Add New.<\/li>\n<li>Install Privacy Drift from the WordPress Plugin Directory, or upload the <code>privacy-drift.zip<\/code> file via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate Privacy Drift.<\/li>\n<li>Open Privacy Drift from the WordPress admin menu.<\/li>\n<li>Review the first-use scope notice and select \u201cGot it \u2014 continue\u201d when you understand the stated limitations.<\/li>\n<li>Run the first browser scan. The first successful browser scan becomes the trusted baseline used for later drift comparisons.<\/li>\n<li>Review the detected third-party services, cookies\/storage names and any technical privacy-risk signals.<\/li>\n<li>Run additional scans after relevant site, plugin, theme or consent-manager changes to see what changed.<\/li>\n<\/ol>\n\n<p>Privacy Drift stores scan and review data locally in the WordPress database. No account or external Privacy Drift service is required for the core plugin.<\/p>\n\n<!--section=changelog-->\n<h4>0.13.10<\/h4>\n\n<ul>\n<li>Removed automated monitoring mail and the Premium early-access mail flow from Free.<\/li>\n<li>Added per-administrator, versioned and revocable RDAP permission before external host research; removed hidden DNS enrichment.<\/li>\n<li>Added Privacy &amp; Data Flows, WordPress privacy-policy guidance and administrator-data export\/erasure, with complete multisite uninstall cleanup.<\/li>\n<li>Removed inline presentation code and moved application state and local script translations to authenticated same-origin requests.<\/li>\n<li>Hardened same-site redirects, response limits, input shapes, accessibility, keyboard focus and internationalization.<\/li>\n<li>Added pinned coding\/static-analysis gates, distributed-package egress checks and observed runtime consent\/egress tests.<\/li>\n<\/ul>\n\n<h4>0.13.9<\/h4>\n\n<ul>\n<li>Replaced direct admin CSS and JavaScript output with screen-scoped enqueued assets.<\/li>\n<li>Corrected WordPress.org contributor and RDAP service disclosures.<\/li>\n<li>Added release-checker regression coverage for direct style and script output.<\/li>\n<\/ul>\n\n<h4>0.13.8<\/h4>\n\n<ul>\n<li>Added CI coverage for the minimum supported WordPress and PHP versions.<\/li>\n<li>Hardened WordPress.org release-package validation and RDAP regression tests.<\/li>\n<\/ul>\n\n<h4>0.13.7<\/h4>\n\n<ul>\n<li>Fixed PHP 8.5 deprecation notices in development regression tests while retaining PHP 8.0 compatibility.<\/li>\n<\/ul>\n\n<h4>0.13.6<\/h4>\n\n<ul>\n<li>Removed the WordPress site URL from on-demand RDAP request User-Agents.<\/li>\n<li>Consolidated host research into a single implementation using the distributed plugin version.<\/li>\n<\/ul>\n\n<h4>0.13.5<\/h4>\n\n<ul>\n<li>Removed GET-based first-use acknowledgement status handling to satisfy WordPress Plugin Check.<\/li>\n<li>Replaced the first-use notice with a local-only blocking modal that matches the Privacy Drift dashboard.<\/li>\n<li>Required every administrator to acknowledge the scope again after plugin reactivation without removing scan or baseline data.<\/li>\n<li>Finalized WordPress.org release hardening and package-only Plugin Check validation.<\/li>\n<\/ul>\n\n<h4>0.13.4<\/h4>\n\n<ul>\n<li>Finalized WordPress.org release disclosures, minimum requirements, installation\/uninstallation guidance and compliance disclaimer.<\/li>\n<li>Added a per-administrator first-use scope acknowledgement that is stored only in local WordPress user metadata and does not block plugin use or transmit data.<\/li>\n<li>Clarified the local-first data model, absence of silent telemetry, on-demand RDAP.org transfer and explicit Premium early-access email data flow.<\/li>\n<li>Added a support\/security contact and GPL license URI to the plugin metadata.<\/li>\n<li>Hardened the WordPress Plugin Check CI path to run the official Plugin Check plugin in a pinned, reproducible Docker environment.<\/li>\n<\/ul>\n\n<h4>0.13.3<\/h4>\n\n<ul>\n<li>Redesigned the dashboard information architecture so actions, informational guidance and scan results are visually distinct.<\/li>\n<li>Reworked the Consent rejection test into a clearer Test &amp; Protect card with plain-language purpose, current status and a visual explanation of why the check matters.<\/li>\n<li>Added clearer result\/review labels and a direct Review changes action for non-clear baseline states.<\/li>\n<li>Kept the redesign presentation-only so scan, consent, nonce, capability and persistence logic remain unchanged.<\/li>\n<\/ul>\n\n<h4>0.13.2<\/h4>\n\n<ul>\n<li>Prepared the plugin for WordPress.org review with aligned release metadata and Tested up to information.<\/li>\n<li>Added explicit in-product and readme disclosures for on-demand RDAP.org host research and Premium early-access email submission.<\/li>\n<li>Added stricter browser-frame referrer handling and release UI\/version cleanup.<\/li>\n<li>Added an official WordPress Plugin Check CI gate and marketplace distribution exclusions.<\/li>\n<li>Expanded release acceptance to lint all PHP\/INC files, validate the clean ZIP layout and test the current WordPress 7.1 release line.<\/li>\n<\/ul>\n\n<h4>0.13.1<\/h4>\n\n<ul>\n<li>Made GDPR\/consent technical risk signals more prominent in the plain-English result summary.<\/li>\n<li>Integrated Consent rejection-test outcomes into the risk explanation while retaining a clear non-legal disclaimer.<\/li>\n<\/ul>\n\n<h4>0.13.0<\/h4>\n\n<ul>\n<li>Added an automated Consent rejection test for supported and safely detectable cookie banners.<\/li>\n<li>Added CMP detection for common WordPress\/enterprise consent platforms plus a conservative generic Reject\/Decline fallback.<\/li>\n<li>Added before\/after Reject resource comparison and post-Reject cookie\/storage-name inspection.<\/li>\n<li>Added plain-language results for clear, review, unsupported-banner and no-banner states.<\/li>\n<li>Added a deliberately leaky test CMP fixture and Playwright regression coverage proving that analytics cookies remaining after Reject are flagged.<\/li>\n<\/ul>\n\n<h4>0.12.0<\/h4>\n\n<ul>\n<li>Added single-page wp-admin interactions for browser scans, review actions, baseline approval, host research, waitlist signup and monitoring pagination.<\/li>\n<\/ul>","raw_excerpt":"Detect privacy drift, find new third-party connections, and test whether optional-looking tracking remains after \u201cReject all\u201d.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/359921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=359921"}],"author":[{"embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/stermole"}],"wp:attachment":[{"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=359921"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=359921"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=359921"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=359921"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=359921"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mfe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=359921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}