Privacy Drift

Description

WordPress changes constantly. A plugin, theme, embed, tag-manager configuration, analytics setting or consent-manager update can silently add a third-party request or change what happens after a visitor selects Reject — while the website and cookie banner still look normal.

Privacy Drift establishes a trusted technical baseline for your WordPress site. Run another browser scan after an update or site change and Privacy Drift shows which external resources were Added or Removed, helping you find privacy regressions that might otherwise go unnoticed.

This is not another cookie banner or cookie-list generator. Third-party requests and browser-visible cookie or storage names are evidence used to monitor change. Privacy Drift does not manage consent, block trackers or decide whether observed activity is legally permitted.

Why Privacy Drift?

  • Detect added or removed external resources since the trusted baseline.
  • See browser-visible cookie, local-storage and session-storage names without collecting their values.
  • Test supported or safely detectable consent banners and inspect observed activity after Reject.
  • Review findings and reversibly mark expected changes.
  • Keep a local history and audit trail of scan changes, review decisions and trusted-baseline approvals.

A typical use case

  1. Install and activate Privacy Drift.
  2. Run the first browser scan.
  3. Use that first successful browser scan as the trusted baseline.
  4. Update WordPress, a plugin, theme, embed, analytics or tag-manager configuration, or consent manager.
  5. Manually run another browser scan.
  6. Review the Added and Removed findings against the trusted baseline.
  7. When relevant, run the Consent rejection test and document the result in your review process.

WordPress updates do not trigger an automatic browser scan or Consent rejection test. The Free plugin sends no monitoring email alerts.

What Privacy Drift observes

Depending on the scan and page state, Privacy Drift can record:

  • External resource activity visible to the browser scan, including resource entries and script URLs.
  • Browser-visible cookie names and local/session-storage names, but not their values.
  • Local classifications for known services and hosts.
  • Added and Removed resources compared with the trusted baseline.
  • Technical observations before and after a supported or safely detectable Reject action.

Browser results depend on the tested page state, caching, consent configuration, browser behaviour, conditional loading and other runtime conditions. They are technical evidence, not an exhaustive inventory of all processing.

Consent rejection test

The rejection test is a technical behaviour check. It loads a fresh page state in a sandboxed same-site browser frame, searches for a supported or unambiguous consent-banner Reject/Decline action, captures third-party activity before the choice, triggers Reject, waits for the page to settle and captures the resulting resources plus browser-visible cookie/storage names.

Privacy Drift includes known Reject selectors for Complianz, Cookiebot, OneTrust, CookieYes, Usercentrics, Real Cookie Banner and Borlabs Cookie. It also has a conservative text fallback inside clearly identified cookie/consent containers.

Results distinguish external resources observed before Reject, after Reject and newly appearing after Reject. Known analytics/advertising services and common analytics/advertising cookie names receive higher attention.

If Privacy Drift cannot safely identify a Reject action, it reports that limitation instead of guessing.

A successful rejection test is not a legal GDPR compliance verdict. It is technical evidence that can reveal obvious consent regressions such as analytics or advertising activity appearing before or remaining after a rejection action.

Local-first by design

Core scan results, trusted baselines, history, Expected classifications and audit events remain in the local WordPress database. No Privacy Drift account is required for core functionality, and the plugin sends no silent usage telemetry to its operator. Cookie and browser-storage values are not collected. Optional RDAP.org host research is a separate external data flow that requires explicit, versioned and revocable permission from each administrator.

See Privacy Drift Privacy & Data Flows and the detailed sections below for the complete storage, retention and external-service disclosures.

What Privacy Drift is not

Privacy Drift is not a cookie banner, consent-management platform, generic tracker blocker, legal adviser, GDPR certification tool or guarantee of compliance.

Privacy and data handling

Privacy Drift follows a local-first approach for its core monitoring features.

  • Scan results, trusted baselines, monitoring history, Expected classifications, host-intelligence cache and the review/audit trail are stored in the local WordPress database.
  • Each administrator’s first-use scope acknowledgement stores only the disclaimer version, activation identifier and acknowledgement timestamp as local WordPress user metadata. This acknowledgement is not sent to the Privacy Drift operator.
  • Privacy Drift does not collect or transmit cookie values or browser-storage values.
  • Privacy Drift does not silently send installation identifiers, site URLs, scan events, usage telemetry or analytics to the plugin operator.
  • Core scanning and review features do not require a Privacy Drift account or an external Privacy Drift service.
  • No host/network lookup is made automatically. Activation, dashboard use and local review do not initiate third-party service requests.
  • Server scans request only the configured WordPress site’s origin, including redirects. They inspect returned HTML without fetching the third-party resources found in it.
  • Browser and consent scans execute the site’s front end. External services already embedded by that website can therefore receive requests from the administrator’s browser; these are website-originated requests, not Privacy Drift telemetry.
  • Presentation assets are packaged locally. There are no remote fonts, scripts, styles, tracking pixels, remote logs or alternate update services supplied by Privacy Drift.
  • The Free plugin sends no automated monitoring email and contains no Premium early-access mail flow.

Administrators remain responsible for the privacy implications of the WordPress site being scanned, including third-party services already configured on that site.

Open Privacy Drift Privacy & Data Flows for the full storage inventory and RDAP permission controls. Baseline and latest scan are replaced when approved or scanned respectively; history and audit log retain up to 100 entries each, Expected classifications up to 250 entries, and host intelligence up to 100 hosts. The latest consent-test result and local browser-scan counter are also retained. There is no automatic time-based expiry. URLs, hostnames, resource types, cookie/storage names, timestamps and technical results can be stored; URLs may contain personal information already present in the inspected website’s paths or query strings. Avoid testing pages containing sensitive personal data unnecessarily.

Audit events associate actions with a WordPress user ID without copying the user’s display name into new events. Administrator-linked acknowledgement, onboarding and RDAP permission metadata are local. WordPress personal-data export includes this metadata and that user’s audit entries. Erasure removes the metadata and anonymizes their identity in retained technical audit events, including legacy copied names; it does not erase unrelated site-wide technical findings. Privacy Drift also supplies suggested text to the WordPress Privacy Policy Guide for the site operator to review and adapt.

Temporary administrator view state (scroll position and expanded review/history details) uses the browser tab’s sessionStorage under privacyDriftExpectedViewportV1 and privacyDriftHistoryViewportV1. It is removed after restoring the view or when the tab session ends. It is not telemetry; uninstall cannot clear storage in an already open browser tab.

External services and explicit data transfers

RDAP.org is the only third-party research service initiated by the Free plugin. A Research host action without current permission opens a disclosure before any external lookup:

  • RDAP.org provides bootstrap access to public domain and network registration information. After “Allow external lookup”, Privacy Drift sends the selected host’s derived root domain, or the selected IP address if the finding is already an IP address. It performs no separate DNS resolution or hidden IP enrichment. RDAP.org may redirect to the authoritative registry or regional Internet registry RDAP service. The HTTP request necessarily exposes the WordPress server’s public IP address and the Privacy Drift version in its User-Agent. Privacy Drift does not add the WordPress site URL, administrator identity, account details, scan history, page content, or cookie/storage values to the request. The selected domain or IP itself may identify the inspected site or its provider. Official usage/rate-limit information: https://about.rdap.org/#how-to-use-rdaporg ; privacy considerations: https://about.rdap.org/#privacy-considerations . Authoritative RDAP services may have their own notices.
  • Permission is stored per administrator in local user metadata with a consent version and approval timestamp. Cancel, including Escape, sends no RDAP request. Later Research host actions by that administrator may use the current permission; no background research is scheduled. Revoke permission on Privacy & Data Flows to require approval again. Material changes to the data flow require a new consent version and renewed approval.

Google, Meta, Stripe, Hotjar, HubSpot, YouTube, Maps and other service signatures are local classification rules, not requests to those companies.

Automated external notifications and email alerts are not part of the Free version.

Security and scope

Administrative mutations use WordPress capability checks and nonces. Browser-scan targets are restricted to the current WordPress site. Scan frames are sandboxed, do not permit top-level navigation, and use a no-referrer policy. Host research uses WordPress safe HTTP requests and only runs on demand.

Because browser-grade inspection intentionally executes the site’s own front-end JavaScript to observe runtime behaviour, administrators should only run browser/consent scans on the WordPress site they intend to inspect. Privacy Drift does not load arbitrary third-party scan targets in the admin frame.

Privacy Drift deliberately reports uncertainty where a technical result is not sufficient for a legal conclusion.

First-use scope acknowledgement

The first time each WordPress administrator opens Privacy Drift after installation or reactivation, the plugin displays a blocking scope modal explaining that findings are technical indicators rather than legal conclusions and that Privacy Drift does not guarantee regulatory compliance.

The administrator can acknowledge the notice with “Got it — continue”. The acknowledgement stores only a disclaimer version, activation identifier and UTC timestamp as user metadata in the local WordPress database. It does not transmit acceptance data, identity data or telemetry to the Privacy Drift operator, and it does not waive rights that cannot lawfully be waived.

Each activation starts a new local acknowledgement cycle, so every administrator must review and acknowledge the scope again after the plugin is reactivated. Scan results, trusted baselines and monitoring history are not removed by deactivation or by this acknowledgement reset.

Support and security contact

For technical support, responsible security reports or questions about Privacy Drift data handling, contact: wordpress@stermole.at

Security issues should not be published publicly before a reasonable opportunity to investigate and provide a fix.

Requirements

  • WordPress 6.4 or newer.
  • PHP 8.0 or newer.
  • A current browser with JavaScript enabled for browser-grade scans and the Consent rejection test.
  • WordPress administrator access (manage_options) to run scans and review findings.

Privacy Drift is currently tested against WordPress up to version 7.1. Older WordPress or PHP versions are not supported.

Uninstallation

Deactivating Privacy Drift stops the plugin but keeps its stored monitoring data so it can be reactivated later.

To remove Privacy Drift completely:

  1. Go to Plugins Installed Plugins.
  2. Deactivate Privacy Drift if it is active.
  3. Click Delete for Privacy Drift.

WordPress then runs the plugin’s uninstall routine. Privacy Drift clears its scheduled monitoring hook and removes its stored baseline, latest scan, monitoring history, audit log, Expected classifications, browser-scan count, host-intelligence cache, latest consent-test result, activation-cycle identifier, legacy Premium-waitlist state, and all plugin-specific first-use, onboarding and RDAP permission user metadata. On multisite it cleans the options and scheduled hook for every site and removes the shared plugin user metadata. Deactivation alone retains these records.

If you may want to keep the existing baseline and monitoring history, deactivate the plugin instead of deleting it.

Disclaimer

Privacy Drift is a technical monitoring and diagnostic tool intended to assist website administrators in identifying privacy-relevant technical behaviour and changes. It is not legal advice, a legal audit, a certification service, a consent-management platform, or a guarantee of GDPR, DSGVO, ePrivacy, cookie-consent or other regulatory compliance.

No plugin can determine or provide complete legal compliance for a website. Legal obligations depend on the website operator, applicable jurisdiction, purposes and legal bases of processing, contracts, consent design, third-party services, organisational measures and facts that a technical browser scan cannot determine.

Privacy Drift can only report technical activity it is able to observe in the tested WordPress and browser state. Results can be affected by caching, consent-manager configuration, browser behaviour, conditional loading, logged-in state, geolocation, network conditions, A/B tests, third-party services and later site changes. A clear result does not prove that no other privacy-relevant processing exists. A warning or risk signal does not by itself establish a legal violation.

Website operators remain responsible for reviewing the results, configuring their website and consent mechanisms correctly, maintaining appropriate privacy notices and agreements, obtaining professional advice where appropriate, and determining the legal requirements that apply to their specific website and organisation.

Privacy Drift does not accept responsibility for legal decisions made solely on the basis of plugin output. To the extent permitted by applicable law, the software is provided under GPLv2-or-later without warranty; there is no warranty that the software will be error-free, uninterrupted, suitable for a particular legal purpose, or capable of detecting every privacy-relevant change.

The first-use acknowledgement documents that the scope notice was presented and acknowledged for that administrator account. It is not a contract replacing applicable terms, does not constitute legal advice, and does not exclude or limit liability or statutory rights where such exclusion or limitation is prohibited by applicable law.

Nothing in this disclaimer excludes or limits liability where such exclusion or limitation is prohibited by applicable law.

Privacy Drift is an independent plugin and is not endorsed by, affiliated with, or sponsored by the WordPress Foundation or WordPress.org.

Screenshots

Installation

  1. In WordPress, go to Plugins Add New.
  2. Install Privacy Drift from the WordPress Plugin Directory, or upload the privacy-drift.zip file via Plugins Add New Upload Plugin.
  3. Activate Privacy Drift.
  4. Open Privacy Drift from the WordPress admin menu.
  5. Review the first-use scope notice and select “Got it — continue” when you understand the stated limitations.
  6. Run the first browser scan. The first successful browser scan becomes the trusted baseline used for later drift comparisons.
  7. Review the detected third-party services, cookies/storage names and any technical privacy-risk signals.
  8. Run additional scans after relevant site, plugin, theme or consent-manager changes to see what changed.

Privacy Drift stores scan and review data locally in the WordPress database. No account or external Privacy Drift service is required for the core plugin.

FAQ

Does Privacy Drift replace my cookie banner?

No. Privacy Drift does not collect consent or manage visitor choices. It observes your existing website and can technically test supported or safely detectable Reject behaviour.

What happens after a WordPress or plugin update?

Run another browser scan manually. Privacy Drift compares the result with the trusted baseline and shows Added and Removed external resources for review.

Does Privacy Drift automatically scan after updates?

No update event triggers a browser scan or Consent rejection test, and the Free plugin sends no monitoring email alerts. A local daily server scan can run only when a server-mode baseline exists; it checks server-rendered HTML and does not replace a manual browser scan or Reject retest.

What does the Consent rejection test verify?

It records observable third-party resource activity before Reject, triggers a supported or unambiguous Reject/Decline action, and then records the resulting resources plus browser-visible cookie/storage names. It tests technical behaviour in that page state, not whether the consent design or website is legally valid.

Which consent plugins are supported?

Privacy Drift includes known Reject selectors for Complianz, Cookiebot, OneTrust, CookieYes, Usercentrics, Real Cookie Banner and Borlabs Cookie. A conservative fallback can use an unambiguous Reject/Decline action inside a clearly identified consent container. If no safe action can be identified, Privacy Drift reports the banner as unsupported instead of guessing.

Does Privacy Drift collect cookie values?

No. It records browser-visible cookie names and local/session-storage names, not their values.

Does a clean result mean my website is GDPR compliant?

No. A clean result only describes the technical activity Privacy Drift observed in the tested state. It does not prove legal compliance or that no other privacy-relevant processing exists.

Reviews

There are no reviews for this plugin.

Contributors and Developers

“Privacy Drift” is open source software. The following people have contributed to this plugin.

Contributors

Translate “Privacy Drift” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Change Log

0.13.10

  • Removed automated monitoring mail and the Premium early-access mail flow from Free.
  • Added per-administrator, versioned and revocable RDAP permission before external host research; removed hidden DNS enrichment.
  • Added Privacy & Data Flows, WordPress privacy-policy guidance and administrator-data export/erasure, with complete multisite uninstall cleanup.
  • Removed inline presentation code and moved application state and local script translations to authenticated same-origin requests.
  • Hardened same-site redirects, response limits, input shapes, accessibility, keyboard focus and internationalization.
  • Added pinned coding/static-analysis gates, distributed-package egress checks and observed runtime consent/egress tests.

Older release history is available in changelog.txt.