Skip to content

WordPress Integration

Last updated: October 5, 2026

Use the Cybexo CMP plugin to load your CYBEXO consent banner and connect visitor choices to Google Consent Mode v2 and compatible WordPress plugins.

Release availability: Version 0.2.8 is available from WordPress.org. This guide applies to that release. Confirm the offered version and complete any legacy App migration before updating.

  • Use WordPress 5.8 or later and PHP 7.4 or later.
  • Create and publish a Web App for your site’s real domain in the CYBEXO dashboard. Copy its actual CYB App ID; it starts with CYB- followed by ten lowercase letters or digits.
  • Keep Consent Mode enabled in that app’s configuration if CYBEXO will publish visitor choices to Google.
  • Choose one CMP installation and one Google consent owner per page. Remove a previous manual loader or GTM CMP tag when switching to the plugin.
  • Install and activate WP Consent API if other plugins or themes need its consent signals.

Migrate an existing legacy App before upgrading. Use a supported migration that preserves its configuration, ownership and consent/report history, then copy the actual new CYB App ID from the dashboard. Do not replace an ID prefix yourself. Creating a separate new App does not migrate the old App’s history or saved visitor choices. If migration is unavailable, contact CYBEXO support before updating that installation.

A retired or invalid saved ID remains visible so you can correct it; it cannot load the CMP. Saving an unrelated setting is not an identity migration.

  1. In WordPress Admin, open Plugins → Add New, search for Cybexo CMP, then install and activate version 0.2.8.
  2. Open Cybexo CMP in the admin menu and enter your dashboard-issued CYB App ID in the App ID setting.
  3. Keep Auto-inject CMP Script enabled for the normal installation.
  4. Keep Consent Model (WP Consent API) set to opt-in unless you have deliberately configured and verified another supported policy.
  5. Save, clear any page cache, and open a public page in a fresh, logged-out browser context.

The WordPress.org slug is cybexo-cmp. The plugin loads https://cmp.cybexo.com/loader.js, requests configuration and vendor-list assets from https://edge.cybexo.com, and uses the normal CYBEXO consent/reporting service. This integration uses the shared Web runtime; its runtime version is separate from the plugin version. Version 0.2.8 is paired with Web CMP 1.5.32 in this guide.

A valid-looking ID is not proof of an active App, permitted domain or published configuration. Confirm those in the dashboard if configuration delivery fails.

Section titled “2. Understand startup and consent ownership”

While the plugin is active, it places the early TCF API and denied Google defaults before normal head tags. This safe startup also applies when the App ID is missing or invalid; the banner loader remains disabled until a supported ID is configured. Disabling auto-injection alone does not turn off these startup defaults.

The early API queues TCF requests until the shared runtime is ready. The plugin sets the four Google defaults—ad_storage, analytics_storage, ad_user_data and ad_personalization—and the shared runtime publishes configured, saved and changed choices. The fixed developer ID is dZTNmYW. The initial 500 ms wait accommodates asynchronous restoration; it does not prove that the banner is ready or wait indefinitely for a visitor.

Do not add a second TCF bootstrap or a separate Google consent-default snippet for this normal plugin installation. Exclude the required early consent script from optimization settings that delay it until after Google or other TCF-dependent scripts. Verify actual page order after changing cache, script-delay or optimization settings.

Keep the App’s Consent Mode setting enabled for Google updates. Disabling it prevents later Google updates and, in the TCF integration, WordPress category publication. It is not a general switch that blocks Google or every third-party plugin. Likewise, a successful loader download does not prove configuration, vendor-list delivery or CMP readiness.

For this setup, CYBEXO owns Google consent. Keep Site Kit’s separate Consent Mode feature off in Site Kit → Settings → Admin Settings, while retaining your intended Analytics connection and tag placement. Do not run both consent writers. Google’s Site Kit guidance warns that overlapping consent features can conflict.

Check the actual public page in Tag Assistant after setup. Logged-in exclusions, staging detection, tag placement and other Site Kit settings can affect whether measurement is delivered. A connected Analytics account or an active plugin alone is not proof of a working visitor integration.

Consent Mode adapts supported Google tags; it does not automatically prevent every request. A Basic setup that blocks tags until consent needs its own verified blocking configuration. Do not assume that enabling WP Consent API blocks arbitrary scripts, embeds or plugins that do not use it.

The bridge publishes the standard categories: functional, preferences, statistics, statistics-anonymous and marketing. It establishes the configured consent type and supplies current category choices to participating plugins. When the API’s cookie settings are available but its script loads late, the plugin writes denied values to the optional category cookies it manages, then synchronizes the latest decision when the API is available. It retains the latest category decisions and retries for up to one minute. A later page lifecycle notification or consent decision can also trigger synchronization. Keep WP Consent API loaded normally; if an optimizer delays it beyond this window, restore normal delivery and reload.

In TCF mode, an explicit preferences choice is saved in this browser for the same App and matching saved TCF choice. The plugin restores it only after the runtime confirms a ready, completed decision. An independent Analytics change does not replace that preferences choice. Loading, pending or failed restoration keeps the preferences category denied until the matching choice can be verified.

Analytics permission drives statistics consent. Marketing uses conservative aggregation: a denied advertising permission must not be turned into category-wide permission by another granted advertising signal. Check mixed choices as well as Accept All and Reject All. A regional Google baseline without a visitor decision is not itself a WordPress category choice; optional WP categories can remain denied until the runtime publishes a real category decision.

WP Consent API stores category choices in cookies. If browser storage refuses a change while retaining an older allowed value, a plugin reading that cookie can still see the older value. Check that the category change was saved; restore normal cookie access and reload if it was not. This bridge does not replace other plugins’ permission checks or guarantee withdrawal when their underlying storage cannot be updated.

This is a category integration. It does not promise individual vendor-to-service mappings, control every plugin, or turn WP Consent API’s public diagnostic status into a visitor-consent record. WP Consent API service-specific decisions override category choices: an explicit service grant can remain allowed after a category denial, and an explicit service denial remains denied after a category grant. This bridge preserves those overrides. Plugins or callers that own service-specific choices must reconcile them separately, including withdrawal; verify their behavior. If WP Consent API is absent, the CYBEXO banner can still load, but other plugins cannot rely on that missing API for coordination.

Place this shortcode in a page, widget or supported content area:

[cybexo_preferences]

It creates a Privacy settings link that opens the real CMP so visitors can review or change their choices. Opening it does not itself grant consent. The shortcode also makes the normal loader available when auto-injection is disabled. Use one installation path and verify that every page requiring consent has the intended loader.

[cybexo_cmp] and the CMP block can also enqueue the loader. For new content, use the CYBEXO shortcode names.

The admin Reset Consent (this browser) tool clears this browser’s consent choices for testing restoration. It preserves pending receipt retries and reporting history. It is not account deletion, a server-side consent-history erasure request or a replacement for the visitor’s privacy settings control.

Use the public, logged-out site and the exact version you plan to release:

  1. Confirm one cybexo-cmp loader and successful configuration/vendor-list delivery for the correct App and domain. Inspect the runtime version separately from the plugin version.
  2. In Tag Assistant, confirm the four denied defaults precede Google initialization and the expected developer ID is present.
  3. Accept All, then check the Google signals, TCF data when applicable, and WP Consent API categories. Confirm an intended test event reaches the correct Analytics property.
  4. Refuse advertising personalization while allowing Analytics, then refuse Analytics separately. Save and reload each choice; confirm the independent signals, saved preferences and category results.
  5. Reopen Privacy settings, Reject All and reload. Confirm the saved rejection and the intended tags’ withdrawal behavior. Judge network activity according to your Basic or Advanced configuration.
  6. Test blocked loader, configuration and vendor-list delivery, then restore delivery and reload. The integration must not report permission or readiness that it has not established.
  7. Check delayed WP Consent API loading after rejection and verify optional categories stay denied before and after the API becomes available. Check the banner, settings and privacy link on mobile and with a keyboard. Verify that the WordPress theme or script optimizer has not hidden controls or delayed startup.

For TCF, an unloaded API may report stub while configuration is unavailable. An initialized runtime’s vendor-list error is a different state. Inspect the actual status and delivery failure rather than treating a script’s load event as completion.

Check normal consent/reporting receipts in the dashboard where enabled. A sent request, a local API snapshot and a stored server record are different checks. Pulse can supplement installation diagnostics; a scan does not replace visitor interaction tests or prove certification.

Back up plugin settings and your site before updating. Complete any legacy App migration first, install the offered release normally, clear relevant caches and repeat the affected checks above. Preserve the prior known-good package and a record of your settings.

If an update fails, restore a compatible known-good plugin package and verify the live site. A code rollback does not undo dashboard configuration or shared-runtime changes, and restoring an old database can overwrite newer content or records. An older plugin may not support your current CYB App ID; check compatibility before using it as recovery.

Deactivation stops the plugin’s integration. Deleting the plugin removes its plugin-owned settings, including retained legacy options. It does not erase cloud consent/report history or every visitor’s browser storage. Keep backups and use the appropriate account/data-management process for broader deletion requests.

Symptom Check and fix
Invalid or retired App warning Copy the actual CYB App ID after supported migration; do not edit an old prefix by hand.
Banner does not appear Check published configuration, allowed domain, entitlement, saved choice, regional policy and delivery errors. Test a fresh logged-out visit.
Choices do not reach Google Enable Consent Mode in the App, keep one consent writer, and inspect configuration/vendor-list delivery and actual Tag Assistant updates.
WP categories are missing or stale Confirm WP Consent API is active and inspect script order, cache/optimization settings and the participating plugin’s supported API behavior.
Duplicate banner or conflicting signals Remove duplicate manual/GTM loaders and overlapping consent writers. Clear cached pages and retest.
Privacy settings link does nothing Confirm normal loader/configuration delivery and check for theme or JavaScript errors.
Google event is absent Check actual tag placement, consent, logged-in/staging exclusions and the intended measurement property; connection status alone is insufficient.