01 — Manual
Manual: setting up and running the cookie plugin
From installation to troubleshooting. If you only want to look one thing up, jump straight to it from the overview.
The screenshots show the German interface. The plugin itself is fully translated — the menu paths in this manual are the English ones.
01Getting started
What Ehrenplatz-Cookie does
Ehrenplatz-Cookie is a consent management plugin for WordPress. It finds the services on your site that send data to third parties, blocks them until the visitor agrees, and documents that agreement in a way you can show later.
Three things set it apart from a plain cookie banner:
- It finds services itself instead of expecting you to know them — by scanning the whole site, and weekly in the background.
- It really blocks, including content a page builder only loads later by JavaScript. A banner that asks but stops nothing does not do its job.
- It hosts Google Fonts and the Tag Manager locally, with no extra plugin and for good.
Requirements
| WordPress | 5.9 or newer |
| PHP | 7.4 or newer |
| Licence | a valid licence key, see chapter 02 |
The plugin runs on ordinary shared hosting. It needs no server of its own, no Node.js and no Chromium.
Installation
- Download the ZIP file
- In WordPress, choose it under Plugins → Add New → Upload Plugin
- Install Now, then Activate
- Ehrenplatz-Cookie appears in the WordPress menu
Finding your way around
The plugin brings a sidebar of its own. You reach every area through the single menu entry Ehrenplatz-Cookie, not through WordPress submenus:
| Area | What it is for |
|---|---|
| Dashboard | Overview and status |
| Scan | Find services automatically |
| Services | Manage and categorise |
| Providers | The organisations responsible |
| AI assistant | Suggestions for the setup |
| Design | Style the banner |
| Google Fonts | Host locally |
| Consent log | Record and export |
| Statistics | Consents at a glance |
| Service list | Shortcode for the privacy policy |
| Custom CSS | For special cases |
| Settings | General, language, AI — the licence lives here too |
Two small things that help day to day: ⌘K opens a command palette and jumps straight to an area. At the bottom of the sidebar you switch between the light and dark appearance.
The dashboard shows at a glance whether automatic blocking is on, how many services are active, how many consents have been logged, when the last scan ran and whether any scan findings are waiting for you. Test as a visitor starts from there as well.
The first step after installing, though, is the licence key — without it the other areas stay locked.
02Licence
Entering the key
The licence key has the form EPC-XXXX-XXXX-XXXX-XXXX. You will find it in the purchase email and in the licence certificate.
As long as no licence is stored, the plugin shows nothing but the licence page — every other area is locked. Once entered, the licence lives under Settings.
- Paste the key
- Save licence
Upper and lower case make no difference, and spaces are stripped. After saving, the key is only ever shown shortened (EPC-A7F3-••••-••••-••••) — so it cannot be read even by someone who gets into your WordPress backend. To change other settings without touching the key, simply leave the field empty.
Below the field you can see how many seats of your licence are taken. Remove licence detaches this installation from the licence again.
How seats are counted
Every installation takes a seat — staging environments, local copies and installations on subdomains included. A project made up of a live site, a staging site and a local copy therefore uses three seats.
www.your-domain.com and your-domain.com count as the same site and take one seat between them.
Moving to another site
- Deactivate the plugin on the old site — the seat is free at once
- Enter the key on the new site
This works as often as you like. You need no customer portal and no word with support.
Support code
In the licence area, Request support code gets you a code. It is valid for 30 minutes and identifies your installation to support.
Include this code with your enquiries — not your licence key. That way your installation can be identified without the key travelling through inboxes and ticket systems.
If the licence server cannot be reached
In short: nothing happens.
The plugin checks the licence once a day and remembers the last valid answer. Trouble at our end does not switch your consent management off — that would be exactly the wrong moment for an outage.
- After 7 days without successful contact a notice appears in the backend
- After 30 days without any contact the licence is downgraded
Only an explicit refusal from the server — for a cancelled licence, say — switches off at once. A freshly entered key never locks immediately either: if the server cannot be reached while you save, the key is stored anyway and the activation is caught up automatically.
Messages during activation
| Message | What it means and what to do |
|---|---|
| This licence key is unknown | Check the spelling. The key always begins with EPC-. |
| All sites for this licence are in use | Deactivate the plugin on a site you no longer need; the seat is free at once. |
| This licence is no longer valid | Check the status of the subscription. |
| The licence server cannot be reached at the moment | Nothing to do. The key is saved and the activation will be caught up. |
03First setup
Setup assistant
Once the licence is active, the setup assistant takes you through the basic settings in five steps. You can call it up again at any time: Settings → Restart setup assistant.
Step 1 — Welcome
The opening screen explains what the next steps will do.
Step 2 — Scan
The assistant searches your site and splits what it finds into two groups: Detected and activated — services the plugin knows and could sort by itself — and Unknown services, which you have to sort. The second group is the important one: anything left there is not categorised correctly.
Step 3 — Design
Here you choose the basic look of the banner. The finer points come later under Design.
Step 4 — Wording
Language, form of address — formal or informal — and the link to your privacy policy. The form of address runs through all the banner wording; setting it right here saves reworking it later.
Step 5 — Done
A summary, and links into the areas that make sense next.
The first scan
Ehrenplatz-Cookie → Scan searches your site for services that send data to third parties.
- Up to 150 addresses per run are checked — not just the home page
- The scan runs in sections so that it does not hit a time limit on your server
- Very large pages are evaluated up to 3 MB
- Sites with more than 150 addresses are catered for; the services found are kept across the runs
On top of that, an automatic scan runs in the background once a week and reports newly added services. That is the case that counts in practice: someone embeds a YouTube video on a subpage, and nobody thinks about the cookie banner.
The four categories
Every service belongs to exactly one category:
| Category | What it covers |
|---|---|
| Essential | Technically necessary, no consent required |
| Statistics | Audience measurement and analysis |
| Marketing | Advertising, retargeting, conversion tracking |
| External media | Embedded third-party content — videos, maps, fonts, reCAPTCHA |
If a service is given no category, it lands under Statistics automatically — never under Essential. So an unknown service is never loaded without consent by accident.
Sorting the services
Under Ehrenplatz-Cookie → Services you give each service found its category and enter the details that later appear in the cookie table.
The AI assistant can suggest that sorting for you. It runs on your own API key at Anthropic or OpenAI — the cost is not included in the licence, and in return there is no limit from us. Do check the suggestions, particularly anything proposed as Essential.
04Banner and design
Under Design you style the banner. At the top you pick a preset as a starting point:
| Preset | Effect |
|---|---|
| Rounded | Soft corners — the Ehrenplatz default |
| Square | Sharp corners with no rounding, technical |
| Soft | Heavily rounded with pill buttons, deliberately friendly |
Worth knowing: a preset sets only the corner radii and the border of the secondary button. Every other setting — colours, type, spacing — stays as it was. So you can pick a preset at any time without losing your detailed work.
The banner renders inside a capsule of its own, the Shadow DOM. That means your theme’s CSS cannot disturb the layout and the type of the banner — not even after a theme update.
Reopen button. Visitors must be able to withdraw their consent. There is a configurable button for that, whose position and spacing you set. Alternatively, place the shortcode [epc_settings] wherever you like, in the footer or the privacy policy for instance.
Test as a visitor. This button shows you the banner as a new visitor sees it — without having to reset your own consent.
Custom CSS under the menu entry of the same name, if you want to go beyond the settings.
05Google Consent Mode v2
Consent Mode tells Google services what the visitor has agreed to. Ehrenplatz-Cookie supports all seven fields:
ad_storage · ad_user_data · ad_personalization · analytics_storage · functionality_storage · personalization_storage · security_storage
Where you assign them
- Open Services and call up the service you want to edit
- Expand the advanced area in the form
- Assign the fields under „Control Google Consent Mode“
Without an assignment of your own:
| Field | Category |
|---|---|
ad_storage, ad_user_data, ad_personalization | Marketing |
analytics_storage | Statistics |
06Hosting Google Fonts and Tag Manager locally
Loading Google Fonts from Google’s servers passes your visitors’ IP addresses to Google — something German courts have ruled on. Ehrenplatz-Cookie downloads the fonts to your own server and serves them from there.
Under Ehrenplatz-Cookie → Google Fonts you switch on automatic local hosting. The plugin finds the fonts in use, downloads them and replaces the embedding — for good, including fonts added later.
The same works for the Google Tag Manager.
07Records and privacy
Shortcodes
| Shortcode | What it outputs |
|---|---|
[epc_cookie_list] | A structured table of all cookies for the privacy policy |
[epc_service_list] | A list of the services in use |
[epc_settings] | A link or button to open the settings again |
[epc_blocked] | A placeholder for blocked content |
For the privacy policy you will usually want [epc_cookie_list] and [epc_settings]. The right shortcode, with a preview, is under Service list.
Consent log
Under Ehrenplatz-Cookie → Consent log you will find the logged consents, exportable as CSV. IP addresses are stored hashed, not in the clear.
Providers
Under Providers you record, for each service, who processes the data. These details appear in the banner and in the cookie table.
Statistics
Statistics shows how visitors respond to the banner — acceptances, refusals, partial consents.
08Questions and troubleshooting
A service is not being blocked
Check the master switch first: Settings → „Automatic blocking“. With it off, the plugin blocks nothing, however the services are configured.
That sounds obvious, but it is by far the most common cause — and it is regularly missed, because people think of caches and configuration errors first. Only once this switch is on is further searching worthwhile.
Whether the switch is on can also be seen at a glance on the Dashboard.
A video in Elementor is not being blocked
Page builders like Elementor often load videos later by JavaScript. Classic blockers that only search the HTML source therefore do not find them. Ehrenplatz-Cookie has a watcher in the browser for exactly that, which catches embeds loaded after the fact.
One special case: YouTube appears under several addresses — youtube.com, youtu.be and youtube-nocookie.com, the last one when Privacy Mode is on in Elementor. All variants are recognised and mapped to the same service definition.
Google Fonts still load despite local hosting
Usually this is because the font is only embedded on a subpage. Run a full scan, not just a check of the home page.
The banner does not appear
A known cause: WP Rocket with LazyRender switched on. The feature sets content-visibility: auto, which leaves the banner present in the DOM but invisible. Exclude the banner container from LazyRender.
If the banner does not appear at all on a fresh installation, check in the browser console whether the configuration could be loaded.
Is Google reCAPTCHA not essential?
No. reCAPTCHA belongs to External media and needs consent.
The common assumption to the contrary is that reCAPTCHA is technically necessary to run the form. That does not hold: there are alternatives for spam protection that need no consent, and that removes the basis for filing it as essential.
Ehrenplatz-Cookie detects reCAPTCHA and, since version 1.52.0, files it correctly.
After a plugin update I see old content
After each of its own updates the plugin automatically clears the cache of the common caching plugins: WP Rocket including its minify cache, W3 Total Cache, WP Super Cache, LiteSpeed Cache and SiteGround Optimizer. You need do nothing.
If you use a different caching plugin or a server cache, clear that yourself after the update.
What happens when my licence runs out?
See chapter 02. In short: trouble at the licence server changes nothing; a licence that has genuinely expired or been cancelled leads to a downgrade.
09Reference
Constants for wp-config.php
| Constant | Purpose |
|---|---|
EPC_LICENSE_API_BASE | A different address for the licence server, for a test instance for example |
EPC_AI_API_KEY | API key for the AI assistant, as an alternative to entering it in the backend |
Limits and intervals
| Addresses per scan run | 150 |
| Maximum response size per page checked | 3 MB |
| Automatic background scan | weekly |
| Licence check | daily |
| Warning without server contact | after 7 days |
| Downgrade without server contact | after 30 days |
| Consent Mode fields | 7 |
| Categories | 4 |
| Validity of the support code | 30 minutes |
Areas in the sidebar
Dashboard · Scan · Services · Providers · AI assistant · Design · Google Fonts · Consent log · Statistics · Service list · Custom CSS · Settings
The licence lives in the settings, as does Restart setup assistant. ⌘K opens the command palette and jumps straight to an area.
02 — Support
Support
Email support answered within 48 hours at cookie@ehrenplatz.ai. Have your support code from the licence page ready — not your licence key.