WPConsent Documentation

Documentation, Reference Materials, and Tutorials for WPConsent

Automatic Script Blocking

Are tracking scripts setting cookies on your site before your visitors have agreed to them? WPConsent holds those scripts back until a visitor makes a choice. All you need is WPConsent on your WordPress site.

This guide covers both blocking settings, which scripts WPConsent recognizes, and what changes on your pages when a visitor consents.

Table of contents

Before you get started, make sure WPConsent is installed and activated on your WordPress site.

Turning On Script Blocking

To get started, we’ll open the screen that holds both blocking settings.

From your WordPress admin sidebar, go to WPConsent » Settings.

Opening Settings from the WPConsent menu in the WordPress admin sidebar

The page opens on the Settings tab. Below the License panel, the Cookies Configuration panel holds every site-wide consent setting your site uses.

The Cookies Configuration panel at the top of the WPConsent Settings tab, with the Consent Banner and Script Blocking rows

The second row in that panel is the one that matters here. To hold known tracking scripts back until a visitor consents, turn on Script Blocking.

The Script Blocking toggle turned on in the Cookies Configuration panel

With this on, WPConsent inspects each page as WordPress builds it, before the page reaches the browser. Any script it recognizes is marked as text/plain, which stops the browser from running it. The tracker never starts and never sets a cookie.

When a visitor accepts the category that script belongs to, WPConsent rebuilds the tag and lets it run. That happens in place without a page reload.

Note: Script Blocking is stored as on only while Consent Banner is on as well. The banner is how visitors give consent, so WPConsent keeps them together.

What that leaves is the question of which scripts WPConsent recognizes in the first place.

How Does WPConsent Decide What to Block?

WPConsent blocks the scripts it recognizes. It keeps a list of known services and matches every script and iframe on your pages against that list.

The list is therefore what decides whether a given tracker is held back.

It covers the analytics and advertising services most sites run, including Google Analytics, Matomo, Facebook Pixel, Google Ads, and TikTok Pixel. Each service is filed under a cookie category, either Statistics or Marketing. That category is what a visitor consents to.

The list lives on WPConsent’s own servers rather than inside the plugin, and your site keeps a copy of it for 24 hours. New services therefore reach your site without a plugin update.

WPConsent never holds back scripts in the Essential category, because a site cannot function without them. It never holds back its own scripts either, since those are what show the banner. And a script that is not on the list runs as normal, because nothing matches it.

That last point is worth planning around. A tracker outside that list needs a rule of your own, which a paid version of WPConsent provides.

Our guide on blocking custom scripts and iFrames covers writing one.

A paid version also recognizes the order attribution tracking that WooCommerce adds to a store.

To see which services a scan has already found on your pages, take a look at our guide on scanning your website.

Blocking Embedded Content

Embedded videos and maps set cookies too, and they need different handling from a tracking script. Removing an embed outright leaves a hole in your page, so WPConsent puts something in its place.

To block embeds until a visitor consents, turn on Content Blocking.

The Content Blocking toggle turned on, with the Content to Block list of providers below it

Turning the toggle on reveals a Content to Block list underneath. It holds a switch for each provider WPConsent can block: YouTube, Recaptcha, Google Maps, Vimeo, and DailyMotion.

Every provider starts switched on. Turning off the ones you do not embed is optional, and leaving them all on has no effect on pages that carry no embed.

For each embed it blocks, WPConsent removes the iframe’s address and puts a placeholder in its spot. The placeholder carries a preview image of the service and a button the visitor presses to load that embed.

Note: Content Blocking runs through the same page inspection as Script Blocking, so keep Script Blocking on as well when you block embeds.

Our guide on content blocking and placeholders covers changing the button wording and the preview image.

Choosing How Google Scripts Are Handled

Google’s own tags have a second option, and it changes what Script Blocking does to them.

To decide how those tags are handled, look at the Google Consent Mode toggle further down the same panel.

The Google Consent Mode toggle turned on, with the URL Passthrough and Ads Data Redaction rows below it

While Google Consent Mode is on, WPConsent leaves Google Analytics, Google Tag Manager, and Google Ads out of script blocking. They load on every page and receive Google’s own consent signals instead.

Those signals switch to granted when a visitor accepts the matching category. Google’s tags then adjust their own behavior rather than being held back entirely.

With Google Consent Mode off, Script Blocking treats Google’s tags like any other tracker and holds them back until consent arrives.

Which state suits your site depends on what you need from Google’s reporting. On keeps the tags in place so Google keeps receiving signals. Off is the stricter outcome, with no Google tag running before consent.

Our guide on Google Consent Mode v2 covers that choice in full, along with the URL Passthrough and Ads Data Redaction rows beneath it.

Microsoft Clarity has the same arrangement under its own setting, Clarity Consent Mode, which sits on the Advanced tab.

Our guide on advanced settings covers that tab.

Saving Your Settings

A single button stores every row in the Cookies Configuration panel, so both blocking settings are saved together.

At the bottom of the panel, click Save Changes.

The Save Changes button at the bottom of the Cookies Configuration panel

Your blocking settings are stored alongside everything else in the panel.

The rest of this panel is covered in our guide on configuring WPConsent general settings. That includes Consent Duration, which sets how long a visitor’s choice is remembered.

Seeing Script Blocking on Your Site

The clearest way to understand what your visitors get is to look at a page that carries an embed.

On a first visit, the consent banner asks for a choice and the embed behind it is already blocked.

A front-end page with the consent banner over it, and a blocked Google Maps embed showing a placeholder behind the banner

The map on that page has already been replaced by its placeholder. Nothing was loaded from Google, and no Google cookie exists yet.

A blocked Google Maps embed showing a preview image and a button reading Click here to accept Marketing cookies and load this content

The button on the placeholder is a shortcut for the visitor. Pressing it consents to that embed’s category, which loads the embed straight away and leaves every other category blocked.

The map is filed under Marketing, so a visitor who presses that button accepts Marketing and nothing else. Their stored choice records that one category, and anything filed under Statistics is still waiting for an answer.

Accepting in the banner does the same thing on a larger scale. Once a visitor clicks Accept All, the placeholder disappears and the real embed loads in its place.

The same area of the page after consent, now showing a fully loaded interactive Google Map

Every script that was held back runs at the same moment. The visitor’s choice is stored in their browser, so return visits skip the banner and load the same set of scripts again.

That’s it! Your site now waits for consent before any script or embed WPConsent recognizes is allowed to run.

Next, take a look at our guide on understanding the preferences panel to see how visitors accept some categories and decline others.

Frequently Asked Questions

Below, we’ve answered some of the most common questions about script and content blocking.

Do I need to change how my tracking scripts are added?

No. WPConsent works on the finished HTML of each page. It makes no difference whether a script arrived from a plugin, your theme, a tag manager, or a snippet you pasted into your header.

Why is my Google Analytics still loading?

Google Consent Mode is on. While that setting is on, WPConsent deliberately leaves Google Analytics, Google Tag Manager, and Google Ads out of script blocking. They run without cookies and receive consent signals instead, and turning that setting off puts them back under Script Blocking.

What happens if I use a tracker that is not on the list?

It loads as normal. WPConsent matches each script against its list of known services, and anything without a match is left alone. Our guide on blocking custom scripts and iFrames covers writing your own rule, which is available in a paid version.

Can I use Content Blocking with Script Blocking turned off?

The two settings work as a pair. Content Blocking relies on the same page inspection that Script Blocking switches on, so keep Script Blocking on whenever you want embeds held back.

Can my visitors accept just a single video or map?

Yes. The button on a placeholder consents to the category that embed belongs to, which loads it along with anything else in the same category. Categories the visitor has not accepted stay blocked.

Why do my pages reload when a visitor changes their mind?

A script that has already run cannot be stopped from inside the browser. When a visitor changes a choice they made earlier, WPConsent clears the cookies set so far and reloads the page. The new choice then applies from a clean start.

How long do my visitors’ choices last?

For the number of days set in Consent Duration on the same settings panel, which starts at 30. The choice is kept in the visitor’s own browser. Our guide on configuring WPConsent general settings covers that field.

Can I block scripts only for visitors in certain countries?

Yes. Geolocation rules carry their own Block Script option. A rule that has it on applies to the visitors it matches even while the site-wide Script Blocking toggle is off. Our guide on setting up geolocation rules covers building those rules.

Was this article helpful?

Related Articles