Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

Legal

Cookie Policy

This Cookie Policy explains what cookies and similar storage are, how we use them on wpsecurityninja.com, and how you control optional ad measurement. For how we handle personal data in general, see our Privacy Policy.

Your consent choice for optional ad measurement applies to wpsecurityninja.com (including www, which redirects here).

What are cookies?

Cookies are small text files stored on your device when a site loads. Sites also use similar tools such as localStorage. Together they help the site work, stay secure, remember choices, and (when you allow it) measure ad performance.

How we use cookies and similar storage

We use first-party and third-party cookies and scripts for a few jobs: keeping forms safe, running Freemius checkout when you buy, remembering your ad-measurement preference, measuring traffic with self-hosted Umami, and (only after you Accept) loading Meta and OpenAI Ads measurement pixels.

Umami (always on)

We run self-hosted Umami analytics. It collects cookieless aggregate pageview stats (URL, referrer, browser, and a hashed IP on the server), optional session replay, and generic interaction events such as checkout opens, scroll depth, lead and hire form starts and submits, and CTA clicks. Those events do not include personal identifiers from the browser (no email, name, or purchase IDs). It does not set marketing cookies and is not gated by the cookie banner. We use it to understand site traffic and usage, not to sell your data.

Optional ad measurement (after Accept)

If you click Accept on the banner, we may load:

  • Meta (Facebook) Pixel for ad measurement and Freemius checkout conversions
  • OpenAI Ads Measurement Pixel for ChatGPT ad attribution (may set __oppref)

If you Decline, those scripts stay off. Umami still loads as described above.

What types of cookies do we use?

Essential: Needed for security and core features, such as Cloudflare Turnstile on forms when enabled. They are not used for ads.

Statistics: Help us see visits, which pages matter, and aggregate site usage. Umami is always on and cookieless.

Marketing: Ad measurement cookies (Meta, OpenAI) load only after Accept.

Functional: Freemius checkout and account portal cookies appear when you open purchase or license flows.

Preferences: We store your Accept/Decline choice in localStorage as wpsn-cookie-consent.

Cookies and storage we use

The list below details the cookies and similar storage used on this website.

Cookies and similar storage used on wpsecurityninja.com
Name Category Consent Provider Description
wpsn-cookie-consent localStorage Preferences N/A First party (wpsecurityninja.com) Stores your Accept or Decline choice for optional ad measurement. This is localStorage, not a cookie.
Umami analytics Script (no cookie) Statistics Always on Self-hosted Umami Cookieless pageviews, optional session replay, and aggregate interaction events (checkout opens, scroll depth, lead and hire form starts and submits, CTA clicks). No marketing cookies and no personal identifiers from the browser. IP addresses are hashed on the Umami server. Loads on every page visit without a consent gate.
_fbp Marketing After accept Meta (Facebook) Facebook Pixel for ad measurement and conversion tracking (including Freemius checkout). Loaded only after Accept.
__oppref Marketing After accept OpenAI Ads ChatGPT ads measurement attribution. Loaded only after Accept via the OpenAI Ads Measurement Pixel.
cf_clearance / Turnstile Essential Always on Cloudflare Bot challenge on contact, newsletter, hire, and similar forms when Turnstile is enabled. Needed for form abuse protection.
Freemius checkout Functional When used Freemius (checkout.freemius.com) Session and purchase cookies set by the Freemius checkout iframe when you buy or start a trial. Only present when you open checkout or use the account portal.
FreeScout support widget Script (no cookie) Functional Always on Self-hosted FreeScout (support.wpsecurityninja.com) Loads the support widget for KB search and ticket creation. Always on so visitors can reach help without waiting for marketing consent.

How can I control cookie preferences?

Use the status box at the top of this page and the Change preferences button. That clears your saved choice and shows the site banner again so you can Accept or Decline.

You can also block or delete cookies in your browser settings. See Wikipedia on HTTP cookies or allaboutcookies.org for browser-specific steps. Blocking all cookies may affect Freemius checkout or Turnstile on forms.

Larger screenshot

Enlarged image