Title: Privacy Drift
Author: Thomas
Published: <strong>ಸೆಪ್ಟೆಂಬರ್ 1, 2026</strong>
Last modified: ಸೆಪ್ಟೆಂಬರ್ 16, 2026

---

ಪ್ಲಗಿನ್‌ಗಳನ್ನು ಹುಡುಕಿ

![](https://ps.w.org/privacy-drift/assets/banner-772x250.png?rev=3676322)

![](https://ps.w.org/privacy-drift/assets/icon.svg?rev=3676322)

# Privacy Drift

 ‍[Thomas](https://profiles.wordpress.org/stermole/) ಮೂಲಕ

[ಡೌನ್ಲೋಡ್](https://downloads.wordpress.org/plugin/privacy-drift.0.13.10.zip)

 * [ವಿವರಗಳು](https://kn.wordpress.org/plugins/privacy-drift/#description)
 * [‍ವಿಮರ್ಶೆಗಳು‍](https://kn.wordpress.org/plugins/privacy-drift/#reviews)
 *  [ಸ್ಥಾಪನೆ](https://kn.wordpress.org/plugins/privacy-drift/#installation)
 * [ಅಭಿವೃದ್ಧಿ](https://kn.wordpress.org/plugins/privacy-drift/#developers)

 [ಬೆಂಬಲ](https://wordpress.org/support/plugin/privacy-drift/)

## ವಿವರಣೆ

WordPress changes constantly. A plugin, theme, embed, tag-manager configuration,
analytics setting or consent-manager update can silently add a third-party request
or change what happens after a visitor selects Reject — while the website and cookie
banner still look normal.

Privacy Drift establishes a trusted technical baseline for your WordPress site. 
Run another browser scan after an update or site change and Privacy Drift shows 
which external resources were Added or Removed, helping you find privacy regressions
that might otherwise go unnoticed.

This is not another cookie banner or cookie-list generator. Third-party requests
and browser-visible cookie or storage names are evidence used to monitor change.
Privacy Drift does not manage consent, block trackers or decide whether observed
activity is legally permitted.

#### Why Privacy Drift?

 * Detect added or removed external resources since the trusted baseline.
 * See browser-visible cookie, local-storage and session-storage names without collecting
   their values.
 * Test supported or safely detectable consent banners and inspect observed activity
   after Reject.
 * Review findings and reversibly mark expected changes.
 * Keep a local history and audit trail of scan changes, review decisions and trusted-
   baseline approvals.

#### A typical use case

 1. Install and activate Privacy Drift.
 2. Run the first browser scan.
 3. Use that first successful browser scan as the trusted baseline.
 4. Update WordPress, a plugin, theme, embed, analytics or tag-manager configuration,
    or consent manager.
 5. Manually run another browser scan.
 6. Review the Added and Removed findings against the trusted baseline.
 7. When relevant, run the Consent rejection test and document the result in your review
    process.

WordPress updates do not trigger an automatic browser scan or Consent rejection 
test. The Free plugin sends no monitoring email alerts.

#### What Privacy Drift observes

Depending on the scan and page state, Privacy Drift can record:

 * External resource activity visible to the browser scan, including resource entries
   and script URLs.
 * Browser-visible cookie names and local/session-storage names, but not their values.
 * Local classifications for known services and hosts.
 * Added and Removed resources compared with the trusted baseline.
 * Technical observations before and after a supported or safely detectable Reject
   action.

Browser results depend on the tested page state, caching, consent configuration,
browser behaviour, conditional loading and other runtime conditions. They are technical
evidence, not an exhaustive inventory of all processing.

#### Consent rejection test

The rejection test is a technical behaviour check. It loads a fresh page state in
a sandboxed same-site browser frame, searches for a supported or unambiguous consent-
banner Reject/Decline action, captures third-party activity before the choice, triggers
Reject, waits for the page to settle and captures the resulting resources plus browser-
visible cookie/storage names.

Privacy Drift includes known Reject selectors for Complianz, Cookiebot, OneTrust,
CookieYes, Usercentrics, Real Cookie Banner and Borlabs Cookie. It also has a conservative
text fallback inside clearly identified cookie/consent containers.

Results distinguish external resources observed before Reject, after Reject and 
newly appearing after Reject. Known analytics/advertising services and common analytics/
advertising cookie names receive higher attention.

If Privacy Drift cannot safely identify a Reject action, it reports that limitation
instead of guessing.

A successful rejection test is not a legal GDPR compliance verdict. It is technical
evidence that can reveal obvious consent regressions such as analytics or advertising
activity appearing before or remaining after a rejection action.

#### Local-first by design

Core scan results, trusted baselines, history, Expected classifications and audit
events remain in the local WordPress database. No Privacy Drift account is required
for core functionality, and the plugin sends no silent usage telemetry to its operator.
Cookie and browser-storage values are not collected. Optional RDAP.org host research
is a separate external data flow that requires explicit, versioned and revocable
permission from each administrator.

See Privacy Drift  Privacy & Data Flows and the detailed sections below for the 
complete storage, retention and external-service disclosures.

#### What Privacy Drift is not

Privacy Drift is not a cookie banner, consent-management platform, generic tracker
blocker, legal adviser, GDPR certification tool or guarantee of compliance.

#### Privacy and data handling

Privacy Drift follows a local-first approach for its core monitoring features.

 * Scan results, trusted baselines, monitoring history, Expected classifications,
   host-intelligence cache and the review/audit trail are stored in the local WordPress
   database.
 * Each administrator’s first-use scope acknowledgement stores only the disclaimer
   version, activation identifier and acknowledgement timestamp as local WordPress
   user metadata. This acknowledgement is not sent to the Privacy Drift operator.
 * Privacy Drift does not collect or transmit cookie values or browser-storage values.
 * Privacy Drift does not silently send installation identifiers, site URLs, scan
   events, usage telemetry or analytics to the plugin operator.
 * Core scanning and review features do not require a Privacy Drift account or an
   external Privacy Drift service.
 * No host/network lookup is made automatically. Activation, dashboard use and local
   review do not initiate third-party service requests.
 * Server scans request only the configured WordPress site’s origin, including redirects.
   They inspect returned HTML without fetching the third-party resources found in
   it.
 * Browser and consent scans execute the site’s front end. External services already
   embedded by that website can therefore receive requests from the administrator’s
   browser; these are website-originated requests, not Privacy Drift telemetry.
 * Presentation assets are packaged locally. There are no remote fonts, scripts,
   styles, tracking pixels, remote logs or alternate update services supplied by
   Privacy Drift.
 * The Free plugin sends no automated monitoring email and contains no Premium early-
   access mail flow.

Administrators remain responsible for the privacy implications of the WordPress 
site being scanned, including third-party services already configured on that site.

Open Privacy Drift  Privacy & Data Flows for the full storage inventory and RDAP
permission controls. Baseline and latest scan are replaced when approved or scanned
respectively; history and audit log retain up to 100 entries each, Expected classifications
up to 250 entries, and host intelligence up to 100 hosts. The latest consent-test
result and local browser-scan counter are also retained. There is no automatic time-
based expiry. URLs, hostnames, resource types, cookie/storage names, timestamps 
and technical results can be stored; URLs may contain personal information already
present in the inspected website’s paths or query strings. Avoid testing pages containing
sensitive personal data unnecessarily.

Audit events associate actions with a WordPress user ID without copying the user’s
display name into new events. Administrator-linked acknowledgement, onboarding and
RDAP permission metadata are local. WordPress personal-data export includes this
metadata and that user’s audit entries. Erasure removes the metadata and anonymizes
their identity in retained technical audit events, including legacy copied names;
it does not erase unrelated site-wide technical findings. Privacy Drift also supplies
suggested text to the WordPress Privacy Policy Guide for the site operator to review
and adapt.

Temporary administrator view state (scroll position and expanded review/history 
details) uses the browser tab’s sessionStorage under privacyDriftExpectedViewportV1
and privacyDriftHistoryViewportV1. It is removed after restoring the view or when
the tab session ends. It is not telemetry; uninstall cannot clear storage in an 
already open browser tab.

#### External services and explicit data transfers

RDAP.org is the only third-party research service initiated by the Free plugin. 
A Research host action without current permission opens a disclosure before any 
external lookup:

 * RDAP.org provides bootstrap access to public domain and network registration 
   information. After “Allow external lookup”, Privacy Drift sends the selected 
   host’s derived root domain, or the selected IP address if the finding is already
   an IP address. It performs no separate DNS resolution or hidden IP enrichment.
   RDAP.org may redirect to the authoritative registry or regional Internet registry
   RDAP service. The HTTP request necessarily exposes the WordPress server’s public
   IP address and the Privacy Drift version in its User-Agent. Privacy Drift does
   not add the WordPress site URL, administrator identity, account details, scan
   history, page content, or cookie/storage values to the request. The selected 
   domain or IP itself may identify the inspected site or its provider. Official
   usage/rate-limit information: https://about.rdap.org/#how-to-use-rdaporg ; privacy
   considerations: https://about.rdap.org/#privacy-considerations . Authoritative
   RDAP services may have their own notices.
 * Permission is stored per administrator in local user metadata with a consent 
   version and approval timestamp. Cancel, including Escape, sends no RDAP request.
   Later Research host actions by that administrator may use the current permission;
   no background research is scheduled. Revoke permission on Privacy & Data Flows
   to require approval again. Material changes to the data flow require a new consent
   version and renewed approval.

Google, Meta, Stripe, Hotjar, HubSpot, YouTube, Maps and other service signatures
are local classification rules, not requests to those companies.

Automated external notifications and email alerts are not part of the Free version.

#### Security and scope

Administrative mutations use WordPress capability checks and nonces. Browser-scan
targets are restricted to the current WordPress site. Scan frames are sandboxed,
do not permit top-level navigation, and use a no-referrer policy. Host research 
uses WordPress safe HTTP requests and only runs on demand.

Because browser-grade inspection intentionally executes the site’s own front-end
JavaScript to observe runtime behaviour, administrators should only run browser/
consent scans on the WordPress site they intend to inspect. Privacy Drift does not
load arbitrary third-party scan targets in the admin frame.

Privacy Drift deliberately reports uncertainty where a technical result is not sufficient
for a legal conclusion.

#### First-use scope acknowledgement

The first time each WordPress administrator opens Privacy Drift after installation
or reactivation, the plugin displays a blocking scope modal explaining that findings
are technical indicators rather than legal conclusions and that Privacy Drift does
not guarantee regulatory compliance.

The administrator can acknowledge the notice with “Got it — continue”. The acknowledgement
stores only a disclaimer version, activation identifier and UTC timestamp as user
metadata in the local WordPress database. It does not transmit acceptance data, 
identity data or telemetry to the Privacy Drift operator, and it does not waive 
rights that cannot lawfully be waived.

Each activation starts a new local acknowledgement cycle, so every administrator
must review and acknowledge the scope again after the plugin is reactivated. Scan
results, trusted baselines and monitoring history are not removed by deactivation
or by this acknowledgement reset.

#### Support and security contact

For technical support, responsible security reports or questions about Privacy Drift
data handling, contact: wordpress@stermole.at

Security issues should not be published publicly before a reasonable opportunity
to investigate and provide a fix.

### Requirements

 * WordPress 6.4 or newer.
 * PHP 8.0 or newer.
 * A current browser with JavaScript enabled for browser-grade scans and the Consent
   rejection test.
 * WordPress administrator access (`manage_options`) to run scans and review findings.

Privacy Drift is currently tested against WordPress up to version 7.1. Older WordPress
or PHP versions are not supported.

### Uninstallation

Deactivating Privacy Drift stops the plugin but keeps its stored monitoring data
so it can be reactivated later.

To remove Privacy Drift completely:

 1. Go to Plugins  Installed Plugins.
 2. Deactivate Privacy Drift if it is active.
 3. Click Delete for Privacy Drift.

WordPress then runs the plugin’s uninstall routine. Privacy Drift clears its scheduled
monitoring hook and removes its stored baseline, latest scan, monitoring history,
audit log, Expected classifications, browser-scan count, host-intelligence cache,
latest consent-test result, activation-cycle identifier, legacy Premium-waitlist
state, and all plugin-specific first-use, onboarding and RDAP permission user metadata.
On multisite it cleans the options and scheduled hook for every site and removes
the shared plugin user metadata. Deactivation alone retains these records.

If you may want to keep the existing baseline and monitoring history, deactivate
the plugin instead of deleting it.

### Disclaimer

Privacy Drift is a technical monitoring and diagnostic tool intended to assist website
administrators in identifying privacy-relevant technical behaviour and changes. 
It is not legal advice, a legal audit, a certification service, a consent-management
platform, or a guarantee of GDPR, DSGVO, ePrivacy, cookie-consent or other regulatory
compliance.

No plugin can determine or provide complete legal compliance for a website. Legal
obligations depend on the website operator, applicable jurisdiction, purposes and
legal bases of processing, contracts, consent design, third-party services, organisational
measures and facts that a technical browser scan cannot determine.

Privacy Drift can only report technical activity it is able to observe in the tested
WordPress and browser state. Results can be affected by caching, consent-manager
configuration, browser behaviour, conditional loading, logged-in state, geolocation,
network conditions, A/B tests, third-party services and later site changes. A clear
result does not prove that no other privacy-relevant processing exists. A warning
or risk signal does not by itself establish a legal violation.

Website operators remain responsible for reviewing the results, configuring their
website and consent mechanisms correctly, maintaining appropriate privacy notices
and agreements, obtaining professional advice where appropriate, and determining
the legal requirements that apply to their specific website and organisation.

Privacy Drift does not accept responsibility for legal decisions made solely on 
the basis of plugin output. To the extent permitted by applicable law, the software
is provided under GPLv2-or-later without warranty; there is no warranty that the
software will be error-free, uninterrupted, suitable for a particular legal purpose,
or capable of detecting every privacy-relevant change.

The first-use acknowledgement documents that the scope notice was presented and 
acknowledged for that administrator account. It is not a contract replacing applicable
terms, does not constitute legal advice, and does not exclude or limit liability
or statutory rights where such exclusion or limitation is prohibited by applicable
law.

Nothing in this disclaimer excludes or limits liability where such exclusion or 
limitation is prohibited by applicable law.

Privacy Drift is an independent plugin and is not endorsed by, affiliated with, 
or sponsored by the WordPress Foundation or WordPress.org.

## ಸ್ಕ್ರೀನ್‌ಶಾಟ್‌ಗಳು

[⌊First browser scan: create a trusted baseline of the third-party services and 
technical privacy signals currently observed on the site.⌉⌊First browser scan: create
a trusted baseline of the third-party services and technical privacy signals currently
observed on the site.⌉[

First browser scan: create a trusted baseline of the third-party services and technical
privacy signals currently observed on the site.

[⌊Baseline changes: review Added and Removed external resources compared with the
trusted baseline.⌉⌊Baseline changes: review Added and Removed external resources
compared with the trusted baseline.⌉[

Baseline changes: review Added and Removed external resources compared with the 
trusted baseline.

[⌊Consent rejection test: compare observed activity before and after Reject and 
highlight optional-looking tracking that remains.⌉⌊Consent rejection test: compare
observed activity before and after Reject and highlight optional-looking tracking
that remains.⌉[

Consent rejection test: compare observed activity before and after Reject and highlight
optional-looking tracking that remains.

[⌊Review findings: inspect resource details and reversibly Mark as Expected when
a change is understood.⌉⌊Review findings: inspect resource details and reversibly
Mark as Expected when a change is understood.⌉[

Review findings: inspect resource details and reversibly Mark as Expected when a
change is understood.

[⌊Recent monitoring and Review & audit log: inspect scan changes, review decisions
and trusted-baseline approvals stored locally.⌉⌊Recent monitoring and Review & audit
log: inspect scan changes, review decisions and trusted-baseline approvals stored
locally.⌉[

Recent monitoring and Review & audit log: inspect scan changes, review decisions
and trusted-baseline approvals stored locally.

[⌊Privacy & Data Flows: review local storage, retention and the permission-gated
RDAP.org host-research data flow.⌉⌊Privacy & Data Flows: review local storage, retention
and the permission-gated RDAP.org host-research data flow.⌉[

Privacy & Data Flows: review local storage, retention and the permission-gated RDAP.
org host-research data flow.

## ಸ್ಥಾಪನೆ

 1. In WordPress, go to Plugins  Add New.
 2. Install Privacy Drift from the WordPress Plugin Directory, or upload the `privacy-
    drift.zip` file via Plugins  Add New  Upload Plugin.
 3. Activate Privacy Drift.
 4. Open Privacy Drift from the WordPress admin menu.
 5. Review the first-use scope notice and select “Got it — continue” when you understand
    the stated limitations.
 6. Run the first browser scan. The first successful browser scan becomes the trusted
    baseline used for later drift comparisons.
 7. Review the detected third-party services, cookies/storage names and any technical
    privacy-risk signals.
 8. Run additional scans after relevant site, plugin, theme or consent-manager changes
    to see what changed.

Privacy Drift stores scan and review data locally in the WordPress database. No 
account or external Privacy Drift service is required for the core plugin.

## FAQ

### Does Privacy Drift replace my cookie banner?

No. Privacy Drift does not collect consent or manage visitor choices. It observes
your existing website and can technically test supported or safely detectable Reject
behaviour.

### What happens after a WordPress or plugin update?

Run another browser scan manually. Privacy Drift compares the result with the trusted
baseline and shows Added and Removed external resources for review.

### Does Privacy Drift automatically scan after updates?

No update event triggers a browser scan or Consent rejection test, and the Free 
plugin sends no monitoring email alerts. A local daily server scan can run only 
when a server-mode baseline exists; it checks server-rendered HTML and does not 
replace a manual browser scan or Reject retest.

### What does the Consent rejection test verify?

It records observable third-party resource activity before Reject, triggers a supported
or unambiguous Reject/Decline action, and then records the resulting resources plus
browser-visible cookie/storage names. It tests technical behaviour in that page 
state, not whether the consent design or website is legally valid.

### Which consent plugins are supported?

Privacy Drift includes known Reject selectors for Complianz, Cookiebot, OneTrust,
CookieYes, Usercentrics, Real Cookie Banner and Borlabs Cookie. A conservative fallback
can use an unambiguous Reject/Decline action inside a clearly identified consent
container. If no safe action can be identified, Privacy Drift reports the banner
as unsupported instead of guessing.

### Does Privacy Drift collect cookie values?

No. It records browser-visible cookie names and local/session-storage names, not
their values.

### Does a clean result mean my website is GDPR compliant?

No. A clean result only describes the technical activity Privacy Drift observed 
in the tested state. It does not prove legal compliance or that no other privacy-
relevant processing exists.

## ‍ವಿಮರ್ಶೆಗಳು‍

ಈ ಪ್ಲಗಿನ್‌ಗೆ ಯಾವುದೇ ವಿಮರ್ಶೆಗಳಿಲ್ಲ.

## ಕೊಡುಗೆದಾರರು & ಡೆವಲಪರ್‌ಗಳು

“Privacy Drift” ಓಪನ್ ಸೋರ್ಸ್ ಸಾಫ್ಟ್‌ವೇರ್ ಆಗಿದೆ. ಕೆಳಗಿನ ಜನರು ಈ ಪ್ಲಗಿನ್‌ಗೆ ಕೊಡುಗೆ ನೀಡಿದ್ದಾರೆ.

ಕೊಡುಗೆದಾರರು

 *   [ Thomas ](https://profiles.wordpress.org/stermole/)

[“Privacy Drift” ಅನ್ನು ನಿಮ್ಮ ಭಾಷೆಗೆ ಅನುವಾದಿಸಿ.](https://translate.wordpress.org/projects/wp-plugins/privacy-drift)

### ಅಭಿವೃದ್ಧಿಯಲ್ಲಿ ಆಸಕ್ತಿ ಇದೆಯೇ?

[ಕೋಡ್ ಬ್ರೌಸ್ ಮಾಡಿ](https://plugins.trac.wordpress.org/browser/privacy-drift/), [SVN ರೆಪೊಸಿಟರಿ](https://plugins.svn.wordpress.org/privacy-drift/)
ಪರಿಶೀಲಿಸಿ, ಅಥವಾ [ಅಭಿವೃದ್ಧಿ ಲಾಗ್](https://plugins.trac.wordpress.org/log/privacy-drift/)
ಗೆ [RSS](https://plugins.trac.wordpress.org/log/privacy-drift/?limit=100&mode=stop_on_copy&format=rss)
ಚಂದಾದಾರರಾಗಿ.

## Changelog

#### 0.13.10

 * Removed automated monitoring mail and the Premium early-access mail flow from
   Free.
 * Added per-administrator, versioned and revocable RDAP permission before external
   host research; removed hidden DNS enrichment.
 * Added Privacy & Data Flows, WordPress privacy-policy guidance and administrator-
   data export/erasure, with complete multisite uninstall cleanup.
 * Removed inline presentation code and moved application state and local script
   translations to authenticated same-origin requests.
 * Hardened same-site redirects, response limits, input shapes, accessibility, keyboard
   focus and internationalization.
 * Added pinned coding/static-analysis gates, distributed-package egress checks 
   and observed runtime consent/egress tests.

Older release history is available in `changelog.txt`.

## ಮೆಟಾ

 *  Version **0.13.10**
 *  ಕೊನೆಯದಾಗಿ ನವೀಕರಿಸಿದ್ದು **10 ಗಂಟೆಗಳು ರ ಮುನ್ನ**
 *  ಸಕ್ರಿಯ ಸ್ಥಾಪನೆಗಳು **10 ಕ್ಕಿಂತ ಕಡಿಮೆ**
 *  ವರ್ಡ್ಪ್ರೆಸ್ ಆವೃತ್ತಿ ** 6.4 ಅಥವಾ ಹೆಚ್ಚಿನದು **
 *  **7.1** ವರೆಗೆ ಪರೀಕ್ಷಿಸಲಾಗಿದೆ
 *  PHP ಆವೃತ್ತಿ ** 8.0 ಅಥವಾ ಹೆಚ್ಚಿನದು **
 *  Language
 * [English (US)](https://wordpress.org/plugins/privacy-drift/)
 * ಟ್ಯಾಗ್‌ಗಳು
 * [consent](https://kn.wordpress.org/plugins/tags/consent/)[cookies](https://kn.wordpress.org/plugins/tags/cookies/)
   [GDPR](https://kn.wordpress.org/plugins/tags/gdpr/)[monitoring](https://kn.wordpress.org/plugins/tags/monitoring/)
   [privacy](https://kn.wordpress.org/plugins/tags/privacy/)
 *  [ಸುಧಾರಿತ ನೋಟ](https://kn.wordpress.org/plugins/privacy-drift/advanced/)

## ರೇಟಿಂಗ್‌ಗಳು

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/privacy-drift/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/privacy-drift/reviews/)

## ಕೊಡುಗೆದಾರರು

 *   [ Thomas ](https://profiles.wordpress.org/stermole/)

## ಬೆಂಬಲ

ಹೇಳಲು ಏನಾದರೂ ಸಿಕ್ಕಿದೆಯೇ? ಸಹಾಯ ಬೇಕೇ?

 [ಬೆಂಬಲ ವೇದಿಕೆಯನ್ನು ವೀಕ್ಷಿಸಿ](https://wordpress.org/support/plugin/privacy-drift/)