Privacy Drift monitors technical privacy changes on WordPress sites and explains them in plain language.
It helps answer:
The browser scan observes runtime requests and browser-visible cookie/storage names without collecting cookie or storage values. The first scan becomes a trusted baseline; later scans show added and removed findings.
Privacy Drift is a technical monitoring aid. It is designed to help website administrators identify privacy-relevant technical changes. It does not create, automate, certify or guarantee legal compliance.
The rejection test is a technical behaviour check. It loads a fresh page state in a sandboxed same-site browser frame, searches for a supported or unambiguous consent-banner Reject/Decline action, captures third-party activity before the choice, clicks Reject, waits for the page to settle and captures the resulting resources plus browser-visible cookie/storage names.
Results distinguish external resources observed before Reject, after Reject and newly appearing after Reject. Known analytics/advertising services and common analytics/advertising cookie names receive higher attention.
If Privacy Drift cannot safely identify a Reject action, it reports that limitation instead of guessing.
A successful rejection test is not a legal GDPR compliance verdict. It is technical evidence that can reveal obvious consent regressions such as analytics or advertising activity appearing before or remaining after a rejection action.
Privacy Drift follows a local-first approach for its core monitoring features.
Administrators remain responsible for the privacy implications of the WordPress site being scanned, including third-party services already configured on that site.
Open Privacy Drift Privacy & Data Flows for the full storage inventory and RDAP permission controls. Baseline and latest scan are replaced when approved or scanned respectively; history and audit log retain up to 100 entries each, Expected classifications up to 250 entries, and host intelligence up to 100 hosts. The latest consent-test result and local browser-scan counter are also retained. There is no automatic time-based expiry. URLs, hostnames, resource types, cookie/storage names, timestamps and technical results can be stored; URLs may contain personal information already present in the inspected website’s paths or query strings. Avoid testing pages containing sensitive personal data unnecessarily.
Audit events associate actions with a WordPress user ID without copying the user’s display name into new events. Administrator-linked acknowledgement, onboarding and RDAP permission metadata are local. WordPress personal-data export includes this metadata and that user’s audit entries. Erasure removes the metadata and anonymizes their identity in retained technical audit events, including legacy copied names; it does not erase unrelated site-wide technical findings. Privacy Drift also supplies suggested text to the WordPress Privacy Policy Guide for the site operator to review and adapt.
Temporary administrator view state (scroll position and expanded review/history details) uses the browser tab’s sessionStorage under privacyDriftExpectedViewportV1 and privacyDriftHistoryViewportV1. It is removed after restoring the view or when the tab session ends. It is not telemetry; uninstall cannot clear storage in an already open browser tab.
RDAP.org is the only third-party research service initiated by the Free plugin. A Research host action without current permission opens a disclosure before any external lookup:
Google, Meta, Stripe, Hotjar, HubSpot, YouTube, Maps and other service signatures are local classification rules, not requests to those companies.
Automated external notifications and email alerts are not part of the Free version.
Administrative mutations use WordPress capability checks and nonces. Browser-scan targets are restricted to the current WordPress site. Scan frames are sandboxed, do not permit top-level navigation, and use a no-referrer policy. Host research uses WordPress safe HTTP requests and only runs on demand.
Because browser-grade inspection intentionally executes the site’s own front-end JavaScript to observe runtime behaviour, administrators should only run browser/consent scans on the WordPress site they intend to inspect. Privacy Drift does not load arbitrary third-party scan targets in the admin frame.
Privacy Drift deliberately reports uncertainty where a technical result is not sufficient for a legal conclusion.
The first time each WordPress administrator opens Privacy Drift after installation or reactivation, the plugin displays a blocking scope modal explaining that findings are technical indicators rather than legal conclusions and that Privacy Drift does not guarantee regulatory compliance.
The administrator can acknowledge the notice with “Got it — continue”. The acknowledgement stores only a disclaimer version, activation identifier and UTC timestamp as user metadata in the local WordPress database. It does not transmit acceptance data, identity data or telemetry to the Privacy Drift operator, and it does not waive rights that cannot lawfully be waived.
Each activation starts a new local acknowledgement cycle, so every administrator must review and acknowledge the scope again after the plugin is reactivated. Scan results, trusted baselines and monitoring history are not removed by deactivation or by this acknowledgement reset.
For technical support, responsible security reports or questions about Privacy Drift data handling, contact: wordpress@stermole.at
Security issues should not be published publicly before a reasonable opportunity to investigate and provide a fix.
manage_options) to run scans and review findings.Privacy Drift is currently tested against WordPress up to version 7.1. Older WordPress or PHP versions are not supported.
Deactivating Privacy Drift stops the plugin but keeps its stored monitoring data so it can be reactivated later.
To remove Privacy Drift completely:
WordPress then runs the plugin’s uninstall routine. Privacy Drift clears its scheduled monitoring hook and removes its stored baseline, latest scan, monitoring history, audit log, Expected classifications, browser-scan count, host-intelligence cache, latest consent-test result, activation-cycle identifier, legacy Premium-waitlist state, and all plugin-specific first-use, onboarding and RDAP permission user metadata. On multisite it cleans the options and scheduled hook for every site and removes the shared plugin user metadata. Deactivation alone retains these records.
If you may want to keep the existing baseline and monitoring history, deactivate the plugin instead of deleting it.
Privacy Drift is a technical monitoring and diagnostic tool intended to assist website administrators in identifying privacy-relevant technical behaviour and changes. It is not legal advice, a legal audit, a certification service, a consent-management platform, or a guarantee of GDPR, DSGVO, ePrivacy, cookie-consent or other regulatory compliance.
No plugin can determine or provide complete legal compliance for a website. Legal obligations depend on the website operator, applicable jurisdiction, purposes and legal bases of processing, contracts, consent design, third-party services, organisational measures and facts that a technical browser scan cannot determine.
Privacy Drift can only report technical activity it is able to observe in the tested WordPress and browser state. Results can be affected by caching, consent-manager configuration, browser behaviour, conditional loading, logged-in state, geolocation, network conditions, A/B tests, third-party services and later site changes. A clear result does not prove that no other privacy-relevant processing exists. A warning or risk signal does not by itself establish a legal violation.
Website operators remain responsible for reviewing the results, configuring their website and consent mechanisms correctly, maintaining appropriate privacy notices and agreements, obtaining professional advice where appropriate, and determining the legal requirements that apply to their specific website and organisation.
Privacy Drift does not accept responsibility for legal decisions made solely on the basis of plugin output. To the extent permitted by applicable law, the software is provided under GPLv2-or-later without warranty; there is no warranty that the software will be error-free, uninterrupted, suitable for a particular legal purpose, or capable of detecting every privacy-relevant change.
The first-use acknowledgement documents that the scope notice was presented and acknowledged for that administrator account. It is not a contract replacing applicable terms, does not constitute legal advice, and does not exclude or limit liability or statutory rights where such exclusion or limitation is prohibited by applicable law.
Nothing in this disclaimer excludes or limits liability where such exclusion or limitation is prohibited by applicable law.
Privacy Drift is an independent plugin and is not endorsed by, affiliated with, or sponsored by the WordPress Foundation or WordPress.org.