2026-10-04 ยท CPH Site Compliance Desk for WordPress
Initial test release of a separate website-review plugin: sixteen evidence-led review areas, selected privacy and image-rights controls, and a private agent API.
What changed
- Adds sixteen review areas with responsible owners, evidence methods, reasons for failed or not-applicable decisions, review dates and history. Every item begins unreviewed; expired reviews and relevant configuration or policy changes invalidate prior conclusions.
- Adds a business applicability profile, third-party service inventory, private request tracking, evidence export and revision-protected WordPress-authenticated API routes.
- Adds optional consent controls for configured classic WordPress scripts and managed embeds, including rejection, acceptance, withdrawal, cached-response safety and GPC suppression of managed marketing. Consent ownership is explicit and controls start disabled.
- Adds purpose-based image alternatives, recorded image-rights evidence and optional checks before new post/page publication. Existing published content is preserved.
- Adds configured links to reviewed public policy pages, collection and affiliate disclosure shortcodes, and signed-in acceptance receipts tied to the exact current terms version.
Verification
- Passed 230 assertions against an isolated WordPress installation: 113 review/API/terms checks, 51 content and publication checks, and 66 real WordPress consent-output checks. Test fixtures were cleaned up and saved settings restored.
- Passed 13 Node tests covering preference validation, dependency ordering, repeated activation, withdrawal, GPC, mounted controls and script gating. All plugin PHP files passed syntax validation.
- Inspected the rendered review desk and consent dialog in Chrome. A local fixture recorded zero optional requests before choice and after rejection, one after acceptance, and no additional request after withdrawal. With simulated GPC, marketing remained disabled after acceptance. Tab and Escape behavior restored focus correctly.
- Reviewed checklist wording against official accessibility, privacy, consumer-protection and related sources. A reference guide is included; this is not a site-wide accessibility audit or legal certification.
Rollout
Isolated-test candidate only. No production website has this plugin installed by this release. The installable package is prepared after these notes are published; production rollout remains pending site selection and integration testing.
Updating
- This is a new, separate plugin. Upload the ZIP into an isolated WordPress test site and open Tools > Site Compliance Desk. Requires WordPress 6.5+, PHP 8.1+ with DOM and mbstring, and MySQL/MariaDB with named locks and InnoDB transactions.
- Inventory data recipients and establish business applicability before recording reviews. Keep one consent owner, map only optional script handles, and test actual requests and complete journeys before enabling controls in production.
- Deactivation retains records but stops the plugin's controls. Replace any active consent or publication gate deliberately before removal; preserve evidence according to the business's reviewed retention policy.
Scope and limitations
- The plugin does not certify compliance, provide an accessibility overlay, generate legal policies, or establish that any law applies to a business. Keyboard, screen-reader, media, policy and specialist legal reviews remain necessary.
- Consent gating covers configured classic WordPress script handles and managed embeds. Raw theme tags, script modules, server-side tracking, unconfigured integrations, vendor opt-out propagation and third-party cookies need separate integration and testing. Preferences are not a central legal consent audit log.
- Stored-content scans and image-rights checks do not inspect every rendered theme, dynamic block, CSS asset or custom publishing path. Recorded evidence does not prove ownership, and existing published content is not retroactively changed.
- Request tracking and terms receipts do not execute vendor erasure, refunds, cancellation, subscription billing, marketing consent or email/SMS suppression. Those systems require their own working integrations and evidence.