Complianz: Automating Cookie Consent on WordPress (and the LiteSpeed Cache Fix You Shouldn’t Skip)

Complianz BV, a software company based in Groningen, in the Netherlands, publishes a WordPress plugin that has passed a million active installs, with a 4.7-star average across more than 1,600 reviews on the WordPress.org plugin directory as of August 2026. As we already covered in our step-by-step guide to installing a WordPress plugin, adding a new plugin is normally a five-minute job. Getting cookie consent right without babysitting it every week is the actual challenge: GDPR (the EU’s General Data Protection Regulation), CCPA (California’s Consumer Privacy Act), and the ePrivacy directive all expect a working banner, an accurate scan of what your site actually does, and legal pages that stay current. Let’s walk through what Complianz automates for you, and one caching conflict worth fixing on day one.

What Complianz actually does for your site

Complianz positions itself as what its own homepage calls the cookie consent solution trusted by “1 million users”, covering the pieces GDPR, CCPA, and the ePrivacy directive actually ask for: a cookie banner that blocks scripts until a visitor consents, an automatic scan of the cookies your site sets, and legal documents, a privacy policy and a disclaimer among them, generated from your answers to a short wizard. The free version, available directly from the WordPress plugin directory, already covers a fully functional banner, the automatic scan, script blocking, and the policy generator, with GDPR, CCPA, and ePrivacy support built in and no cap on consent records. It’s the kind of tool you’d reach for after outgrowing a manual “add a cookie notice” plugin, without yet needing an external consent-management platform billed separately from your hosting.

Installing Complianz and running your first scan

From your WordPress dashboard, search for “Complianz” through Plugins → Add New, listed there as the Complianz — GDPR/CCPA Cookie Consent Banner plugin, and install it the same way as any other plugin. The first screen you land on afterward is the setup wizard, not a scan: you tell it your site’s target regions, the EU, California, or both, before Complianz scans your pages for cookies and third-party embeds. In one public walkthrough of that scan, the WordPress consultant known as Ferdy says he ran it against his own site and it surfaced 25 cookies, cross-checked against the cookiedatabase.org reference list, a demonstration of scope rather than a guaranteed count for every site (yours will differ).

Close-up of a person's hands typing on a laptop keyboard
Running the first scan and reviewing what it turns up takes a few minutes, but it’s worth reading closely.

One honest caveat worth carrying into that first scan: according to an independent review by devowl.io, Complianz’s own documentation acknowledges the automatic scan doesn’t reliably catch every third-party cookie, particularly ones injected by scripts loaded from elsewhere. A manual pass through your site’s actual cookie list after the automatic scan is worth the ten minutes it takes, rather than trusting the scan as the final word.

Walking through the compliance wizard

The wizard walks through the parts of a site that usually create cookies without an owner necessarily noticing: user accounts and login forms, contact and newsletter forms, an analytics tool like Google Analytics, embedded social media posts, and any advertising scripts. Answer honestly for each category, and Complianz adjusts both the scan and the legal pages it’s about to generate. Once the wizard finishes, it drafts the missing legal pages, typically a privacy policy and a cookie policy, and links them into your site’s footer automatically, so you’re not hand-building pages you’d otherwise copy from a template.

Two colleagues in an office reviewing printed documents together
Read through the generated pages once yourself before you consider the legal side settled.

Complianz is explicit that this automation helps you structure compliance, not that it guarantees it: a generated privacy policy still needs a read-through for anything specific to your business, and no plugin can promise your site is fully compliant on your behalf.

Customizing the banner to match your brand

Once the legal groundwork is in place, the banner itself lives on a separate settings screen: colors, the corner radius on the buttons, and a custom CSS box if you want finer control than the visual options expose. The defaults are unobtrusive enough to ship without touching them, but matching your site’s palette takes a few minutes and reads as more deliberate to a visitor than a generic grey bar bolted onto the bottom of the page.

Free plugin or a paid plan: what you actually need

Complianz pricing plans: Personal, Professional, and Agency
Complianz’s three annual plans, priced by number of sites rather than by page count.

Complianz sells three annual plans directly from complianz.io/pricing: Personal at $59 (€35) for one site, Professional at $179 (€109) for five sites, and Agency at $399 (€239) for twenty-five sites plus a bundled multisite plugin for cross-domain consent, each backed by a 30-day refund window. What the free version already gives you, the banner, the scan, script blocking, and the policy generator, covers a single small-business site reasonably well. The paid tiers add geo-targeted banners and legal documents for visitors in different regions, A/B testing with statistics on banner performance, an audited log of who consented and when, and certification under the Transparency and Consent Framework run by the Interactive Advertising Bureau, relevant if your site runs programmatic advertising. If none of that applies to you, the free version is, in practice, where most single-site WordPress owners should start, with the paid tiers mainly earning their keep through the features above: regional targeting, A/B testing, the consent log, and IAB TCF certification.

THE catch: Complianz and LiteSpeed Cache don’t get along by default

If your host runs LiteSpeed Cache, a caching layer bundled by default on plenty of shared hosting plans, there’s a specific conflict worth fixing before you consider the setup finished. A cached page can be served to a visitor before Complianz’s own script gets a chance to run, so the banner never appears at all, not delayed, just absent, while scripts that should have waited for consent load anyway. It isn’t a bug in either plugin so much as a timing collision: the cache serves a saved snapshot faster than the consent script can attach itself to the page. This isn’t a rare edge case: it shows up across at least six separate WordPress.org support threads, all describing the same symptom on LiteSpeed-cached sites.

Complianz official instructions for excluding scripts in LiteSpeed Cache
Complianz’s own fix page for the LiteSpeed (and WP Rocket) caching conflict.

Complianz’s own fix, documented on its support site, is a short list of manual exclusions rather than a single toggle, so it takes a few minutes of copy-pasting rather than one click. In LiteSpeed Cache, under Page Optimization → Tuning, add these paths to the JS Excludes field: complianz, cmplz, complianz-gdpr-premium/pro/tcf/build/index.js, complianz-gdpr-premium/pro/tcf-stub/build/index.js, complianz-gdpr-premium/cookiebanner/js/complianz.min.js, and complianz-gdpr/cookiebanner/js/complianz.min.js (the free and premium versions live at different paths, so both are worth adding even if you only run one). If Load JS is set to Deferred or Delayed under the JS Settings tab, repeat the same list in the JS Deferred/Delayed Excludes field. Then, under the Tuning – CSS tab, add cmplz, complianz-gdpr-premium/assets/css/*, complianz-gdpr-premium/cookiebanner/css/*, complianz-gdpr/assets/css/*, and complianz-gdpr/cookiebanner/css/* to the CSS Excludes, UCSS File Excludes, and Inline fields. THE fix takes about five minutes once you know where to paste it; skipping it means every visitor on a cached page loads your site’s scripts with no consent prompt in front of them.

How Complianz compares to an external service like Cookiebot

Complianz isn’t the only way to run cookie consent on WordPress. Cookiebot, now sold under the Usercentrics brand after Cookiebot’s standalone plans were folded into it, is a common point of comparison. The two aren’t quite the same shape of tool: Complianz is a WordPress plugin billed per site, while Usercentrics’ Cookiebot integration is a hosted service billed per subpage crawled, free up to 50 subpages on a domain and starting at €7 a month above that, scaling through named tiers as a site grows. For a single WordPress site with a modest page count, that structural difference usually favors Complianz’s flat per-site pricing; for an agency running consent across non-WordPress properties too, or needing subpage-level control Complianz doesn’t offer, the calculation can go the other way. Neither is a universally better tool, just a different pricing shape for a different kind of site portfolio.

Our take

Complianz earns the trust its own homepage claims, “1 million users,” more honestly than most plugin taglines do: the free tier alone covers what a small WordPress site actually needs for cookie consent, and the paid tiers exist for genuinely different use cases, agencies, regional targeting, ad-network certification, rather than gatekeeping basic functionality behind a paywall. The one step we’d flag as non-optional, not just recommended, is the LiteSpeed Cache exclusion list if that’s your caching layer, since a silently absent banner defeats the entire point of installing a consent plugin in the first place.

Here’s where that leaves you, depending on your setup:

  • If you run a single WordPress site and don’t run programmatic ads, install the free version, run the wizard once, and stop there.
  • If your host runs LiteSpeed Cache, apply the JS and CSS exclusions above before you consider the banner live, then reload a cached page in a private window to confirm it actually shows.
  • If you manage several sites or need geo-targeted consent, compare the Professional and Agency plans against what you’d pay for a per-subpage service like Cookiebot before committing to either.
  • Whichever route you take, read the generated privacy policy once yourself; treat it as a solid draft, not a finished legal document.

As with any plugin you’re evaluating for the first time, our guide to choosing WordPress plugins and their pitfalls is worth a look before you commit to your final settings. Test any consent tool on a staging copy of your site first, and confirm the banner actually blocks scripts before you call the setup done.