Skip to main content

WordPress Plugin

The Contentpass WordPress Plugin integrates Contentpass with your WordPress site and supports multiple Consent Management Platforms (you can find the full list here). It includes a built-in script and iframe blocker to prevent third-party resources from loading before consent.

1. Create a Contentpass account and property

Go to publisher.contentpass.net and create your publisher account. The wizard will guide you through the steps of creating a publisher profile as well as the first property. The property's status page will present the required steps for a successful Contentpass integration. This document contains further details that should help you with the process.

You will need your Property ID and Base URL for the plugin configuration. These can be found in your property's settings in the Publisher Dashboard.

2. Install the plugin

  1. In WordPress Admin, go to Plugins → Add Plugin.
  2. Search for Contentpass Integration and install it from the WordPress plugin directory.
  3. Activate the plugin.
  4. After activation, the Contentpass menu appears in the WordPress admin sidebar with three items:
    • Integration – CMP and Contentpass configuration
    • Blocking Rules – Third-party script blocking
    • Request Contract – Link to contact form

3. Configure CNAME

Since 3rd-party cookies don't work reliably anymore in most browsers, Contentpass subscribers must be identified using a 1st-party session.

To simplify handling of these 1st-party sessions, Contentpass provides an endpoint that must be configured behind a CNAME subdomain of the publisher's first-party domain.

In the following example we assume that the publisher's website is: https://www.example.com and the propertyId is 1234abcd. You can find your propertyId in the settings of your property. Can't find it? Get in touch with us to obtain your propertyId.

A CNAME must be set up as follows:

cp.example.com. 300 IN CNAME 1234abcd.12.with.contentpass.net.

Once the CNAME has been set up, Contentpass will automatically provision the required SSL certificates.

The plugin automatically checks if the CNAME is set up. As soon as it's found, the plugin will display the full Integration settings form and you can continue integration.

info

DNS propagation can take up to 24 hours. If the CNAME has just been configured, please try again later or use the "Check again" button on the Integration page.

4. Fill out the Integration page

Once the CNAME is configured and verified, the full Integration form will be available under Contentpass → Integration.

CMP integration mode

Choose how the plugin handles your CMP:

  • CMP already integrated on my site – The plugin loads only the Contentpass stub for the selected CMP; it does not load the CMP script.
  • Plugin should also load the CMP (default for new setups) – The plugin loads the CMP and Contentpass.

Click Save after changing the mode. CMP credential fields only appear when Plugin should also load the CMP is selected.

Common fields (all CMPs)

FieldDescription
Base URLThe CNAME subdomain for your property (e.g. cp.example.com). Usually pre-filled from your site domain.
Property IDYour Property ID from the Publisher Dashboard (e.g. abc123). When you open a property in the dashboard, it also appears as the last segment of the URL in your browser's address bar (e.g. the abc123 in .../properties/view/abc123).
CMPSelect your Consent Management Platform. After choosing and saving, CMP-specific fields will appear (only when Plugin should also load the CMP is selected). If the CMP is already on your site, choose CMP already integrated on my site under CMP integration mode instead.
Debug URL passwordPassword required for debug URL query parameters (see Debug URLs below). Logged-in WordPress administrators (manage_options) may omit the password.
Code to load after consentOptional custom <script> or <style> blocks that load after consent. Only <script> and <style> tags are allowed.

Where to find CMP-specific IDs

Depending on the CMP you select, additional fields will appear. Use the tabs below to find each value in your CMP's dashboard:

When Plugin should also load the CMP and Consentmanager is selected, paste the external semi-automatic <script> snippet from Consentmanager → Get Code into the textarea in the plugin settings. Use the semi-automatic snippet, not the automatic-blocking snippet (typical src: https://cdn.consentmanager.net/delivery/js/semiautomatic.min.js).

The plugin validates the snippet (allowed hosts and allowlisted data-cmp-* attributes only).

Consentmanager ID (cmID)

  • Go to your Consentmanager client and select your CMP.

  • The ID is shown in the script snippet or in the CMP settings (e.g. in the URL or under "CMP ID").

  • It is a numeric value like 12345 or an alphanumeric identifier.

CMP-specific steps

By default, the plugin runs in staging mode until your Contentpass property is live. While staging is active, anonymous visitors see no Contentpass, no CMP (from the plugin), and no script blocking or placeholders; only logged-in Editors and Administrators see the full integration. Staging is forced when Contentpass config.json has isApproved=false or isLive=false — you cannot disable it in WordPress until the property is live.

Debug URLs

Set a Debug URL password under Contentpass → Integration, then append these query parameters to any front-end URL:

  • ?cpdebug=settings&cpdebug_key=PASSWORD — logs front-end plugin config to the browser console only; does not load Contentpass.
  • ?cpdebug=staging&cpdebug_key=PASSWORD — loads the full integration (Contentpass + CMP + blocking) for that request, even for anonymous visitors.

Without a saved password, debug URLs have no effect for anonymous visitors. Logged-in WordPress administrators (manage_options) may omit cpdebug_key. Full-page cache or CDN may serve stale HTML — purge cache or test with a fresh query string after changes.

There are no specific steps for other CMPs aside from those in the tabs above.

5. Block third-party resources ("Blocking Rules")

To comply with Contentpass requirements, third-party resources (scripts, iframes) must not load before the user has given consent. The plugin includes a script and iframe blocker for this purpose. Script blocking follows the same staging rules as Contentpass and the CMP: in staging, only the preview audience (Editors/Administrators) is affected; in production, all visitors.

info

Visit our docs on Third Party Resources for more information on how to block third parties and the technical details on why this is important.

Using the Blocking Rules page

Go to Contentpass → Blocking Rules in the WordPress admin.

Block List (Scripts to Block)

Add URL patterns that should be blocked until consent is given. Any script or iframe whose src contains the pattern will be blocked and replaced with a placeholder (or hidden, if configured via the checkbox).

ColumnDescription
URL / Script SourceA substring of the URL to block (e.g. facebook.com, youtu.be, googletagmanager). It does not have to be a full URL.
Vendor nameWhen set, it will overwrite the automatically detected vendor name in the placeholder.
Privacy LinkOptional, but highly recommended to be set URL to the service's privacy policy. Shown below the placeholder button.
Hide PlaceholderWhen enabled, the content is blocked without showing a visible placeholder (stealth mode).
tip

Examples of useful patterns: doubleclick, analytics, facebook, youtube, googletagmanager, hotjar.com.

Please check the findings on the Publisher Dashboard for your site to identify third-party resources to block.

6. Mention Contentpass in your Privacy Policy

While we do not process any data of non-subscribers, we receive the IP addresses of your visitors for technical reasons. Please inform your visitors about this data processing and link to our privacy policy by including the following snippet on your privacy policy page:

Contentpass

Auf unserer Website bieten wir Ihnen einen Service zum werbe- und tracking-freien Zugang mit Contentpass an. Dies ist ein Angebot der Content Pass GmbH, Wolfswerder 58, 14532 Kleinmachnow, Deutschland. Beim Abschluss des Service wird Contentpass Ihr Vertragspartner.

Um Ihnen diesen Service auf unserer Website anzuzeigen und damit anbieten zu können, verarbeitet Contentpass, in unserem Auftrag, mit dem Besuch unserer Website Ihre IP-Adresse. Für die Registrierung sowie die Vertragsabwicklung des Contentpass und die damit einhergehende Datenverarbeitung ist Contentpass Verantwortlicher im Sinne der DSGVO. Wir sind ausschließlich Verantwortlicher für die Verarbeitung Ihrer IP-Adresse.

Grundlage für die Datenverarbeitung der IP-Adresse, im Rahmen unserer Auftragsverarbeitung mit Contentpass, ist unser berechtigtes Interesse Ihnen die Möglichkeit zu bieten, unsere Website werbe- und tracking-frei aufrufen zu können und Ihr Interesse an der Nutzung unserer Website praktisch ohne Werbung und Tracking [Art. 6 Abs. 1 lit. f) DSGVO]. Zudem erfüllen wir hiermit die rechtliche Verpflichtung, eine rechtskonforme Einwilligung in einwilligungsbedürftige Datenverarbeitungen einzuholen [Art. 6 Abs. 1 lit. c) DSGVO].

Bitte klicken Sie auf die folgenden Links, um mehr zum Datenschutz bei Contentpass zu erfahren, sich in Ihr Contentpass-Konto einzuloggen, oder sich für Contentpass zu registrieren.

Note:

Link target for login:

javascript: cp('login');

Link target for signup:

javascript: cp('signup');
tip

Since these are not quite ordinary links, it may happen that your CMS does not support them. In that case, you can simply link to https://www.contentpass.net/login and https://www.contentpass.net/signup instead.

7. Using the cpauthenticated CSS class

While the stealth mode hides the placeholder, it does not automatically hide its parent container, to not interfere with your website and possibly hide other elements within this container you wish to not hide.

To improve the experience for Contentpass subscribers (e.g. hiding ad slots), the Contentpass script adds the class cpauthenticated to the <body> when the user is logged in and has a valid subscription.

You can use this in your CSS to adjust layout for subscribers:

/* Hide ad containers for Contentpass subscribers */
body.cpauthenticated .ad-container {
display: none;
}
info

Apply this CSS as early as possible to avoid layout shifts—e.g. in the first CSS file loaded or as high as possible in the <head>.

warning

We do not recommend relying on this as a robust method for recognizing Contentpass users for business logic. CSS classes can be easily manipulated by the user or any other javascript running on the page. Additionally there is no guarantee that the CSS styles are applied before your javascript runs.

For more examples of styling with cpauthenticated, refer to the Web SDK documentation and the Contentpass integration guides for your CMP.

8. Placeholder CSS settings in Block Scripts

The Blocking Rules page includes a Placeholder Styling section to customize the appearance of blocked content placeholders.

A live preview (desktop, tablet, mobile) shows how the placeholder will look with your current settings.

Button text and privacy link text must be customized per language. The provided languages are configured in the settings in our Publisher Dashboard.

SettingDescription
Border ColorColor of the placeholder box border (default: #212121).
Border WidthBorder width (e.g. 2px).
PaddingInternal spacing of the box (e.g. 20px).
Background ColorBackground color of the placeholder (default: #f5faff).
Background ImageOptional background image URL.
Text ColorColor of the placeholder text.
Border RadiusCorner roundness (e.g. 8px).
Button BackgroundBackground color of the "Load" button.
Button Text ColorText color of the button.
Content AlignmentText alignment inside the box (left, center, right).
Placeholder TextHTML template. Use {name} for the automated script/iframe name and {type} for script or iframe.
Button TextTemplate for the button label (supports {name}).
Privacy Link TextTemplate for the privacy link. Use [priv]…[/priv] to mark the clickable part (e.g. Read more [priv]here[/priv]). This is a dummy for the privacy link provided in the block list. There is no link needed here and only text must be provided.
Additional CSSExtra CSS rules for the placeholder box (e.g. box-shadow, font-size).