Key takeaways
A free cookie banner can be a sensible starting point. It can also be only a visible notice. Those are very different things. A banner that offers “Accept” and “Reject” while non-essential analytics or advertising tags have already run has not solved the timing problem; it has only put a choice on screen after the relevant technical event. Test behaviour rather than trusting the banner’s appearance.
Updated: 29 August 2026 · Last reviewed: 29 August 2026
There is no single best free option. Hosted freemium products can reduce setup work but may limit traffic, pages, domains, features, or support. Open-source projects can remove subscription cost but transfer scanning, script mapping, records, updates, hosting, and testing to your team. A manual implementation offers maximum control only if someone can maintain it.
Choose with five questions: what fires before a choice, how is it held back, can you evidence choices, does it pass the consent signals your advertising stack needs, and who owns the work when the site changes? This is an unranked, criteria-led guide—not a legal opinion or a performance ranking. Free plans and product terms change, so confirm the provider’s current documentation before rollout.
Disclosure: ConsentEase, the publisher of this article, is a consent management platform vendor. This guide is not independent procurement advice; verify every option against your technical, operational, and legal requirements before choosing.
Free routes: capability meets maintenance
| Responsibility | Hosted free tier | CMS plugin | Open source | GTM / manual |
|---|---|---|---|---|
| Banner UI | Usually possible | Usually possible | Usually possible | Usually possible |
| Discovery / inventory | Scope may be limited | May need a separate process | Usually your process | Your process |
| Prior control | Verify integrations | Configure every relevant path | Precise when integrated | Entirely yours |
| Consent records | Check export and retention | Design or confirm storage | Often your responsibility | Your evidence design |
| Platform signals | Check plan and setup | May need custom integration | Configure supported paths | Configure supported paths |
| Maintenance owner | Provider + site owner | Plugin / theme team | Engineering team | Named internal owner |
Test the delivered page: inspect clean-session requests, storage, tag behaviour, refusal, withdrawal, records, and the change process—not only the banner surface.
A banner is not the whole consent implementation
“Free cookie banner” is an imprecise shopping category. It can describe a WordPress plugin that draws a notice, a hosted consent management platform (CMP), a JavaScript library, a Google Tag Manager template, or a few lines of custom code. Their common output is a user interface. Their operational responsibilities are not the same.
For an EU-facing website, the practical starting point is commonly Article 5(3) of the ePrivacy Directive as implemented in relevant national law. It addresses storing information on, or accessing information from, a visitor’s device. GDPR can also apply when personal data are processed. The exact legal position depends on the technology, purpose, applicable national law, and facts. This article explains implementation choices; it does not decide whether a particular cookie or tag is exempt. Our guide to the ePrivacy Directive explains the framework in more detail.
The operational lesson is clear: assess the page’s behaviour before a visitor makes a choice, not just the copy on the banner. A useful implementation separates six jobs.
| Job | What it means | Why a free option may differ |
|---|---|---|
| Banner UI | Displays notice, purposes, accept/reject controls, and preference centre | This is the most visible and often easiest part to provide free. |
| Discovery | Finds cookies, tags, embeds, local storage, and changing page templates | Some tools scan automatically; a library or manual build needs an inventory process. |
| Prior control | Stops optional technology from loading or operating until the applicable choice | It requires integration with every tag path, not merely a banner setting. |
| Consent records | Retains evidence of the choice, notice/configuration context, and change history | Browser-only storage may be useful technically but may not meet a team’s evidence needs. |
| Platform signals | Sends choices to systems such as Google tags where configured | Support, setup scope, and available controls vary by product and plan. |
| Operations | Updates, monitoring, support, accessibility work, and regression testing | A subscription can shift work to the vendor; open source and DIY retain it in-house. |
Do not treat the rows as a checklist that automatically proves compliance. They are separate engineering and governance tasks. A provider can offer a polished UI while asking you to configure every script gate. Conversely, a self-hosted library can be technically capable but leave your team responsible for records, releases, and keeping its configuration accurate.
The free routes: an unranked decision framework
This guide groups options by delivery model rather than declaring winners. Vendors appear as examples of routes that are publicly documented as of the review date. Inclusion is not an endorsement, and omission is not a negative finding. We have not assigned scores for scan coverage, page speed, support quality, or legal outcomes because doing so would require a controlled, repeatable test and broader evidence.
1. Hosted freemium CMPs
Hosted CMPs usually combine a banner with a dashboard and vendor-managed software. Their free tiers can be appropriate for a small, stable site if the published allowance and feature set match the site’s needs.
CookieYes publishes a free plan and describes it as including up to 5,000 pageviews per month, one website, a cookie scanner, and Consent Mode support. Its pricing and feature pages should be the source of truth for current entitlements. That can make it a practical route for a low-traffic site, but check what happens at the allowance, which customization and geotargeting controls apply to the plan, and whether the current configuration covers every tag you use.
Cookiebot by Usercentrics publishes a free subscription for a single domain with up to 50 subpages. Its documentation also describes Google Consent Mode support. The page-based allowance is especially important for a site with a blog, product catalogue, or language variants: count the pages that the product defines as in scope, rather than assuming that a small homepage means a small implementation.
Termly publishes a free plan for its consent management product and identifies a monthly banner-view allowance on its pricing page. It also documents automatic blocking as a product capability. Before depending on the free tier, verify the current allowance, the region and languages needed, the set-up steps for your particular scripts, and whether you can retrieve the records your organisation needs.
These examples are not interchangeable. “Free” may be limited by pageviews, banner views, pages scanned, domains, features, or a combination. A cap does not itself make a product unsuitable. It means you need an owner who watches usage and a plan for the point at which the site exceeds it.
2. A WordPress plugin free tier
For a WordPress-only site, a plugin can be convenient because its configuration lives near the theme and plugins that introduce many trackers. Complianz offers a free WordPress plugin, while its published comparison of free and premium features identifies some advanced functions—including Google Consent Mode integrations—as premium capabilities. Confirm the current feature matrix for the edition and region you use rather than relying on an old tutorial.
A plugin does not eliminate the integration problem. A tag can enter WordPress through a theme header, a page builder, a caching/optimization plugin, WooCommerce extension, embedded video, custom code, or Google Tag Manager. The consent plugin has to see or govern the relevant path. Changes to plugins, themes, caching, and script optimization can also change execution order.
The route fits best when WordPress is the only property, someone can keep plugins updated, and the team is willing to test templates after changes. It may fit less well when the same brand runs a separate shop, app, campaign landing pages, or several CMSs that need one governance process. See our WordPress consent setup guide for the implementation issues to test.
3. Open-source and self-hosted projects
Open source can be a strong answer when an organisation has the engineering capacity to own the result. It does not mean that discovery, enforcement, evidence, hosting, and change management happen automatically.
Silktide Cookie Banner is published as an open-source project and its official site presents it as free to use. Its documentation describes features including Google Consent Mode support and script blocking. That makes it worth evaluating for teams able to integrate and maintain a front-end library. Read the project licence, documentation, release notes, accessibility information, and implementation instructions directly; “open source” says something about the code licence and availability, not about a completed configuration on your website.
Klaro! is another open-source consent manager. Its project documentation explains that services and purposes are configured by the implementer. That explicit configuration can be an advantage: a developer can decide precisely how a service is loaded and what choice it requires. The corresponding obligation is to maintain the list when marketing adds a pixel, a developer adds an embed, or a vendor changes its implementation.
An open-source library is not automatically a scanner or an audit-record service. If those functions are absent or you do not configure them, build a process around the gap: inventory the site, document changes, retain appropriate evidence, and test releases. Budget for engineer time, code review, accessibility review, security patching, hosting where relevant, and incident ownership—not only the zero licence fee.
4. Google Tag Manager-led or manual implementation
Some teams build a lightweight consent layer in Google Tag Manager (GTM) or in their own application. Google documents consent mode and GTM consent settings, but Google’s product documentation is not a substitute for implementing a banner, deciding categories, or ensuring that unrelated tags do not run prematurely.
A manual route typically needs all of the following:
- a clear mechanism to save and retrieve a visitor’s preference;
- a default state that is applied before relevant Google tags execute;
- triggers or code paths that hold each optional vendor until the matching choice;
- a way to enable, deny, and withdraw categories consistently;
- a method to show the right information and controls to the visitor;
- records and configuration history appropriate to the organisation’s accountability needs; and
- regression testing whenever a tag, container, plugin, template, or app release changes.
This can be the lowest-cash route for a small, developer-run product with few optional services. It becomes fragile when multiple people can publish tags, when there are several sites, or when the person who built it is unavailable. Treat custom consent code as a maintained product component, with tests and a named owner.
Compare scope, not marketing labels
The table below is deliberately qualitative. Exact allowances and plan boundaries move frequently. It identifies what to verify, rather than presenting a stale price comparison or an invented feature score.
| Route | Banner UI | Scanning and inventory | Blocking/control | Records | Updates and support | Typical trade-off |
|---|---|---|---|---|---|---|
| Hosted freemium CMP | Usually included | Often offered, but scope can vary | May be automated or require tag configuration | Often dashboard-based; check export and retention | Vendor releases; free support may be limited | Allowances, branding, plan-gated controls, or growth cost |
| WordPress free plugin | Usually included | May scan or classify within WordPress | Depends on plugin coverage and how tags enter the site | Check edition, storage, and export | Plugin/theme/cache compatibility remains yours | WordPress-only scope and plugin maintenance |
| Open-source library | Configurable | Usually a separate process unless supplied | Can be precise when correctly integrated | Often your design responsibility | Community/project releases; your team operates it | Engineering and governance cost |
| GTM/manual build | Entirely yours | Your inventory process | Entirely dependent on your implementation | Your storage and evidence design | Your release, monitoring, and support burden | Flexibility with the highest ownership burden |
Use the table to expose a common mistake: comparing a free banner UI to a paid managed CMP as if both include the same operational work. They may not. A lower subscription cost can be a good decision when the team knowingly accepts the work. It is a poor decision when everyone assumes that blocking, records, and updates are included but nobody owns them.
Five questions to ask any free tool
Does it stop the actual technology before the relevant choice?
Ask for a description of what the tool controls: HTTP cookies only, scripts, tags, iframe embeds, local storage, or a limited integration list. Then test your own site. In a clean browser profile, visit important pages before clicking the banner. Inspect network requests, storage, and tag activity. Repeat after rejecting all optional categories, accepting only one category, and withdrawing a previous choice.
Do not infer success from a vendor saying “auto-blocking.” It may need attribute changes, GTM configuration, a specific installation position, manual classification, or exclusions for optimization tools. Our guide on blocking cookies before consent explains why execution order matters.
What evidence can we retrieve?
Where consent is relied on, an organisation may need to demonstrate its process. Ask what is recorded, where it is stored, how long it is retained, whether you can export it, how configuration and notice versions are associated with a choice, and who can access it. Avoid treating a preference cookie in one browser as equivalent to a complete organisational evidence process.
The answer need not force every hobby project into enterprise recordkeeping. It should match the organisation’s risk, scale, jurisdictions, and accountability requirements. Document the decision and seek legal advice where the evidence standard is uncertain.
Does our Google setup require Consent Mode, and can we configure it correctly?
Google explains that Consent Mode adjusts Google tag behaviour based on consent choices. Organisations using Google advertising or measurement should read Google’s current requirements and implementation documentation, then test the signals on their own deployment. A tool’s marketing claim that it “supports Consent Mode” does not show that your container defaults, update calls, tag order, and consent choices are correct.
Consent Mode is not a general legal-compliance certificate, and it does not block every non-Google vendor. It is one integration in a wider consent implementation. For a careful walkthrough, see Google Consent Mode v2 explained.
What is limited, and what happens when we exceed it?
Read the plan page for limits on domains, subpages, pageviews, banner views, scans, languages, users, exports, integrations, or support. Clarify whether a limit stops serving the banner, stops scanning, prevents new records, triggers an upgrade, or merely sends an alert. Keep a record of the plan page and terms reviewed at the time you choose.
Also model normal growth: new articles, product pages, localized versions, ad campaigns, and seasonal traffic. The relevant cost is not only today’s free allowance but the transition path when it no longer fits.
Who maintains the implementation after launch?
Name an owner. That person does not have to be a lawyer or full-time privacy specialist, but they need authority to coordinate releases. Their recurring work includes reviewing new tags, testing campaign pages, updating vendor lists and categories, checking that refusal still works, and responding when a provider changes features or documentation.
This question is particularly important for open source and DIY, but it applies to hosted tools too. A CMP can make configuration easier; it cannot know that an agency pasted a new pixel into a landing-page template unless the site and process reveal it.
Which route fits which situation?
A hobby, portfolio, or pre-revenue site
Free can be proportionate where the site has very little optional technology, a stable design, and an owner who can test it. Start by reducing the number of third-party services rather than adding a complicated control layer around them. A hosted free tier or a simple, carefully configured open-source tool can be reasonable. Keep an inventory and retest after changes.
A brochure site that collects leads
A lead-generation site often adds analytics, forms, chat, video, scheduling, and campaign tags over time. Choose a route that makes the owner visible and has a workable process for new services. The decision may still be free, but do not select it solely because the banner can match your brand. Check blocking, records, usage limits, and the pages created by campaigns.
An ecommerce site
Commerce sites have more templates, third parties, checkout flows, plugins, and seasonal changes. Essential functions such as a shopping basket need a fact-specific assessment; marketing and analytics services should not be casually labelled essential because they help the business. Prioritize testing across product, cart, checkout, account, and localized templates. Managed support or a mature plugin workflow may be worth more here than the lowest initial cost.
A site using Google Ads or other advertising platforms
Start with the platform’s own current documentation and the tags actually deployed. Confirm whether Consent Mode is needed for your Google setup, then verify its technical implementation separately from your wider script controls. Check advertising pixels, conversion tags, audience tags, and embedded services too. A free option with documented support can be viable; one without the integration or an owner able to configure it may create avoidable work.
A practical selection and test process
Shortlist no more than two or three routes. For each, use the same site and the same test questions. This is more useful than comparing template counts or star ratings.
- Inventory first. List every tag, plugin, embed, pixel, storage method, and service. A cookie audit can help identify technical signals, but it cannot make the legal classification for you.
- Map purposes and owners. Ask why each service exists, who introduced it, whether it is optional, and how it loads. Get advice for uncertain classifications.
- Implement in a staging environment where possible. Follow the provider’s documented install order and any cache, Content Security Policy, or tag-manager requirements.
- Test clean journeys. Test before interaction, reject, partial acceptance, full acceptance, later withdrawal, and a returning visitor. Use key templates and devices.
- Check evidence and administration. Attempt to retrieve the relevant records, update a vendor/category, and understand how the configuration is reviewed.
- Record the decision. Save the plan terms, configuration, test date, results, outstanding gaps, and owner. Repeat after meaningful changes.
The cookie consent best-practices checklist has a broader operational checklist. A scanner can surface trackers that warrant investigation, but no scanner can guarantee legal compliance or detect every conditional user journey.
When paying may be the cheaper operational choice
“Free” describes licence or subscription cost, not total cost. A paid tool may be worth considering when your team needs managed scanning, centralized records, multiple sites, dependable support, broader integrations, or an easier ownership model. That is a purchasing judgment, not proof that paid software is legally superior.
ConsentEase publishes its own pricing and feature information on its pricing page. We are not an independent reviewer of our own product. If you compare ConsentEase with a free option, compare like with like: exact site count, operating regions, blocking responsibilities, records, Google configuration, migration work, support, and the person-hours needed to run each route. Confirm all current product claims directly with the provider.
If you do not know what loads before a visitor chooses, begin with the free scanner. Treat its results as a technical inventory to investigate, not a legal conclusion.

