Install StrongPrivacy on WordPress.

Install the first-party plugin, pair it to one property, and confirm both the runtime heartbeat and WordPress Consent API integration.

Installing a managed property?

Verify domain authorization and complete reviewed activation before a new managed property can serve its configuration. Follow the managed-service handoff, then return here for your platform’s installation steps. Installation status alone is not a live verification result.

Requirements

The connector is designed for an administrator-controlled WordPress installation.

  • WordPress 6.2 or newer and PHP 7.4 or newer.
  • Administrator access to install and activate a plugin.
  • A StrongPrivacy property using the site’s public production hostname.
  • Outbound HTTPS access from WordPress to your StrongPrivacy app.

Install and pair the plugin

Use the packaged plugin and one-time pairing flow shown in the dashboard. Do not reuse another property’s identifier.

  1. 1

    Verify the website domain

    Open the property’s Manage page, add its DNS verification record, and verify ownership before generating a pairing code. This prevents another workspace from claiming your website.
  2. 2

    Download the plugin

    Open Integrations → WordPress, select the correct property, and download the packaged plugin ZIP.
  3. 3

    Install it in WordPress

    Open Plugins → Add New Plugin → Upload Plugin, choose the ZIP, then install and activate StrongPrivacy.
  4. 4

    Generate a pairing code

    Back in StrongPrivacy, select Generate pairing code for that property. Pairing codes are short lived and single use.
  5. 5

    Complete pairing

    In WordPress, open Settings → StrongPrivacy, enter the hosted app URL and pairing code, then choose Connect site.

Connection status has one source of truth

Not connected means the installation is absent or was revoked. Waiting for runtime means pairing succeeded but the live plugin has not checked in yet. Runtime connected only appears for a currently active pairing with a recorded heartbeat.

Connect optional scripts to consent

Pairing confirms the connection. Verify tracking behavior before treating the installation as ready.

For scripts registered by a theme or plugin, open Settings → StrongPrivacy and map each optional script handle to functional, analytics, marketing, or media. Enter one mapping per line, such as my-analytics=analytics. The selected script and its inline setup wait for consent and execute in their original order. Ask the plugin author for the correct handle and check its dependencies before enabling the rule.

Check every tracking source

This setting covers registered WordPress scripts. Raw HTML tags, iframes, preload links, scripts from a tag manager, and cookies set by the server need their own consent-aware configuration. Remove duplicate vendor installations, map each detected tracker, then run fresh-visit, reject, accept, custom-choice, and withdrawal checks.

Exclude strongprivacy and wp-consent-api from script aggregation and delayed execution. For optimizers that aggregate inline scripts, also exclude consent_api and wp_fallback_consent_type. Preserve text/plain consent wrappers and data-noptimize attributes, clear caches, and repeat the checks on the cached page.

Verify the installation

Clear every active cache layer before testing in a private browser window.

  • Purge page, object, CDN, and optimization-plugin caches.
  • Confirm the banner appears when no consent decision is stored.
  • Confirm optional vendor requests wait for an allowed category.
  • Confirm the dashboard changes from Waiting for runtime to Runtime connected.
  • Confirm the footer privacy control reopens preferences.

Still stuck? Follow the WordPress troubleshooting flow.