Appearance
NexusConsent — Changelog (Free)
What's new in the Free edition, written for site owners and administrators.
1.9.0 - 2026-10-01
- Accept all now grants only the categories shown in the banner, so sites without Marketing services no longer send advertising consent to Google and Clarity.
- Returning visitors are asked to choose once more, so every saved choice reflects what they were actually shown.
- The Patterns help explains when to increase Config version so existing visitors are asked about a newly added category.
- A short review request for the Joomla Extensions Directory appears once on the plugin settings page, about two weeks after first use, and can be dismissed for good.
1.8.0 - 2026-09-27
- Fixed cases where valid page markup or an inline initializer could let a configured resource run before consent.
- CSV Export denials now return a clean response, and administrator Scan and Export labels are safely escaped.
- Each grant decision now sends one Google and Clarity consent update.
1.7.4 - 2026-09-13
- Fixed some scripts and embedded content failing to load after consent when their addresses contain multiple query parameters.
1.7.3 - 2026-09-08
- Vertically centred the text in the Patterns category heading boxes.
1.7.2 - 2026-09-08
- Aligned the category headings in Patterns and made their section layout consistent.
1.7.1 - 2026-09-08
- Consent exports no longer put the session security token in the download URL.
- Blocked resources no longer retain inline event handlers or iframe inline documents for restoration.
1.7.0 - 2026-09-07
- Safer blocked-frame handling. Blocked iframe placeholders keep useful dimensions and accessibility details while one-time restoration excludes executable or control attributes.
1.6.0 - 2026-09-05
- Prepared for managed PRO rule publishing. NexusConsent PRO can now ask Free to clear Joomla's built-in page cache through a small supported interface after consent-rule changes are published. Free remains the owner of visitor protection, and this release does not change existing settings or public-page behaviour on its own.
1.5.0 - 2026-09-05
- Ready for NexusConsent PRO. The plugin now exposes a read-only interface that lets NexusConsent PRO read and validate your blocking rules exactly as this plugin applies them. Nothing changes in how the plugin behaves for visitors or in your settings.
1.4.1 - 2026-08-31
- Pattern categories are easier to scan. Clear Analytics, Marketing, Functional, and Preferences headings now separate each group in the plugin settings, including Joomla's dark administrator theme.
1.4.0 - 2026-08-31
- Microsoft Advertising consent, built in. Selecting the Microsoft Ads preset now enables UET Basic Consent Mode, keeps it denied until Marketing permission, and supports both current and legacy official loaders without adding another visitor choice.
- Consent text that follows your site language. Leave a Texts field empty to use the active Joomla Site language and its overrides, or fill it once to keep that value global; the optional attribution is translated too.
- A more polished and accessible consent experience. Choose a
0–24px corner radius, use balanced mobile-friendly actions, and rely on improved keyboard focus in required-decision dialogs while existing sites retain the familiar8px default. - Consent choices react reliably across tabs and connection problems. Grants restore eligible services, downgrades stop optional services promptly, and revoke remains immediate in the browser with an automatic server retry when needed.
- Stronger tracker blocking and Joomla cache safety. Improved URL matching, placeholder restoration, provider-signal ordering, and automatic Joomla page-cache handling help prevent optional services from starting under the wrong consent state.
- Clearer and safer administration. Invalid cookie, retention, version, and pattern settings are rejected with useful feedback, while Site Scanner explains its no-redirect policy and the right way to scan multilingual routes.
- Safer consent records and privileged tools. Consent data is validated more strictly, CSV exports stay bounded, and Scan, Export, and the Insiders card remain limited to Super Users.
- NXP Insiders access. Super Users can open the optional NXP Insiders membership card from the plugin settings to support continued development and join the private community.
1.3.4 - 2026-08-14
Fixed
- Joomla configuration data is no longer mistaken for a tracker. Inert JSON stays intact while executable scripts remain protected by the configured blocking rules.
1.3.3 - 2026-07-25
Fixed
- Consent you have already given is no longer held back. Previously, if any category was denied, scripts belonging to categories the visitor had accepted were still delayed until JavaScript restored them.
- Google Consent Mode signals are now sent before Google tags load, instead of shortly after. This closes a gap where advertising consent could be unset for the very first measurement on a page.
- Config version now works. Increasing it retires earlier decisions and asks visitors to choose again, as the setting has always described. Previously it had no effect.
- Page caching could show one visitor's consent state to another. Each consent state is now cached separately, so System – Page Cache can stay enabled.
- With page caching enabled, consent records could silently fail to save. The consent form now requests a security token that matches the visitor's own session.
- Behind a reverse proxy or CDN, all visitors were treated as a single address. NexusConsent now follows Joomla's Behind Load Balancer setting, so visitors are counted and logged individually.
- A failed database write is no longer reported as success, and no longer triggers the developer events.
- The "Powered by NexusConsent" link no longer appears unless you explicitly enable it.
- Categories with no patterns configured can no longer block inline scripts.
- Very large pages now receive the correct Consent Mode defaults.
Added
- Rate limiting for the consent log, protecting the audit table from flooding. Enabled by default, with per-session and per-IP limits and a configurable time window under the Advanced tab. Visitor consent is always stored in the browser first, so limiting never affects what visitors see or choose.
- Separate Texts and Patterns tabs in the plugin settings. Your existing settings move across untouched.
Improved
- Noticeably lighter download: the installation package is around two-thirds smaller, as documentation images are no longer bundled.
- Faster page rendering — the plugin's configuration is now built once per request instead of several times.
- Consent Mode defaults respect Content Security Policy nonces.
- Licensing information is now consistent across the plugin (GNU GPL version 3 or later).
Using a CDN or reverse proxy?
Joomla's own page cache is handled automatically. External caches are not: configure them to bypass or vary on the consent cookie, so the publicly cached page is always the "no consent yet" version.
1.3.2 - 2026-07-05
Added
- Added iframe blocking for embeds such as videos, maps, and widgets.
- Site Scanner now detects iframe embeds and shows whether each result is a script, stylesheet, or iframe.
- Added German, French, and Dutch language files to the installer.
Improved
- Consent banner and modal text is now more translation-friendly.
- Admin pattern help and product docs now explain iframe blocking.
- Common map, chat, and widget snippets are handled better by the blocking engine.
Fixed
- Improved consent revoke request hardening.
- Fixed encoded ampersands in the frontend config URL.
1.3.1 - 2026-03-05
Fixed
- Google consent is withdrawn before the page reloads. Revoking now denies both analytics and advertising permissions immediately.
1.3.0 - 2026-02-20
Changed
- Improved compatibility with current Joomla releases. The plugin now uses Joomla's modern extension and event architecture for a more dependable upgrade path.
Added
- Clearer legal guidance and faster cleanup of consent records that have reached their configured retention age.
Fixed
- Blocking and Site Scanner now recognise protocol-relative service URLs correctly.
- Preset pattern lists no longer show literal
\ncharacters. - Saving an unchanged consent choice no longer reports a false failure.
Security
- CSV exports now neutralize spreadsheet formulas before a file is opened.
- Browser-side blocking now handles protocol-based URL bypasses more safely.
- Custom consent endpoint overrides reject deceptive lookalike domains.
1.2.0 - 2026-02-11
Added
- Microsoft Clarity Consent API v2 integration
- Clarity added to default analytics block patterns
- Preset Library for quick-add service patterns
- Site Scanner for server-side detection of external scripts/styles
- Empty category hiding in consent UI when no patterns exist
- "Only essential cookies" message when all optional categories are empty
- Per-category "Reset to defaults" actions for pattern fields
Changed
- Pattern defaults now apply only on first install
- Saved empty pattern fields remain empty after save
- Frontend category payload now includes only categories with patterns
1.1.0 - 2026-01-30
Maintenance release. Detailed notes were not recorded for this version.
1.0.2 - 2026-01-08
Fixed
- Minor bug fixes and stability improvements
1.0.1 - 2026-01-06
Fixed
- Compatibility improvements for Joomla 5.2+
- Cookie path handling edge cases
1.0.0 - 2025-10-12
Initial public release of NexusConsent for Joomla 4.x/5.x.
Added
Consent Categories
- Analytics (Google Analytics, Hotjar, Mixpanel, etc.)
- Marketing (Facebook Pixel, LinkedIn, TikTok, etc.)
- Functional (Google Fonts, Maps, OpenStreetMap)
- Preferences (custom patterns)
- Necessary (always enabled, non-optional)
Consent UI
- Banner or full-screen modal (require-decision mode)
- Light/Dark/Auto theme support
- Custom accent colors
- Repositionable floating "cookie settings" button
- ARIA live regions and keyboard navigation
- Focus trapping in modal mode
Server-Side Blocking
- Blocks scripts, styles, and inline initialisers until consent
- Pattern-based URL matching for third-party services
- Preserves CSP nonces and integrity attributes
- Works with strict Content Security Policy
Google Consent Mode
- Analytics and ad storage defaults to denied
- Instant updates when visitors change choices
- Compatible with Google Tag Manager
Privacy Features
- Consent cookie contains only version, timestamp, UUID, and category map
- IP addresses masked in audit log (IPv4 /24, IPv6 /64)
- Configurable cookie name, path, and lifetime
- Database retention controls with auto-cleanup
Audit Trail
- Optional database logging of consent events
- CSV export for compliance reporting
- Configurable retention period
Developer Features
onNexusConsentGivenevent hookonNexusConsentRevokedevent hook- Manual script guarding via
data-consentattribute - Optional TCF v2 stub for ad platform compatibility
Security
- First-party cookie only
- No external dependencies for core functionality
- CSRF protection on consent save endpoint