Configure your banner and copy the code. 100% free, GDPR-first, with Google Consent Mode v2 and GPC signal support (CCPA).
No configuration needed — WebLegal CCB detects and manages these third-party services according to the visitor's choice.
Paste this code first in the <head> section of your site, before all other scripts, so that cookie detection and blocking works correctly. Never through a tag manager or a dynamic loader, and never with defer or async: the banner must run before the trackers, otherwise it can no longer block anything.
<script src="https://weblegal.ai/js/wl-cookie-consent.js" data-position="popup" data-color="#10b981"></script> The code Google Analytics or Meta ask you to paste sits directly in the HTML. The browser downloads it while reading the page, before the banner can act: no cookie is set, but your visitor's IP address has already left. Neutralise the tag by changing its type — the banner restores it on acceptance. before <script async src="https://www.googletagmanager.com/gtag/js?id=G-XXX"></script> after <script type="javascript/blocked" data-wl-src="https://www.googletagmanager.com/gtag/js?id=G-XXX"></script>
What the banner does not do. It acts on scripts and iframes: image pixels, fetch/XHR requests and server-side tracking are not covered. And an SDK installed via npm cannot be blocked by any banner, ours or anyone else's.
The WebLegal.ai cookie banner conforms to WCAG 2.2 level AA. Last audit: 29 September 2026.
Method: automated axe-core audit (WCAG 2.0, 2.1 and 2.2 rules, levels A and AA) of the banner, the customisation panel, the reopen button, the GPC notice and the blocked-video placeholder, in light and dark themes; 38 automated keyboard checks; manual screen-reader pass.
Limits: this statement covers the banner itself, not the website that embeds it. The NVDA and JAWS screen readers (Windows) have not been tested yet.
Found an accessibility problem? Write to contact@weblegal.ai.
A consent banner is essential, but it must be paired with a detailed cookie policy explaining which cookies you use, why, and how visitors can manage them. This is a legal requirement (GDPR, ePrivacy).
Generate my cookie policy with WebLegal