The cookie consent plugin for WordPress: an Arabic banner for Saudi PDPL, with Consent Mode v2 set in the page head
Arqam360 is a free plugin on WordPress.org that adds an Arabic and English cookie banner to your site, passes each visitor's choice to Google Consent Mode v2, and keeps a dated record of every decision. It works on any WordPress site, WooCommerce stores included.
Get it from WordPress.org: search for Arqam360 under Plugins → Add New.
- Loads in the page head
- Arabic and English
- Free on WordPress.org
Why a banner
Does a WordPress site need a cookie banner under PDPL?
If it runs analytics or advertising tags for visitors in Saudi Arabia, yes. The Personal Data Protection Law (PDPL) covers any processing of personal data about people in the Kingdom, and a tag that can single out a visitor is processing personal data. On WordPress those tags arrive from many directions — Site Kit, a page builder's integrations, a WooCommerce extension, a line pasted into the theme — so the banner has to cover all of them. One that holds up does four things:
- 01
Hold non-essential tags until the visitor agrees
Analytics and advertising need the visitor's explicit, informed consent unless another legal basis applies. Cookies the site cannot run without — cart, checkout, login, security — stay on.
- 02
Offer a real way to refuse
Refusing has to be as clear as accepting. A banner with only an "OK" button does not give a free choice.
- 03
Keep settings reachable
PDPL lets people withdraw consent at any time, so the visitor needs a way back to their settings after the banner closes.
- 04
Record every decision
If SDAIA or a customer asks, you need to show what was agreed and when.
SDAIA confirmed 48 enforcement decisions in its January 2026 announcement. Administrative fines under PDPL reach up to SAR 5,000,000.
Read the full Saudi PDPL cookie consent guideLoad order
Why the plugin loads in the page head
Google Consent Mode v2 only protects a page if its "denied" default is set before a Google tag reads it. The plugin prints its script in the <head>, synchronously and ahead of the other scripts WordPress enqueues, so Google tags added through WordPress — a plugin, a tag manager container, Site Kit — find the default already in place.
One case it cannot control: a Google Tag Manager or GA4 snippet pasted into your theme's header.php above the wp_head() call runs before anything WordPress outputs. Move that snippet below wp_head(), or load the tag through a plugin, and the order is right.
Install
How the plugin installs
Five steps. WordPress has no app store sign-in, so you connect the plugin to your Arqam360 account yourself.
- 01
Install the plugin
In wp-admin go to Plugins → Add New, search for Arqam360, then Install and Activate.
- 02
Create a free Arqam360 account
Sign up at arqam360.com. No card is needed, and a new account starts with a 14-day trial with Pro features.
- 03
Copy your two credentials
In the Arqam360 dashboard open API Keys and copy the Widget Key (it starts with ciq_live_) and the Site Token (it starts with ciq_sk_live_). The Site Token is shown once, when you create it.
- 04
Paste them in Arqam360 → Settings
The plugin adds an Arqam360 menu to wp-admin. Paste both credentials under Settings and save. The Widget Key runs the banner; the Site Token opens your Arqam360 dashboard inside wp-admin and is never written to your pages. A credential pasted into the wrong field is refused.
- 05
Check it in a private window
Open your site in a private window: the banner appears before you choose. Saving settings purges the page cache of WP Engine, WP Rocket, W3 Total Cache, WP Super Cache, SiteGround Optimizer, LiteSpeed and Cache Enabler, so a cached page does not hide the change.
Settings
What you can set from wp-admin
- 01
Split or combined loading
Split loading, the default, prints a small script that sets the consent default at once and loads the banner in the background. Combined loading is one larger file with the same behaviour.
- 02
Enforce script blocking
Holds known tracker scripts — the Meta Pixel, TikTok and others that do not read Consent Mode — until the visitor agrees. It is off by default, because blocking scripts can break a page; test your site after switching it on.
- 03
Auto-detect the regime
Applies the rules for the visitor's country: opt-in with Arabic by default for Saudi Arabia, the UAE and the other Gulf states. If the country cannot be determined, the banner keeps its default opt-in model.
- 04
Respect Global Privacy Control
On unless you switch it off: a new visitor whose browser sends the GPC signal is opted out of non-essential categories.
- 05
Banner language
Follows each visitor's browser by default. Pin it to Arabic or English if your site serves one language.
Google and Meta
Google Consent Mode v2 and Meta on WordPress
When the page loads, Arqam360 sets analytics_storage, ad_storage, ad_user_data and ad_personalization to denied. When the visitor decides, it sends an update: the analytics category controls analytics_storage, and the marketing category controls the three advertising signals. On every later page the saved choice is sent again.
The Meta Pixel does not read Consent Mode; script blocking is what holds it back. On the Pro and Managed plans, once you connect Meta in the dashboard, Arqam360 can also forward events to Meta's Conversions API from our servers with the visitor's consent state attached. The same works for GA4, server-side Google Tag Manager, TikTok and Snap.
| Banner category | Consent Mode signals | Before a choice |
|---|---|---|
| Necessary | functionality_storage, security_storage | granted |
| Analytics | analytics_storage | denied |
| Marketing | ad_storage, ad_user_data, ad_personalization | denied |
Arabic
An Arabic banner, right to left
Arabic visitors get the banner and the settings panel right to left, with the category toggles mirrored and Arabic button labels. The plugin's own settings and dashboard screens in wp-admin also lay out right to left on an Arabic WordPress install.
Arabic cookie banner guide: layout, wording and testingRecords
A record you can show
Each decision is stored with its date and time and the categories the visitor accepted or refused. Browse the records in the dashboard — inside wp-admin once the Site Token is set — and export them for your domain as a CSV file.
Pricing
What it costs
The plugin is free on WordPress.org, and the banner runs on a free Arqam360 account. Paid plans are billed on arqam360.com, not through WordPress, and the pricing page shows them in your currency. A new account starts with a 14-day trial with Pro features, so you can try the paid features before deciding.
See pricingFAQ
Questions WordPress site owners ask
Does it work with WooCommerce?
Yes. The plugin works on any WordPress site, and on a WooCommerce store the banner appears across the storefront like any other page.
Do I need to edit my theme?
No. The plugin prints the banner script itself. The only theme change you might need is moving a tag that is hard-coded above wp_head() in header.php, so the consent default is set before it runs.
Why are there two credentials?
The Widget Key is public: it appears in your page source and only loads the banner. The Site Token is secret: it opens your Arqam360 dashboard inside wp-admin and is never written to your pages. Keeping them apart means your page source cannot open your account.
My site uses a caching plugin. Will visitors see the banner?
Saving the plugin's settings purges the page cache of the common caching plugins and hosts. If you use a CDN cache such as Cloudflare in front of the site, purge it too.
My site sends a Content Security Policy. What does the banner need?
script-src for https://cdn.arqam360.com, connect-src for https://api.arqam360.com, and style-src 'unsafe-inline'. The dashboard page in wp-admin also needs frame-src https://app.arqam360.com.
Is it free?
The plugin is free, and so is the banner on a free Arqam360 account. Paid plans add features such as server-side event forwarding.
Related
Find out what your WordPress site sets
The scan is free and only needs your site address. When you are ready, install the plugin from WordPress.org and connect it to a free account.