Skip to content

Repository files navigation

Web Respect

Release 0.5.1 makes Feed, Sitemap and robots.txt a required skill integration step. The agent asks what may be published, preserves existing routes and crawler rules, and verifies connected resources. Installation alone never publishes content.

Release 0.5.0 adds an owner-approved public feed and discovery workflow. Generate a host-branded /feed/ hub, RSS, Atom, JSON Feed, sitemap and llms files using web-respect-feed; the agent skill guides publication choices and site-wide localized consent/footer integration. Only the main hub includes a small text-only Powered by Dpro link. These files support discovery without guaranteeing search rankings or AI ingestion.

Owner-declared DSGVO and GDPR compliance Owner-declared EU AI Act compliance

Owner-declared compliance statements; not independently certified. Applicability and compliance depend on the host deployment. See regional guidance.

License: MIT

Status: initial release

npm

A free, open-source cookie banner, accessibility and privacy toolkit developed by Dpro. Includes a local Cookie Checker / Cookie Scanner, configurable data-deletion request controls, a framework-neutral TypeScript core, isolated browser UI, bundled agent skill and optional backend adapters. No trackers or external service calls are enabled by default.

Source: https://github.com/9mtm/Web-Respect

Node.js React Astro Svelte Vue Next.js WordPress Angular Python TypeScript PHP HTML

Tested frontend integrations and optional backend runtimes; exact versions are listed in verification.

Release 0.5.0 adds configurable controls, improved Feed hub icons, reviewed robots.txt integration and technical SEO skill guidance. Cookie attribution is a text-only Dpro link shown beneath withdrawal only while About Cookies is selected. Download the package, skill and WordPress plugin from the 0.5.0 release. Install with npm install web-respect-dpro@0.5.0 once available in the registry, or use the release tarball. Service discovery and deletion integrations remain host-configured; credentials and verified privacy requests remain host-owned.

npm ci

npm run build

npm test

node scripts/build-examples.mjs

node scripts/preview.mjs

# Open http://127.0.0.1:4328/examples/html/index.html

npm pack
import {mount, mountFooter} from 'web-respect-dpro/browser';

const toolkit = mount(document.querySelector('#respect')!, {

  namespace: 'my-site', locale: document.documentElement.lang,

  content: document.querySelector('main')!, // mount outside this element

  consent: {policyVersion: '2026-10'},

  policies: {cookies: '/cookies/', privacy: '/privacy/', accessibility: '/accessibility/'},

  themeVariables: {primary: '--brand', surface: '--surface', text: '--ink'},

});

const removeFooter = mountFooter(document.querySelector('footer')!, toolkit, {

  discoverLinks: true, // declared feed/MCP links only; no fetching

});

// On navigation/unmount:

removeFooter(); await toolkit.dispose();

The browser UI includes its own prebuilt scoped CSS. Consumers need neither Next nor Tailwind. Import web-respect-dpro/accessibility or /consent for state controllers without UI. register() defines the <web-respect> custom element only when explicitly called in the browser; module imports are SSR safe. Configure its .config before appending it. The standalone dist/web-respect.js exposes WebRespect.mount, mountFooter and register.

Optional services need real lifecycle callbacks. The host must remove unconditional SDK initialization and stop capture, listeners, queues and future collection on withdrawal:

consent: {

  policyVersion: '2026-10',

  services: [{id: 'measurement', category: 'analytics',

    start: async signal => { if (!signal.aborted) await sdk.start(); },

    stop: async () => { await sdk.optOut(); await sdk.shutdown(); }

  }],

  record: async record => { /* POST to your CSRF-protected host gateway */ }

}

No server is required for local accessibility or choices. npm ships backend reference files; PHP/Laravel and Python execute in their own runtimes. Native Composer/PyPI distribution is unavailable. Use the same contract to add Go/Java/.NET adapters.

Agent audit skill

The Web Respect skill starts with company establishment, target countries and US states, actual customers, service type and audience. It guides source/browser/backend inspection, current official legal research, vendor and AI-provider data flows, tenant-specific processing regions, transfers, retention and backups, privacy requests and downstream deletion, and accessibility evaluation. Initial research profiles cover EU/EEA, Brazil, the US and Australia; additional markets need their own research.

This is an agent workflow, not an automatic all-laws scanner or certification. It distinguishes observed behavior, owner declarations, missing provider access and legal decisions. Review requests remain reviews until implementation is authorized. Reports and sensitive evidence stay private unless sanitized publication is authorized.

Agent skill path: node_modules/web-respect-dpro/skill/web-respect/SKILL.md. Copy the complete folder including references, or download the standalone skill ZIP. Extract its web-respect folder into your agent's skills directory. The audit references work separately; implementation also needs the package API/backend documentation linked by the skill.

After installing the package, install into a project-local agent skills directory:

npx --no-install web-respect-skill --target .agents/skills

For an agent that uses another location, supply that directory explicitly. The installer only copies the skill; it never overwrites an existing web-respect entry, installs trackers, changes the host application or contacts providers. It needs Node 22 or newer. If installation fails after creating a new folder, inspect that partial folder before retrying.

Ask your coding agent:

Use $web-respect to audit this project. Ask for missing company and market facts first. Inspect real services, privacy choices, accessibility, processing locations, retention and deletion. Verify current official sources. Produce an evidence-based action plan, mark unknowns and keep private information out of public output. Start with a review.

Configuration/API · Frontend examples · Backend integration · Regions · WordPress

The toolkit supports engineering and compliance work. Installation is not legal advice, verified identity/age, an accessibility repair service or a WCAG/legal certificate. Canvas/3D accessibility, server-side tracking, provider data deletion, notices, lawful bases, transfers, child/guardian obligations and operational privacy requests remain host responsibilities. Refusal preserves required site features.

Cookie Checker and data deletion

Use the local cookie scanner internally during development or an authorized agent audit; never render it as a visitor control. Separately, offer a confirmed data-deletion request for your own website and configured AI/CRM/storage providers. Provider mapping, identity verification, durable jobs and credentials belong to your backend; service detection alone cannot discover or delete a visitor’s provider accounts. See API examples, limits and host setup. The bundled skill includes matching scanner and deletion integration guidance.

Updating an existing installation

From the project that uses Web Respect, run:

npm install web-respect-dpro@latest

Review release notes, rebuild and verify cookie consent, withdrawal, accessibility and Feed links locally before deploying. A separately copied agent skill must also be refreshed using the documented skill installer. Updates do not deploy your website automatically.

To review updated skill instructions without overwriting your existing skill:

npx --no-install web-respect-skill --target .agents/skill-update-review

Use a new empty review directory for subsequent updates. Compare its web-respect folder with the active skill, preserve your customizations, and replace the active copy after review.

Releases

Packages

Contributors

Languages