FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Nucleus CMS
N

Nucleus CMS

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Nucleus CMS do?

Open source PHP and MySQL content management system focused on blogs and small publishing sites. Self hosted by the operator, it sets a PHPSESSID and administration cookies for authenticated users.

What is Nucleus CMS

Nucleus CMS is a free and open source content management system written in PHP and backed by a MySQL database. It was first released in the early 2000s as a blog focused publishing engine, with support for multiple weblogs, member accounts, comments, skins and plugins. The application is fully self hosted, meaning the website operator installs the code on their own web server, manages updates and acts as the sole data controller for every visitor or author who interacts with the site.

What data and cookies Nucleus CMS collects

By default Nucleus CMS sets a PHPSESSID session cookie when an authenticated session starts, a NP_Auth login cookie for the administration area and may set comment author cookies that store the visitor name, email and website on the public side. On the server it stores blog posts, drafts, member accounts (login, hashed password, email, real name), comments, IP addresses of commenters, referrer logs and any data added by third party plugins such as statistics modules or contact form extensions.

GDPR and ePrivacy implications

The administration session and login cookies are strictly necessary to deliver the editing service that the editor has requested, so they fall under the exemption of Article 5(3) ePrivacy Directive. Comment author cookies, statistics plugin cookies and any social or advertising integration however require prior informed consent. Storing the IP address of commenters and members triggers the GDPR, with a clear legal basis, a retention period and a privacy notice mandatory under Articles 6, 13 and 14.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and user controls

On the public side, only the strictly necessary cookies should be set before consent. Comment author cookies, analytics plugins and any embedded media should be loaded after explicit opt in through a cookie banner with refusal as easy as acceptance. Members and commenters must be able to access, rectify and erase their data under Articles 15 to 17 GDPR, and a clear procedure should be documented to delete comments and member accounts on request.

Data transfers and hosting

Nucleus CMS is entirely self hosted, so there is no built in transfer to a vendor. The transfer question depends on where the operator runs the web server and the MySQL database. Hosting in the EU or EEA keeps the data inside the GDPR perimeter. Hosting in the United States, the United Kingdom or another third country triggers Chapter V of the GDPR and requires an adequacy decision, standard contractual clauses or binding corporate rules with a documented transfer impact assessment.

Practical compliance steps

Keep Nucleus CMS updated, prefer EU hosting, audit installed plugins for hidden tracking, configure a consent management platform to gate non essential cookies, set a short retention period for IP addresses in comment logs, restrict the administration backend through HTTPS and strong passwords, document the processing in the Article 30 records and update the privacy and cookie policy with a clear mention of Nucleus CMS, the categories of data, the recipients and the retention periods.

GDPR consent category

Other

Websites using Nucleus CMS must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Article 6(1)(f) GDPR) for the strictly necessary login session and CSRF cookies of the administration area. Consent (Article 5(3) ePrivacy Directive and Article 6(1)(a) GDPR) for any analytics, comment author or plugin cookie set on public pages.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), national implementations such as the French Data Protection Act, the German TDDDG and the Spanish LSSI, plus the EU NIS2 Directive for self hosted publishing infrastructure.

DPIA considerations

A DPIA is generally not required for a personal blog or small editorial site running Nucleus CMS, but becomes recommended when the site collects comments at scale, hosts user profiles, processes special category data or targets children. Document the categories of data stored in the MySQL database, retention of comment logs, plugin behaviour and the moderation workflow.

Sample consent text

We use Nucleus CMS to publish this website. The authoring tools set a session cookie and a login cookie when an editor signs in, and may set comment author cookies when you post a comment. Strictly necessary cookies are exempt from consent. You can accept, refuse or withdraw your consent for optional cookies at any time.

Technical details

Tracking methodPHP application setting first party HTTP session and authentication cookies
Server locationSelf hosted (server location depends on the operator)

Third-party domains contacted

nucleuscms.orgdocs.nucleuscms.org

Cookies placed

NameTypeDurationPurpose
PHPSESSIDhttp_sessionSessionIdentifies the visitor PHP session used by Nucleus CMS for authenticated administration.
NP_Authhttp_persistent30 daysKeeps editors logged in to the Nucleus CMS administration area between visits.
comment_userhttp_persistent1 yearStores the commenter name, email and website to prefill the comment form on return visits.
loginlanghttp_persistent1 yearRemembers the language selected in the Nucleus CMS administration backend.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Nucleus CMS set?

Nucleus CMS sets a PHPSESSID session cookie when an authenticated session starts, a NP_Auth login cookie for editors, and may set comment author cookies storing the visitor name, email and website when commenting. Installed plugins (statistics, contact forms) can add their own cookies.

Is consent required for Nucleus CMS?

No consent is needed for the strictly necessary administration session and login cookies, since they support a service requested by the editor. Comment author cookies, statistics plugin cookies and any social or advertising embeds require prior informed consent through a cookie banner.

What is the legal basis for processing?

The administration cookies and editor accounts rely on legitimate interest under Article 6(1)(f) GDPR or on performance of a contract for paid editors. Commenter data and optional cookies rely on consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive.

Are data transferred to the United States?

There is no built in transfer because Nucleus CMS is self hosted. Transfers happen only if the operator chooses a hosting provider, CDN or backup service in the US or another third country. In that case Chapter V of the GDPR applies and standard contractual clauses with a transfer impact assessment are required.

Do I need a DPIA for Nucleus CMS?

A DPIA is generally not required for a small personal or editorial blog. It becomes recommended when comments are collected at scale, when special category data is published, when minors are part of the audience or when third party plugins introduce additional tracking or profiling.

How do I implement Nucleus CMS in a compliant way?

Keep the core and plugins updated, prefer EU hosting, restrict the admin backend through HTTPS and strong passwords, gate optional cookies behind a consent management platform, set short retention for IP addresses in comment logs and document the processing in the Article 30 records.

Are there alternatives to Nucleus CMS?

Mature alternatives include WordPress, Ghost, Drupal, Joomla and static site generators such as Hugo or Eleventy. The choice depends on the size of the audience, available technical skills, expected plugin ecosystem and the privacy by design effort the operator is willing to invest.

How do I update my cookie policy for Nucleus CMS?

Add a dedicated entry that names Nucleus CMS, lists PHPSESSID, NP_Auth and comment author cookies with their purpose and duration, mentions any plugin specific cookies, identifies the operator as the data controller and explains how visitors can refuse or withdraw consent and request deletion of their data.