{"id":364875,"date":"2026-09-08T13:11:48","date_gmt":"2026-09-08T13:11:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cachesafe-for-woocommerce\/"},"modified":"2026-09-08T13:11:20","modified_gmt":"2026-09-08T13:11:20","slug":"cachesafe-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/cachesafe-for-woocommerce\/","author":23549143,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1","requires":"6.9","requires_php":"7.4","requires_plugins":null,"header_name":"CacheSafe for WooCommerce","header_author":"Cobalt Branch Labs","header_description":"Diagnostic evidence plugin that proves WooCommerce cart\/session isolation across caching stacks. Free v1.0 manual scans with local-only evidence.","assets_banners_color":"334675","last_updated":"2026-09-08 13:11:20","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/cobaltbranchlabs.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":37,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"bananasaging","date":"2026-09-08 13:11:20","revision":3686678}},"upgrade_notice":{"1.0.1":"<p>Includes unminified front-end source and build tooling in the plugin package for public source access.<\/p>","1.0.0":"<p>First public free release with complete manual scan workflow. Review Settings for test product ID before scanning.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3686673,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3686673,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3686673,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3686673,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3686673,"resolution":"1","location":"assets","locale":"","width":3436,"height":1854},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3686673,"resolution":"2","location":"assets","locale":"","width":3436,"height":1664},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3686673,"resolution":"3","location":"assets","locale":"","width":3436,"height":2064}},"screenshots":{"1":"CacheSafe overview and scan summary","2":"Live scan progress with stage timeline","3":"Findings with sanitized evidence drawer"}},"plugin_section":[],"plugin_tags":[146,3047,600,14950,286],"plugin_category":[45,52,54],"plugin_contributors":[276392],"plugin_business_model":[],"class_list":["post-364875","plugin","type-plugin","status-publish","hentry","plugin_tags-cache","plugin_tags-cart","plugin_tags-security","plugin_tags-session","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-bananasaging","plugin_committers-bananasaging"],"banners":{"banner":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/banner-772x250.png?rev=3686673","banner_2x":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/banner-1544x500.png?rev=3686673","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/icon-128x128.png?rev=3686673","icon_2x":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/icon-256x256.png?rev=3686673","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/screenshot-1.png?rev=3686673","caption":"CacheSafe overview and scan summary"},{"src":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/screenshot-2.png?rev=3686673","caption":"Live scan progress with stage timeline"},{"src":"https:\/\/ps.w.org\/cachesafe-for-woocommerce\/assets\/screenshot-3.png?rev=3686673","caption":"Findings with sanitized evidence drawer"}],"raw_content":"<!--section=description-->\n<p>CacheSafe for WooCommerce is a diagnostic evidence plugin by <strong>Cobalt Branch Labs<\/strong>. It runs controlled anonymous cart sessions through your store's public WooCommerce surfaces and reports whether cache behavior, cookies, headers, and Store API responses preserve customer isolation.<\/p>\n\n<p><strong>Free v1.0<\/strong> includes manual scans, sanitized findings, provider-aware remediation guidance, WP-CLI, and local-only evidence. No telemetry, no accounts, no automatic cache changes.<\/p>\n\n<h4>What it does<\/h4>\n\n<ul>\n<li><strong>Preflight checks<\/strong> \u2014 WooCommerce pages, loopback reachability, Store API, test product, runner health, perspective<\/li>\n<li><strong>Manual staged scans<\/strong> \u2014 Store API Cart-Token A\/B isolation plus classic cookie\/add-to-cart flow where supported<\/li>\n<li><strong>16 safety checks (CS-101\u2013116)<\/strong> \u2014 headers, Set-Cookie, session isolation, replay, cleanup, perspective<\/li>\n<li><strong>Sanitized reports<\/strong> \u2014 copy or download JSON, text, or HTML without cookie values, tokens, or raw bodies<\/li>\n<li><strong>Provider guidance<\/strong> \u2014 evidence-linked remediation for generic stacks and common cache\/CDN plugins<\/li>\n<li><strong>WP-CLI<\/strong> \u2014 <code>wp cachesafe preflight<\/code>, <code>scan<\/code>, <code>status<\/code>, <code>report<\/code>, <code>cancel<\/code>, <code>cleanup<\/code>, <code>purge<\/code><\/li>\n<li><strong>Retention<\/strong> \u2014 keeps the last five completed scans within 30 days (configurable shorter); automatic daily purge<\/li>\n<\/ul>\n\n<h4>What it does not do<\/h4>\n\n<ul>\n<li>Place orders, process payments, or call checkout write endpoints<\/li>\n<li>Change cache, CDN, DNS, or host settings automatically<\/li>\n<li>Send telemetry or require an account<\/li>\n<li>Show a numeric \"safety score\"<\/li>\n<\/ul>\n\n<h4>Admin<\/h4>\n\n<p>WooCommerce \u2192 <strong>CacheSafe<\/strong> with tabs for Overview, Preflight, Live scan, Results, History, Settings, and Tools.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>All scan evidence stays on your WordPress site. CacheSafe does not phone home. Reports are sanitized to exclude cookie values, Cart-Tokens, nonces, Authorization headers, raw bodies, secrets, and customer PII. Retention is bounded and configurable; uninstall can remove plugin-owned data when enabled in Settings.<\/p>\n\n<h3>Development<\/h3>\n\n<p>Unminified JavaScript and CSS live in <code>assets\/src\/<\/code>. Built admin assets are written to <code>assets\/build\/<\/code> via <code>@wordpress\/scripts<\/code>.<\/p>\n\n<p>To regenerate the compiled files from this plugin directory:<\/p>\n\n<ol>\n<li><code>npm install<\/code><\/li>\n<li><p><code>npm run build<\/code><\/p>\n\n<p>package.json and <code>webpack.config.js<\/code> ship with the plugin so the build can be reproduced without a separate repository.<\/p><\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>cachesafe-for-woocommerce<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Ensure WooCommerce is active and configure a <strong>test product ID<\/strong> under CacheSafe \u2192 Settings.<\/li>\n<li>Run <strong>Preflight<\/strong>, then start a scan from <strong>Live scan<\/strong> or WP-CLI.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20place%20test%20orders%3F\"><h3>Does this place test orders?<\/h3><\/dt>\n<dd><p>No. CacheSafe only creates ephemeral anonymous carts using an approved simple product. It never completes checkout or captures customer PII.<\/p><\/dd>\n<dt id=\"is%20this%20a%20cache%20optimizer%3F\"><h3>Is this a cache optimizer?<\/h3><\/dt>\n<dd><p>No. It is an evidence-led auditor, not a performance plugin. It does not change cache provider settings for you.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20wp-cron%3F\"><h3>Does it work without WP-Cron?<\/h3><\/dt>\n<dd><p>Yes. The Live scan tab advances scans while you watch; Action Scheduler is used when available but is not required for manual scans.<\/p><\/dd>\n<dt id=\"how%20long%20is%20scan%20history%20kept%3F\"><h3>How long is scan history kept?<\/h3><\/dt>\n<dd><p>By default, the last five completed scans within 30 days. Failed or cancelled scans are purged sooner. You can purge manually from Tools or WP-CLI.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20storefront%3F\"><h3>Will this slow down my storefront?<\/h3><\/dt>\n<dd><p>Scans are admin-triggered and budget-limited (default \u226430 HTTP requests, short timeouts). They are not continuous background traffic.<\/p><\/dd>\n<dt id=\"where%20can%20i%20get%20support%3F\"><h3>Where can I get support?<\/h3><\/dt>\n<dd><p>Use the WordPress.org support forum for this plugin after it is published, or contact Cobalt Branch Labs through the Author URI listed on the plugin page.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Ship unminified <code>assets\/src<\/code> plus build tooling in the distributable package for Guideline 4 source access<\/li>\n<li>List WordPress.org username bananasaging in Contributors<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Free v1.0 release: full manual scan pipeline, 16 checks, admin UI, WP-CLI, sanitized reports<\/li>\n<li>Store API and classic cookie A\/B session isolation in live scans<\/li>\n<li>Automatic retention purge (daily cron + after scan completion)<\/li>\n<li>Provider-aware remediation catalog (Cloudflare, LiteSpeed, WP Rocket, WP Super Cache, W3 Total Cache, host-cache)<\/li>\n<li>Request-budget accounting and duplicate-finding fixes for live polling<\/li>\n<\/ul>\n\n<h4>0.1.0-alpha.0<\/h4>\n\n<ul>\n<li>Early lab scaffold and quality toolchain<\/li>\n<\/ul>","raw_excerpt":"Prove that WooCommerce cart and customer sessions stay isolated across your real caching stack \u2014 without placing an order.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364875"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bananasaging"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364875"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364875"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364875"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364875"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364875"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}