Title: Yindle Share Cart
Author: yindle
Published: <strong>September 28, 2026</strong>
Last modified: September 28, 2026

---

Search plugins

![](https://ps.w.org/yindle-share-cart/assets/banner-772x250.png?rev=3717715)

![](https://ps.w.org/yindle-share-cart/assets/icon.svg?rev=3717715)

# Yindle Share Cart

 By [yindle](https://profiles.wordpress.org/yindle/)

[Download](https://downloads.wordpress.org/plugin/yindle-share-cart.1.0.4.zip)

 * [Details](https://wordpress.org/plugins/yindle-share-cart/#description)
 * [Reviews](https://wordpress.org/plugins/yindle-share-cart/#reviews)
 *  [Installation](https://wordpress.org/plugins/yindle-share-cart/#installation)
 * [Development](https://wordpress.org/plugins/yindle-share-cart/#developers)

 [Support](https://wordpress.org/support/plugin/yindle-share-cart/)

## Description

Yindle Share Cart adds a **Share Cart** button to the WooCommerce cart. It
 creates
a link that carries only the products, variations and quantities that were in the
cart — never prices, coupons, customer details or session data.

Opening the link shows a preview built from the shop’s **current** catalogue:
 today’s
prices, today’s stock, today’s purchase rules. Nothing is added to the recipient’s
cart until they choose **Replace my current cart** or **Merge with my current cart
and submit the form.

All free features listed below are included and enabled. There is no paid usage

quota, expiring trial, telemetry, Yindle account requirement or forced credit link
on your storefront. Short rate limits protect the public sharing endpoint from abuse;
they do not require payment to reset.

#### What it does

 * **Share Cart button** on the classic cart and the WooCommerce Cart Block.
 * **Capability links.** The public link is a 64-character random capability.
    Only
   a purpose-separated HMAC-SHA-256 hash of it is ever stored, so a database copy
   does not hand anyone a working link.
 * **Current-price preview.** Prices and availability come from live product
    objects
   at the moment the link is opened, not from the snapshot.
 * **Deliberate replace or merge.** A GET request only ever renders the preview.
   
   Importing needs a WordPress nonce, an explicit mode choice and a signed single-
   use intent.
 * **Guest revocation.** Creating a link also hands the sender a separate
    management
   capability. It can revoke the link but cannot read the cart, and the read capability
   cannot revoke anything.
 * **Expiry.** 1–365 days, 30 by default, rechecked in the database on every
    request
   rather than relying on a cron run.
 * **Atomic import.** The whole plan is validated before the cart is touched. A
   
   failure restores the previous cart, its coupons and its session data.
 * **Stock and purchase rules.** Product existence, published state, variation
    
   ownership, purchasability, sold-individually, maximum quantity and combined merge
   quantities are all revalidated at import time.
 * **Privacy.** Registered with WordPress’s personal-data eraser, and user
    deletion
   removes the matching rows.
 * **Classic and Blocks.** One server-side service behind both cart renderers.

#### Separate Pro plugin

Share Cart Pro by Yindle is a separate plugin available from Yindle, with named

saved carts, account management and printing. These implementations are not included
or locked inside this directory package. Existing published links and shared data
remain readable when switching editions.

#### Moving from Share Cart by Yindle 1.0.1

The directory name is now Yindle Share Cart and its folder is `yindle-share-cart`.

This is a manual replacement: the older `share-cart-by-yindle` installation cannot
receive an automatic update across the folder change.

 1. Back up your database and plugin files.
 2. In WooCommerce settings, turn off **Delete data on uninstall** before
     removing
    the old installation. Keep it off when removing an older Pro installation too; 
    older uninstall scripts do not recognize this new folder.
 3. Install Yindle Share Cart, then deactivate the old Free copy without deleting
     
    it and activate the new copy. If both remain active, the new copy stands by until
    the old Free copy is deactivated. Pro takes precedence when active.
 4. Verify your existing share links and settings.
     Delete it only after confirming
    deletion is disabled. Keeping it inactive is also safe. Do not reset capability
    secrets or remove shared database tables.

When this new plugin is active it protects shared data during companion
 uninstallation
without changing the saved deletion preference. That protection cannot run while
it is inactive. Deactivation always preserves data.

### Privacy

Share snapshots store product and variation IDs, selected attributes, quantities,

creation and expiry times, hashed link capabilities and, for signed-in creators,
their WordPress user ID. Prices, coupons, addresses, payment information and WooCommerce
session contents are not included in the shared snapshot.

The plugin uses the shop’s WooCommerce session to bind import confirmation to
 the
current visitor and may ask WooCommerce to create its session cookie when opening
a share preview. The creator’s browser stores one revocation capability in local
storage (`yindleCartManagementToken`); it is replaced by the next share and removed
when revoked or when the visitor clears site data.

Abuse prevention uses short-lived local counters keyed by a salted hash of the
 
visitor’s session/user identity and peer IP address, with a five-minute default 
window. The raw IP address is not stored by this plugin. One-use import markers 
expire after one day. Shared links expire after the configured 1–365 days (default
30); scheduled cleanup removes expired records that are not referenced by a retained
saved cart.

WordPress’s privacy export includes your saved-cart names and owned product
 selections
without link tokens or keys. The eraser and user-deletion hooks remove saved-cart
relations and anonymise creator IDs. Network deletions use bounded background jobs;
per-site orphan cleanup retries when the plugin and cron are available, including
data from former memberships. Product selections may remain when another saved cart
references them. Store owners should describe this behavior in their shop’s privacy
notice.

### Third-party assets

Plus Jakarta Sans and Geist Mono fonts are bundled under the SIL Open Font
 License
1.1. Lucide icons are bundled under the ISC license. Their notices and source provenance
are included in `assets/yindle/`. Runtime JavaScript is human-readable and uses 
WordPress/WooCommerce-provided libraries.

#### Translations

This directory package uses WordPress language packs from translate.wordpress.org

for PHP and Cart Block strings. It ships no bundled translation catalogues and needs
no custom translation loader. Until a language pack is available, English source
strings remain usable. Community translations are welcome.

## Installation

For the existing Free 1.0.2 and sold Pro 2.0.0 upgrade path, deactivate Free
 without
deleting it before activating the paid ZIP. Keep shared data deletion off.

 1. Upload the plugin folder to `/wp-content/plugins/`, or install the ZIP under
     **
    Plugins  Add New  Upload Plugin**.
 2. Install and activate WooCommerce 8.0 or later, then activate this plugin.
 3. Configure it under **WooCommerce  Settings  Yindle Share Cart**.

If Share Cart Pro by Yindle is already active, this edition stands by and
 does 
not load its sharing runtime. It retains compatibility declarations and a standby
notice. The Pro edition contains every free feature.

## FAQ

### Does the link contain prices?

No. The stored snapshot holds product IDs, variation IDs, quantities and the
 selected
variation attributes. Prices, coupons, totals, tax, customer details and session
data are rejected by the schema before anything is saved.

### Can a recipient’s cart be changed just by opening the link?

No. Opening the link renders a preview and changes nothing. The cart is only
 modified
by a POST that carries a valid nonce, an explicit replace/merge choice and a signed
single-use import intent.

### What happens if a product sold out after the link was created?

The preview reports that the shared cart can no longer be imported, and nothing

is added. Partial imports are not possible: the plan is validated in full first.

### Does an expired licence disable anything?

This edition has no licence client at all. In the Pro edition, a licence governs

updates and support only and never disables an installed feature.

### Is any data sent anywhere?

Sharing and importing contact only the current shop. This edition has no
 external
service, telemetry, Yindle account, licence check or custom updater. Fonts, styles,
scripts and icons are bundled locally. WordPress itself can contact WordPress.org
for normal plugin updates and translations.

### Which product types are supported?

Simple and variable WooCommerce products are supported. Extensions that add
 custom
cart item data need a compatible adapter. An unsupported cart is rejected with an
explanation; its extra selections are not silently discarded.

### How should I configure caching?

Exclude the configured share URL path (by default `/cart/<share-key>/`) from
 full-
page and CDN caching. The plugin sends private, no-store and noindex headers for
these pages. Verify that your cache honors them with two separate guest sessions.
Treat a share URL as a secret: anyone with it can preview and import its product
selections until it expires or is revoked.

### What happens when I deactivate or delete the plugin?

Deactivation retains data. Deleting the plugin also retains data by default.
 The
optional **Delete data on uninstall** setting enables permanent cleanup. Free preserves
shared data if Pro is installed or saved cart/licence data indicates a Pro installation,
even when that setting is enabled.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Yindle Share Cart” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Yindle ](https://profiles.wordpress.org/yindle/)

[Translate “Yindle Share Cart” into your language.](https://translate.wordpress.org/projects/wp-plugins/yindle-share-cart)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/yindle-share-cart/),
check out the [SVN repository](https://plugins.svn.wordpress.org/yindle-share-cart/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/yindle-share-cart/)
by [RSS](https://plugins.trac.wordpress.org/log/yindle-share-cart/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.4

 * Security: stop retaining a copy of the WordPress AUTH key and salt. The capability
   
   key moves to a new random `yindle_cart_capability_key` option. Both earlier yindle_cart_capability_pepper
   options are deleted by name on first load. Their values are never read or written
   into queries. Loading fails closed if they cannot be removed.
 * Remove the verification fallback to a retired key. Share and revoke links created
   
   by every earlier version, including 1.0.3, no longer resolve. Stored carts, expiry
   and revocations are unchanged. Unmigrated plaintext 1.x links still migrate.

#### 1.0.3

 * Make first capability-key creation, legacy rotation and rate admission atomic.
 * Reject exhausted peers before creating new identity counters and expire
    database
   counters when a persistent object cache is active.
 * Add paged personal-data exports and durable deletion across relevant sites,
    
   including former memberships and an unloaded network-hook fallback.
 * Isolate Free implementation functions and constants as well as classes.
 * Preserve shared privacy and expiry jobs when another edition remains.
 * Verify separate native WordPress activation, real two-process MySQL/Redis
    races,
   multisite rollback/retry and independently composed runtime packages.

#### 1.0.2

 * Use the distinctive Yindle Share Cart name and yindle-share-cart directory.
 * Remove unused saved-cart creation, issuance, account and paid styling code.
 * Use standard WordPress language packs instead of bundled catalogues/loaders.
 * Protect old/new edition transitions and document safe removal of older copies.
 * Clarify that bundled asset provenance does not restrict modification rights.

#### 1.0.1

 * Give all nine Free runtime classes the distinctive YindleShareCart_ prefix.
 * Register bundled translations at init for older supported WordPress versions.
 * Compile bundled catalogues compatibly with the WordPress 6.4 translation reader.
 * Link the plugin header to the verified public product page.
 * Preserve shared storage, hooks and capability links; Pro files are unchanged.

#### 1.0.0

 * Initial free release of Yindle Share Cart.
 * Declares WooCommerce as a plugin dependency.
 * Documents local privacy, browser storage, caching and edition changes.
 * Contains the complete share service: capability links, current-price preview,
   
   deliberate replace/merge, guest revocation, expiry, rate limiting, atomic import
   and the privacy eraser.
 * Contains no licence client, no update client and no paid feature code.

## Meta

 *  Version **1.0.4**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [cart](https://wordpress.org/plugins/tags/cart/)[cart sharing](https://wordpress.org/plugins/tags/cart-sharing/)
   [share cart](https://wordpress.org/plugins/tags/share-cart/)[share link](https://wordpress.org/plugins/tags/share-link/)
   [woocommerce](https://wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://wordpress.org/plugins/yindle-share-cart/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/yindle-share-cart/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/yindle-share-cart/reviews/)

## Contributors

 *   [ Yindle ](https://profiles.wordpress.org/yindle/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/yindle-share-cart/)