CacheSafe for WooCommerce
CacheSafe for WooCommerce

CacheSafe for WooCommerce

0/5 (0 ratings) — active installs Updated Sep 21, 2026
CacheSafe overview and scan summary

CacheSafe overview and scan summary

CacheSafe for WooCommerce checks cart caching and customer session isolation using controlled anonymous cart sessions. Use it to investigate whether caching could mix cart responses between sessions.

Run a manual scan, review the findings, and share a sanitized report with your developer or hosting provider. Results describe the tested requests and scan conditions; a passing scan is not a guarantee for every customer or cache path.

Scans create temporary anonymous carts using a configured test product. They do not place orders or process payments. CacheSafe provides guidance so you can investigate findings; it does not change cache settings automatically.

Manual scans, sanitized reports, provider guidance, and WP-CLI are included. Evidence stays on your site, with no telemetry or account required.

What it does

  • Preflight checks — WooCommerce pages, loopback reachability, Store API, test product, runner health, perspective
  • Manual staged scans — Store API Cart-Token A/B isolation plus classic cookie/add-to-cart flow where supported
  • 16 safety checks (CS-101–116) — headers, Set-Cookie, session isolation, replay, cleanup, perspective
  • Sanitized reports — copy or download JSON, text, or HTML without cookie values, tokens, or raw bodies
  • Provider guidance — evidence-linked remediation for generic stacks and common cache/CDN plugins
  • WP-CLI — wp cachesafe preflight, scan, status, report, cancel, cleanup, purge
  • Retention — keeps the last five completed scans within 30 days (configurable shorter); automatic daily purge

What it does not do

  • Place orders, process payments, or call checkout write endpoints
  • Change cache, CDN, DNS, or host settings automatically
  • Send telemetry or require an account
  • Show a numeric “safety score”

Admin

WooCommerce CacheSafe with tabs for Overview, Preflight, Live scan, Results, History, Settings, and Tools.

Privacy

All scan evidence stays on your WordPress site. CacheSafe does not phone home. Reports are sanitized to exclude cookie values, Cart-Tokens, nonces, Authorization headers, raw bodies, secrets, and customer PII. Retention is bounded and configurable; uninstall can remove plugin-owned data when enabled in Settings.

Development

Unminified JavaScript and CSS live in assets/src/. Built admin assets are written to assets/build/ via @wordpress/scripts.

To regenerate the compiled files from this plugin directory:

  1. npm install
  2. npm run build

    package.json and webpack.config.js ship with the plugin so the build can be reproduced without a separate repository.