
CacheSafe for WooCommerce is a diagnostic evidence plugin by Cobalt Branch Labs. It runs controlled anonymous cart sessions through your store’s public WooCommerce surfaces and reports whether cache behavior, cookies, headers, and Store API responses preserve customer isolation.
Free v1.0 includes manual scans, sanitized findings, provider-aware remediation guidance, WP-CLI, and local-only evidence. No telemetry, no accounts, no automatic cache changes.
What it does
- Preflight checks — WooCommerce pages, loopback reachability, Store API, test product, runner health, perspective
- Manual staged scans — Store API Cart-Token A/B isolation plus classic cookie/add-to-cart flow where supported
- 16 safety checks (CS-101–116) — headers, Set-Cookie, session isolation, replay, cleanup, perspective
- Sanitized reports — copy or download JSON, text, or HTML without cookie values, tokens, or raw bodies
- Provider guidance — evidence-linked remediation for generic stacks and common cache/CDN plugins
- WP-CLI —
wp cachesafe preflight,scan,status,report,cancel,cleanup,purge - Retention — keeps the last five completed scans within 30 days (configurable shorter); automatic daily purge
What it does not do
- Place orders, process payments, or call checkout write endpoints
- Change cache, CDN, DNS, or host settings automatically
- Send telemetry or require an account
- Show a numeric “safety score”
Admin
WooCommerce CacheSafe with tabs for Overview, Preflight, Live scan, Results, History, Settings, and Tools.
Privacy
All scan evidence stays on your WordPress site. CacheSafe does not phone home. Reports are sanitized to exclude cookie values, Cart-Tokens, nonces, Authorization headers, raw bodies, secrets, and customer PII. Retention is bounded and configurable; uninstall can remove plugin-owned data when enabled in Settings.
Development
Unminified JavaScript and CSS live in assets/src/. Built admin assets are written to assets/build/ via @wordpress/scripts.
To regenerate the compiled files from this plugin directory:
npm install-
npm run buildpackage.json and
webpack.config.jsship with the plugin so the build can be reproduced without a separate repository.
Screenshots

CacheSafe overview and scan summary

Live scan progress with stage timeline

Findings with sanitized evidence drawer