CacheSafe for WooCommerce is a diagnostic evidence plugin by Cobalt Branch Labs. It runs controlled anonymous cart sessions through your store’s public WooCommerce surfaces and reports whether cache behavior, cookies, headers, and Store API responses preserve customer isolation.
Free v1.0 includes manual scans, sanitized findings, provider-aware remediation guidance, WP-CLI, and local-only evidence. No telemetry, no accounts, no automatic cache changes.
wp cachesafe preflight, scan, status, report, cancel, cleanup, purgeWooCommerce CacheSafe with tabs for Overview, Preflight, Live scan, Results, History, Settings, and Tools.
All scan evidence stays on your WordPress site. CacheSafe does not phone home. Reports are sanitized to exclude cookie values, Cart-Tokens, nonces, Authorization headers, raw bodies, secrets, and customer PII. Retention is bounded and configurable; uninstall can remove plugin-owned data when enabled in Settings.
Unminified JavaScript and CSS live in assets/src/. Built admin assets are written to assets/build/ via @wordpress/scripts.
To regenerate the compiled files from this plugin directory:
npm installnpm run build
package.json and webpack.config.js ship with the plugin so the build can be reproduced without a separate repository.