StaticQ Headless turns WordPress into the CMS behind a Cloudflare-hosted Astro frontend. Editors keep the familiar WordPress admin; visitors get static-fast pages served from Cloudflare’s edge and a durable R2 cache; and the plugin keeps both sides in sync automatically, without a full rebuild, a cron job, or a manual cache purge on every edit.
When you publish, update, unpublish, or reschedule a post, the plugin works out exactly which URLs changed (the post’s permalink, the archives and paginated archives it appears on, the relevant feeds, and the sitemap) and refreshes only those. Nothing else is touched, so a single edit never invalidates your whole site.
Important: everything the plugin does runs against your own Cloudflare and GitHub accounts, using credentials you provide. StaticQ Headless does not send your content or credentials to any StaticQ-operated server. There is no telemetry and no phone-home. See External services below.
git push./wp-json/sqheadless/v1/ (site config, homepage, archive, single, SEO head, sitemap) collapse WordPress’s _embed N+1 fan-out into a handful of SQL queries, for much faster SSR on media-heavy archives. The frontend uses them automatically and falls back to standard WordPress REST when they are absent.<head> and structured data; breadcrumb schema is filled in when your SEO plugin does not emit it. No SEO plugin required.The StaticQ Astro starter (the repository the wizard generates into your GitHub account) is a starting point, not a straitjacket. Replace its pages and components with your own design and deploy through the same managed pipeline (connect your repository and push). The one requirement is that your project keeps the plugin’s caching contract that the starter ships with (the edge/R2 middleware, the cache-key module, and the WordPress data client), so per-URL invalidation keeps working. The built-in Tutorials cover exactly what to keep.
StaticQ Headless connects to external services only when you ask it to (during setup and deploy actions in wp-admin, and when your content changes), and only to accounts and endpoints you configure. It never contacts a StaticQ-operated service, and it sends no analytics.
A note on bundled code: the receiver Worker the plugin uploads to your Cloudflare account ships inside the plugin as a small prebuilt bundle (assets/worker/dist.js, ~13 KB). Its full human-readable TypeScript source ships right next to it in assets/worker/src/, with build instructions and an integrity hash in assets/worker/README.md.
1. Cloudflare API (https://api.cloudflare.com).
Used when you configure and deploy the Cloudflare side from the Setup tab and the Astro Setup wizard (all admin-triggered, never on the front end and never automatically). Using the Cloudflare API token, account ID, and zone ID you enter, the plugin creates and updates the receiver Worker (uploading its bundled script), provisions the frontend Worker and an R2 bucket, sets Worker variables and secrets, manages the workers.dev subdomain, and binds a custom domain. This is your own Cloudflare account. Cloudflare terms: https://www.cloudflare.com/website-terms/ (privacy policy: https://www.cloudflare.com/privacypolicy/).
2. GitHub API (https://api.github.com).
Used when you set up and deploy the Astro frontend (the Astro Setup wizard), and only when you trigger those actions. Using a GitHub personal access token you provide, the plugin verifies or creates a repository (a new one is created by generating it from the public StaticQ Astro starter template at https://github.com/daixtech/staticq-headless-starter, which GitHub copies into your account server-side), sets GitHub Actions variables and (libsodium-encrypted) secrets, and dispatches and monitors the deploy workflow. This is your own GitHub account. GitHub terms: https://docs.github.com/site-policy/github-terms/github-terms-of-service (privacy statement: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement).
3. Your receiver endpoint (a URL you configure).
When content changes (and when you use the manual refresh or warmup tools), the plugin POSTs to the URL you set, normally the Cloudflare Worker you deployed above. The request contains the list of changed absolute URLs plus basic post metadata (event type, post ID, post type) and your site’s home_url(), signed with an HMAC secret for authenticity. No API tokens or account IDs are ever sent to this endpoint. Because the URL is yours, its terms are yours.