[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEsXQlyoLRE68WcVKIJXlT01o-ObNjl4v0Ab6wobHpBo":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"harborplugins","https:\u002F\u002Fprofiles.wordpress.org\u002Fharborplugins\u002F",2,0,100,30,94,"2026-08-29T10:12:20.079Z",[13,34],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"harbor-order-analytics-for-woocommerce","Harbor Order Analytics for WooCommerce","1.0.0","\u003Cp>Harbor Order Analytics for WooCommerce is an admin dashboard that reports on your store’s orders by querying WooCommerce’s High-Performance Order Storage (HPOS) tables directly. It runs entirely on your own server using standard WordPress and WooCommerce APIs.\u003C\u002Fp>\n\u003Cp>High-Performance Order Storage, introduced in WooCommerce 8.2, stores orders in dedicated \u003Ccode>wc_orders\u003C\u002Fcode> tables rather than the legacy \u003Ccode>wp_posts\u003C\u002Fcode> table. This plugin reads those HPOS tables directly, so its figures reflect the current order storage whether you run HPOS-only mode or keep both storage methods in sync.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No setup required\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Install, activate, and open \u003Cstrong>WooCommerce > Order Analytics\u003C\u002Fstrong>. The plugin declares HPOS compatibility on activation and detects your storage mode automatically. There is no configuration, no account, and no API keys.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Works with all payment gateways\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Revenue figures are read from the order record in the HPOS tables, not from gateway-specific meta, so orders from any gateway (Stripe, PayPal, Square, WooPayments, manual orders, and others) appear in every report.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Revenue over time (daily, weekly, or monthly chart)\u003C\u002Fli>\n\u003Cli>Average order value over time\u003C\u002Fli>\n\u003Cli>Top products by revenue\u003C\u002Fli>\n\u003Cli>Orders by status (doughnut chart)\u003C\u002Fli>\n\u003Cli>New vs. returning customers\u003C\u002Fli>\n\u003Cli>KPI summary cards: total revenue, total orders, average order value, new customers\u003C\u002Fli>\n\u003Cli>Date-range presets and a custom range picker\u003C\u002Fli>\n\u003Cli>Results cached for performance and refreshed automatically when orders change\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Requirements\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress 6.0 or later\u003C\u002Fli>\n\u003Cli>WooCommerce 8.2 or later\u003C\u002Fli>\n\u003Cli>PHP 7.4 or later\u003C\u002Fli>\n\u003Cli>HPOS enabled under \u003Cstrong>WooCommerce > Settings > Advanced > Features\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium version\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A separate premium version, distributed from \u003Ca href=\"https:\u002F\u002Fharborplugins.com\" rel=\"nofollow ugc\">harborplugins.com\u003C\u002Fa>, adds cohort retention analysis, customer lifetime value, product profitability, refund rate by product, CSV export, and a weekly email digest. The version hosted here is fully functional on its own; none of these premium features are included in or disabled within this plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All report data is queried from your own WordPress database and is never sent to an external server. See the Privacy Policy section below for details on the licensing SDK.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>All report data (orders, revenue, customers) is queried directly from your own WordPress database and is never transmitted to any external server.\u003C\u002Fp>\n\u003Cp>This plugin uses the Freemius SDK for licensing and updates. On activation you are shown a one-time opt-in screen; if you skip it, no diagnostic data is collected. If you opt in, Freemius collects non-personally-identifiable environment data (site URL, WordPress version, PHP version, plugin version) for update delivery and, where applicable, license validation. No order data, customer data, or personally identifiable information is transmitted. See the \u003Ca href=\"https:\u002F\u002Ffreemius.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Freemius privacy policy\u003C\u002Fa>.\u003C\u002Fp>\n","Order analytics for WooCommerce that read High-Performance Order Storage (HPOS) tables directly: revenue, top products, order status, and customers.",67,"2026-07-11T17:18:00.000Z","7.0.2","6.0","7.4",[25,26,27,28,29],"analytics","hpos","orders","reports","woocommerce","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fharbor-order-analytics-for-woocommerce.1.0.0.zip",null,"2026-07-22T17:31:50.256Z",{"slug":35,"name":36,"version":37,"author":4,"author_profile":5,"description":38,"short_description":39,"active_installs":7,"downloaded":40,"rating":7,"num_ratings":7,"last_updated":41,"tested_up_to":21,"requires_at_least":42,"requires_php":23,"tags":43,"homepage":30,"download_link":48,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"harbor-privacy-guard-for-woocommerce","Harbor Privacy Guard for WooCommerce","1.5.1","\u003Cp>Harbor Privacy Guard for WooCommerce enforces visitor privacy choices on the server. Instead of setting a client-side consent flag for tracking scripts to read, it detects the visitor’s consent state in PHP and dequeues known tracking script handles before WordPress renders the page, so scripts that were declined never load.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>GPC Browser Signal Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>GPC (Global Privacy Control) is a browser-level opt-out signal that is legally binding in 12 US states. When a user enables it — through their browser settings or a privacy extension — their browser sends \u003Ccode>Sec-GPC: 1\u003C\u002Fcode> on every HTTP request. This plugin detects that header server-side, requiring no user interaction with a banner. A small JavaScript snippet also reads \u003Ccode>navigator.globalPrivacyControl\u003C\u002Fcode> and sets a first-party cookie (\u003Ccode>gpcg_gpc_js\u003C\u002Fcode>) so GPC is honored even when the header is absent (some proxies strip it).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Google Consent Mode v2\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin emits \u003Ccode>gtag('consent','default',{...})\u003C\u002Fcode> before GTM loads, at \u003Ccode>wp_head\u003C\u002Fcode> priority 1 — the integration point Google’s Consent Mode v2 documentation requires. Google’s GA4 behavioral modeling needs this consent signal to be present even for visitors who deny tracking; the plugin supplies it so modeling continues to work for users who have denied or not yet responded.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>California CPRA Opt-Out Audit Trail\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>California’s CPRA regulations (effective January 2026) require stores to log opt-out signals with a timestamped record. This plugin stores consent decisions in a dedicated database table (\u003Ccode>{prefix}gpcg_opt_out_log\u003C\u002Fcode>) rather than \u003Ccode>wp_options\u003C\u002Fcode>. Opt-outs are recorded where they happen — when a visitor declines (or accepts) the banner, when an automatic GPC signal is detected (deduplicated to once per visitor per day), and at WooCommerce checkout — so the trail covers non-purchasers, not only completed orders. Each row records the hashed IP address (SHA-256 with a dedicated, stored plugin salt kept separate from WordPress auth keys so it survives key rotation — the raw IP is never written to disk), the consent state (granted \u002F denied \u002F gpc), the signal source (banner \u002F gpc_header \u002F gpc_js \u002F default), the WooCommerce order ID, the page URL, and a UTC timestamp. A confirmation notice is displayed on the WooCommerce thank-you page to satisfy the California requirement that users receive visible confirmation of their opt-out.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Minimal Performance Impact\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>On the fast path — consent granted, no GPC signal — there is no output buffering and no HTML rewriting; the expensive work never runs. To keep per-visitor consent state correct, responses that depend on a consent cookie or GPC signal are automatically excluded from full-page caches (and the consent cookies are registered with WP Rocket and LiteSpeed Cache); first-visit pages remain cacheable. Output buffering for script stripping is a Pro feature and is never activated for consented users.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Free vs Pro\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>  Feature\u003Cbr \u002F>\n  Free\u003Cbr \u002F>\n  Pro\u003C\u002Fp>\n\u003Cp>  GPC header detection (Sec-GPC)\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  GPC JavaScript detection\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Block WooCommerce Google Analytics integration\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Block Facebook \u002F Meta Pixel\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Block TikTok Pixel\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Block Bing \u002F Microsoft UET\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Google Consent Mode v2 dataLayer defaults\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Consent banner (accept \u002F decline)\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Opt-out confirmation on WooCommerce thank-you page\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Audit log of banner, GPC, and checkout consent events (hashed IP, order ID, state, source)\u003Cbr \u002F>\n  ✓\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Output-buffer script stripping (catches inline + third-party injected scripts)\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Custom domain blocklist\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  CSV compliance export\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>  Multi-state consent UI (California vs Virginia vs Colorado)\u003Cbr \u002F>\n  —\u003Cbr \u002F>\n  ✓\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How It Works\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>On every request, PHP checks the \u003Ccode>Sec-GPC\u003C\u002Fcode> header and the \u003Ccode>gpcg_gpc_js\u003C\u002Fcode> cookie (set by a tiny JS snippet that reads \u003Ccode>navigator.globalPrivacyControl\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>If GPC or no consent: known tracking script handles are dequeued; \u003Ccode>gtag('consent','default',{ad_storage:'denied',...})\u003C\u002Fcode> fires before GTM at \u003Ccode>wp_head\u003C\u002Fcode> priority 1.\u003C\u002Fli>\n\u003Cli>Consent decisions are logged to a dedicated audit table (SHA-256 hashed IP, UTC timestamp) when the visitor uses the banner, when GPC is detected (once per visitor per day), and at WooCommerce checkout completion.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin stores consent decisions in the database table \u003Ccode>{prefix}gpcg_opt_out_log\u003C\u002Fcode>. Visitor IP addresses are hashed with SHA-256 and a site-specific salt before storage — raw IPs are never written to disk. The hashed IP, consent state (granted\u002Fdenied\u002Fgpc), signal source (banner\u002Fgpc_header\u002Fgpc_js\u002Fdefault), WooCommerce order ID (when applicable), and page URL are retained until the plugin is uninstalled or the site administrator exports and purges the table. This plugin transmits nothing to external servers; the bundled Freemius SDK is opt-in only, used solely for Pro license activation if you choose to enter a license key.\u003C\u002Fp>\n","WooCommerce-specific server-side enforcement of GPC browser signals, Google Consent Mode v2, and California opt-out audit logging.",42,"2026-07-19T18:23:00.000Z","5.8",[44,45,46,47,29],"ccpa","consent","gpc","privacy","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fharbor-privacy-guard-for-woocommerce.1.5.1.zip"]