| 1 |
# CartFlows Free — Abilities Audit Discovery |
| 2 |
|
| 3 |
**Date:** 2026-03-04 |
| 4 |
**Plugin:** CartFlows Free v2.2.2 |
| 5 |
**Plugin slug:** `cartflows` |
| 6 |
**Audit phase:** Phase 0 complete |
| 7 |
|
| 8 |
--- |
| 9 |
|
| 10 |
## Plugin Architecture Summary |
| 11 |
|
| 12 |
CartFlows Free is a WooCommerce-dependent funnel/checkout builder built on two primary entity types: |
| 13 |
|
| 14 |
- **Flow** (`cartflows_flow` CPT): The funnel container — holds ordered Steps. |
| 15 |
- **Step** (`cartflows_step` CPT): Individual pages within a funnel (checkout, thank-you, landing, optin). |
| 16 |
|
| 17 |
### Core Admin Layers |
| 18 |
|
| 19 |
| Layer | Directory | Purpose | |
| 20 |
|-------|-----------|---------| |
| 21 |
| Ajax handlers | `admin-core/ajax/` | CRUD, lifecycle, stats operations | |
| 22 |
| REST API | `admin-core/api/` | Read endpoints for flow and step data | |
| 23 |
| Helper | `classes/class-cartflows-helper.php` | Settings access, global options | |
| 24 |
| Modules | `modules/{type}/` | Per-step-type rendering logic | |
| 25 |
|
| 26 |
### Custom Capabilities Used |
| 27 |
|
| 28 |
- `cartflows_manage_flows_steps` — Manage funnels and steps (flows/steps CRUD) |
| 29 |
- `cartflows_manage_settings` — Manage global plugin settings |
| 30 |
|
| 31 |
### Key Settings Store |
| 32 |
|
| 33 |
- `_cartflows_common` option — serialized array of global settings (page builder, global checkout, tracking) |
| 34 |
- `_cartflows_store_checkout` option — ID of the store checkout flow |
| 35 |
- Per-flow meta: `wcf-steps`, `wcf-testing`, `wcf-flow-id`, `wcf-step-type` |
| 36 |
|
| 37 |
--- |
| 38 |
|
| 39 |
## Modules Inventory |
| 40 |
|
| 41 |
| Module | Directory | Priority | Rationale | |
| 42 |
|--------|-----------|----------|-----------| |
| 43 |
| Flow (Funnel) | `admin-core/ajax/flows.php`, `admin-core/api/flows.php`, `admin-core/api/flow-data.php` | P0 | Core funnel CRUD — list, get, create, update, delete, clone, status | |
| 44 |
| Step | `admin-core/ajax/steps.php`, `admin-core/api/step-data.php` | P0 | Core step CRUD — get, update, clone, delete | |
| 45 |
| Analytics/Stats | `admin-core/ajax/flows-stats.php` | P0 | Revenue + order stats by date range and flow | |
| 46 |
| Admin/Settings | `admin-core/ajax/common-settings.php`, `classes/class-cartflows-helper.php` | P1 | Global settings read/write | |
| 47 |
| Checkout module | `modules/checkout/` | P1 | Checkout step settings | |
| 48 |
| Thank You module | `modules/thankyou/` | P1 | Thank-you step settings | |
| 49 |
| Optin module | `modules/optin/` | P1 | Opt-in step settings | |
| 50 |
| Landing module | `modules/landing/` | P1 | Landing page step settings | |
| 51 |
| Email Report | `modules/email-report/` | P2 | Email report config | |
| 52 |
| Woo Dynamic Flow | `modules/woo-dynamic-flow/` | P2 | Dynamic product routing | |
| 53 |
| Gutenberg | `modules/gutenberg/` | P2 | Block registration | |
| 54 |
| Elementor | `modules/elementor/` | P2 | Elementor widget | |
| 55 |
|
| 56 |
--- |
| 57 |
|
| 58 |
## Key Operations Identified (pre-mining summary) |
| 59 |
|
| 60 |
### Flow operations (admin-core/ajax/flows.php) |
| 61 |
- `get_items` (REST) — list flows with pagination, status, search |
| 62 |
- `get_item` (REST) — get full flow data including steps |
| 63 |
- `update_flow_title` — rename a flow |
| 64 |
- `clone_flow` — duplicate a flow with all steps |
| 65 |
- `delete_flow` — permanent delete |
| 66 |
- `trash_flow` — move to trash |
| 67 |
- `restore_flow` — untrash |
| 68 |
- `reorder_flow_steps` — change step order in a flow |
| 69 |
- `trash_flows_in_bulk` — bulk trash |
| 70 |
- `update_flow_post_status` — bulk status change |
| 71 |
- `delete_flows_permanently` — bulk permanent delete |
| 72 |
- `save_flow_meta_settings` — save flow settings (title, slug, meta) |
| 73 |
- `export_flows_in_bulk` — export flow data as JSON |
| 74 |
- `update_status` — toggle single flow publish/draft |
| 75 |
- `get_published_flows` — list published flow IDs+titles for analytics |
| 76 |
|
| 77 |
### Step operations (admin-core/ajax/steps.php) |
| 78 |
- `get_item` (REST) — get step data with type, settings, options |
| 79 |
- `clone_step` — duplicate a step |
| 80 |
- `delete_step` — permanent delete step |
| 81 |
- `save_meta_settings` — save step settings |
| 82 |
- `update_step_title` — rename a step |
| 83 |
|
| 84 |
### Analytics (admin-core/ajax/flows-stats.php) |
| 85 |
- `get_all_flows_stats` — earnings, orders by date range, per-flow, recent orders |
| 86 |
|
| 87 |
### Settings (admin-core/ajax/common-settings.php) |
| 88 |
- `save_global_settings` — save global plugin settings |
| 89 |
|
| 90 |
### Product/Coupon search (admin-core/ajax/meta-data.php) |
| 91 |
- `json_search_products` — search WooCommerce products |
| 92 |
- `json_search_coupons` — search WooCommerce coupons |
| 93 |
|
| 94 |
--- |
| 95 |
|
| 96 |
## WooCommerce Dependency Note |
| 97 |
|
| 98 |
Checkout, thank-you, optin, email-report, woo-dynamic-flow and analytics modules only load when `WC()` function exists (`$this->is_woo_active`). Abilities from these modules should declare WooCommerce as a requirement in their description. |
| 99 |
|
| 100 |
--- |
| 101 |
|
| 102 |
## Phase 0 Status: COMPLETE |
| 103 |
|