PluginProbe
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN / 1.3.6
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN v1.3.6
1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.4 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 All 32 releases
xspeed / uninstall.php

uninstall.php in xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN 1.3.6, at uninstall.php

267 lines 12.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Uninstall handler — deletes options, cache, and drop-in.
4 *
5 * @package XSpeed
6 */
7
8 if ( ! defined( 'WP_UNINSTALL_PLUGIN' ) ) {
9 exit;
10 }
11
12 xspeed_uninstall_cleanup();
13
14 /**
15 * Run all uninstall cleanup. Wrapped in a function so locals don't pollute global scope.
16 */
17 function xspeed_uninstall_cleanup() {
18 /*
19 * Everything here is ours to delete. `wpdeveloper_xspeed_offer` is NOT — it
20 * is the site's answer about whether it wants this plugin, written by
21 * whichever WPDeveloper plugin offered it. Removing xSpeed is itself an
22 * answer — the siblings read it as one, from that row plus the absent plugin
23 * files. Deleting it here would make every one of them offer xSpeed again to
24 * the user who just took it off.
25 * See docs/guides/installing-from-another-plugin.md.
26 */
27 delete_option( 'xspeed_options' );
28
29 /*
30 * Per-module rows, for the modules THIS plugin ships. The slugs are read
31 * out of the module files rather than kept as a list here, so a module
32 * added later cannot leave its row behind; and only Free's, because
33 * xspeed-pro keeps its own rows under the same prefix and a Free uninstall
34 * is not a decision about Pro's settings.
35 *
36 * These have to go. The conflict-safe profile writes an explicit `false`
37 * into every one of them when another plugin owns the page cache, and
38 * seeding on the next install only fills ABSENT keys — so a row that
39 * survived uninstall kept every switch off on a site that had since been
40 * cleared, with no way back but the dashboard (PR #295 review).
41 */
42 foreach ( glob( __DIR__ . '/includes/modules/*/*Module.php' ) ?: array() as $module_file ) {
43 $source = @file_get_contents( $module_file ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- own plugin file, uninstall.
44 if ( is_string( $source ) && preg_match( "/const\s+SLUG\s*=\s*'([^']+)'/", $source, $m ) ) {
45 delete_option( 'xspeed_module_' . $m[1] );
46 }
47 }
48 delete_option( 'xspeed_data_version' );
49 delete_option( 'xspeed_activity_log' );
50 delete_option( 'xspeed_server_type' );
51 delete_option( 'xspeed_oc_dropin_synced' );
52 delete_option( 'xspeed_oc_generation' );
53 delete_option( 'xspeed_oc_sync_attempts' );
54 delete_option( 'xspeed_overridden_constants' );
55 delete_option( 'xspeed_last_mobile_separate' );
56 delete_option( 'xspeed_redirect_to_onboarding' );
57 delete_option( 'xspeed_preloader_firewall_block' );
58 delete_option( 'xspeed_onboarding_complete' );
59 // Provenance a host plugin wrote before it activated us, and the profile
60 // that install came up with.
61 delete_option( 'xspeed_installed_by' );
62 delete_option( 'xspeed_installer' );
63 delete_option( 'xspeed_install_profile' );
64 // Written by the copy-vendored Setup that host plugins used to carry
65 // before xSpeed seeded its own conflict-safe profile on activation. We no
66 // longer write it; an older host may have, and it is ours to clean up.
67 delete_option( 'xspeed_setup_snapshot' );
68 delete_option( 'xspeed_stats' );
69 delete_option( 'xspeed_gc_cursor' );
70 wp_clear_scheduled_hook( 'xspeed_gc' );
71
72 global $wpdb;
73
74 // Hit counters and the Hub attachment flag — ours, and simply never named
75 // here before. xspeed_hit_buffer is BOTH an option and a transient of the
76 // same name (Hit_Counter uses one string for the memory buffer and the
77 // durable counter), so both stores need clearing.
78 delete_option( 'xspeed_hit_buffer' );
79 delete_transient( 'xspeed_hit_buffer' );
80 delete_option( 'xspeed_hit_daily' );
81 delete_option( 'xspeed_hub_site_attached' );
82
83 // Usage-tracking state, which lives in the shared WP Insights rows rather
84 // than under our own prefix. Left behind, the consent key survives an
85 // uninstall: a REINSTALL then reads as already opted in before the wizard
86 // has asked anything, and a later deactivation posts a diagnostic payload
87 // for a consent this install never collected (#439).
88 //
89 // The two keyed rows are SHARED with sibling WPDeveloper plugins, so only
90 // our own key comes out and the row itself is deleted only once nothing
91 // else is using it. Deleting them outright would wipe another plugin's
92 // consent state.
93 foreach ( array( 'wpins_allow_tracking', 'wpins_last_track_time' ) as $shared ) {
94 $value = get_option( $shared );
95 if ( ! is_array( $value ) ) {
96 continue; // Absent, or a shape we did not write — leave it alone.
97 }
98 unset( $value['xspeed'] );
99 if ( empty( $value ) ) {
100 delete_option( $shared );
101 } else {
102 update_option( $shared, $value );
103 }
104 }
105 // The deactivation-feedback payload. Normally consumed-then-deleted by the
106 // tracker's own deactivation send, but that only happens when consent
107 // passes and the send succeeds — a user who deactivates without consent
108 // leaves both rows behind, and they are exactly the orphaned diagnostic
109 // payload #439 describes.
110 delete_option( 'wpins_deactivation_reason_xspeed' );
111 delete_option( 'wpins_deactivation_details_xspeed' );
112 // The tracker's recurring send. Cleared on opt-out, but nothing guarantees
113 // an opt-out ever happened before the uninstall.
114 wp_clear_scheduled_hook( 'xspeed_do_weekly_action' );
115 // Our own WP Insights rows: the site id, the original URL, and the last
116 // payload — whose name embeds the site id. The payload names are
117 // derivable from the id, but a failed earlier uninstall or a renamed row
118 // shape would strand them, so sweep the prefix. `xspeed-pro`'s rows
119 // survive this only because its slug's HYPHEN doesn't match the
120 // underscore in `wpins_xspeed_%` — that separator is load-bearing.
121 delete_option( 'wpins_xspeed_site_id' );
122 delete_option( 'wpins_xspeed_original_url' );
123 // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- options API has no prefix delete; uninstall only.
124 $wpins_rows = $wpdb->get_col(
125 $wpdb->prepare(
126 "SELECT option_name FROM {$wpdb->options} WHERE option_name LIKE %s",
127 $wpdb->esc_like( 'wpins_xspeed_' ) . '%'
128 )
129 );
130 foreach ( (array) $wpins_rows as $wpins_row ) {
131 delete_option( $wpins_row );
132 }
133
134 // Score history — the plugin's own table, plus the legacy option the
135 // table was migrated from (kept on upgrade so a bad migration is
136 // recoverable; there is nothing to recover on uninstall).
137 // phpcs:ignore WordPress.DB.DirectDatabaseQuery, WordPress.DB.PreparedSQL.InterpolatedNotPrepared -- own table, uninstall.
138 $wpdb->query( 'DROP TABLE IF EXISTS ' . $wpdb->prefix . 'xspeed_scores' );
139 delete_option( 'xspeed_score_schema' );
140 delete_option( 'xspeed_score_history' );
141
142 if ( ! function_exists( 'WP_Filesystem' ) ) {
143 require_once ABSPATH . 'wp-admin/includes/file.php';
144 }
145 WP_Filesystem();
146 global $wp_filesystem;
147 if ( ! $wp_filesystem ) {
148 return;
149 }
150
151 $cache_dir = WP_CONTENT_DIR . '/cache/xspeed';
152 if ( $wp_filesystem->is_dir( $cache_dir ) ) {
153 $wp_filesystem->delete( $cache_dir, true );
154 }
155
156 // nginx hit log (FBS-82478). It lives under uploads/xspeed/, NOT the
157 // cache dir, precisely so that a pasted nginx `access_log` directive
158 // pointing at it does NOT get its parent directory deleted here — if it
159 // did, `nginx -t` would fail [emerg] and refuse to (re)start, taking
160 // down EVERY vhost on the host until someone manually finds the orphaned
161 // directive. We therefore EMPTY the log file but DELIBERATELY LEAVE THE
162 // DIRECTORY in place, so any still-pasted directive keeps a valid,
163 // openable target after the plugin is gone. (A stray empty dir is
164 // harmless; a broken nginx is not.) Users are also warned in the admin
165 // UI to remove the snippet before uninstalling.
166 $hits_log = WP_CONTENT_DIR . '/uploads/xspeed/hits.log';
167 if ( function_exists( 'wp_upload_dir' ) ) {
168 $uploads = wp_upload_dir( null, false );
169 if ( is_array( $uploads ) && empty( $uploads['error'] ) && ! empty( $uploads['basedir'] ) ) {
170 $hits_log = rtrim( (string) $uploads['basedir'], '/' ) . '/xspeed/hits.log';
171 }
172 }
173 if ( $wp_filesystem->exists( $hits_log ) ) {
174 // Truncate, don't delete the dir — keep the access_log target openable.
175 $wp_filesystem->put_contents( $hits_log, '', FS_CHMOD_FILE );
176 }
177
178 // Static-cache tree — separate from the flat-hash cache dir, holds
179 // the {host}/{path}/index.html files the .htaccess rewrite block
180 // serves directly. Same teardown rules as XSPEED_CACHE_DIR.
181 $static_dir = WP_CONTENT_DIR . '/cache/xspeed-static';
182 if ( $wp_filesystem->is_dir( $static_dir ) ) {
183 $wp_filesystem->delete( $static_dir, true );
184 }
185
186 // Rewrite block in site-root .htaccess. WP's marker helpers handle
187 // the "remove only our block" semantics — passing an empty array
188 // strips the markers in place.
189 $htaccess = ABSPATH . '.htaccess';
190 if ( $wp_filesystem->exists( $htaccess ) && $wp_filesystem->is_writable( $htaccess ) ) {
191 if ( ! function_exists( 'insert_with_markers' ) ) {
192 require_once ABSPATH . 'wp-admin/includes/misc.php';
193 }
194 insert_with_markers( $htaccess, 'xSpeed Static Cache', array() );
195 }
196
197 // Serialize the shared drop-in/config teardown with Cache::toggle(). If
198 // the lock is unavailable, leave shared state and its receipt untouched.
199 // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen,WordPress.PHP.NoSilencedErrors.Discouraged -- flock requires a local handle; failure is fail-closed.
200 $ownership_lock = @fopen( WP_CONTENT_DIR . '/.xspeed-page-cache.lock', 'c+' );
201 if ( ! is_resource( $ownership_lock ) || ! flock( $ownership_lock, LOCK_EX ) ) {
202 return;
203 }
204
205 require_once __DIR__ . '/includes/wp-cache-constant.php';
206 $drop_in = WP_CONTENT_DIR . '/advanced-cache.php';
207 $dropin_ours = false;
208 if ( $wp_filesystem->exists( $drop_in ) ) {
209 $contents = $wp_filesystem->get_contents( $drop_in );
210 $dropin_ours = is_string( $contents ) && xspeed_has_canonical_dropin_signature( $contents );
211 if ( $dropin_ours ) {
212 $wp_filesystem->delete( $drop_in );
213 }
214 }
215
216 $wp_config = file_exists( ABSPATH . 'wp-config.php' ) ? ABSPATH . 'wp-config.php' : dirname( ABSPATH ) . '/wp-config.php';
217 // `defined()` alone, not `&& WP_CACHE`: the old truthiness test skipped
218 // the removal whenever the constant was false/0 — exactly the orphan we
219 // are here to clean up — while still entering it for TRUE/1, where the
220 // hardcoded-lowercase regex then matched nothing and reported success.
221 // Strip whatever spelling is there. (#9)
222 //
223 // Gated on the drop-in being ours: if another caching plugin holds
224 // advanced-cache.php, WP_CACHE is the switch that loads THEIR file, and
225 // stripping it on our way out would silently disable their page cache.
226 if ( $wp_filesystem->is_writable( $wp_config ) ) {
227 $config = $wp_filesystem->get_contents( $wp_config );
228 if ( is_string( $config ) ) {
229 // Same helper Cache::set_wp_cache_constant() uses — one pattern,
230 // one place. uninstall.php loads no plugin classes, hence a
231 // plain requirable function rather than a method.
232 require_once __DIR__ . '/includes/wp-cache-constant.php';
233 $receipt = get_option( 'xspeed_page_cache_ownership_receipt', '' );
234 $marked = xspeed_wp_cache_receipt_matches( $config, $receipt );
235 /*
236 * A receipt proves WE wrote the line; it does not prove the line
237 * is still ours to remove. If a competitor has since taken over
238 * advanced-cache.php, WP_CACHE is what loads THEIR drop-in — they
239 * had no reason to touch an already-true define, so our receipt
240 * comment is still sitting beside it. Stripping on the receipt
241 * alone silently stopped their live page cache.
242 *
243 * A foreign drop-in therefore vetoes the removal outright, which
244 * is the same rule Cache::set_wp_cache_constant() applies in the
245 * running plugin; only this path was missing it. `$dropin_ours`
246 * covers the file we just deleted, `$marked` the case where there
247 * is no drop-in left at all.
248 */
249 $foreign_dropin = $wp_filesystem->exists( $drop_in ) && ! $dropin_ours;
250 if ( ! $foreign_dropin && ( $dropin_ours || $marked ) ) {
251 $config = xspeed_strip_wp_cache_define( $config );
252 $wp_filesystem->put_contents( $wp_config, $config, FS_CHMOD_FILE );
253 }
254 }
255 }
256 delete_option( 'xspeed_page_cache_ownership_receipt' );
257 flock( $ownership_lock, LOCK_UN );
258 fclose( $ownership_lock );
259 // Our own lock file, left in wp-content after everything else of ours is
260 // gone. Deleted last, after the handle is closed, so we are not
261 // unlinking a lock we are still inside. That ordering is hygiene, not a
262 // guarantee: a request already past the fopen would hold a handle to an
263 // unlinked inode. Harmless here — by this point the plugin is being
264 // removed and nothing will take the lock again.
265 $wp_filesystem->delete( WP_CONTENT_DIR . '/.xspeed-page-cache.lock' );
266 }
267