PluginProbe
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN / 1.3.7
xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN v1.3.7
1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.4 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 All 33 releases
xspeed / uninstall.php

uninstall.php in xSpeed Cache: AI-Powered Performance Hub with MCP, Caching & CDN 1.3.7, at uninstall.php

268 lines 12.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Uninstall handler — deletes options, cache, and drop-in.
4 *
5 * @package XSpeed
6 */
7
8 if ( ! defined( 'WP_UNINSTALL_PLUGIN' ) ) {
9 exit;
10 }
11
12 xspeed_uninstall_cleanup();
13
14 /**
15 * Run all uninstall cleanup. Wrapped in a function so locals don't pollute global scope.
16 */
17 function xspeed_uninstall_cleanup() {
18 /*
19 * Everything here is ours to delete. `wpdeveloper_xspeed_offer` is NOT — it
20 * is the site's answer about whether it wants this plugin, written by
21 * whichever WPDeveloper plugin offered it. Removing xSpeed is itself an
22 * answer — the siblings read it as one, from that row plus the absent plugin
23 * files. Deleting it here would make every one of them offer xSpeed again to
24 * the user who just took it off.
25 * See docs/guides/installing-from-another-plugin.md.
26 */
27 delete_option( 'xspeed_options' );
28
29 /*
30 * Per-module rows, for the modules THIS plugin ships. The slugs are read
31 * out of the module files rather than kept as a list here, so a module
32 * added later cannot leave its row behind; and only Free's, because
33 * xspeed-pro keeps its own rows under the same prefix and a Free uninstall
34 * is not a decision about Pro's settings.
35 *
36 * These have to go. The conflict-safe profile writes an explicit `false`
37 * into every one of them when another plugin owns the page cache, and
38 * seeding on the next install only fills ABSENT keys — so a row that
39 * survived uninstall kept every switch off on a site that had since been
40 * cleared, with no way back but the dashboard (PR #295 review).
41 */
42 foreach ( glob( __DIR__ . '/includes/modules/*/*Module.php' ) ?: array() as $module_file ) {
43 $source = @file_get_contents( $module_file ); // phpcs:ignore WordPress.WP.AlternativeFunctions.file_get_contents_file_get_contents -- own plugin file, uninstall.
44 if ( is_string( $source ) && preg_match( "/const\s+SLUG\s*=\s*'([^']+)'/", $source, $m ) ) {
45 delete_option( 'xspeed_module_' . $m[1] );
46 }
47 }
48 delete_option( 'xspeed_data_version' );
49 delete_option( 'xspeed_activity_log' );
50 delete_option( 'xspeed_server_type' );
51 delete_option( 'xspeed_oc_dropin_synced' );
52 delete_option( 'xspeed_oc_generation' );
53 delete_option( 'xspeed_oc_sync_attempts' );
54 delete_option( 'xspeed_overridden_constants' );
55 delete_option( 'xspeed_last_mobile_separate' );
56 delete_option( 'xspeed_redirect_to_onboarding' );
57 delete_option( 'xspeed_preloader_firewall_block' );
58 delete_option( 'xspeed_onboarding_complete' );
59 // Provenance a host plugin wrote before it activated us, and the profile
60 // that install came up with.
61 delete_option( 'xspeed_installed_by' );
62 delete_option( 'xspeed_installer' );
63 delete_option( 'xspeed_install_profile' );
64 // Written by the copy-vendored Setup that host plugins used to carry
65 // before xSpeed seeded its own conflict-safe profile on activation. We no
66 // longer write it; an older host may have, and it is ours to clean up.
67 delete_option( 'xspeed_setup_snapshot' );
68 delete_option( 'xspeed_stats' );
69 delete_option( 'xspeed_gc_cursor' );
70 delete_option( 'xspeed_mcp_rl_gen' );
71 wp_clear_scheduled_hook( 'xspeed_gc' );
72
73 global $wpdb;
74
75 // Hit counters and the Hub attachment flag — ours, and simply never named
76 // here before. xspeed_hit_buffer is BOTH an option and a transient of the
77 // same name (Hit_Counter uses one string for the memory buffer and the
78 // durable counter), so both stores need clearing.
79 delete_option( 'xspeed_hit_buffer' );
80 delete_transient( 'xspeed_hit_buffer' );
81 delete_option( 'xspeed_hit_daily' );
82 delete_option( 'xspeed_hub_site_attached' );
83
84 // Usage-tracking state, which lives in the shared WP Insights rows rather
85 // than under our own prefix. Left behind, the consent key survives an
86 // uninstall: a REINSTALL then reads as already opted in before the wizard
87 // has asked anything, and a later deactivation posts a diagnostic payload
88 // for a consent this install never collected (#439).
89 //
90 // The two keyed rows are SHARED with sibling WPDeveloper plugins, so only
91 // our own key comes out and the row itself is deleted only once nothing
92 // else is using it. Deleting them outright would wipe another plugin's
93 // consent state.
94 foreach ( array( 'wpins_allow_tracking', 'wpins_last_track_time' ) as $shared ) {
95 $value = get_option( $shared );
96 if ( ! is_array( $value ) ) {
97 continue; // Absent, or a shape we did not write — leave it alone.
98 }
99 unset( $value['xspeed'] );
100 if ( empty( $value ) ) {
101 delete_option( $shared );
102 } else {
103 update_option( $shared, $value );
104 }
105 }
106 // The deactivation-feedback payload. Normally consumed-then-deleted by the
107 // tracker's own deactivation send, but that only happens when consent
108 // passes and the send succeeds — a user who deactivates without consent
109 // leaves both rows behind, and they are exactly the orphaned diagnostic
110 // payload #439 describes.
111 delete_option( 'wpins_deactivation_reason_xspeed' );
112 delete_option( 'wpins_deactivation_details_xspeed' );
113 // The tracker's recurring send. Cleared on opt-out, but nothing guarantees
114 // an opt-out ever happened before the uninstall.
115 wp_clear_scheduled_hook( 'xspeed_do_weekly_action' );
116 // Our own WP Insights rows: the site id, the original URL, and the last
117 // payload — whose name embeds the site id. The payload names are
118 // derivable from the id, but a failed earlier uninstall or a renamed row
119 // shape would strand them, so sweep the prefix. `xspeed-pro`'s rows
120 // survive this only because its slug's HYPHEN doesn't match the
121 // underscore in `wpins_xspeed_%` — that separator is load-bearing.
122 delete_option( 'wpins_xspeed_site_id' );
123 delete_option( 'wpins_xspeed_original_url' );
124 // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- options API has no prefix delete; uninstall only.
125 $wpins_rows = $wpdb->get_col(
126 $wpdb->prepare(
127 "SELECT option_name FROM {$wpdb->options} WHERE option_name LIKE %s",
128 $wpdb->esc_like( 'wpins_xspeed_' ) . '%'
129 )
130 );
131 foreach ( (array) $wpins_rows as $wpins_row ) {
132 delete_option( $wpins_row );
133 }
134
135 // Score history — the plugin's own table, plus the legacy option the
136 // table was migrated from (kept on upgrade so a bad migration is
137 // recoverable; there is nothing to recover on uninstall).
138 // phpcs:ignore WordPress.DB.DirectDatabaseQuery, WordPress.DB.PreparedSQL.InterpolatedNotPrepared -- own table, uninstall.
139 $wpdb->query( 'DROP TABLE IF EXISTS ' . $wpdb->prefix . 'xspeed_scores' );
140 delete_option( 'xspeed_score_schema' );
141 delete_option( 'xspeed_score_history' );
142
143 if ( ! function_exists( 'WP_Filesystem' ) ) {
144 require_once ABSPATH . 'wp-admin/includes/file.php';
145 }
146 WP_Filesystem();
147 global $wp_filesystem;
148 if ( ! $wp_filesystem ) {
149 return;
150 }
151
152 $cache_dir = WP_CONTENT_DIR . '/cache/xspeed';
153 if ( $wp_filesystem->is_dir( $cache_dir ) ) {
154 $wp_filesystem->delete( $cache_dir, true );
155 }
156
157 // nginx hit log (FBS-82478). It lives under uploads/xspeed/, NOT the
158 // cache dir, precisely so that a pasted nginx `access_log` directive
159 // pointing at it does NOT get its parent directory deleted here — if it
160 // did, `nginx -t` would fail [emerg] and refuse to (re)start, taking
161 // down EVERY vhost on the host until someone manually finds the orphaned
162 // directive. We therefore EMPTY the log file but DELIBERATELY LEAVE THE
163 // DIRECTORY in place, so any still-pasted directive keeps a valid,
164 // openable target after the plugin is gone. (A stray empty dir is
165 // harmless; a broken nginx is not.) Users are also warned in the admin
166 // UI to remove the snippet before uninstalling.
167 $hits_log = WP_CONTENT_DIR . '/uploads/xspeed/hits.log';
168 if ( function_exists( 'wp_upload_dir' ) ) {
169 $uploads = wp_upload_dir( null, false );
170 if ( is_array( $uploads ) && empty( $uploads['error'] ) && ! empty( $uploads['basedir'] ) ) {
171 $hits_log = rtrim( (string) $uploads['basedir'], '/' ) . '/xspeed/hits.log';
172 }
173 }
174 if ( $wp_filesystem->exists( $hits_log ) ) {
175 // Truncate, don't delete the dir — keep the access_log target openable.
176 $wp_filesystem->put_contents( $hits_log, '', FS_CHMOD_FILE );
177 }
178
179 // Static-cache tree — separate from the flat-hash cache dir, holds
180 // the {host}/{path}/index.html files the .htaccess rewrite block
181 // serves directly. Same teardown rules as XSPEED_CACHE_DIR.
182 $static_dir = WP_CONTENT_DIR . '/cache/xspeed-static';
183 if ( $wp_filesystem->is_dir( $static_dir ) ) {
184 $wp_filesystem->delete( $static_dir, true );
185 }
186
187 // Rewrite block in site-root .htaccess. WP's marker helpers handle
188 // the "remove only our block" semantics — passing an empty array
189 // strips the markers in place.
190 $htaccess = ABSPATH . '.htaccess';
191 if ( $wp_filesystem->exists( $htaccess ) && $wp_filesystem->is_writable( $htaccess ) ) {
192 if ( ! function_exists( 'insert_with_markers' ) ) {
193 require_once ABSPATH . 'wp-admin/includes/misc.php';
194 }
195 insert_with_markers( $htaccess, 'xSpeed Static Cache', array() );
196 }
197
198 // Serialize the shared drop-in/config teardown with Cache::toggle(). If
199 // the lock is unavailable, leave shared state and its receipt untouched.
200 // phpcs:ignore WordPress.WP.AlternativeFunctions.file_system_operations_fopen,WordPress.PHP.NoSilencedErrors.Discouraged -- flock requires a local handle; failure is fail-closed.
201 $ownership_lock = @fopen( WP_CONTENT_DIR . '/.xspeed-page-cache.lock', 'c+' );
202 if ( ! is_resource( $ownership_lock ) || ! flock( $ownership_lock, LOCK_EX ) ) {
203 return;
204 }
205
206 require_once __DIR__ . '/includes/wp-cache-constant.php';
207 $drop_in = WP_CONTENT_DIR . '/advanced-cache.php';
208 $dropin_ours = false;
209 if ( $wp_filesystem->exists( $drop_in ) ) {
210 $contents = $wp_filesystem->get_contents( $drop_in );
211 $dropin_ours = is_string( $contents ) && xspeed_has_canonical_dropin_signature( $contents );
212 if ( $dropin_ours ) {
213 $wp_filesystem->delete( $drop_in );
214 }
215 }
216
217 $wp_config = file_exists( ABSPATH . 'wp-config.php' ) ? ABSPATH . 'wp-config.php' : dirname( ABSPATH ) . '/wp-config.php';
218 // `defined()` alone, not `&& WP_CACHE`: the old truthiness test skipped
219 // the removal whenever the constant was false/0 — exactly the orphan we
220 // are here to clean up — while still entering it for TRUE/1, where the
221 // hardcoded-lowercase regex then matched nothing and reported success.
222 // Strip whatever spelling is there. (#9)
223 //
224 // Gated on the drop-in being ours: if another caching plugin holds
225 // advanced-cache.php, WP_CACHE is the switch that loads THEIR file, and
226 // stripping it on our way out would silently disable their page cache.
227 if ( $wp_filesystem->is_writable( $wp_config ) ) {
228 $config = $wp_filesystem->get_contents( $wp_config );
229 if ( is_string( $config ) ) {
230 // Same helper Cache::set_wp_cache_constant() uses — one pattern,
231 // one place. uninstall.php loads no plugin classes, hence a
232 // plain requirable function rather than a method.
233 require_once __DIR__ . '/includes/wp-cache-constant.php';
234 $receipt = get_option( 'xspeed_page_cache_ownership_receipt', '' );
235 $marked = xspeed_wp_cache_receipt_matches( $config, $receipt );
236 /*
237 * A receipt proves WE wrote the line; it does not prove the line
238 * is still ours to remove. If a competitor has since taken over
239 * advanced-cache.php, WP_CACHE is what loads THEIR drop-in — they
240 * had no reason to touch an already-true define, so our receipt
241 * comment is still sitting beside it. Stripping on the receipt
242 * alone silently stopped their live page cache.
243 *
244 * A foreign drop-in therefore vetoes the removal outright, which
245 * is the same rule Cache::set_wp_cache_constant() applies in the
246 * running plugin; only this path was missing it. `$dropin_ours`
247 * covers the file we just deleted, `$marked` the case where there
248 * is no drop-in left at all.
249 */
250 $foreign_dropin = $wp_filesystem->exists( $drop_in ) && ! $dropin_ours;
251 if ( ! $foreign_dropin && ( $dropin_ours || $marked ) ) {
252 $config = xspeed_strip_wp_cache_define( $config );
253 $wp_filesystem->put_contents( $wp_config, $config, FS_CHMOD_FILE );
254 }
255 }
256 }
257 delete_option( 'xspeed_page_cache_ownership_receipt' );
258 flock( $ownership_lock, LOCK_UN );
259 fclose( $ownership_lock );
260 // Our own lock file, left in wp-content after everything else of ours is
261 // gone. Deleted last, after the handle is closed, so we are not
262 // unlinking a lock we are still inside. That ordering is hygiene, not a
263 // guarantee: a request already past the fopen would hold a handle to an
264 // unlinked inode. Harmless here — by this point the plugin is being
265 // removed and nothing will take the lock again.
266 $wp_filesystem->delete( WP_CONTENT_DIR . '/.xspeed-page-cache.lock' );
267 }
268