{"id":378018,"date":"2026-10-04T08:36:48","date_gmt":"2026-10-04T08:36:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/staging-superpowers-for-woocommerce\/"},"modified":"2026-10-06T14:21:04","modified_gmt":"2026-10-06T14:21:04","slug":"staging-superpowers","status":"publish","type":"plugin","link":"https:\/\/pan.wordpress.org\/plugins\/staging-superpowers\/","author":11816692,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.3","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"Staging Superpowers","header_author":"Rodolfo Melogli","header_description":"Make a staging copy of your site safe to test on: block emails, block outside services, freeze scheduled tasks and send visitors to your live site. With WooCommerce, it also swaps payment methods for a test gateway and pauses webhooks.","assets_banners_color":"393642","last_updated":"2026-10-06 14:21:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/businessbloomer.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":342,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.0":{"tag":"1.1.0","author":"BusinessBloomer","date":"2026-10-04 08:36:35","revision":3727184},"1.1.1":{"tag":"1.1.1","author":"BusinessBloomer","date":"2026-10-04 18:06:45","revision":3727685},"1.1.2":{"tag":"1.1.2","author":"BusinessBloomer","date":"2026-10-04 19:03:38","revision":3727731},"1.2.0":{"tag":"1.2.0","author":"BusinessBloomer","date":"2026-10-06 14:21:04","revision":3731006}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3727184,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3727184,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3727184,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3727184,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.0","1.1.1","1.1.2","1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3727685,"resolution":"1","location":"assets","locale":"","width":1280,"height":640},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3727685,"resolution":"2","location":"assets","locale":"","width":1280,"height":960},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3727685,"resolution":"3","location":"assets","locale":"","width":1280,"height":640},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3727685,"resolution":"4","location":"assets","locale":"","width":1280,"height":640},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3727685,"resolution":"5","location":"assets","locale":"","width":1280,"height":640},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3727660,"resolution":"6","location":"assets","locale":"","width":1280,"height":640}},"screenshots":{"1":"The status bar shows every protection at a glance, with links to manage each one.","2":"The protection settings, with a plain-English explanation for each one.","3":"On a WooCommerce store, the Staging Test Gateway is the only payment method at checkout, so no real money moves.","4":"Troubleshooting: every plugin with its status, its version on this site and its latest release. Disable or enable one, or several at once; a fatal error is undone straight away.","5":"The changelog: a list of everything you changed on staging, to redo on your live site.","6":"The message visitors can be shown instead of the staging site."}},"plugin_section":[],"plugin_tags":[734,2483,19979,1591,286],"plugin_category":[41,45],"plugin_contributors":[275526],"plugin_business_model":[],"class_list":["post-378018","plugin","type-plugin","status-publish","hentry","plugin_tags-development","plugin_tags-emails","plugin_tags-staging","plugin_tags-testing","plugin_tags-woocommerce","plugin_category-communication","plugin_category-ecommerce","plugin_contributors-businessbloomer","plugin_committers-businessbloomer"],"banners":{"banner":"https:\/\/ps.w.org\/staging-superpowers\/assets\/banner-772x250.png?rev=3727184","banner_2x":"https:\/\/ps.w.org\/staging-superpowers\/assets\/banner-1544x500.png?rev=3727184","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/staging-superpowers\/assets\/icon-128x128.png?rev=3727184","icon_2x":"https:\/\/ps.w.org\/staging-superpowers\/assets\/icon-256x256.png?rev=3727184","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-1.png?rev=3727685","caption":"The status bar shows every protection at a glance, with links to manage each one."},{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-2.png?rev=3727685","caption":"The protection settings, with a plain-English explanation for each one."},{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-3.png?rev=3727685","caption":"On a WooCommerce store, the Staging Test Gateway is the only payment method at checkout, so no real money moves."},{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-4.png?rev=3727685","caption":"Troubleshooting: every plugin with its status, its version on this site and its latest release. Disable or enable one, or several at once; a fatal error is undone straight away."},{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-5.png?rev=3727685","caption":"The changelog: a list of everything you changed on staging, to redo on your live site."},{"src":"https:\/\/ps.w.org\/staging-superpowers\/assets\/screenshot-6.png?rev=3727660","caption":"The message visitors can be shown instead of the staging site."}],"raw_content":"<!--section=description-->\n<p><strong>Live stays safe. Every time.<\/strong><\/p>\n\n<p>Your staging copy has your real customers, your real payment keys and your real automations. One test can email thousands of people or charge a real card. Staging Superpowers stops all of it, the moment you activate it.<\/p>\n\n<p>https:\/\/www.youtube.com\/watch?v=azXQoueJlTs<\/p>\n\n<h4>What it blocks<\/h4>\n\n<ul>\n<li><strong>Emails:<\/strong> every email to real people is blocked, even through SMTP plugins. Or forward them all to yourself.<\/li>\n<li><strong>Outside services:<\/strong> Stripe, PayPal, Mailchimp, Klaviyo, Zapier, CRMs and 50+ more can't be reached.<\/li>\n<li><strong>Automations:<\/strong> WP-Cron and scheduled actions are frozen, so nothing runs twice.<\/li>\n<li><strong>Search engines and AI bots:<\/strong> noindex, robots.txt, no sitemaps, and known crawlers refused.<\/li>\n<li><strong>Analytics:<\/strong> test visits stay out of Google Analytics and Meta reports.<\/li>\n<li><strong>Page caching:<\/strong> off, so you always see your latest change.<\/li>\n<\/ul>\n\n<h4>What it adds<\/h4>\n\n<ul>\n<li><strong>Staging look:<\/strong> a red STAGING badge and a status bar showing every protection.<\/li>\n<li><strong>Changelog:<\/strong> every change you make on staging, so you know what to redo on live.<\/li>\n<li><strong>Troubleshooting:<\/strong> switch plugins off and on in bulk. A fatal error is undone automatically.<\/li>\n<li><strong>Visitors:<\/strong> let everyone in, or show logged-out visitors a \"We'll be right back\" message.<\/li>\n<li><strong>Emails log:<\/strong> every email it stopped or forwarded, with recipient, subject and sender plugin. Never the message body.<\/li>\n<li><strong>Requests log:<\/strong> every outgoing request it blocked, with the plugin that tried.<\/li>\n<\/ul>\n\n<h4>On WooCommerce stores<\/h4>\n\n<ul>\n<li>Payment methods are swapped for a Staging Test Gateway, so no real card is charged.<\/li>\n<li>Subscriptions copied from live are locked, so live renewals keep working.<\/li>\n<li>Webhooks are paused.<\/li>\n<\/ul>\n\n<h4>Safe to keep on your live site<\/h4>\n\n<p>It only switches itself on where the address looks like staging (staging., dev., .local, WP Engine, Kinsta, Cloudways and more) or WP_ENVIRONMENT_TYPE is staging, development or local. On your live site it stays off. Every clone of your site already has it, and protects itself straight away. Push staging back to live and it switches itself off again.<\/p>\n\n<p>Nothing in your database is changed by the protections. Deactivate it and the site behaves as before.<\/p>\n\n<h4>Staging Superpowers Pro<\/h4>\n\n<p><a href=\"https:\/\/www.businessbloomer.com\/plugins\/staging-superpowers-pro\/\">Staging Superpowers Pro<\/a> adds tools for working on the copy: anonymize customers and staff before handing the site to an agency, send visitors to your live site, compare pages with live side by side, find staging links on live, see and block every outgoing request, and WooCommerce test data and switches.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin does not connect to any external service and does not send data anywhere.<\/p>\n\n<p>The web addresses listed in its settings are services the plugin blocks. The default list is: api.stripe.com, api.paypal.com, api-m.paypal.com, api.braintreegateway.com, connect.squareup.com, api.mollie.com, api.authorize.net, api.mailchimp.com, a.klaviyo.com, api.brevo.com, api.sendinblue.com, connect.mailerlite.com, api.omnisend.com, api.kit.com, api.convertkit.com, api.hubapi.com, ssapi.shipstation.com, api.taxjar.com, rest.avatax.com, graph.facebook.com, google-analytics.com, api.twilio.com, slack.com, hooks.zapier.com, make.com, integromat.com, api-us1.com, api.createsend.com, api.getdrip.com, api.sendgrid.com, mailgun.net, api.postmarkapp.com, sheets.googleapis.com, api.sparkpost.com, mandrillapp.com, bridge.mailpoet.com, api.mailjet.com, api.resend.com, api.mailersend.com, api.smtp2go.com, api.elasticemail.com, api.twitter.com, api.linkedin.com, developer.blog2social.com, blog2social-wordpress-api.adenion.de, onesignal.com, api.pushengage.com, rpc.pingomatic.com, api.cloudflare.com, api.automatorplugin.com, api.shortpixel.com and smushpro.wpmudev.com. When \"Connected services\" is on, the plugin stops the staging site from contacting them, so a staging copy cannot reach your live accounts. The plugin never sends requests to them itself.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Staging Superpowers, on your live site or on staging.<\/li>\n<li>On a staging address it switches itself on: you'll see a red STAGING badge. Anywhere else it stays off, or click \"This is a staging site: turn on\" in the notice.<\/li>\n<li>Everything is on by default. Settings are at Tools &gt; Staging Superpowers.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20woocommerce%3F\"><h3>Do I need WooCommerce?<\/h3><\/dt>\n<dd><p>No. It works on any WordPress site. The payment, subscription and webhook protections turn on by themselves when WooCommerce is active.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20it%20active%20on%20my%20live%20site%3F\"><h3>Can I keep it active on my live site?<\/h3><\/dt>\n<dd><p>Yes. It stays off there, and switches on by itself in every staging copy. That way you never forget to install it on a new clone.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20my%20host%27s%20staging%3F\"><h3>Does it work with my host's staging?<\/h3><\/dt>\n<dd><p>Yes, with any staging copy: made by your host, a staging plugin or by hand. If yours isn't recognized, click the button in the notice once.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20push%20staging%20to%20live%3F\"><h3>What happens when I push staging to live?<\/h3><\/dt>\n<dd><p>It notices the address changed and switches itself off, so your live site keeps working normally.<\/p><\/dd>\n<dt id=\"does%20it%20stop%20bots%20that%20ignore%20robots.txt%3F\"><h3>Does it stop bots that ignore robots.txt?<\/h3><\/dt>\n<dd><p>Known crawlers and AI bots, Bytespider included, are refused whatever robots.txt says. For full lockdown, also password-protect staging at your host.<\/p><\/dd>\n<dt id=\"some%20background%20tasks%20are%20not%20running\"><h3>Some background tasks are not running<\/h3><\/dt>\n<dd><p>That's the automations freeze. Untick \"Scheduled actions\" or \"WP-Cron\" in Tools &gt; Staging Superpowers, or run single tasks by hand.<\/p><\/dd>\n<dt id=\"does%20blocking%20services%20stop%20every%20request%3F\"><h3>Does blocking services stop every request?<\/h3><\/dt>\n<dd><p>It blocks requests made through the WordPress HTTP API, which almost every plugin uses. A plugin with its own connection code, such as WP Offload Media, can't be blocked: switch it off on staging.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: Emails log. Every email the staging site tried to send is listed with its recipients, subject, the plugin that sent it, what happened (blocked or forwarded) and a count. Message bodies, headers and attachments are never kept, and CC and BCC addresses are only counted.<\/li>\n<li>New: Requests log. Every request to a blocked service is listed with the address, the plugin that made it and a count. Only the method, host and path are kept, never what was sent.<\/li>\n<li>The status bar shows how many emails and requests were stopped, with a link to each log.<\/li>\n<li>Shorter, clearer plugin description, and new FAQ answers.<\/li>\n<li>It's safe to keep the plugin active on your live site: it stays off there and switches on by itself in every staging copy.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Fix: automatic background updates of plugins and themes are now recorded in the changelog, like updates made from the Plugins screen.<\/li>\n<li>Fix: saving the settings no longer records \"Blocked services changed\" when the list did not change.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Settings moved to Tools &gt; Staging Superpowers, in a clearer order: staging look, search engines and caching first, then visitors, emails, WooCommerce, then automations and connected services. Old links to Settings &gt; Staging Superpowers still work.<\/li>\n<li>New: Crawlers and AI bots (on by default). robots.txt asks every crawler to stay away, the WordPress sitemaps are off, and known search and AI crawlers are refused.<\/li>\n<li>Visitors now have two choices: everyone sees the site (the new default), or logged-out visitors see a message with your own heading and text. The message page never mentions staging. The redirect to the live site and the visitor STAGING bar were removed, together with the live site address setting.<\/li>\n<li>Troubleshooting is now a table: one plugin or theme per row, active first, with its status, the version on this site (red when a newer version is out, green when up to date) and the latest release with its date and changelog. Disable or enable each plugin from its row, or several at once with Disable selected and Enable selected. Premium plugins show the version their own updater reports, and add-ons can supply release details with the sspw_plugin_release_info filter.<\/li>\n<li>The changelog now records the old and the new version when a plugin or theme is updated.<\/li>\n<li>Troubleshooting: WooCommerce can be disabled like any other plugin. Plugins that need it are disabled with it, and the message says so. After every change the site checks itself, and a fatal error undoes the change and names the plugin or theme that caused it.<\/li>\n<li>Troubleshooting actions write one changelog entry each, however many plugins they change. The status bar no longer shows disabled plugins or a switched theme.<\/li>\n<li>The changelog is now always kept and shown on its own page, also on WooCommerce stores (it used to go to the WooCommerce logs). It keeps the latest 1,000 changes.<\/li>\n<li>The page heading now includes the tagline, and every section has a clearer heading and description.<\/li>\n<li>When the admin bar wraps onto two rows on narrow screens, the status bar moves down instead of covering it.<\/li>\n<li>The Plugin check list was removed from the settings page; the protections it described still work.<\/li>\n<li>A short list of what Staging Superpowers Pro adds, above the Save button.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New name: Staging Superpowers. It now works on any WordPress site, and its WooCommerce protections turn on by themselves when WooCommerce is active.<\/li>\n<li>Settings moved to Settings &gt; Staging Superpowers.<\/li>\n<li>New: Plugin check lists active plugins that talk to live services, with Covered or Check and what to do. It replaces the email plugin list.<\/li>\n<li>New: Jetpack safe mode, no scheduled UpdraftPlus backups, test mode for Easy Digital Downloads, GiveWP and Paid Memberships Pro, and no pingbacks, trackbacks or update-service pings.<\/li>\n<li>New: \"Stop analytics on staging\" setting (on by default) for Site Kit by Google, MonsterInsights, GTM4WP and the Meta pixel's Conversions API.<\/li>\n<li>New: block social sharing, push notification, Cloudflare, Uncanny Automator, Ping-O-Matic, ShortPixel and Smush services by default, and every Google Analytics address.<\/li>\n<li>Without WooCommerce, the changelog keeps its latest 500 entries and shows them on its own page.<\/li>\n<li>New: email check. Warns when a plugin replaces the WordPress email function, lists active email plugins and whether they are covered, blocks more email sending services, and readdresses anything that still reaches the WordPress mailer.<\/li>\n<li>New: lock subscriptions copied from the live store (and their orders and customers) against deletion and edits, so a staging clean-up cannot remove saved cards the live store needs for renewals.<\/li>\n<li>New: freeze WP-Cron tasks as well as scheduled actions, so no automation runs by itself on staging.<\/li>\n<li>New: block Twilio, Slack, Zapier, Make, ActiveCampaign, Campaign Monitor, Drip, SendGrid, Mailgun, Postmark and Google Sheets by default.<\/li>\n<li>Status bar: one \"Automations\" entry, warnings shown first.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Make a staging copy of your site safe to test on: blocks emails and outside services, freezes scheduled tasks, keeps search engines and AI bots out.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/378018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=378018"}],"author":[{"embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/businessbloomer"}],"wp:attachment":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=378018"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=378018"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=378018"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=378018"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=378018"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=378018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}