CapiFlow – Conversions API (CAPI) Tracking for WooCommerce

Description

CapiFlow is a 100% self-hosted, enterprise-grade server-side tracking engine for WooCommerce. Send conversion events directly from your WordPress server to the Meta Conversions API (CAPI) with zero cloud hosting bills, 3-click setup, and intelligent algorithm protection.

Unlike conventional tracking tools, CapiFlow eliminates the need for expensive external server containers (saving you $240+/year), ensures 0ms checkout speed impact, and prevents fake or unverified orders from corrupting your Meta ad optimization.

42% of online shoppers run ad blockers, and Apple Safari ITP silently wipes out 30%–40% of standard browser pixel conversions. CapiFlow restores your lost revenue attribution by bypassing browser restrictions completely — sending high-fidelity conversion events directly from your WordPress server to Meta Events Manager.

For Store Owners & Media Buyers

  • For WooCommerce Store Owners: Maximize real ROAS, stop fake Cash-on-Delivery (COD) orders from poisoning your ad optimization, and save $240–$1,200/year in cloud server bills.
  • For Media Buyers & Agencies: Achieve 9.0+ Event Match Quality (EMQ), 100% deterministic deduplication, and 180-day Safari ITP first-party cookie attribution without touching GTM.

💰 Save $240+/Year — 100% Self-Hosted ($0 Cloud Hosting Fees)

Why pay $20 to $100 every single month to third-party services like Stape.io, Google Cloud, or AWS just to run a server GTM container?

  • Zero Cloud Bills: CapiFlow runs 100% natively on your existing WordPress server.
  • Unlimited Events: Track unlimited page views, carts, and purchases without event tier limits or surprise overage charges.
  • No GTM Required (3-Click Setup): Completely removes web/server GTM container complexity, triggers, and dataLayer debugging. Simply paste your Pixel ID and Access Token, toggle on, and click Save. Setup takes under 3 minutes.

🚀 Zero-GTM Nightmare — Skip 25+ Tags, Containers & Hours of Debugging Hell

95% of store owners are not tracking engineers or programmers. You got into e-commerce to sell great products and grow your brand — not to spend your weekends configuring complex tracking infrastructure:

  • The 4-Layer GTM Nightmare (Designed for Coders): Traditional server tracking forces merchants through an excruciating technical gauntlet:
    1. Build TWO Separate GTM Containers: Must create and juggle both a Web and a Server GTM container.
    2. Write 25+ Custom DataLayer Variables (DLVs): Manually mapping ecommerce.items.price, currency, user_data.email, transaction_id, etc.
    3. Configure Complex Triggers & Client Templates: Manually setting triggers for every event and configuring HTTP client request templates.
    4. Connect Stape.io or GCP Custom Domains: Setting up DNS records, provisioning SSL certificates, and configuring transport URLs.
  • The Silent Attribution Killer (Zero Error Warnings): In GTM, a single missing comma, an event_id mismatch between web and server containers, or a tiny dataLayer discrepancy (like ecommerce.items vs. items) breaks tracking completely in silence. Your store shows ZERO error messages, yet data stops reaching Meta, Event Match Quality (EMQ) plummets to 3/10, Meta’s AI optimization flies blind, and your ad costs (CPA) double without warning! Most store owners end up spending $150–$300 hiring tracking freelancers just to debug the mess.
  • The CapiFlow 3-Click Freedom: Everything is 100% pre-engineered, native, and automated. No GTM containers. No dataLayer code. No tags or triggers to configure:
    1. Paste your Pixel ID & Meta Access Token.
    2. Toggle the events you want to track.
    3. Click Save & Test Connection.
      Setup takes under 3 minutes, saves you $150–$300 in agency setup fees, eliminates debugging headaches forever, and delivers a 9+ EMQ score straight out of the box!

🛡️ Confirmed Purchase Control (Ad Algorithm Anti-Poisoning)

The Competitor Flaw: Conventional tracking plugins (PixelYourSite, Conversios, GTM) prematurely fire the Purchase event the exact millisecond a customer clicks “Place Order”. If an order is a fake Cash-on-Delivery (COD) submission, entered with a wrong phone number, or cancelled an hour later — Meta’s AI algorithm has already marked it as a successful high-value buyer, actively training Meta Advantage+ to find more fake buyers and chronic returners!

  • CapiFlow Free (Confirmed Purchase Control): CapiFlow does NOT fire Purchase prematurely upon checkout placement. Instead, it holds the event until the store owner verifies the order and marks it as “Confirmed” or “Completed” in WooCommerce. Only 100% real, verified purchases reach Meta Events Manager!
  • CapiFlow Pro (Courier API Automation): Automatically verifies delivery status in real-time with courier networks (Pathao, Steadfast, REDX, DHL, FedEx) and auto-fires Purchase upon delivery confirmation. If an order is returned or cancelled, it dispatches Negative Purchase Signals to retrain ad algorithms away from chronic returners!

⚡ 0ms Checkout Speed Impact (100% Asynchronous Background Queuing)

Never sacrifice checkout conversion rates for tracking accuracy.
* Non-Blocking Architecture: CapiFlow offloads all server-side CAPI API dispatches to background workers using WordPress Action Scheduler.
* 0ms Latency: Your customers experience instant checkout confirmation with zero API timeout delays, perfectly protecting your Core Web Vitals.

🍪 180-Day Cache-Safe Persistent Server Cookies

  • Safari ITP & Ad Blocker Immune: While Apple Safari and browser privacy shields wipe JavaScript cookies (document.cookie) within 1 to 7 days, CapiFlow sets first-party HttpOnly server cookies that persist for up to 180 days.
  • Page-Cache Bypass: Cookies are delivered via uncacheable REST response headers, ensuring 100% functionality even on aggressive caching stacks (LiteSpeed Cache, WP Rocket, Varnish, Cloudflare).
  • Skyrocket Event Match Quality (EMQ): Matches returning customers months after their first ad click with full SHA-256 hashed customer parameters, achieving 9+ EMQ scores.

Core Features

Direct Server-to-Server Tracking
* 🎯 7 Standard Events Supported: Purchase, InitiateCheckout, AddPaymentInfo, AddToCart, ViewContent, Search, PageView.
* 🔄 Deterministic Deduplication: Browser and server events share the exact same synchronized event_id to guarantee Meta never double-counts conversions.
* 🛡️ First-Party Proxy Endpoint: Client tracking scripts can be routed through your own domain, bypassing ad-blocker domain blocklists.
* 🔐 SHA-256 PII Advanced Matching: Automatically hashes customer email, phone, first name, last name, city, and state before leaving your server.

WooCommerce Control & Monitoring
* 📈 Interactive Dashboard: Real-time event analytics, browser vs. server delivery ratios, and conversion trends.
* 🔍 Live Debug Console: Inspect exact server payloads, timestamp logs, and Meta Graph API response codes.
* 🏥 System Health Inspector: Instant verification of Meta Access Token validity, queue backlog, and cURL connectivity.
* 📞 Checkout Phone Validator: Automatically cleans and validates customer phone formatting at checkout.
* 📋 Order Column Badges: Per-order CAPI dispatch status badges directly inside the WooCommerce Orders screen.

Free vs Pro Comparison

Feature
CapiFlow Free
CapiFlow Pro

100% Self-Hosted (Zero Monthly Cloud Fees)
✅ Yes
✅ Yes

Meta Conversions API (CAPI) Core Events
✅ Yes
✅ Yes (All + Custom)

Multi-Platform Support (GA4, Google Ads, TikTok, Pinterest…)
Meta CAPI Only
✅ All 8 Platforms

Browser & Server Event Deduplication (event_id)
✅ Yes
✅ Yes

Purchase Event Firing Logic
Manual Confirmed Purchase Control
✅ Fully Automated via Courier APIs

Negative Purchase Signals (Ad Budget Optimization)
❌ No
✅ Yes (Automated on Returns)

0ms Async Background Queuing
✅ Yes
✅ Yes

Cache-Safe 180-Day Persistent Server Cookies
✅ Yes
✅ Yes

Category-Based Multi-Pixel Routing
❌ No
✅ Yes

3-Layer AI Fraud Defense & Phone OTP Verification
❌ No
✅ Yes (Full Suite)

Multi-Carrier Courier Auto-Booking (Pathao, Steadfast, DHL…)
❌ No
✅ Yes

Smart Cart Recovery with Dynamic Single-Use Auto-Coupons
❌ No
✅ Yes (SMS + Email)

CapiFlow Pro

Ready to automate your entire post-purchase pipeline? CapiFlow Pro upgrades your store into an automated powerhouse:
* 8-Platform Multi-CAPI: Track Meta, Google Analytics 4, Google Ads Enhanced Conversions, TikTok, Pinterest, Snapchat, LinkedIn, and X.
* Automated Courier Logistics: 1-click booking and real-time delivery status syncing with Pathao, Steadfast, REDX, DHL, FedEx, and custom webhooks.
* Negative Purchase Signals: Automatically signal ad platforms when orders are cancelled or returned to reduce your Cost Per Acquisition (CPA) by 20%–40%.
* Smart Cart Recovery & Dynamic Coupons: Recovers abandoned checkout drafts with single-use, time-limited auto-coupons sent via SMS & Email.
* 3-Layer AI Fraud Guard: Delivery success rate prediction and phone OTP verification to stop fake buyers before shipment.

Learn more on the CapiFlow Pro Website.

Compatibility

  • Payment Gateways: bKash, Nagad, Rocket, SSLCommerz, Stripe, PayPal, COD (Cash on Delivery), and all standard WooCommerce gateways.
  • Themes: 100% compatible with Classic themes, Block themes (FSE), Elementor, Divi, Bricks, and custom WooCommerce templates.
  • Storage Engines: Full native support for High-Performance Order Storage (HPOS) and legacy custom post types.
  • Consent Management Platforms (CMP): Seamless integration with CookieYes, Complianz, CookieBot, and custom hooks (capiflow_has_tracking_consent).

Requirements

  • WordPress 6.0+
  • WooCommerce 7.0+
  • PHP 7.4+ (PHP 8.0, 8.1, 8.2, 8.3 fully supported)
  • OpenSSL PHP extension
  • Meta Pixel ID & System User Access Token

External Services

This plugin connects to the following third-party services:

Meta (Facebook) Conversions API

CapiFlow sends WooCommerce event data to the Meta Conversions API via: https://graph.facebook.com/

This connection is made from your server to Meta’s servers when a configured tracking event occurs. No data is sent until a valid Pixel ID and Access Token are configured.

Data transmitted includes:

  • Hashed email, phone, first and last name (SHA-256)
  • Client IP address and Browser User Agent
  • Meta Click ID (_fbc) and Browser ID (_fbp) cookies
  • Order total, currency, and event metadata

All personal data is SHA-256 hashed before transmission.

Meta Pixel JavaScript SDK

This plugin loads the Meta Pixel SDK from: https://connect.facebook.net/en_US/fbevents.js

Loaded on frontend pages when a Pixel ID is configured. The SDK is hosted by Meta.

Privacy

For server-side events, all personal data is SHA-256 hashed before transmission. For browser events, the Meta Pixel SDK handles hashing via Advanced Matching. This plugin does not store raw PII in its own tables. See Meta’s privacy policy.

Cookies

  • cs_uid — Random visitor identifier for external_id deduplication. 180 days. No PII.
  • _fbc — Meta Click ID. Set by Meta SDK on ad click. CapiFlow reads/extends server-side. 180 days.
  • _fbp — Meta Browser ID. Set by Meta SDK. CapiFlow reads/extends server-side. 180 days.

All cookies are first-party and contain no personally identifiable information.

Data Storage

  • {prefix}_capiflow_events — Queued/sent event payloads. Auto-purged after delivery.
  • {prefix}_capiflow_analytics — Daily aggregated analytics. Auto-purged by retention settings.
  • Order metadata with _capiflow_ prefix. Removed on uninstall if “Keep Data” is disabled.
  • Logs in wp-content/uploads/capiflow-logs/ with .htaccess protection. Auto-cleaned daily.

Consent

By default, events fire once configured. Enable “Consent Enforcement” in Settings to respect CMP signals for both browser and server events.

Supported CMPs: CookieYes, Complianz, CookieBot, GDPR Cookie Consent. Custom integration via capiflow_has_tracking_consent filter.

When Consent Enforcement is enabled, browser and server-side events are blocked until valid tracking consent is detected.

Store owners are responsible for lawful consent configuration where required by privacy regulations.

Screenshots

Installation

  1. Install from WordPress plugins screen or upload capiflow to /wp-content/plugins/.
  2. Activate through the Plugins menu.
  3. Setup wizard launches — enter Pixel ID and Access Token.
  4. Click Test Connection — check CapiFlow Dashboard to monitor.

Getting an Access Token

  1. Meta Events Manager Select Pixel Settings Conversions API
  2. Click Generate Access Token or create a System User
  3. Paste into CapiFlow Settings Pixel Settings

FAQ

Can I use CapiFlow for Meta Pixel server-side tracking without GTM?

Yes! CapiFlow is built specifically for WooCommerce stores to enable full server-side Conversions API (CAPI) and Meta Pixel tracking without needing Google Tag Manager (sGTM), complex dataLayers, triggers, or custom code. Everything is 100% pre-engineered, native, and automated. You simply paste your Pixel ID and Access Token, and tracking starts in under 3 minutes.

Can I run Meta Conversions API without Stape.io, Google Cloud, or monthly fees?

Yes, absolutely. You do not need Stape.io, Google Cloud Platform (GCP), AWS, or any paid cloud server container. CapiFlow runs 100% natively on your existing WordPress server and offloads events via Action Scheduler, saving you $240 to $1,200+ every year in cloud hosting subscriptions.

Does this replace the Meta browser pixel or run dual-tracking?

CapiFlow runs Meta’s officially recommended dual-tracking setup: it fires both client-side Meta Pixel (fbq) and server-side Conversions API (CAPI) simultaneously. Both streams share identical, synchronized cryptographic event_id values for 100% deterministic deduplication in Meta Events Manager.

Will dual tracking cause duplicate events or inflated conversion numbers?

No. Matching event_id values guarantee that Meta automatically deduplicates browser and server events within Meta’s 48-hour deduplication window. You get 100% accurate conversion reporting with zero double-counting.

How does CapiFlow bypass Apple Safari ITP and iOS 14.5+ tracking loss?

While Apple Safari and ad blockers wipe JavaScript cookies (document.cookie) within 1 to 7 days, CapiFlow sets persistent first-party identity cookies (_fbp and _fbc) via uncacheable REST response headers that persist for up to 180 days. This bypasses page caching layers (LiteSpeed, WP Rocket, Varnish, Cloudflare) and recovers 25%+ of lost conversions.

How does CapiFlow achieve a 9+ Event Match Quality (EMQ) score on Meta?

CapiFlow normalizes and SHA-256 hashes customer data (E.164 phone numbers, lowercase trimmed emails, names, cities, postal codes) and pairs them with fbc, fbp, external_id, client IP, and browser user agent. This multi-signal matching consistently delivers 9.0+ EMQ scores in Meta Events Manager.

Does CapiFlow slow down my checkout or store page speed?

No. CapiFlow offloads all server-side CAPI dispatches to background workers using WordPress Action Scheduler. It adds 0ms delay to customer checkout or page load speeds, keeping your Core Web Vitals 100% green.

Does this work with caching plugins like LiteSpeed Cache, WP Rocket, or Cloudflare?

Yes! CapiFlow sets persistent server identity cookies directly via uncacheable REST response headers. This completely bypasses page caching layers (LiteSpeed, WP Rocket, Varnish, Cloudflare) and ensures cookies are never cached statically.

How does Confirmed Purchase Control protect my ad budget from fake orders?

Conventional tracking plugins fire a Purchase event the exact moment a customer submits checkout. If that order is a fake Cash-on-Delivery (COD) submission or gets cancelled, Meta’s algorithm still counts it as a successful sale, poisoning your ad optimization. CapiFlow Free holds the Purchase event until you verify the order and mark it “Confirmed” or “Completed” in WooCommerce. In CapiFlow Pro, this is fully automated via Courier APIs (Pathao, Steadfast, REDX, DHL, FedEx) and Negative Purchase signals!

Which WooCommerce payment gateways, themes, and order storage engines are supported?

100% compatible with all standard gateways (bKash, Nagad, SSLCommerz, Stripe, PayPal, COD), all themes (Classic, Block/FSE, Elementor, Divi, Bricks), and both High-Performance Order Storage (HPOS) and legacy posts-based order storage.

How is customer privacy and GDPR/CCPA consent handled?

All PII is SHA-256 hashed before transmission. CapiFlow includes a built-in Consent Enforcement toggle that blocks both browser and server events until CMP consent is granted (compatible with CookieYes, Complianz, CookieBot, and custom filters). Privacy policy content is auto-added to your WordPress Privacy Policy page.

What is CapiFlow Pro?

A separate addon that adds 8-platform multi-CAPI, courier automation, negative Purchase signals, cart recovery with auto-coupons, and AI fraud protection. Learn more.

Reviews

جولای 29, 2026
This is a genuinely good and useful plugin. It helped me bridge the gap between my WooCommerce site and Meta's Conversions API system, to help get cleaner data allowing us to optimize Instagram and Facebook ads. The support from CapiFlow is top-notch, this plugin deserves a lot more attention than it's getting. 5 stars from me every day of the week.
Read all 3 reviews

Contributors & Developers

“CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” is open source software. The following people have contributed to this plugin.

Contributors

“CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.3 — 2026-09-28

  • Fix: E.164 domestic trunk-zero stripping — normalize_phone_e164() now correctly strips domestic trunk zeros when the number already starts with the country dialing code (e.g. +880017... 8801712345678 instead of retaining the leading 0). Affects Meta Advanced Matching phone hashing accuracy.
  • New: hash_postcode() method added to Data_Normalizer as an alias of hash_zip() for international postal code taxonomy compatibility.
  • New: get_universal_uid() utility method added — reads first-party visitor UID from cs_uid or cs_vid cookies for cross-session identity stitching.

1.1.2 — 2026-09-19

  • Fix: Universal Price Normalization — introduced dual-tier price parsing engine (parsePrice) to accurately handle European and international currency price formatting (e.g. comma as decimal separator like €14,21), preventing 100x price inflation in Meta Pixel Helper and CAPI.
  • Fix: International Currency Safeguards — added automatic sanitization for Unicode whitespace (non-breaking spaces), apostrophes (Swiss Franc CHF), Eastern Arabic & Persian numerals and punctuation (٫ and ٬), and zero-decimal currencies (JPY, KRW, VND).
  • Fix: Currency Abbreviation Dot Collision Protection — strips non-digit periods to prevent regional currency abbreviations (e.g. kr., Rs., руб., грн., د.إ, S/.) from colliding with decimal separators.
  • Fix: Dual-Tier Heuristic Fallback — added intelligent single-comma ambiguity analysis for cached pages to preserve correct decimal/thousands separator distinctions even if client configuration is missing.
  • Fix: AJAX & Block Cart Resolution — upgraded Handler 2 (classic AJAX cart) and Handler 3 (WooCommerce Blocks) to dynamically scrape and transmit real product price, name, and quantity rather than fallback zeros.
  • Fix: Precision & Variation Guards — formatted multi-quantity AddToCart event values to eliminate IEEE-754 floating-point noise (e.g. 42.63000000000001), and added variation selection guards to prevent false AddToCart events on unselected variable products.
  • Fix: Server-Side Deferred Rounding — rounded deferred session AddToCart payloads according to WooCommerce store decimal settings.

1.1.1 — 2026-08-21

  • Fix: predicted_ltv is now only sent in Purchase events when COGS (Cost of Goods Sold) data is actually populated. Previously, missing _woo_capi_cogs meta caused predicted_ltv to always equal the order total, which Meta flagged as an invalid value and could distort Value-Based Bidding optimization.

1.1.0 — 2026-08-20

  • New: Marketplace Catalog Verified — Content ID Strategy setting (SKU / Parent SKU / WooCommerce Product ID) for pixel-to-catalog alignment.
  • New: Event_Builder::resolve_content_id() static resolver — single source of truth for all event methods (Purchase, InitiateCheckout, AddToCart, ViewContent, AddPaymentInfo, Negative Events).
  • New: Event_Builder::resolve_content_type() — automatically switches between product and product_group based on ID strategy and product type.
  • New: Event_Builder::resolve_item_price() — tax-parity normalizer ensures item_price matches catalog feed pricing (incl./excl. tax).
  • New: Search event now includes content_ids and contents arrays from search results (up to 10 products).
  • New: Guard 5 — Order Source Filter blocks CAPI Purchase events for marketplace/external channel orders (configurable via Settings > Events).
  • New: Guard 6 — capiflow_should_track_purchase filter provides a clean developer escape hatch to suppress individual Purchase events without setting a dedup lock.
  • New: capiflow_content_id filter allows custom catalog integrations to override resolved content IDs.
  • Fix: content_category now correctly uses the parent product ID for variable product variations (variations have no direct category assignment).
  • Fix: get_product_sku_map() in Pixel Injector now uses resolve_content_id() so JS AddToCart content_ids always match server-side events.
  • Fix: store_deferred_addtocart() now uses resolve_content_type() for the deferred AddToCart pixel event.
  • Fix: Cart loop guards now check instanceof WC_Product before processing to prevent TypeError on malformed cart data.
  • Fix: Order item loops now check instanceof WC_Order_Item_Product to skip shipping/fee/coupon line items silently.
  • Deprecated: Event_Builder::get_content_type() and get_content_id() now proxy to new static resolvers for backward compatibility.

1.0.2 — 2026-07-29

  • Fix: Prevent firing Purchase events for pre-existing orders created prior to CapiFlow installation or >7 days ago when order status is changed in WP Admin/background.
  • Fix: Add self-healing installation timestamp and multi-layered pre-installation protection guard to prevent invalid server-side Purchase attribution.

1.0.1 — 2026-05-22

  • Update WordPress compatibility header to Tested up to 7.0 for WordPress 7.0 “Armstrong” release.

1.0.0 — 2026-05-01

  • Initial public release
  • Server-side tracking for 7 Meta standard events via Conversions API
  • Browser + server event deduplication with matching event_id
  • First-party event endpoint, SHA-256 PII hashing, Advanced Matching
  • COD Purchase gate, phone validation, analytics dashboard
  • Debug console, system health, setup wizard
  • HPOS compatible, Action Scheduler queue, CMP integration