Description
CapiFlow is a 100% self-hosted, enterprise-grade server-side tracking engine for WooCommerce. Send conversion events directly from your WordPress server to the Meta Conversions API (CAPI) with zero cloud hosting bills, 3-click setup, and intelligent algorithm protection.
Unlike conventional tracking tools, CapiFlow eliminates the need for expensive external server containers (saving you $240+/year), ensures 0ms checkout speed impact, and prevents fake or unverified orders from corrupting your Meta ad optimization.
42% of online shoppers run ad blockers, and Apple Safari ITP silently wipes out 30%–40% of standard browser pixel conversions. CapiFlow restores your lost revenue attribution by bypassing browser restrictions completely — sending high-fidelity conversion events directly from your WordPress server to Meta Events Manager.
For Store Owners & Media Buyers
- For WooCommerce Store Owners: Maximize real ROAS, stop fake Cash-on-Delivery (COD) orders from poisoning your ad optimization, and save $240–$1,200/year in cloud server bills.
- For Media Buyers & Agencies: Achieve 9.0+ Event Match Quality (EMQ), 100% deterministic deduplication, and 180-day Safari ITP first-party cookie attribution without touching GTM.
💰 Save $240+/Year — 100% Self-Hosted ($0 Cloud Hosting Fees)
Why pay $20 to $100 every single month to third-party services like Stape.io, Google Cloud, or AWS just to run a server GTM container?
- Zero Cloud Bills: CapiFlow runs 100% natively on your existing WordPress server.
- Unlimited Events: Track unlimited page views, carts, and purchases without event tier limits or surprise overage charges.
- No GTM Required (3-Click Setup): Completely removes web/server GTM container complexity, triggers, and dataLayer debugging. Simply paste your Pixel ID and Access Token, toggle on, and click Save. Setup takes under 3 minutes.
🚀 Zero-GTM Nightmare — Skip 25+ Tags, Containers & Hours of Debugging Hell
95% of store owners are not tracking engineers or programmers. You got into e-commerce to sell great products and grow your brand — not to spend your weekends configuring complex tracking infrastructure:
- The 4-Layer GTM Nightmare (Designed for Coders): Traditional server tracking forces merchants through an excruciating technical gauntlet:
- Build TWO Separate GTM Containers: Must create and juggle both a Web and a Server GTM container.
- Write 25+ Custom DataLayer Variables (DLVs): Manually mapping
ecommerce.items.price,currency,user_data.email,transaction_id, etc. - Configure Complex Triggers & Client Templates: Manually setting triggers for every event and configuring HTTP client request templates.
- Connect Stape.io or GCP Custom Domains: Setting up DNS records, provisioning SSL certificates, and configuring transport URLs.
- The Silent Attribution Killer (Zero Error Warnings): In GTM, a single missing comma, an
event_idmismatch between web and server containers, or a tiny dataLayer discrepancy (likeecommerce.itemsvs.items) breaks tracking completely in silence. Your store shows ZERO error messages, yet data stops reaching Meta, Event Match Quality (EMQ) plummets to 3/10, Meta’s AI optimization flies blind, and your ad costs (CPA) double without warning! Most store owners end up spending $150–$300 hiring tracking freelancers just to debug the mess. - The CapiFlow 3-Click Freedom: Everything is 100% pre-engineered, native, and automated. No GTM containers. No dataLayer code. No tags or triggers to configure:
- Paste your Pixel ID & Meta Access Token.
- Toggle the events you want to track.
- Click Save & Test Connection.
Setup takes under 3 minutes, saves you $150–$300 in agency setup fees, eliminates debugging headaches forever, and delivers a 9+ EMQ score straight out of the box!
🛡️ Confirmed Purchase Control (Ad Algorithm Anti-Poisoning)
The Competitor Flaw: Conventional tracking plugins (PixelYourSite, Conversios, GTM) prematurely fire the Purchase event the exact millisecond a customer clicks “Place Order”. If an order is a fake Cash-on-Delivery (COD) submission, entered with a wrong phone number, or cancelled an hour later — Meta’s AI algorithm has already marked it as a successful high-value buyer, actively training Meta Advantage+ to find more fake buyers and chronic returners!
- CapiFlow Free (Confirmed Purchase Control): CapiFlow does NOT fire
Purchaseprematurely upon checkout placement. Instead, it holds the event until the store owner verifies the order and marks it as “Confirmed” or “Completed” in WooCommerce. Only 100% real, verified purchases reach Meta Events Manager! - CapiFlow Pro (Courier API Automation): Automatically verifies delivery status in real-time with courier networks (Pathao, Steadfast, REDX, DHL, FedEx) and auto-fires
Purchaseupon delivery confirmation. If an order is returned or cancelled, it dispatches Negative Purchase Signals to retrain ad algorithms away from chronic returners!
⚡ 0ms Checkout Speed Impact (100% Asynchronous Background Queuing)
Never sacrifice checkout conversion rates for tracking accuracy.
* Non-Blocking Architecture: CapiFlow offloads all server-side CAPI API dispatches to background workers using WordPress Action Scheduler.
* 0ms Latency: Your customers experience instant checkout confirmation with zero API timeout delays, perfectly protecting your Core Web Vitals.
🍪 180-Day Cache-Safe Persistent Server Cookies
- Safari ITP & Ad Blocker Immune: While Apple Safari and browser privacy shields wipe JavaScript cookies (
document.cookie) within 1 to 7 days, CapiFlow sets first-partyHttpOnlyserver cookies that persist for up to 180 days. - Page-Cache Bypass: Cookies are delivered via uncacheable REST response headers, ensuring 100% functionality even on aggressive caching stacks (LiteSpeed Cache, WP Rocket, Varnish, Cloudflare).
- Skyrocket Event Match Quality (EMQ): Matches returning customers months after their first ad click with full SHA-256 hashed customer parameters, achieving 9+ EMQ scores.
Core Features
Direct Server-to-Server Tracking
* 🎯 7 Standard Events Supported: Purchase, InitiateCheckout, AddPaymentInfo, AddToCart, ViewContent, Search, PageView.
* 🔄 Deterministic Deduplication: Browser and server events share the exact same synchronized event_id to guarantee Meta never double-counts conversions.
* 🛡️ First-Party Proxy Endpoint: Client tracking scripts can be routed through your own domain, bypassing ad-blocker domain blocklists.
* 🔐 SHA-256 PII Advanced Matching: Automatically hashes customer email, phone, first name, last name, city, and state before leaving your server.
WooCommerce Control & Monitoring
* 📈 Interactive Dashboard: Real-time event analytics, browser vs. server delivery ratios, and conversion trends.
* 🔍 Live Debug Console: Inspect exact server payloads, timestamp logs, and Meta Graph API response codes.
* 🏥 System Health Inspector: Instant verification of Meta Access Token validity, queue backlog, and cURL connectivity.
* 📞 Checkout Phone Validator: Automatically cleans and validates customer phone formatting at checkout.
* 📋 Order Column Badges: Per-order CAPI dispatch status badges directly inside the WooCommerce Orders screen.
Free vs Pro Comparison
Feature
CapiFlow Free
CapiFlow Pro
100% Self-Hosted (Zero Monthly Cloud Fees)
✅ Yes
✅ Yes
Meta Conversions API (CAPI) Core Events
✅ Yes
✅ Yes (All + Custom)
Multi-Platform Support (GA4, Google Ads, TikTok, Pinterest…)
Meta CAPI Only
✅ All 8 Platforms
Browser & Server Event Deduplication (event_id)
✅ Yes
✅ Yes
Purchase Event Firing Logic
Manual Confirmed Purchase Control
✅ Fully Automated via Courier APIs
Negative Purchase Signals (Ad Budget Optimization)
❌ No
✅ Yes (Automated on Returns)
0ms Async Background Queuing
✅ Yes
✅ Yes
Cache-Safe 180-Day Persistent Server Cookies
✅ Yes
✅ Yes
Category-Based Multi-Pixel Routing
❌ No
✅ Yes
3-Layer AI Fraud Defense & Phone OTP Verification
❌ No
✅ Yes (Full Suite)
Multi-Carrier Courier Auto-Booking (Pathao, Steadfast, DHL…)
❌ No
✅ Yes
Smart Cart Recovery with Dynamic Single-Use Auto-Coupons
❌ No
✅ Yes (SMS + Email)
CapiFlow Pro
Ready to automate your entire post-purchase pipeline? CapiFlow Pro upgrades your store into an automated powerhouse:
* 8-Platform Multi-CAPI: Track Meta, Google Analytics 4, Google Ads Enhanced Conversions, TikTok, Pinterest, Snapchat, LinkedIn, and X.
* Automated Courier Logistics: 1-click booking and real-time delivery status syncing with Pathao, Steadfast, REDX, DHL, FedEx, and custom webhooks.
* Negative Purchase Signals: Automatically signal ad platforms when orders are cancelled or returned to reduce your Cost Per Acquisition (CPA) by 20%–40%.
* Smart Cart Recovery & Dynamic Coupons: Recovers abandoned checkout drafts with single-use, time-limited auto-coupons sent via SMS & Email.
* 3-Layer AI Fraud Guard: Delivery success rate prediction and phone OTP verification to stop fake buyers before shipment.
Learn more on the CapiFlow Pro Website.
Compatibility
- Payment Gateways: bKash, Nagad, Rocket, SSLCommerz, Stripe, PayPal, COD (Cash on Delivery), and all standard WooCommerce gateways.
- Themes: 100% compatible with Classic themes, Block themes (FSE), Elementor, Divi, Bricks, and custom WooCommerce templates.
- Storage Engines: Full native support for High-Performance Order Storage (HPOS) and legacy custom post types.
- Consent Management Platforms (CMP): Seamless integration with CookieYes, Complianz, CookieBot, and custom hooks (
capiflow_has_tracking_consent).
Requirements
- WordPress 6.0+
- WooCommerce 7.0+
- PHP 7.4+ (PHP 8.0, 8.1, 8.2, 8.3 fully supported)
- OpenSSL PHP extension
- Meta Pixel ID & System User Access Token
External Services
This plugin connects to the following third-party services:
Meta (Facebook) Conversions API
CapiFlow sends WooCommerce event data to the Meta Conversions API via: https://graph.facebook.com/
This connection is made from your server to Meta’s servers when a configured tracking event occurs. No data is sent until a valid Pixel ID and Access Token are configured.
Data transmitted includes:
- Hashed email, phone, first and last name (SHA-256)
- Client IP address and Browser User Agent
- Meta Click ID (_fbc) and Browser ID (_fbp) cookies
- Order total, currency, and event metadata
All personal data is SHA-256 hashed before transmission.
Meta Pixel JavaScript SDK
This plugin loads the Meta Pixel SDK from: https://connect.facebook.net/en_US/fbevents.js
Loaded on frontend pages when a Pixel ID is configured. The SDK is hosted by Meta.
Privacy
For server-side events, all personal data is SHA-256 hashed before transmission. For browser events, the Meta Pixel SDK handles hashing via Advanced Matching. This plugin does not store raw PII in its own tables. See Meta’s privacy policy.
Cookies
cs_uid— Random visitor identifier forexternal_iddeduplication. 180 days. No PII._fbc— Meta Click ID. Set by Meta SDK on ad click. CapiFlow reads/extends server-side. 180 days._fbp— Meta Browser ID. Set by Meta SDK. CapiFlow reads/extends server-side. 180 days.
All cookies are first-party and contain no personally identifiable information.
Data Storage
{prefix}_capiflow_events— Queued/sent event payloads. Auto-purged after delivery.{prefix}_capiflow_analytics— Daily aggregated analytics. Auto-purged by retention settings.- Order metadata with
_capiflow_prefix. Removed on uninstall if “Keep Data” is disabled. - Logs in
wp-content/uploads/capiflow-logs/with.htaccessprotection. Auto-cleaned daily.
Consent
By default, events fire once configured. Enable “Consent Enforcement” in Settings to respect CMP signals for both browser and server events.
Supported CMPs: CookieYes, Complianz, CookieBot, GDPR Cookie Consent. Custom integration via capiflow_has_tracking_consent filter.
When Consent Enforcement is enabled, browser and server-side events are blocked until valid tracking consent is detected.
Store owners are responsible for lawful consent configuration where required by privacy regulations.
Screenshots










Installation
- Install from WordPress plugins screen or upload
capiflowto/wp-content/plugins/. - Activate through the Plugins menu.
- Setup wizard launches — enter Pixel ID and Access Token.
- Click Test Connection — check CapiFlow Dashboard to monitor.
Getting an Access Token
- Meta Events Manager Select Pixel Settings Conversions API
- Click Generate Access Token or create a System User
- Paste into CapiFlow Settings Pixel Settings
FAQ
-
Can I use CapiFlow for Meta Pixel server-side tracking without GTM?
-
Yes! CapiFlow is built specifically for WooCommerce stores to enable full server-side Conversions API (CAPI) and Meta Pixel tracking without needing Google Tag Manager (sGTM), complex dataLayers, triggers, or custom code. Everything is 100% pre-engineered, native, and automated. You simply paste your Pixel ID and Access Token, and tracking starts in under 3 minutes.
-
Can I run Meta Conversions API without Stape.io, Google Cloud, or monthly fees?
-
Yes, absolutely. You do not need Stape.io, Google Cloud Platform (GCP), AWS, or any paid cloud server container. CapiFlow runs 100% natively on your existing WordPress server and offloads events via Action Scheduler, saving you $240 to $1,200+ every year in cloud hosting subscriptions.
-
Does this replace the Meta browser pixel or run dual-tracking?
-
CapiFlow runs Meta’s officially recommended dual-tracking setup: it fires both client-side Meta Pixel (
fbq) and server-side Conversions API (CAPI) simultaneously. Both streams share identical, synchronized cryptographicevent_idvalues for 100% deterministic deduplication in Meta Events Manager. -
Will dual tracking cause duplicate events or inflated conversion numbers?
-
No. Matching
event_idvalues guarantee that Meta automatically deduplicates browser and server events within Meta’s 48-hour deduplication window. You get 100% accurate conversion reporting with zero double-counting. -
How does CapiFlow bypass Apple Safari ITP and iOS 14.5+ tracking loss?
-
While Apple Safari and ad blockers wipe JavaScript cookies (
document.cookie) within 1 to 7 days, CapiFlow sets persistent first-party identity cookies (_fbpand_fbc) via uncacheable REST response headers that persist for up to 180 days. This bypasses page caching layers (LiteSpeed, WP Rocket, Varnish, Cloudflare) and recovers 25%+ of lost conversions. -
How does CapiFlow achieve a 9+ Event Match Quality (EMQ) score on Meta?
-
CapiFlow normalizes and SHA-256 hashes customer data (E.164 phone numbers, lowercase trimmed emails, names, cities, postal codes) and pairs them with
fbc,fbp,external_id, client IP, and browser user agent. This multi-signal matching consistently delivers 9.0+ EMQ scores in Meta Events Manager. -
Does CapiFlow slow down my checkout or store page speed?
-
No. CapiFlow offloads all server-side CAPI dispatches to background workers using WordPress Action Scheduler. It adds 0ms delay to customer checkout or page load speeds, keeping your Core Web Vitals 100% green.
-
Does this work with caching plugins like LiteSpeed Cache, WP Rocket, or Cloudflare?
-
Yes! CapiFlow sets persistent server identity cookies directly via uncacheable REST response headers. This completely bypasses page caching layers (LiteSpeed, WP Rocket, Varnish, Cloudflare) and ensures cookies are never cached statically.
-
How does Confirmed Purchase Control protect my ad budget from fake orders?
-
Conventional tracking plugins fire a Purchase event the exact moment a customer submits checkout. If that order is a fake Cash-on-Delivery (COD) submission or gets cancelled, Meta’s algorithm still counts it as a successful sale, poisoning your ad optimization. CapiFlow Free holds the Purchase event until you verify the order and mark it “Confirmed” or “Completed” in WooCommerce. In CapiFlow Pro, this is fully automated via Courier APIs (Pathao, Steadfast, REDX, DHL, FedEx) and Negative Purchase signals!
-
Which WooCommerce payment gateways, themes, and order storage engines are supported?
-
100% compatible with all standard gateways (bKash, Nagad, SSLCommerz, Stripe, PayPal, COD), all themes (Classic, Block/FSE, Elementor, Divi, Bricks), and both High-Performance Order Storage (HPOS) and legacy posts-based order storage.
-
How is customer privacy and GDPR/CCPA consent handled?
-
All PII is SHA-256 hashed before transmission. CapiFlow includes a built-in Consent Enforcement toggle that blocks both browser and server events until CMP consent is granted (compatible with CookieYes, Complianz, CookieBot, and custom filters). Privacy policy content is auto-added to your WordPress Privacy Policy page.
-
What is CapiFlow Pro?
-
A separate addon that adds 8-platform multi-CAPI, courier automation, negative Purchase signals, cart recovery with auto-coupons, and AI fraud protection. Learn more.
Reviews
Contributors & Developers
“CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” is open source software. The following people have contributed to this plugin.
Contributors“CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” has been translated into 1 locale. Thank you to the translators for their contributions.
Translate “CapiFlow – Conversions API (CAPI) Tracking for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.3 — 2026-09-28
- Fix: E.164 domestic trunk-zero stripping —
normalize_phone_e164()now correctly strips domestic trunk zeros when the number already starts with the country dialing code (e.g.+880017...8801712345678instead of retaining the leading0). Affects Meta Advanced Matching phone hashing accuracy. - New:
hash_postcode()method added toData_Normalizeras an alias ofhash_zip()for international postal code taxonomy compatibility. - New:
get_universal_uid()utility method added — reads first-party visitor UID fromcs_uidorcs_vidcookies for cross-session identity stitching.
1.1.2 — 2026-09-19
- Fix: Universal Price Normalization — introduced dual-tier price parsing engine (
parsePrice) to accurately handle European and international currency price formatting (e.g. comma as decimal separator like€14,21), preventing 100x price inflation in Meta Pixel Helper and CAPI. - Fix: International Currency Safeguards — added automatic sanitization for Unicode whitespace (non-breaking spaces), apostrophes (Swiss Franc
CHF), Eastern Arabic & Persian numerals and punctuation (٫and٬), and zero-decimal currencies (JPY,KRW,VND). - Fix: Currency Abbreviation Dot Collision Protection — strips non-digit periods to prevent regional currency abbreviations (e.g.
kr.,Rs.,руб.,грн.,د.إ,S/.) from colliding with decimal separators. - Fix: Dual-Tier Heuristic Fallback — added intelligent single-comma ambiguity analysis for cached pages to preserve correct decimal/thousands separator distinctions even if client configuration is missing.
- Fix: AJAX & Block Cart Resolution — upgraded Handler 2 (classic AJAX cart) and Handler 3 (WooCommerce Blocks) to dynamically scrape and transmit real product price, name, and quantity rather than fallback zeros.
- Fix: Precision & Variation Guards — formatted multi-quantity AddToCart event values to eliminate IEEE-754 floating-point noise (e.g.
42.63000000000001), and added variation selection guards to prevent false AddToCart events on unselected variable products. - Fix: Server-Side Deferred Rounding — rounded deferred session AddToCart payloads according to WooCommerce store decimal settings.
1.1.1 — 2026-08-21
- Fix:
predicted_ltvis now only sent in Purchase events when COGS (Cost of Goods Sold) data is actually populated. Previously, missing_woo_capi_cogsmeta causedpredicted_ltvto always equal the order total, which Meta flagged as an invalid value and could distort Value-Based Bidding optimization.
1.1.0 — 2026-08-20
- New: Marketplace Catalog Verified — Content ID Strategy setting (SKU / Parent SKU / WooCommerce Product ID) for pixel-to-catalog alignment.
- New:
Event_Builder::resolve_content_id()static resolver — single source of truth for all event methods (Purchase, InitiateCheckout, AddToCart, ViewContent, AddPaymentInfo, Negative Events). - New:
Event_Builder::resolve_content_type()— automatically switches betweenproductandproduct_groupbased on ID strategy and product type. - New:
Event_Builder::resolve_item_price()— tax-parity normalizer ensures item_price matches catalog feed pricing (incl./excl. tax). - New: Search event now includes
content_idsandcontentsarrays from search results (up to 10 products). - New: Guard 5 — Order Source Filter blocks CAPI Purchase events for marketplace/external channel orders (configurable via Settings > Events).
- New: Guard 6 —
capiflow_should_track_purchasefilter provides a clean developer escape hatch to suppress individual Purchase events without setting a dedup lock. - New:
capiflow_content_idfilter allows custom catalog integrations to override resolved content IDs. - Fix:
content_categorynow correctly uses the parent product ID for variable product variations (variations have no direct category assignment). - Fix:
get_product_sku_map()in Pixel Injector now usesresolve_content_id()so JS AddToCart content_ids always match server-side events. - Fix:
store_deferred_addtocart()now usesresolve_content_type()for the deferred AddToCart pixel event. - Fix: Cart loop guards now check
instanceof WC_Productbefore processing to prevent TypeError on malformed cart data. - Fix: Order item loops now check
instanceof WC_Order_Item_Productto skip shipping/fee/coupon line items silently. - Deprecated:
Event_Builder::get_content_type()andget_content_id()now proxy to new static resolvers for backward compatibility.
1.0.2 — 2026-07-29
- Fix: Prevent firing Purchase events for pre-existing orders created prior to CapiFlow installation or >7 days ago when order status is changed in WP Admin/background.
- Fix: Add self-healing installation timestamp and multi-layered pre-installation protection guard to prevent invalid server-side Purchase attribution.
1.0.1 — 2026-05-22
- Update WordPress compatibility header to Tested up to 7.0 for WordPress 7.0 “Armstrong” release.
1.0.0 — 2026-05-01
- Initial public release
- Server-side tracking for 7 Meta standard events via Conversions API
- Browser + server event deduplication with matching event_id
- First-party event endpoint, SHA-256 PII hashing, Advanced Matching
- COD Purchase gate, phone validation, analytics dashboard
- Debug console, system health, setup wizard
- HPOS compatible, Action Scheduler queue, CMP integration
