In 2026, Cloudflare’s Cache Rules (the successor to Page Rules) have redefined how WooCommerce performance is handled. By utilizing “Edge-Cache” (also known as “Guest Caching” or APO), you can achieve TTFB (Time to First Byte) under 100ms globally.
The core objective on mybox is to serve static HTML to guests while ensuring the cache is instantly bypassed the moment a user interacts with the cart, logs in, or personalizes their session.
Table of Contents
1. Global Cache Rules and Header Template
On mybox, you should move away from the “standard” caching level to a more aggressive Cache Everything strategy, but only for specific traffic.
Rule 1: Aggressive Guest Caching
- Field:
Cookie(does not containwordpress_logged_in) ANDURI Path(does not contain/wp-admin) ANDCookie(does not containwp_woocommerce_session). - Setting: Eligible for Cache + Edge Cache TTL (e.g., 2 hours).
- Normalization: Use Cache Key settings to “Ignore Query Strings” like
utm_source,gclid, andfbclidto avoid cache fragmentation.
Rule 2: Browser TTL and Stale-While-Revalidate
- Configure Browser Cache TTL to be shorter than Edge TTL (e.g., 30 minutes).
- Enable Stale-While-Revalidate in Cloudflare Speed settings. This allows the edge to serve a “stale” version of your mybox site instantly while fetching a fresh copy in the background.
2. Hard Bypasses for WooCommerce & Session Integrity
WooCommerce requires “Stateful” integrity. If a user sees another person’s cart, it is a critical security failure.
Paths to Bypass (Hard Rules):
You must set a Bypass Cache rule for the following URI paths:
/cart/*/checkout/*/my-account/*/wp-admin/*/wc-ajax/*(Critical for dynamic price updates and fragments).
Cookie-Based Bypasses:
Configure Cloudflare to bypass the cache if any of these cookies are present:
wp_woocommerce_session_*woocommerce_items_in_cartwoocommerce_cart_hashwordpress_logged_in_*
3. Advanced Performance: Early Hints & 103 Status
Early Hints (103) is a breakthrough for 2026. It allows Cloudflare to send “hints” to the browser about critical assets (fonts, hero images, main CSS) before the server has finished generating the HTML.
- Implementation on mybox: Enable “Early Hints” in the Cloudflare Speed dashboard.
- Link Headers: Use a plugin or a WPCode snippet to add
Linkheaders to your initial response:Link: </wp-content/themes/my-theme/style.css>; rel=preload; as=style - Result: This can reduce LCP (Largest Contentful Paint) by up to 200–400ms.
4. Security and Origin Protection
Cashing is useless if your origin server is overwhelmed by bots.
- Turnstile (CAPTCHA replacement): Use Cloudflare Turnstile on your login and registration pages. It provides zero-friction protection against brute-force attacks on your mybox admin.
- WAF (Web Application Firewall): Enable the “WordPress” managed rule set. This automatically blocks known vulnerabilities in popular plugins like Elementor, Contact Form 7, and WooCommerce.
- Authenticated Origin Pulls: Ensure that your mybox server only accepts traffic from Cloudflare’s IP ranges. This prevents attackers from bypassing Cloudflare to attack your IP directly.
5. Troubleshooting and Cache Validation
To verify your setup is working on mybox, open the browser console (F12) -> Network Tab and check the cf-cache-status header:
| Header Value | Meaning | Action for mybox |
| HIT | Served from Cloudflare Edge. | Correct for Guest Home/Product pages. |
| BYPASS | Ignored due to a Rule/Cookie. | Correct for Cart, Checkout, and Admin. |
| DYNAMIC | Passed to origin (uncacheable). | Correct for Search or private dynamic data. |
| STALE | Serving old data while refreshing. | Normal if “Stale-While-Revalidate” is on. |
Summary
The ultimate mybox + Cloudflare setup uses Cache Rules to turn your dynamic WordPress site into a static-speed powerhouse for guests, while using Cookie Bypasses to maintain a perfect shopping experience for customers. By enabling Early Hints and Brotli compression, you ensure your store is among the fastest 1% on the web in 2026.