In 2026, Cloudflare’s Cache Rules (the modern successor to Page Rules) have redefined how WooCommerce performance is handled. By utilizing “Edge-Cache” (also known as “Guest Caching” or APO), you can achieve TTFB (Time to First Byte) under 100ms globally while protecting your mybox server from dynamic request spikes.
The core objective is to serve static HTML to guests while ensuring the cache is instantly bypassed the moment a user adds an item to their cart, logs in, or personalizes their session.
Table of Contents
1. Cache Rules and Header Template
On mybox, you should use Cache Rules for more granular control than traditional page rules.
Rule 1: Aggressive Guest HTML Caching
- Field:
Cookie(does not containwordpress_logged_in) ANDCookie(does not containwp_woocommerce_session) ANDURI Path(does not contain/wp-admin). - Setting: Eligible for Cache + Edge Cache TTL (e.g., 2 hours).
- Normalization: Enable Cache Key settings to “Ignore Query Strings” like
utm_source,gclid, andfbclidto avoid cache fragmentation.
Rule 2: Browser TTL & Stale-While-Revalidate
- Configure Browser Cache TTL to 30 minutes.
- Enable Stale-While-Revalidate in Cloudflare Speed settings. This allows the edge to serve a “stale” version of your mybox site instantly while fetching a fresh copy in the background, ensuring zero-latency for users.
2. Hard Bypasses for WooCommerce & Session Integrity
WooCommerce requires “Stateful” integrity. If a user sees another person’s cart, it is a critical security failure.
Paths to Bypass (Hard Rules):
Set a Bypass Cache rule for these URI paths:
/cart/*/checkout/*/my-account/*/wp-admin/*/wc-ajax/*(Critical for dynamic price updates).
Cookie-Based Bypasses:
Configure Cloudflare to bypass the cache if any of these cookies are present:
wp_woocommerce_session_*woocommerce_items_in_cartwoocommerce_cart_hashwordpress_logged_in_*
3. Advanced Performance: Early Hints (103)
Early Hints is a breakthrough for 2026. It allows Cloudflare to send “hints” to the browser about critical assets (fonts, hero images) before the server has finished generating the HTML.
- Implementation: Enable “Early Hints” in the Cloudflare Speed dashboard.
- Link Headers: Use a plugin or WPCode to add
Linkheaders to your response:Link: </wp-content/themes/mybox-theme/style.css>; rel=preload; as=style - Result: This can reduce LCP (Largest Contentful Paint) by up to 200–400ms by starting the download of critical assets sooner.
4. Safety and Reliability on mybox
Caching is useless if your origin server is overwhelmed by bots.
- Turnstile (CAPTCHA replacement): Use Cloudflare Turnstile on your login and registration pages. It provides zero-friction protection against brute-force attacks on your mybox admin.
- Authenticated Origin Pulls: Ensure your mybox server only accepts traffic from Cloudflare’s IP ranges. This prevents attackers from bypassing Cloudflare to attack your IP directly.
- WAF (Web Application Firewall): Enable the “WordPress” managed rule set. This automatically blocks known vulnerabilities in WooCommerce and common plugins.
5. Troubleshooting and Cache Validation
To verify your setup is working on mybox, open the browser console (F12) -> Network Tab and check the cf-cache-status header:
| Header Value | Meaning | Expected Location |
| HIT | Served from Cloudflare Edge. | Guest Home/Product pages. |
| BYPASS | Ignored due to a Rule/Cookie. | Cart, Checkout, and Admin. |
| DYNAMIC | Passed to origin (uncacheable). | Search results or private data. |
| STALE | Serving old data while refreshing. | Normal with Stale-While-Revalidate. |
Summary
The ultimate mybox + Cloudflare setup uses Cache Rules to turn your dynamic WordPress site into a static-speed powerhouse for guests, while using Cookie Bypasses to maintain a perfect shopping experience. By enabling Early Hints and Brotli compression, you ensure your store is among the fastest 1% on the web this year.