WPCalibrate Cloud Storage & Delivery
Production-grade cloud storage & delivery for WordPress Media Library and WooCommerce downloadable products in Amazon S3 and CloudFront.
by WPCalibrate · github.com/zeeshanraza-official/wpcalibrate-cloud-storage-delivery · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/zeeshanraza-official/wpcalibrate-cloud-storage-delivery/archive/refs/heads/main.zipEnterprise-grade cloud storage and global content delivery for WordPress Media Library and WooCommerce downloadable products, powered by Amazon S3 and Amazon CloudFront CDN.
Developed by WPCalibrate.
Table of Contents
- About
- Features
- Architecture & Design
- Documentation & Setup
- WP-CLI Commands
- Hooks & Extensibility
- Security & Compliance
- Changelog
- Support & Community
- License
About
WPCalibrate Cloud Storage & Delivery solves scaling, performance, and disk storage challenges for growing WordPress websites and high-volume WooCommerce stores.
By default, WordPress stores all media files and digital WooCommerce downloads on local server storage. As your catalog grows, this causes large server backups, disk capacity bottlenecks, slow page load times, and risk of unauthorized direct downloads of paid digital assets.
WPCalibrate Cloud Storage & Delivery offloads your WordPress media uploads and WooCommerce downloadable products to Amazon S3, delivering them through Amazon CloudFront edge caches worldwide. It features enterprise-grade signed download URLs, tamper-proof token authorization, dual-track background migration (using Action Scheduler or WP-Cron), and full restore capabilities — keeping your WordPress database clean and your server lean.
Features
🚀 Amazon S3 Cloud Storage
- Automatic Uploads: Offload newly uploaded images, videos, audio, documents, and archives to Amazon S3 automatically.
- Image Sub-size Management: Offloads WordPress thumbnail sizes (e.g., medium, large, custom cropped sizes) to cloud storage with atomic tracking.
- Local File Cleanup: Optional automated removal of local media files once safely uploaded and verified on S3, reclaiming massive server disk space.
- Selective Sync: Upload media immediately on upload or queue for non-blocking background processing.
- Custom S3 Endpoints: Supports custom endpoints for S3-compatible providers (MinIO, Wasabi, DigitalOcean Spaces, Cloudflare R2).
⚡ Amazon CloudFront CDN Delivery
- Lightning-Fast Global Delivery: Route media requests through your custom CloudFront distribution domain (
cdn.example.com). - Custom CNAME & SSL: Full support for custom domain mappings and alternate domain names.
- Instant Cache Invalidation: Invalidate media files on CloudFront directly from the WordPress admin or automatically upon file replacement/deletion.
🔒 WooCommerce Download Protection
- HPOS & Blocks Compatible: Fully declared and tested with High-Performance Order Storage (HPOS) and Cart/Checkout Blocks.
- Secure Expiring Signed URLs: Generate time-limited signed S3/CloudFront URLs for paid digital downloads.
- Anti-Hotlinking & IP/User Binding: Prevents download link sharing with HMAC token protection and optional IP/User-Agent validation.
- Download Restrictions: Enforces WooCommerce download limits, order status checks, and customer access permissions.
- Stream vs. Redirect Delivery: Configure seamless streaming through PHP or high-speed authenticated redirect to signed URLs.
🔄 Resilient Migration & Restore Engine
- Dual-Engine Background Processing: Integrates with WooCommerce Action Scheduler if installed, falling back gracefully to reliable batch WP-Cron.
- Resilient Batch Migration: Offload existing media library attachments in batches with exponential backoff and retry policies.
- One-Click Reversible Restore: Download all cloud-hosted files back to your local server storage with integrity checks whenever needed.
- Zero Lock-In: Complete bidirectional sync ensures you retain full ownership of your data at all times.
🛡️ Enterprise Security & Observability
- Encrypted Credential Storage: AWS Access Keys, Secret Keys, and Passphrases can be defined in
wp-config.phpconstants or encrypted via WordPress salts in the database. - Read-Only Secret Masking: Credentials entered in the admin are masked (
AKIA••••••••••••••••) and never printed in HTML forms. - Connection Diagnostics: Instant one-click connection tester validating S3 read/write/delete permissions and CloudFront distribution status.
- Centralized Event Logging: Dedicated debug and audit log recording uploads, download authorization attempts, errors, and migrations with rotation.
🔄 WordPress Dashboard Updates
- Automatic GitHub Release Sync: Automatically detects new releases published on this repository and notifies administrators inside the WordPress Plugins dashboard.
- 1-Click In-Dashboard Update: Update directly from the WordPress Plugins screen without manual FTP or ZIP upload.
- Git Updater Compatible: Native support for Git Updater and GitHub Updater plugins.
Architecture & Design
┌───────────────────────────────────┐
│ WordPress Admin & Media Library │
└─────────────────┬─────────────────┘
│
Attachment Upload / Edit
│
▼
┌───────────────────────────────────┐
│ WPCalibrate Storage Manager │
└──────┬─────────────────────┬──────┘
│ │
Offload Path│ │Public URL Resolver
▼ ▼
┌─────────────────────────┐ ┌─────────────────────────┐
│ Amazon S3 Object Bucket │ │ Amazon CloudFront │
│ (Public Media Objects) │ │ Global CDN Edge │
└─────────────────────────┘ └─────────────────────────┘
▲ ▲
│ │
Authorized Signed URL Protected Edge URL
│ │
┌─────────────────────────┴─────────────────────────┐
│ WooCommerce Download Authorizer & Security │
│ (HMAC Signed, Order Verified, Expiring URLs) │
└─────────────────────────▲─────────────────────────┘
│
Customer Request
The plugin adopts strict PSR-4 autoloading under the WPCalibrate\CloudStorageDelivery namespace, modular single-responsibility service classes, and full isolation of dependencies.
Documentation & Setup
Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| WordPress | 6.4 | 6.7+ |
| PHP | 8.2 | 8.3 |
| WooCommerce (optional) | 9.0 | 9.5+ (HPOS enabled) |
| PHP Extensions | curl, json, mbstring, openssl, simplexml |
Installation
Option 1: WordPress Dashboard (Recommended)
- Download the latest
wpcalibrate-cloud-storage-delivery-1.0.0.zipfrom Releases. - Go to WordPress Admin > Plugins > Add New Plugin > Upload Plugin.
- Select the downloaded ZIP file and click Install Now.
- Click Activate Plugin.
Option 2: Manual Installation via FTP/SFTP
- Extract the
wpcalibrate-cloud-storage-delivery-1.0.0.ziparchive. - Upload the
wpcalibrate-cloud-storage-deliveryfolder to your/wp-content/plugins/directory. - In WordPress Admin, navigate to Plugins and click Activate under WPCalibrate Cloud Storage & Delivery.
AWS IAM Permissions Policy
Create a dedicated IAM user in the AWS Management Console with programmatic access (Access Key ID and Secret Access Key). Attach the following least-privilege IAM policy (replace your-bucket-name with your actual S3 bucket):
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "WPCalibrateS3BucketAccess",
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetBucketLocation"
],
"Resource": "arn:aws:s3:::your-bucket-name"
},
{
"Sid": "WPCalibrateS3ObjectOperations",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject",
"s3:PutObjectAcl"
],
"Resource": "arn:aws:s3:::your-bucket-name/*"
},
{
"Sid": "WPCalibrateCloudFrontInvalidation",
"Effect": "Allow",
"Action": [
"cloudfront:CreateInvalidation",
"cloudfront:GetInvalidation",
"cloudfront:GetDistribution"
],
"Resource": "*"
}
]
}
AWS Configuration
You can configure AWS credentials via the WordPress Admin interface (WPCalibrate > Connection) or securely via your wp-config.php file (recommended for production):
// In wp-config.php (Recommended)
define( 'WPCALIBRATE_CSD_AWS_KEY', 'AKIAIOSFODNN7EXAMPLE' );
define( 'WPCALIBRATE_CSD_AWS_SECRET', 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY' );
define( 'WPCALIBRATE_CSD_AWS_REGION', 'us-east-1' );
define( 'WPCALIBRATE_CSD_AWS_BUCKET', 'my-site-media-bucket' );
- Navigate to WPCalibrate > Connection in your WordPress dashboard.
- Enter your Bucket Name, AWS Region, and Credentials (if not using constants).
- Click Save Settings.
- Click Test S3 Connection to verify permissions. You should see a green success notice confirming read, write, and delete permissions.
CloudFront CDN Integration
- Go to WPCalibrate > CloudFront.
- Toggle Enable CloudFront CDN.
- Enter your CloudFront Domain (e.g.,
d111111abcdef8.cloudfront.netor custom CNAMEcdn.example.com). - (Optional) Provide your Distribution ID to enable instant cache invalidations when media files are updated.
- Save settings. Media URLs will now automatically resolve through CloudFront!
WooCommerce Integration
- Ensure WooCommerce is active.
- Go to WPCalibrate > WooCommerce Downloads.
- Toggle Offload Downloadable Products to store WooCommerce downloadable files on S3.
- Select the Delivery Method:
- Signed Redirect (Recommended): Redirects customer to a high-speed, secure, expiring S3/CloudFront signed URL.
- Stream Through Server: Streams data via PHP without revealing cloud storage URLs.
- Set the Signed URL Expiration Time (default:
15 minutes). - Toggle IP Address Binding or Strict User-Agent Verification for added digital download protection.
Background Migration & Restore
- Go to WPCalibrate > Migration.
- Bulk Offload to S3: Click Start Migration to offload existing media attachments to S3 in background batches. You can pause or cancel at any time.
- Restore to Local Server: Click Start Restore to safely download all cloud files back to your WordPress local
/wp-content/uploads/directory.
Dashboard Updates from GitHub
This plugin includes an integrated update listener that communicates with the official GitHub Releases API.
- When an update is published on GitHub, WordPress will automatically display an update notification on Dashboard > Updates and the Plugins page.
- You can upgrade with a single click directly from the WordPress administration panel.
- To force an immediate check, click Check Again under Dashboard > Updates.
WP-CLI Commands
WPCalibrate Cloud Storage & Delivery supports native command-line operations for DevOps automation and high-scale deployments:
# Test AWS S3 connection and bucket access
wp wpcalibrate test-connection
# Trigger background offload of all local media to S3
wp wpcalibrate media offload --batch-size=100
# Restore all cloud-stored media back to local storage
wp wpcalibrate media restore
# Invalidate specific file or pattern on CloudFront
wp wpcalibrate cloudfront invalidate --paths="/wp-content/uploads/2026/*"
# View storage statistics and object counts
wp wpcalibrate stats
Hooks & Extensibility
Developers can customize behaviors, URLs, and authorization logic via standard WordPress filters:
// Customize S3 Object Key naming pattern
add_filter( 'wpcalibrate_csd_s3_object_key', function( $key, $attachment_id, $file_path ) {
return 'custom-prefix/' . $key;
}, 10, 3 );
// Filter whether a specific attachment should be offloaded
add_filter( 'wpcalibrate_csd_should_offload_attachment', function( $should_offload, $attachment_id ) {
// Skip offloading PDFs
if ( get_post_mime_type( $attachment_id ) === 'application/pdf' ) {
return false;
}
return $should_offload;
}, 10, 2 );
// Modify WooCommerce signed URL expiration (in seconds)
add_filter( 'wpcalibrate_csd_signed_url_expiration', function( $expiration, $product_id, $order_id ) {
return 30 * MINUTE_IN_SECONDS; // 30 minutes
}, 10, 3 );
Security & Compliance
- No Secrets in Frontend / Logs: AWS Secret keys and signatures are never logged or exposed in client-facing HTML.
- Cryptographic Signatures: S3 signed URLs utilize SigV4 HMAC-SHA256 authenticated requests.
- Path Traversal Protection: All local and cloud paths are validated with strict canonicalization against traversal attacks (
../,%00). - Capability Checks: All management endpoints require
manage_optionsor the customwpcalibrate_manage_storagecapability. - WP Nonce Protection: All admin actions and AJAX endpoints require secure nonce tokens.
Changelog
[1.0.0] - 2026-10-05
Added
- Initial Release of WPCalibrate Cloud Storage & Delivery.
- Amazon S3 integration with AWS SDK v3.
- Media Library offloader for main files and all thumbnail sub-sizes.
- Option to retain or remove local files after verified cloud offload.
- Amazon CloudFront CDN support with custom domain mapping and invalidation triggers.
- WooCommerce downloadable product offloader with expiring signed URLs and token security.
- High-Performance Order Storage (HPOS) and Cart/Checkout Blocks full compatibility.
- Two-way background migration engine supporting Action Scheduler and WP-Cron fallback.
- Bidirectional restore tool to download all cloud files back to local server storage.
- Comprehensive diagnostic tools, storage usage statistics, and debug logging.
- GitHub-based native WordPress dashboard update engine.
- Responsive, accessible administrative interface with dark-mode sidebar branding.
Support & Community
- Website: wpcalibrate.com
- Marketplace: marketplace.wpcalibrate.com
- Documentation: docs.wpcalibrate.com
- Issues & Bug Reports: GitHub Issues
- Email Support: support@wpcalibrate.com
License
This software is released under the GNU General Public License v2.0 or later (GPL-2.0-or-later).
Please see the LICENSE file for more details.