ShopiPress.
Explore

EN

ShopiPress 1.0.0 · 08

Handle tokens, packages and optional telemetry

Keep public and private credentials distinct, limit administrator access and understand optional Freemius data flow.

Applies to ShopiPress 1.0.0, officially published on Freemius.

Verified workflow

  1. Use only the public Storefront token requested by ShopiPress.
  2. Keep candidate ZIPs and test material outside the public web root.
  3. Review optional telemetry and licence activation before providing consent.

This guide applies to the ShopiPress version identified in the page header, officially published on Freemius. Confirm the installed version before applying the procedure. Later versions may change screens, defaults or service boundaries.

Expected result

Administrators can explain what ShopiPress reads from Shopify, what it stores in WordPress, which optional services are involved and which sensitive data must never enter evidence or page content.

Keep public and private credentials distinct, limit administrator access and understand optional Freemius data flow.

Before you begin

  • The exact candidate’s product and commercial authority records.
  • An inventory of WordPress administrators allowed to manage the connection.
  • The Shopify public Storefront token and intended catalog scopes.
  • A decision about optional Freemius opt-in and premium licensing.

Prepare a rollback point and identify the authoritative Shopify record and the WordPress URL or administration surface that will prove the result. The test should be small enough to repeat without creating ambiguous catalog state.

Scope and current limits

The observed candidate uses a public Storefront token for catalog and cart requests. It does not make WordPress the system of record for customers, orders, payments or checkout, and it sends no plugin-usage telemetry or licensing request directly to Pagup.

Keep the responsibility model visible throughout the task: Shopify remains the commercial source and checkout system; ShopiPress connects, synchronizes and renders the catalog according to delivered contracts; WordPress owns the publishing context. A successful WordPress result must not be interpreted as a transfer of orders, customers, payments or inventory authority.

Procedure

  1. Document the Shopify store endpoint and confirm that the credential is a public Storefront token.
  2. List the WordPress post types, taxonomies and options created or updated by the candidate.
  3. Review the Freemius opt-in and licensing path separately from Shopify catalog requests.
  4. Verify that support, logs, screenshots and video contain no token, customer, order, payment or private address data.
  5. Test downgrade and uninstall behavior in a disposable environment before deciding what operational cleanup is acceptable.

Do not skip the review step between an administrative action and public publication. A successful control response is only one layer of evidence; the stored WordPress record, rendered page and Shopify commerce path must agree.

Verify the result

  • Catalog records are identifiable as WordPress product posts and taxonomy terms.
  • Cart and checkout requests remain associated with Shopify.
  • Optional services are described as optional and no public commercial flow is inferred from source configuration.

Verify the result in the rendered WordPress page and in the authoritative Shopify surface, not only inside the ShopiPress administration screen. Use a representative product with price, availability, variant and collection data. Repeat the smallest safe operation when idempotence matters, and record any difference before broadening the test.

Common mistakes

  • A private credential appears in evidence: stop distribution, remove the artifact and rotate the credential when exposure cannot be ruled out.
  • A service is contacted unexpectedly: capture the destination and triggering action, then compare it with the documented service boundary.
  • Content disappears during lifecycle testing: restore the database and verify the scoped uninstall and non-destructive downgrade contracts.

When a result is unexpected, stop broad actions and reduce the case to one record, one URL and one renderer. Preserve the failing response before changing settings or clearing caches so the diagnosis remains reproducible.

Troubleshooting

  1. Confirm the package version and edition.
  2. Reproduce the smallest safe case with controlled data.
  3. Identify whether Shopify, ShopiPress or WordPress owns the failing step.
  4. Compare the observed result with the delivered, partial or absent capability state.
  5. Restore the test environment, repeat once and record whether the result is stable.

Security and data

Apply least privilege to WordPress administration, protect backups and logs, and never treat a public Storefront token as permission to disclose it casually. Public does not mean irrelevant to abuse prevention.

Record the installed version, edition, WordPress and PHP versions, active builder or SEO integration, exact URL, viewport and the ordered actions that produced the result. Capture only controlled catalog data. Redact the Storefront token, customer data, order information, private domains and any environment secret before an artifact leaves the validation workspace.

SEO consequences

Privacy and security choices affect what can be rendered and indexed. Keep private test environments noindex, prevent internal templates from entering sitemaps and ensure public structured data contains no administrative or credential material.

Evidence to record

Record the installed version, edition, WordPress and PHP versions, active builder or SEO integration, exact URL, viewport and the ordered actions that produced the result. Capture only controlled catalog data. Redact the Storefront token, customer data, order information, private domains and any environment secret before an artifact leaves the validation workspace.

Version and product state

ShopiPress is officially published on Freemius. This guide describes the documented version. Purchase and download links will be added to this site once their destinations are configured.

Keep the system boundary visible

Shopify remains the commerce source; ShopiPress moves catalog records and rendering contracts; WordPress owns publication.

Shopify · catalog source and checkout

ShopiPress · manual sync and rendering

WordPress · content, templates and SEO surface

Verify before moving on

  • Confirm the result in WordPress, not only in the ShopiPress interface.
  • Keep cart and checkout on Shopify.
  • Record the installed version when reporting a defect.