Skip to content

cwp scrub

shipped 1.0.0
cwp scrub [flags]

Local only: it acts on no environment.

FlagWhat it doesDefault
--with-agentwith —dry-run on a host with no shell: install and remove the PHP agent so the plan is realoff

Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.

What it does

Removes production personal data from the local copy, and installs the mail guard.

cwp pull runs it for you as part of a pull, which is where it normally happens. Run it on its own when the data arrived another way: a ddev pull, a dump someone sent you, a pull run with --no-scrub.

The pipeline anonymises users outside pull.keep_roles. It deletes the log post types listed in pull.truncate_post_types and truncates the tables in pull.truncate_tables. It installs the mail guard that stops the local site sending real mail to real addresses.

Two of those steps are fatal on failure rather than degrading to a warning: anonymisation and log deletion. Reporting a clean scrub over surviving personal data is the failure the step exists to prevent.

Deletion goes through WordPress rather than SQL, and past the trash. A trashed log is still the full record. The IP addresses and user agents live in postmeta and term relationships that a row delete would leave behind.

Example

cwp scrub
cwp scrub --dry-run   # what it would remove, and from where

What it does not do

It acts on the local site only and names no environment. There is no flag that points it at a remote. Nothing talks this command into scrubbing production.

It does not remove content. It leaves posts, pages and attachments alone. It leaves the redirect rules that sit one word away from the redirect logs in the same plugin.

It installs the mail guard even when you switch scrubbing off. That is a rule rather than a default.