cwp scrub
shipped 1.0.0cwp scrub [flags]
Local only: it acts on no environment.
| Flag | What it does | Default |
|---|---|---|
--with-agent | with —dry-run on a host with no shell: install and remove the PHP agent so the plan is real | off |
Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.
What it does
Removes production personal data from the local copy, and installs the mail guard.
cwp pull runs it for you as part of a pull, which is where it
normally happens. Run it on its own when the data arrived another way: a
ddev pull, a dump someone sent you, a pull run with --no-scrub.
The pipeline anonymises users outside pull.keep_roles. It deletes the log
post types listed in pull.truncate_post_types and truncates the tables in
pull.truncate_tables. It installs the mail guard that stops the local site
sending real mail to real addresses.
Two of those steps are fatal on failure rather than degrading to a warning: anonymisation and log deletion. Reporting a clean scrub over surviving personal data is the failure the step exists to prevent.
Deletion goes through WordPress rather than SQL, and past the trash. A trashed log is still the full record. The IP addresses and user agents live in postmeta and term relationships that a row delete would leave behind.
Example
cwp scrub
cwp scrub --dry-run # what it would remove, and from where
What it does not do
It acts on the local site only and names no environment. There is no flag that points it at a remote. Nothing talks this command into scrubbing production.
It does not remove content. It leaves posts, pages and attachments alone. It leaves the redirect rules that sit one word away from the redirect logs in the same plugin.
It installs the mail guard even when you switch scrubbing off. That is a rule rather than a default.