CoCart - Headless REST API for WooCommerce
by CoCart Headless 4.9 (21 reviews)

CoCart - Headless REST API for WooCommerce

Ship your headless WooCommerce storefront faster. CoCart is the REST API built for Next.js, React, Vue, and any modern frontend — developer-first.

CoCart ranks #7,057 among WordPress.org plugins with 900+ active installations, is #1,133 of 12,226 in the E-commerce category, a 4.9/5 rating from 21 reviews, and was last updated Sep 10, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v4.9.6 Current Version v4.9.6
Updated 5 days ago Last Update on 10 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#1,133 of 12,226 in E-commerce Top 10% by installs Downloads -18.2% this week Actively maintained
View on WordPress.org
Rank
#7,057
+18 this week
Active Installs
900+
-15.9%
KW Avg Position
53.8
0.5 better
Downloads
94.9K
+7 today
Support Resolved
0%
No change
Rating
98%
Review 4.9 out of 5
4.9 (21 reviews)

Next Milestone 1K

Total Progress 91%
900+ 1K+
48
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 1K+

Rank Changes

7,015 7,034 7,053 7,071 7,090 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
7,015 7,034 7,053 7,071 7,090 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #7,057
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 50 100 150 200 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 50 100 150 200 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
21 reviews
Overall 98%
5
20 (95%)
4
0 (0%)
3
0 (0%)
2
1 (5%)
1
0 (0%)

Security History

Source: WPVulnerability

2 known vulnerabilities on record · 0 in the last 24 months · checked 1 month ago

  1. CoCart – Headless REST API for WooCommerce [cart-rest-api-for-woocommerce] < 3.12.0

    CVE-2023-47241 · Fixed in v3.12.0

  2. CoCart – Headless REST API for WooCommerce [cart-rest-api-for-woocommerce] < 4.9.0

    CVE-2026-59536 · Fixed in v4.9.0

TL;DR

AI summary of the plugin's readme

CoCart is for developers building headless WooCommerce storefronts with frontends like React, Next.js, Vue, or Astro. It solves the problem of WooCommerce lacking a proper frontend-friendly REST API by providing cookie-less session management, authentication, and CORS support out of the box.

  • Cookie-less session management
  • Guest customer support
  • Load session into checkout
  • Add, update, remove cart items
  • Product search by name/SKU/ID
  • Name Your Price support
  • Bulk cart requests
  • Flexible authentication options

Frequently Asked Questions

Common questions about CoCart - Headless REST API for WooCommerce

Developers building headless or decoupled WooCommerce storefronts. If you can make HTTP requests and read JSON, you’re ready. No WordPress development experience required — CoCart abstracts the complexity and gives you clean, predictable API responses. Perfect for: Frontend developers building with React, Next.js, Astro, Vue, or any modern framework Agencies creating high-performance client storefronts Mobile app developers who need a reliable eCommerce API
Install WooCommerce and configure your store, then install and activate CoCart. You’re immediately ready to call the API — no additional setup required. Check the installation section for requirements, then follow the API reference to start building.
Nothing. The free community stays fully functional. It covers sessions, authentication, CORS, cart operations, and product queries — everything you need to build a working headless cart. CoCart Plus adds advanced features like coupons, shipping, fees, and rate limiting for when you need them.
No. CoCart runs entirely on your WordPress server. No customer data, cart contents, or store information is ever sent to CoCart’s servers. The plugin collects no analytics without your consent. Full privacy policy →
Plugins that modify backend functionality — payment gateways, shipping, tax, inventory — continue to work. Plugins that only modify the PHP frontend (themes, shortcodes, widgets) won’t apply to the REST API layer, which is expected in a headless setup.
WooCommerce’s Store API can be used headless, but it was designed for the Gutenberg block editor ecosystem. Its session model relies on nonces passed via response headers — suited for anonymous single-session shoppers, but tied to WordPress’s nonce lifecycle and less straightforward to persist across sessions or devices. CoCart is purpose-built for headless: cart sessions identified by a persistent key and authentication that supports any shop requirement.
Headless storefronts are stateless by nature — there’s no browser session to rely on, and concurrent requests are common. CoCart’s session handler is cookie-less, database-stored, and safe for concurrent requests, with full support for both guest and authenticated customers from day one.
Yes — that’s the primary use case CoCart is built for. Enable CORS via the free CORS add-on or manually via the filter documented here.
Yes. CoCart doesn’t block or replace any other API. Once authenticated, your frontend can access CoCart endpoints, WooCommerce endpoints, and any custom endpoints you’ve built — all at the same time.
CoCart does not implement SSO itself — it authenticates customers against WordPress user accounts using Basic Auth or JWT (via add-on). It does not natively speak SAML, OAuth 2.0, or OIDC. That said, CoCart can work alongside SSO in a headless setup. The typical pattern is: Your identity provider (Google, Okta, Auth0, etc.) authenticates the user via your frontend. A WordPress SSO plugin (e.g. one handling OAuth 2.0 or SAML) creates or matches a WordPress user account for that identity. Your frontend then authenticates with CoCart using Basic Auth or JWT as that WordPress user. The SSO layer handles identity; CoCart handles the commerce session from that point on. Whether this works smoothly depends on how your chosen SSO plugin manages WordPress user creation and session state — that part is outside CoCart's scope.

Sign In / Register

You need to sign in or register to use this feature.