Skip to content

Exclude the plugin's scripts from Hummingbird's optimizations - #332

Merged
Dan0sz merged 1 commit into
developfrom
hummingbird_compatibility
Oct 1, 2026
Merged

Dan0sz merged 1 commit into
developfrom
hummingbird_compatibility

Conversation

@Dan0sz

@Dan0sz Dan0sz commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

A user reported plausible is not a function on their search results page, caused by Hummingbird (WPMU DEV). In their page source, the plausible-analytics-js-after inline script only contained the search queries event: the window.plausible stub and the plausible.init(...) call that normally precede it were gone.

Cause

"Not a function" (rather than "not defined") means the tracker did load: it leaves window.plausible as a placeholder object until plausible.init() runs, so without the init the queued plausible('WP Search Queries', …) fails.

Reproduced with Hummingbird 3.21.2 (free), Asset Optimization on (default "speedy" mode), on 2.6.2:

  • it combines the tracker into a group with other scripts (/**handles:wpml-cookie,plausible-analytics**/) and copies our inline script to that group as well, so the stub, the init and the search event ran twice (and the search event was sent twice);
  • with other settings it serves its own minified copy of the (proxied) tracker from hummingbird-assets/, which goes stale when the plugin updates the local file.

The exact split in the user's page depends on their Hummingbird configuration and other plugins; in every case the fix is the same: keep Hummingbird away from our scripts, like we already do for WP Rocket, LiteSpeed, SG Optimizer, Autoptimize, W3TC and WP-Optimize.

Changes

  • wphb_dont_add_handle_to_collection: return our handles (plausible-*) to WordPress untouched. This is the filter Hummingbird itself uses to leave GTranslate's scripts alone.
  • wphb_delay_js_exclusions: exclude them from Delay JavaScript. Exclusions are matched (as regex) against each script tag including its inline code, so plausible covers our handles, URLs and inline code.
  • Tests for both; changelog entry under 2.6.3.

Testing

  • Test suite passes on PHP 7.4 and 8.3.
  • Live, logged out, on a search page with Hummingbird's Asset Optimization (and Delay JS) enabled: all plausible-* scripts keep their original URLs and attributes (tracker async), the inline script appears once, window.plausible is a function, and exactly 2 events are sent (pageview + search). Hummingbird keeps optimizing the site's other scripts.
  • Delay JavaScript only works with a WPMU DEV membership (Utils::is_member()), so that part is covered by the unit test only.

Summary by CodeRabbit

  • Bug Fixes
    • Improved compatibility with Hummingbird: Plausible scripts are excluded from asset optimization and delayed JavaScript, preventing a “plausible is not a function” error when those features are enabled.

Hummingbird's Asset Optimization combines the tracker with other scripts
and moves (or duplicates) the inline script that initializes it. That can
leave the inline plausible() calls, e.g. the search queries event, without
the plausible.init() call, so window.plausible is still the tracker's
placeholder object: "plausible is not a function". It also serves its own
copy of the (proxied) tracker, which goes stale when the plugin updates the
local file, and in our tests sent the search event twice.

Return our handles (plausible-*) to WordPress untouched through
wphb_dont_add_handle_to_collection, which Hummingbird itself uses to leave
GTranslate's scripts alone, and exclude them from Delay JavaScript through
wphb_delay_js_exclusions (matched against each script tag, including its
inline code).
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 6ffde48e-5dd2-4ebd-a900-cb3d3eaef51d

📥 Commits

Reviewing files that changed from the base of the PR and between 1d10b1a and 9870914.

📒 Files selected for processing (3)
  • readme.txt
  • src/Compatibility.php
  • tests/integration/CompatibilityTest.php

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The plugin registers Hummingbird filters to exclude Plausible scripts from Asset Optimization and Delay JavaScript. Integration tests cover the exclusions, and the 2.6.3 changelog notes the compatibility.

Changes

Hummingbird compatibility

Layer / File(s) Summary
Register Hummingbird script exclusions
src/Compatibility.php, tests/integration/CompatibilityTest.php, readme.txt
When Hummingbird is active, the compatibility class excludes Plausible scripts from Asset Optimization and adds plausible to Delay JavaScript exclusions. Integration tests cover these filters, and the 2.6.3 changelog records the compatibility.

Priority: ➖ Normal

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 98709

The change adds targeted Hummingbird compatibility while preserving existing exclusions. No actionable merge-blocking risk is identified; it is ready to merge subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 98709

The inspected callbacks make narrowly scoped compatibility changes without adding script sources or privileges. Risk is low, but Hummingbird’s downstream handling of the exclusions has not been verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The visible exposure is script processing on sites where Hummingbird is active. Asset matching covers any plausible-prefixed script handle, not a single tracker handle. The effective reach of the broader plausible delay pattern depends on Hummingbird’s unavailable matcher.

Trust Boundaries and Controls

  • observed — The plugin-side gate preserves unrelated asset decisions and existing delay exclusions. It bypasses the named optimization and delay processing, but available evidence does not establish that those mechanisms enforce a security or consent boundary.

Resilience and Maintainability Implications

  • inferred — The two registrations target independent hooks, and the callbacks do not implement reservations, durable writes, or a recovery protocol. No insecure partial terminal state was demonstrated. Consumer ordering, interrupted host processing, and persistent-worker cleanup remain outside the verified scope.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: excluding the plugin's scripts from Hummingbird optimizations.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 2 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@Dan0sz
Dan0sz merged commit 6df5f4e into develop Oct 1, 2026
7 checks passed
@Dan0sz
Dan0sz deleted the hummingbird_compatibility branch October 1, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant