{"id":377306,"date":"2026-10-06T17:53:49","date_gmt":"2026-10-06T17:53:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/coriunder-payment-gateway\/"},"modified":"2026-10-06T17:53:40","modified_gmt":"2026-10-06T17:53:40","slug":"coriunder-payment-gateway","status":"publish","type":"plugin","link":"https:\/\/jv.wordpress.org\/plugins\/coriunder-payment-gateway\/","author":23575745,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.3","stable_tag":"1.3.3","tested":"7.1.3","requires":"6.9","requires_php":"7.4","requires_plugins":null,"header_name":"Coriunder Payment Gateway","header_author":"Coriunder","header_description":"Coriunder Payment Gateway integration for WooCommerce","assets_banners_color":"","last_updated":"2026-10-06 17:53:40","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/coriunder.com\/","header_author_uri":"https:\/\/coriunder.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":57,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3.3":{"tag":"1.3.3","author":"coriunder","date":"2026-10-06 17:53:40","revision":3731330}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[3148,284762,6593,1887,286],"plugin_category":[45],"plugin_contributors":[284763],"plugin_business_model":[],"class_list":["post-377306","plugin","type-plugin","status-publish","hentry","plugin_tags-checkout","plugin_tags-hosted-payments","plugin_tags-payment-gateway","plugin_tags-payments","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-coriunderdev","plugin_committers-coriunder"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/coriunder-payment-gateway.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Coriunder Payment Gateway connects WooCommerce stores to the Coriunder hosted payment service. During checkout, customers are redirected to Coriunder to enter their payment details and are then returned to the store.<\/p>\n\n<p>The plugin supports classic checkout, Cart and Checkout Blocks, and High-Performance Order Storage (HPOS). A Coriunder merchant account, merchant ID, personal hash, and HTTPS-enabled store are required.<\/p>\n\n<h4>External service<\/h4>\n\n<p>This plugin connects to Coriunder's hosted payment service to process payments and verify transaction results. When a customer places an order using this gateway, the plugin sends the order number, amount, currency, payment description, customer name, billing address, postal code, city, country, email address, and phone number to the configured Coriunder hosted payment URL. The customer is redirected to that service to complete payment.<\/p>\n\n<p>The plugin also contacts <code>https:\/\/process.coriunder.cloud\/member\/getStatus.asp<\/code> after a payment response to verify the transaction before changing the WooCommerce order status. This request includes the merchant ID, order number, and a verification signature.<\/p>\n\n<p>Use of this gateway is subject to the agreement and privacy terms supplied with your Coriunder merchant account. More information about Coriunder is available at https:\/\/coriunder.com\/.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP through <strong>Plugins &gt; Add Plugin &gt; Upload Plugin<\/strong>, or copy the <code>coriunder-payment-gateway<\/code> directory to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>Coriunder Payment Gateway<\/strong> in WordPress.<\/li>\n<li>Go to <strong>WooCommerce &gt; Settings &gt; Payments &gt; Coriunder Gateway<\/strong>.<\/li>\n<li>Enter the merchant ID, personal hash, and hosted payment URL supplied by Coriunder.<\/li>\n<li>Choose the payment action and payment-page language, then enable and save the gateway.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20gateway%20support%203-d%20secure%3F\"><h3>Does the gateway support 3-D Secure?<\/h3><\/dt>\n<dd><p>3-D Secure availability depends on the configuration of your Coriunder merchant account. Contact Coriunder to enable or confirm this feature.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20card%20details%3F\"><h3>Does this plugin collect card details?<\/h3><\/dt>\n<dd><p>No. Customers enter their payment details on the Coriunder hosted payment page. The plugin sends the order and billing information described in the External service section.<\/p><\/dd>\n<dt id=\"which%20checkout%20types%20are%20supported%3F\"><h3>Which checkout types are supported?<\/h3><\/dt>\n<dd><p>The plugin supports the classic WooCommerce checkout and WooCommerce Cart and Checkout Blocks.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>Version 1.3.3 - 23092026<\/h4>\n\n<ul>\n<li>Compatibility - Verified against WordPress 7.1.2 and WooCommerce 11.1.2<\/li>\n<li>Compatibility - Plugin header and readme now agree on WC tested up to 11.1.2 (previously 11.1.0 \/ 11.0.1)<\/li>\n<\/ul>\n\n<h4>Version 1.3.2 - 26082026<\/h4>\n\n<ul>\n<li>Localization - Payment-page language selector labels now use language\/country codes only; native-language names removed<\/li>\n<li>Localization - Added WordPress translation catalogs for 15 languages using the coriunder-payment-gateway text domain<\/li>\n<li>Cleanup - Removed legacy Finateco\/GR8Pay translation files and obsolete text domains<\/li>\n<\/ul>\n\n<h4>Version 1.3.1 - 25082026<\/h4>\n\n<ul>\n<li>Security - Payment callbacks are verified against Coriunder transaction status before an order can be marked paid or failed<\/li>\n<li>Security - Callback verification now checks merchant, order, transaction, amount, currency and transaction type where available<\/li>\n<li>Security - Debug logs no longer write full payment URLs, customer PII or callback signatures<\/li>\n<li>Security - Base URL is restricted to a valid HTTPS URL<\/li>\n<li>Compatibility - HPOS order metadata now uses the WooCommerce order CRUD API<\/li>\n<li>Compatibility - Blocks checkout availability now respects the configured store currency<\/li>\n<li>Compatibility - Updated compatibility metadata for WordPress 7.1 \/ 7.0.4 and WooCommerce 11.0.1 \/ 10.9.4<\/li>\n<li>Fix - Authorization-only payments are kept on hold instead of being treated as captured payments<\/li>\n<li>Fix - Added direct-access guard and removed generic callback function names<\/li>\n<\/ul>\n\n<h4>Version 1.3.0 - 24082026<\/h4>\n\n<ul>\n<li>Feature - Gateway Logo: the logo shown on the settings screen and at checkout is now uploaded by the merchant through the WordPress media library. A \"Select image\" \/ \"Remove\" picker was added to the General section<\/li>\n<li>Change - No logo is bundled with the plugin any more. When no logo has been uploaded, the settings header and the checkout payment method render without an image instead of falling back to the built-in Coriunder logo<\/li>\n<li>Change - Removed the \"Test &amp; Debug\" sandbox settings: Enable Test Mode, Test Merchant ID, Test Personal Hash and Test Base URL are gone. The gateway always uses the Live Credentials<\/li>\n<li>Change - Removed the \"Test mode is active\" admin notice and the \"Test Mode Active\" badge from both the classic and Blocks checkout<\/li>\n<li>Change - Debug Logging kept, moved into its own \"Debug\" section<\/li>\n<li>Change - Blocks checkout availability and webhook signature verification now read the live Personal Hash directly; the sandbox branch was removed<\/li>\n<li>Note - Merchants upgrading from 1.2.x who were running in test mode must fill in the Live Credentials; previously saved test credentials are no longer used<\/li>\n<\/ul>\n\n<h4>Version 1.2.1 - 16042026<\/h4>\n\n<ul>\n<li>Fix - Plugin header updated: WC tested up to 10.7.0, Requires WordPress 6.8+, Requires PHP 7.4+<\/li>\n<li>Fix - validate_fields(): billing_phone is now sanitized with sanitize_text_field() before use<\/li>\n<li>Fix - validate_fields(): error notice strings wrapped in esc_html__() for translatability<\/li>\n<li>Fix - process_payment(): replaced $woocommerce-&gt;cart-&gt;empty_cart() with WC()-&gt;cart-&gt;empty_cart()<\/li>\n<li>Fix - Orders no longer stuck in pending after payment: reply code and order status are now resolved on the thank-you page via the woocommerce_thankyou_coriunder hook, which reads Coriunder's redirect params (replyCode, trans_id, trans_refNum) and calls payment_complete() immediately when the customer returns<\/li>\n<li>Fix - Signature verification corrected for both the redirect and webhook: Coriunder sends raw base64 (not URL-encoded), and the redirect uses SHA256(reply_code . trans_id . personal_hash)<\/li>\n<\/ul>\n\n<h4>Version 1.2.0 - 09042026<\/h4>\n\n<ul>\n<li>Improvement - Blocks checkout: logo in label row enlarged (28px height) for better visibility<\/li>\n<li>Improvement - Blocks checkout: payment method title is now bold<\/li>\n<li>Improvement - Blocks checkout: removed duplicate logo from the description row<\/li>\n<li>Improvement - Blocks checkout: reduced spacing between title and description<\/li>\n<\/ul>\n\n<h4>Version 1.1.9 - 09042026<\/h4>\n\n<ul>\n<li>Improvement - Classic checkout: logo shown inside the payment box with styled description area<\/li>\n<li>Improvement - Classic checkout: light blue hover (#eef3fb) on the payment method label row<\/li>\n<li>Improvement - Classic checkout: focus-visible ring on keyboard navigation to the radio button<\/li>\n<li>Improvement - Blocks checkout: logo displayed inline beside the payment method title in the label<\/li>\n<li>Improvement - Blocks checkout: styled content area (logo + description + test badge) when selected<\/li>\n<li>Improvement - Blocks checkout: hover highlight on the option row via :has() selector<\/li>\n<li>Improvement - Test mode badge shown in checkout description for both classic and blocks checkout<\/li>\n<li>Improvement - Frontend CSS enqueued via wp_enqueue_scripts only on checkout pages (no impact elsewhere)<\/li>\n<\/ul>\n\n<h4>Version 1.1.8 - 09042026<\/h4>\n\n<ul>\n<li>Improvement - Replaced settings page with responsive card-based UI (grouped into General, Live Credentials, Test &amp; Debug sections)<\/li>\n<li>Improvement - Replaced native checkboxes with accessible toggle switches (WCAG 2.1 AA compliant focus management)<\/li>\n<li>Improvement - All form controls now have explicit labels, aria-describedby help text, and visible focus rings<\/li>\n<li>Improvement - Settings sections use semantic HTML (section + aria-labelledby, role attributes)<\/li>\n<li>Improvement - Hash fields use type=\"password\" and autocomplete=\"new-password\" to prevent credential exposure<\/li>\n<li>Improvement - Test-mode banner shown inline on settings page when sandbox is active<\/li>\n<li>Improvement - Two-column responsive grid collapses to single column on mobile (\u2264782px)<\/li>\n<\/ul>\n\n<h4>Version 1.1.7 - 09042026<\/h4>\n\n<ul>\n<li>Security - Added webhook signature verification to prevent forged payment confirmations<\/li>\n<li>Security - Added input sanitization for all webhook parameters (trans_order, trans_id, reply_code, reply_desc)<\/li>\n<li>Security - Fixed stored XSS vulnerability in admin order view (utm_source output now escaped)<\/li>\n<li>Security - Fixed esc_html__() misuse with dynamic strings in order notes<\/li>\n<li>Security - Debug logging in webhook handler is now gated on the debug setting<\/li>\n<li>Security - Removed deprecated webhook() method that used unsanitized $_REQUEST data<\/li>\n<li>Improvement - Added \"Settings\" action link on the Plugins page<\/li>\n<\/ul>\n\n<h4>Version 0.9.0.0 - 25042014<\/h4>\n\n<ul>\n<li>Feature - Initial release<\/li>\n<\/ul>\n\n<h4>Version 0.9.0.5 - 04022016<\/h4>\n\n<ul>\n<li>Feature - small updates<\/li>\n<\/ul>","raw_excerpt":"Accept WooCommerce payments through the Coriunder hosted payment page.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/377306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=377306"}],"author":[{"embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/coriunder"}],"wp:attachment":[{"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=377306"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=377306"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=377306"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=377306"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=377306"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/jv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=377306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}