PayPlus Payment Gateway
PayPlus Payment Gateway for WooCommerce Accept debit and credit cards on your WooCommerce store in a secure way with the ability to design your own payment page and add high functionalities to it. SSL is not required. Supported PHP Versions: This plugin is compatible with PHP versions from 7.4 up to 8.3. Before installation: You need your account credentials. For that, you have to contact PayPlus and to join the service. Plugin Disclaimer: PayPlus does not accept liability for any damage, loss, cost (including legal costs), expenses, indirect losses or consequential damage of any kind which may be suffered or incurred by the user from the use of this service. It is important to know that this plugin relies on third-party services. However, the third-party so mentioned is the PayPlus core engine at their servers – the providers of this plugin. By being a payment processor, just like many of its kind, it must send some transaction details to the third-party server (itself) for token generation and transaction logging statistics and connecting to invoices. It is this transfer back and forth of data between your WooCommerce and the PayPlus servers that we would like to bring to your attention clearly and plainly. The main links to PayPlus, its terms and conditions, and privacy policy are as listed: – Home Page: https://www.payplus.co.il – Plugin Instruction page: https://www.payplus.co.il/wordpress – Terms and Conditions: https://www.payplus.co.il/privacy The above records, the transaction details, are not treated as belonging to PayPlus and are never used for any other purposes. The external files referenced by this plugin, due to WordPress policy recommendations, are all included in the plugin directory. 8.2.4 – 10-08-2026 Feature – New “Open payment page in website language” option: when enabled, the payment page uses the storefront language; when disabled, previous locale behavior is unchanged. Fix – Blocks: payment method initialize no longer boots all WooCommerce gateways on every page; payment method icons restored. Fix – Blocks checkout: payment payload is built once for the selected method instead of once per registered PayPlus method. Fix – Classic checkout: Place Order button no longer flickers when switching methods unless J5 Weight Estimate refresh is required. Fix – Callback/IPN: more reliable order status updates when multiple success responses arrive for the same payment. Tweak – Ensure WooCommerce is active before loading PayPlus payment gateways. 8.2.3 – 08-07-2026 Feature – New “Show loader during iframe payment & redirect” option: displays a processing spinner over the iframe when payment is submitted, then a full-screen redirect loader when order completes. Fix – Classic checkout: reopening an iframe popup/same-page payment after closing without paying no longer falls back to redirect mode (duplicate payment page fix now correctly returns the cached link for inline modes). Fix – Blocks checkout: processing loader, if activated, no longer appears immediately when the iframe opens; it now correctly waits for the user’s payment submission. Fix – Cron: payment_complete() now fires while the order is still pending (matching regular callback behavior), ensuring the “Payment complete” order note is recorded. 8.2.2 – 24-06-2026 Security – Hosted payment and order completion AJAX handlers now verify order ownership before acting. Prevents unauthenticated metadata tampering and order-key disclosure. (Reported by Pedro Pinho and kevin @OPCIA via WPScan/Automattic) Fix – Checkout: “Place Order” button no longer flickers when switching payment methods. Fix – Cron: when “Payment Completed” is enabled, cron-recovered orders now correctly fire the woocommerce_payment_complete hook. 8.2.1 – 10-06-2026 Fix – Payment page: prevented duplicate payment page creation per order by saving the meta fields the existing duplicate-prevention guard relies on. Eliminates duplicate PRUID entries. 8.2.0 – 07-06-2026 Fix – Cron: when “Exclude manually cancelled orders from cron” checkbox is enabled, orders cancelled by an admin or shop manager are now excluded from cron instead of deleting payment data. Fix – Cron: order status change hook registers only once, preventing duplicate order notes. Works for admins and shop managers via admin, AJAX, or REST. Fix – Cron: minimum order age reduced to 10 minutes for faster processing. Tweak – Settings: cancel checkbox relabeled to “Exclude manually cancelled orders from cron”. 8.1.9 – 03-06-2026 Fix – Blocks checkout: validation errors no longer show a persistent PayPlus error popup; WooCommerce native inline notices are used instead. Fix – Blocks checkout: corrected set_payment_details calls to pass arrays instead of strings, preventing PHP foreach warnings. Fix – Hosted Fields: card number field now shows a green checkmark when card brand is detected. Fix – Hosted Fields: lock and CVV icons now use inline data URIs, eliminating CORS errors on local/dev environments. Fix – SEO: noindex meta tag for error page no longer incorrectly applied to other pages. 8.1.8 – 19-05-2026 Feature – Invoice+ Documents: Added POS EMV to the “Do not create documents” exclusion list. Fix – Invoice+ Documents: POS EMV exclusion now works correctly (POS EMV orders are detected via transaction meta). Fix – Invoice+ Documents: Payment method detection now uses alternative_method_name (bit, apple-pay, google-pay) when available. Fix – Invoice+ Documents: Payment query is now HPOS-compatible (queries correct meta table on High-Performance Order Storage sites) – Fix for docs that came out as other instead of payment app. Fix – Payment meta is now fully stored before order save, preventing race conditions with automatic invoice creation hooks. 8.1.7 – 05-05-2026 Fix – Resolved WC_Order_Item_Coupon::offsetGet deprecation notice (since WooCommerce 4.4.0) when coupons are applied at checkout. Feature – Refund fee: Option to automatic 5% or 100 NIS (whichever is lower) refund fee for PayPlus refunds. Feature – POS Only Mode option for dedicated POS terminal setups. Fix – Hide PayPlus Gateway checkbox now works reliably for all checkout types (Classic and Blocks), regardless of Hosted Fields or EMV configuration. Fix – Hosted Fields: resolved duplicate rendering issues on Blocks checkout. Fix – Subscriptions: token now correctly retrieved from subscription or parent order (ON ALL CASES). Fix – Blocks checkout: payment errors now display correctly to frontend users. Fix – Cron job no longer fires at order creation, only at scheduled intervals. Tweak – Optimized user_has_cap filter: now registers only once and only in admin, eliminating ~200ms overhead on every frontend request. 8.1.6 – 18-03-2026 Fix – PayPlus payment gateway now displays correctly in the WooCommerce Blocks checkout page editor (resolved “payment methods not supported” message). Feature – Blocks checkout: closing a payment page (iframe/popup) or re-selecting a payment method no longer requires a full page reload. Fix – Blocks checkout: PayPlus Embedded (hosted fields) no longer requires a full page reload on payment failure or when coupons/gift cards change. Fix – Order status polling now stops correctly when a payment page is closed or the cart total changes (both Classic and Blocks checkout). Feature – J5 Weight Estimate: added a configurable percentage-based cart fee (5%–20%) for Authorization (J5) mode, visible only when a PayPlus gateway is selected. Feature – J5 Weight Estimate: customizable fee name and optional description message displayed below the fee line. Feature – New option to prevent double rendering of the payment page iframe on the receipt page (common with Elementor or other page builders). Tweak – Removed TV power-down effect feature. 8.1.5 – 15-03-2026 Feature – Added VAT selection prompt for partial refunds, allowing admins to choose whether the refunded amount includes VAT or is VAT-exempt. Fix – Resolved an issue where saved payment tokens could override the PayPlus Embedded selection, causing the checkout to revert to a previously saved card instead of using newly entered card details. Fix – Fixed token saving failure when the optional “Name for Invoice” or “Alternative ID/VAT” fields were filled during PayPlus Embedded checkout. Feature – PRUID history tracking: all payment page request UIDs are now stored with timestamps, enabling recovery of orders where the UID changed. The “Get PayPlus Data” button shows a selection popup with a “Try All” option. Feature – Optional order total display inside PayPlus Embedded payment form for both Classic and Blocks checkout, with automatic updates on coupon/shipping changes. Tweak – Reduced checkout order-status polling frequency to prevent excessive server load on slower sites. Fix – Fixed Hebrew character corruption (appearing as raw Unicode escapes) in PayPlus API payloads for certain server configurations. Tweak – PRUID history is now used by the cron job and the Orders Validator for more reliable order status recovery. Fix – Fixed expiry field order in PayPlus Embedded for LTR locales. Fix – The “Include Apple Pay Script” setting now correctly loads the Apple Pay script on Blocks checkout for all iframe display modes. 8.1.4 – 10-03-2026 Fix – Fixed an issue where redirect URLs after payment could be malformed (& converted to &), potentially causing broken thank-you page loads or missing order details. See changelog for all versions.
Top keywords
- payment41×2.86%
- fix39×2.72%
- payplus24×1.68%
- order22×1.54%
- now21×1.47%
- checkout20×1.40%
- page20×1.40%
- blocks14×0.98%
- blocks checkout12×0.84%
- cron10×0.70%
- longer10×0.70%
- payment page10×0.70%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!