The Order Confirmation preview now reflects a customized includes/classes/order.php.
If your store has changed how order.php builds the confirmation email — for example a wholesale store that leads each line with the product's model/SKU — the preview renders the product and totals rows from your store's own order.php, so what you see matches what your customers receive. A store running stock Zen Cart is unaffected: it uses the stock-faithful rendering, and nothing is evaluated.
How it works: the preview reads your store's own order.php and, when its product-line markup differs from stock, evaluates that file's own line-building expressions against a recent order. It only ever evaluates a string-concatenation expression taken from your own, already-trusted order.php (never any request input), and falls back to the stock rendering on anything unexpected.
Install / upgrade: upload zc_plugins/PreviewEmail/v3.0.3/ and upgrade in place through Modules > Plugin Manager.
Raised by Scott C. Wilson.