Repository navigation
Releases: didit-protocol/plugin-wordpress
Release list
Didit Verify 0.3.4
Security update for protected content: a revocation now takes effect even when the customer has started another verification attempt.
Previously received revocations also take effect after upgrading, and obsolete sessions cannot replace a newer approval.
Validated with 102 PHP assertions, green CI on PHP 7.4 and 8.4, and a WordPress 7.1.2 HTTP verification and upgrade test using synthetic upstream responses.
The Didit branding and merchant configuration are unchanged.
Didit Verify 0.3.3
Didit branding and grouped settings in the actual WordPress admin. Readable verification badges on Users and WooCommerce order details, with direct links to user results, Didit Console and documentation.
Includes the server-confirmed approval protections from 0.3.2.
Validated with all 84 PHP checks, PHP 7.4/8.4 CI, settings-save verification, and real WordPress/WooCommerce screens using synthetic fixture data.
Didit Verify 0.3.2
This update requires a server-confirmed Didit decision and the session binding created by the site before granting protected content or WooCommerce checkout access.
It also fixes verification assets on embedded checkout-block pages and adds clear confirmation, review and retry states.
Use API Session mode for protected content and checkout.
Users verified with 0.3.1 or earlier must verify again after the upgrade.
UniLink mode remains available for manual verification flows.
Validated with PHP 7.4 and 8.4 CI, 84 automated PHP checks, a fresh ZIP installation on WordPress 7.1.2 / WooCommerce 11.1.2, and synthetic end-to-end checks for classic checkout, block checkout and guest post-purchase webhooks.
v0.3.1
- Page builders that render shortcode content outside the post content (for example Oxygen) no longer show an unstyled verification button or embedded container. The plugin stylesheet and the button appearance CSS are now always queued in the header, while the SDK script is still enqueued when the shortcode itself renders.
- Webhook receiver now verifies
X-Signature-V2first, falls back to the legacyX-Signature, and finally toX-Signature-Simple. A delivery is accepted as soon as one variant verifies, so a reverse proxy, CDN rule or security plugin that strips a singleX-*header no longer causes a 401 "Missing or stale webhook signature". - Middleware that re-encodes the request body (Unicode escaping, slash escaping, key reordering) no longer breaks verification:
X-Signature-V2is computed over the canonical JSON form rather than the raw bytes. - Freshness is now checked against the signed
timestampinside the payload, which also rejects a replayed delivery re-sent with a refreshedX-Timestampheader. - When only
X-Signature-Simpleverifies, the payload is authenticated forsession_id,statusandwebhook_typeonly, so the user is resolved from the session mapping this site stored itself instead of the unsignedmetadata.wp_user_id/vendor_datafields. - Enabling Debug Logging now records which signature headers arrived when a webhook is rejected.
v0.3.0
- Customizable WooCommerce copy: new settings for the verification section title, checkout message, and post-purchase message (GitHub issue #2).
- Translation support: load the plugin text domain from
languages/, POT file included, and German translations (de_DEinformal,de_DE_formalformal) for all customer-facing text (GitHub issue #2). - Frontend JavaScript strings ("Creating session…", "Verification In Review", error messages) are now translatable.
- Product scope for WooCommerce verification: require verification for all products, only selected products, or all products except selected (GitHub issue #3).
- New "Didit verification" checkbox on the product edit page (Product data → Advanced) to select products for the include/exclude scope.
- Product scope is enforced in classic checkout, block checkout, and after-purchase mode (confirmation box, emails, reminders, order hold).
- Button text and success text settings now fall back to translatable defaults when left empty.
v0.2.0
After-purchase WooCommerce verification mode: keep checkout low-barrier and verify on the order confirmation page, My Account order view, and order emails (issue #1). Guest verification via order key. Webhook receiver (HMAC-SHA256 + timestamp) so results land even if the browser is closed. Optional hold-until-approved and capped reminder emails (Action Scheduler). Sessions built server-side from order billing and reused. Verification status shown in the admin order screen. Update Didit Web SDK to 0.2.1.
v0.1.4
Match verification status handling like in woocommerce. Differentiate Approved, Declined, and In Review states in button, content gate, status shortcode, and admin users list. Use Didit design system colors for status indicators.^
v0.1.3
- Update Didit Web SDK to version 0.1.8
- Improved support for Woocommerce block based checkout on new versions
v0.1.2
- Update Didit Web SDK to version 0.1.6
- Document bundled SDK source code repository, license, and build instructions in readme
- Move admin inline scripts to enqueued JavaScript file
- Fix contributors username
v0.1.1
- Bundle SDK JavaScript locally (no more external CDN)
- Add third-party service disclosure (Didit Terms & Privacy Policy)
- Add all 49 supported languages
- Fix Plugin Check (PCP) compliance
- Fix Plugin URI for WordPress.org submission
Install: Download didit-verify.zip, then in WordPress go to Plugins → Add New → Upload Plugin.