Skip to content

v1.12.0 — Classic checkout lock

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 10 Sep 11:37
· 4 commits to main since this release

Added

  • Classic checkout lock. On a store whose checkout page renders the Block Checkout, the classic checkout's AJAX endpoints (wc-ajax=checkout, wc-ajax=update_order_review and their admin-ajax forms) are answered with HTTP 403 before any order is created or any gateway contacted. No customer of such a store sends those requests; card-testing toolkits that walk the legacy flow with one stolen card per fresh IP do. Engages only while the Block Checkout is detected, lets allowlisted IPs pass, counts refusals as refused:classic_checkout, and emails the alert recipients at most once an hour. Customer-facing text via the wcaf_classic_lock_message filter. On by default for new installs; existing installs are pinned off by the one-time option upgrade (schema version 2) and can turn it on under Detection Rules > Checkout Surface.
  • Refused Before Payment table on the Reports tab, built from the daily counters (pre-payment refusals by rule, REST hardening blocks, classic checkout lock).