Releases: wcpos/woocommerce-pos
Release list
Release v1.9.17
What's Changed
- Smaller plugin package — the download is around 2.4 MB smaller (optimized template gallery images, removed unused bundled files). This also shrinks the Pro package and resolves installation failures on hosts with restrictive upload or disk limits. (#1538)
- Fixed Pro update downloads using a stale licence key — changing or re-activating a WCPOS Pro licence now clears WordPress's cached update information, so the next update download always uses the current licence key. (#1444, #1480)
- Fixed duplicate cashier identity on multisite — on multisite networks a cashier could be assigned two different internal IDs depending on which endpoint served them, splitting one user into two identities in the POS. All endpoints now serve a single ID per user. (#1465)
- Hardened the orders API against malformed metadata — a malformed metadata entry in a batch create/update could cause a server error partway through the batch, risking duplicate orders on retry. Malformed entries are now safely skipped and invalid IDs rejected up front. (#1473)
- POS audit metadata is now server-authoritative — order metadata recording which cashier and store created an order is now stamped by the server and can no longer be altered by the client. Cash amounts are also validated more strictly. (#1464)
- Internal cloud print improvements — consolidated printer-provider handling; the server now reports which template engines each print provider supports. (#1463)
Full Changelog: v1.9.16...v1.9.17
Release v1.9.16
Bug fix
Fixed stale price ranges on variable products. The POS product grid could show an outdated price or price range for a variable product even after variation prices changed — and clearing local data did not help — because the freshly recomputed range was discarded in favour of an old stored value when building the server response. Responses now always serve the current values, so the displayed range matches the live variation prices. The price charged at checkout was always correct; this fixes what the grid displays. Server-side fix — no app update needed.
Full changelog: https://github.com/wcpos/woocommerce-pos/blob/v1.9.16/readme.txt
Release v1.9.15
Security patch
Custom thermal receipt templates can no longer run PHP. A user with POS management access (eg: a shop manager) could embed PHP in a custom thermal receipt template and have it execute when a receipt was rendered, because the thermal engine fell through to the legacy PHP renderer. Thermal templates now render exclusively through the safe Mustache/XML pipeline, which discards embedded PHP; malformed markup fails closed. If you use custom receipt templates, please update.
More reliable thermal receipt rendering. Thermal render failures are now logged so a broken template is diagnosable, and browser-printed HTML receipts are constrained to the configured paper width so wide rows no longer overflow the roll.
Full changelog: https://github.com/wcpos/woocommerce-pos/blob/v1.9.15/readme.txt
Release v1.9.14
Fixed
- Receipt timestamps now respect your WordPress time format. Receipts could force 12-hour AM/PM times even when your site is set to a 24-hour clock. The receipt date formatter now follows the time format configured under Settings → General, while the store locale continues to control the date language.
- Hardened cloud-print job handling. Bulk-cancelling print jobs now verifies it is acting on actual print jobs (a POS-level user could previously trigger status changes on unrelated posts), and cancelling is refused for jobs that are not waiting — so a failed job keeps its payload and stays retryable. Also adds regression coverage proving receipt text cannot inject printer control bytes into thermal output (a protection already shipped in earlier releases).
Changed
- PHP 8.4+ build hardening. The bundled PDF engine now calls PHP 8.4's new functions directly instead of relying on runtime compatibility shims. Installs that loaded the shims were already protected, but a bootstrap that missed them (e.g. a partial plugin update) could fatal when rendering PDF receipts — that failure class is now gone entirely. The same issue broke PDF receipts on WCPOS Pro on PHP 8.4+, fixed separately in Pro 1.9.14.
- Updated translations.
Release v1.9.13
Fixed
- Garbled prints on Star CloudPRNT printers. After 1.9.12, receipts sent to Star CloudPRNT printers (the TSP100 line) could print the plain text lines followed by a metre of garbage characters, because cashier-initiated prints were still rendered as ESC/POS — which no Star CloudPRNT printer can decode. WCPOS now serves these printers native StarPRNT for cashier prints too, and automatically corrects the stored printer language on existing installs on the next settings sync (no reconfiguration needed). Other cloud printers are unaffected.
This is the print-path follow-up to 1.9.12's TSP100 StarPRNT fix.
Release v1.9.12
Patch release fixing Cloud Print on Star TSP100 printers and making customer receipt downloads opt-in.
- Fixed cloud printing to Star TSP100 printers — StarPRNT-native Star printers (the TSP100/TSP100IV line) rejected Cloud Print jobs with a "510 Incompatible Media Type" error and never printed, because WCPOS sent them ESC/POS. WCPOS now serves these printers native StarPRNT, so Cloud Print works on the whole TSP100 family. Other cloud printers are unaffected.
- Customer receipt downloads are now opt-in — the Receipt button on My Account → Orders (added in 1.9.11) is now off by default and turned on under Settings → General → Customers, with an optional picker to choose which template customers get. Stores that want it must enable it; the
[wcpos_receipt]shortcode is unaffected. - Fixed the Cloud Print printer name being squeezed — a long or translated status label (eg: French "En attente de l'imprimante") no longer shrinks the editable printer-name field to a few characters; the status now sits on its own row.
- Fixed receipt template selection for downloaded receipts — gallery templates now resolve correctly for customer receipt links, and the storefront receipt uses the template you selected.
- Updated translations.
Release v1.9.11
🛠️ Changelog
✨ New Features
- WCPOS Cloud Print relay — if your hosting or firewall blocks a cloud printer's direct connection (a permanent "Waiting for printer"), WCPOS now routes Star CloudPRNT and Epson Server Direct Print polling through the WCPOS Cloud Print relay automatically, and print jobs start on the printer's next poll instead of waiting for the next heartbeat. Printer cards tell you when a security layer is blocking cloud print. When the relay is used, print jobs (receipt contents) pass through
cloudprint.wcpos.com— see the privacy FAQ. Site owners can opt out in code. - Cloud Print queue — the Cloud Print settings screen now shows a live queue of your print jobs and their status, so you can see what has printed, retry a failed job, and clear the backlog. Completed job payloads are stripped and old jobs are purged automatically.
- Receipts on your online store — customers can download their order receipt as a PDF, rendered with your WCPOS receipt template, from a new Receipt button on My Account → Orders. A
[wcpos_receipt]shortcode is also available for the order-received or custom pages.
🐞 Bug Fixes
- Cloud printers that mangle the poll URL — printer credentials now travel in the URL path, so printer firmware that URL-encodes the query string (eg: Star TSP100IV) can authenticate. Existing configured printer URLs keep working.
- WCPOS Pro license image — the Pro panel now loads its image correctly.
🧰 Maintenance
- Updated translations (
2026.7.6); CI merge-gate hardening and dev-dependency housekeeping.
Release v1.9.10
🛠️ Changelog
🐞 Bug Fixes
- Stale prices on products converted from simple to variable — variable products now show the lowest price of their current visible variations in the POS, instead of a leftover price left behind by the conversion.
- Fatal error in the receipt template editor on translated stores — receipt previews no longer crash when a translated label contains a literal percent sign (reported on Czech stores).
- Cloud printer polling — Star CloudPRNT and Epson Server Direct Print polling URLs now include the marker WCPOS requires, so the URL you copy from the settings screen works as-is. Star results in the
2xxfamily (eg:211 Paper Low) now count as printed rather than failed, and polling problems are recorded in the WCPOS logs with enough detail to act on. - Missing POS favicon — POS browser tabs and home-screen shortcuts show the WCPOS icon again.
✨ Improvements
- Refresh button on the Extensions screen — re-check the extensions catalogue on demand instead of waiting for the hourly cache to expire.
🧰 Maintenance
- Updated translations (
2026.7.2); dev-dependency and CI housekeeping.
Release v1.9.9
🛠️ Changelog
🔒 Security
- Hardened receipt/report template file resolution — the templates REST endpoint now validates the requested template
typeand confirms that resolved template files stay inside the plugin's trusted template directories, closing a path-traversal issue. All stores should update.
🐞 Bug Fixes
- POS checkout, receipt and login URLs now follow your site's permalink trailing-slash style, so rewrite rules that force a trailing slash no longer redirect these links to an
httptarget and get blocked as mixed content.
🧰 Maintenance
- Updated translations; CI / test-matrix housekeeping.
Stores updating from 1.9.7 also receive the 1.9.8 changes in this release (checkout/receipt/login links respect the Force SSL setting; Force SSL toggle restored under Advanced settings).
Release v1.9.7
Receipts can now show savings
Receipt templates can display regular prices, per-line savings and a Total Saved line (Receipt Data v1.1). Right-to-left (RTL) previews render savings totals correctly with localized labels.
Other changes
- Better black & white printing — gallery receipt templates now print safely on B&W receipt printers, while PDF receipts keep their colours.
- Resizable template editor panel — drag to resize the fields panel in the receipt template editor.
- Improved welcome-screen analytics — consented admin landing payloads now include hostname-only site and admin domains, so WCPOS can understand where opted-in stores come from without sending full URLs or paths.
- Fixes — order version stamping now only happens when the POS creates an order; safer file-permission fallback when WCPOS writes files.
- Updated translations.