Coriunder Payment Gateway

Opis

Coriunder Payment Gateway connects WooCommerce stores to the Coriunder hosted payment service. During checkout, customers are redirected to Coriunder to enter their payment details and are then returned to the store.

The plugin supports classic checkout, Cart and Checkout Blocks, and High-Performance Order Storage (HPOS). A Coriunder merchant account, merchant ID, personal hash, and HTTPS-enabled store are required.

Full setup documentation: https://devcenter.coriunder.cloud/website/Extensions-WooCommerce.aspx

External services

This plugin relies on Coriunder, a third-party payment service provided by Coriunder Limited. It is required to take payments: without it the plugin does nothing. The plugin connects to two Coriunder services.

1. Coriunder hosted payment page (default https://uiservices.coriunder.cloud/hosted/default.aspx; the URL is configurable in the gateway settings)

  • What it is for: the customer enters their payment details on this page instead of on your store, and the payment is processed there.
  • When: each time a customer places an order and chooses Coriunder as the payment method. The customer’s browser is redirected to the page.
  • What is sent: your merchant ID, the order number, amount and currency, the payment type (capture or authorization), the payment description, the payment-page language, the order’s UTM source (if one was recorded at checkout), the return and notification URLs of your store, and the customer’s name, email address, phone number, billing address, postal code, city and country, together with a signature of these values.

2. Coriunder transaction status service (https://process.coriunder.cloud/member/getStatus.asp)

  • What it is for: confirming that a payment really happened, with the right amount and currency, before the WooCommerce order is marked as paid or failed.
  • When: each time Coriunder returns the customer to your store or sends a payment notification to your store.
  • What is sent: your merchant ID, the order number and a signature. No customer data is sent.

Coriunder’s terms and privacy policy:

  • Terms and Conditions: https://www.coriunder.com/Terms.html
  • Privacy Policy: https://www.coriunder.com/Privacy.html

Instalacija

  1. Upload the plugin ZIP through Plugins > Add Plugin > Upload Plugin, or copy the coriunder-payment-gateway directory to /wp-content/plugins/.
  2. Activate Coriunder Payment Gateway in WordPress.
  3. Go to WooCommerce > Settings > Payments > Coriunder Gateway.
  4. Enter the merchant ID, personal hash, and hosted payment URL supplied by Coriunder.
  5. Choose the payment action and payment-page language, then enable and save the gateway.

Pitanja i odgovori

Does the gateway support 3-D Secure?

3-D Secure availability depends on the configuration of your Coriunder merchant account. Contact Coriunder to enable or confirm this feature.

Does this plugin collect card details?

No. Customers enter their payment details on the Coriunder hosted payment page. The plugin sends the order and billing information described in the External services section.

Which checkout types are supported?

The plugin supports the classic WooCommerce checkout and WooCommerce Cart and Checkout Blocks.

How do I refund an order?

Refunds are issued from your Coriunder merchant dashboard. After refunding the transaction there, open the order in WooCommerce, click Refund, enter the amount and choose Refund manually to record it on the order (and restock items if needed).

Recenzije

Nema recenzija za ovaj dodatak.

Suradnici i Programeri

“Coriunder Payment Gateway” je softver otvorenog koda. Sljedeće osobe su doprinijele ovom dodatku.

Suradnici

Dnevnik promjena

Version 1.3.4 – 07102026

  • Localization – WordPress.org package no longer bundles .po/.mo files; translations are delivered from translate.wordpress.org
  • Localization – Translation template (.pot) updated with all 85 translatable strings
  • Compatibility – Settings-screen styles and scripts moved to enqueued assets; Google Fonts request removed
  • Security – Checkout handlers verify the WooCommerce checkout nonce; admin warnings limited to the Coriunder settings screen
  • Readme – External services section added

Version 1.3.3 – 23092026

  • Compatibility – Verified against WordPress 7.1.2 and WooCommerce 11.1.2
  • Compatibility – Plugin header and readme now agree on WC tested up to 11.1.2 (previously 11.1.0 / 11.0.1)

Version 1.3.2 – 26082026

  • Localization – Payment-page language selector labels now use language/country codes only; native-language names removed
  • Localization – Added WordPress translation catalogs for 15 languages using the coriunder-payment-gateway text domain
  • Cleanup – Removed legacy Finateco/GR8Pay translation files and obsolete text domains

Version 1.3.1 – 25082026

  • Security – Payment callbacks are verified against Coriunder transaction status before an order can be marked paid or failed
  • Security – Callback verification now checks merchant, order, transaction, amount, currency and transaction type where available
  • Security – Debug logs no longer write full payment URLs, customer PII or callback signatures
  • Security – Base URL is restricted to a valid HTTPS URL
  • Compatibility – HPOS order metadata now uses the WooCommerce order CRUD API
  • Compatibility – Blocks checkout availability now respects the configured store currency
  • Compatibility – Updated compatibility metadata for WordPress 7.1 / 7.0.4 and WooCommerce 11.0.1 / 10.9.4
  • Fix – Authorization-only payments are kept on hold instead of being treated as captured payments
  • Fix – Added direct-access guard and removed generic callback function names

Version 1.3.0 – 24082026

  • Feature – Gateway Logo: the logo shown on the settings screen and at checkout is now uploaded by the merchant through the WordPress media library. A “Select image” / “Remove” picker was added to the General section
  • Change – No logo is bundled with the plugin any more. When no logo has been uploaded, the settings header and the checkout payment method render without an image instead of falling back to the built-in Coriunder logo
  • Change – Removed the “Test & Debug” sandbox settings: Enable Test Mode, Test Merchant ID, Test Personal Hash and Test Base URL are gone. The gateway always uses the Live Credentials
  • Change – Removed the “Test mode is active” admin notice and the “Test Mode Active” badge from both the classic and Blocks checkout
  • Change – Debug Logging kept, moved into its own “Debug” section
  • Change – Blocks checkout availability and webhook signature verification now read the live Personal Hash directly; the sandbox branch was removed
  • Note – Merchants upgrading from 1.2.x who were running in test mode must fill in the Live Credentials; previously saved test credentials are no longer used

Version 1.2.1 – 16042026

  • Fix – Plugin header updated: WC tested up to 10.7.0, Requires WordPress 6.8+, Requires PHP 7.4+
  • Fix – validate_fields(): billing_phone is now sanitized with sanitize_text_field() before use
  • Fix – validate_fields(): error notice strings wrapped in esc_html__() for translatability
  • Fix – process_payment(): replaced $woocommerce->cart->empty_cart() with WC()->cart->empty_cart()
  • Fix – Orders no longer stuck in pending after payment: reply code and order status are now resolved on the thank-you page via the woocommerce_thankyou_coriunder hook, which reads Coriunder’s redirect params (replyCode, trans_id, trans_refNum) and calls payment_complete() immediately when the customer returns
  • Fix – Signature verification corrected for both the redirect and webhook: Coriunder sends raw base64 (not URL-encoded), and the redirect uses SHA256(reply_code . trans_id . personal_hash)

Version 1.2.0 – 09042026

  • Improvement – Blocks checkout: logo in label row enlarged (28px height) for better visibility
  • Improvement – Blocks checkout: payment method title is now bold
  • Improvement – Blocks checkout: removed duplicate logo from the description row
  • Improvement – Blocks checkout: reduced spacing between title and description

Version 1.1.9 – 09042026

  • Improvement – Classic checkout: logo shown inside the payment box with styled description area
  • Improvement – Classic checkout: light blue hover (#eef3fb) on the payment method label row
  • Improvement – Classic checkout: focus-visible ring on keyboard navigation to the radio button
  • Improvement – Blocks checkout: logo displayed inline beside the payment method title in the label
  • Improvement – Blocks checkout: styled content area (logo + description + test badge) when selected
  • Improvement – Blocks checkout: hover highlight on the option row via :has() selector
  • Improvement – Test mode badge shown in checkout description for both classic and blocks checkout
  • Improvement – Frontend CSS enqueued via wp_enqueue_scripts only on checkout pages (no impact elsewhere)

Version 1.1.8 – 09042026

  • Improvement – Replaced settings page with responsive card-based UI (grouped into General, Live Credentials, Test & Debug sections)
  • Improvement – Replaced native checkboxes with accessible toggle switches (WCAG 2.1 AA compliant focus management)
  • Improvement – All form controls now have explicit labels, aria-describedby help text, and visible focus rings
  • Improvement – Settings sections use semantic HTML (section + aria-labelledby, role attributes)
  • Improvement – Hash fields use type=”password” and autocomplete=”new-password” to prevent credential exposure
  • Improvement – Test-mode banner shown inline on settings page when sandbox is active
  • Improvement – Two-column responsive grid collapses to single column on mobile (≤782px)

Version 1.1.7 – 09042026

  • Security – Added webhook signature verification to prevent forged payment confirmations
  • Security – Added input sanitization for all webhook parameters (trans_order, trans_id, reply_code, reply_desc)
  • Security – Fixed stored XSS vulnerability in admin order view (utm_source output now escaped)
  • Security – Fixed esc_html__() misuse with dynamic strings in order notes
  • Security – Debug logging in webhook handler is now gated on the debug setting
  • Security – Removed deprecated webhook() method that used unsanitized $_REQUEST data
  • Improvement – Added “Settings” action link on the Plugins page

Version 0.9.0.5 – 04022016

  • Feature – small updates

Version 0.9.0.0 – 25042014

  • Feature – Initial release