{"id":304109,"date":"2026-05-20T17:57:23","date_gmt":"2026-05-20T17:57:23","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/"},"modified":"2026-07-07T13:13:25","modified_gmt":"2026-07-07T13:13:25","slug":"secure-card-gateway-for-epay-paycenter-piraeus-bank","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/","author":20433288,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.34","stable_tag":"1.0.34","tested":"7.0.2","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"WebHosting4U Secure Card Gateway for ePay Paycenter (Piraeus Bank)","header_author":"WebHosting4U","header_description":"WooCommerce gateway for ePay Paycenter (Piraeus Bank\/Euronet). SOAP ticketing, HMAC-SHA256 callback verification, HPOS and Blocks support.","assets_banners_color":"fafbfd","last_updated":"2026-07-07 13:13:25","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/webhosting4u.gr\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":424,"num_ratings":0,"support_threads":1,"support_threads_resolved":1,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.27":{"tag":"1.0.27","author":"webhosting4ugr","date":"2026-05-20 18:03:44"},"1.0.28":{"tag":"1.0.28","author":"webhosting4ugr","date":"2026-05-20 18:17:47"},"1.0.30":{"tag":"1.0.30","author":"webhosting4ugr","date":"2026-05-21 11:57:46"},"1.0.31":{"tag":"1.0.31","author":"webhosting4ugr","date":"2026-05-21 18:08:08"},"1.0.32":{"tag":"1.0.32","author":"webhosting4ugr","date":"2026-06-18 10:32:07"},"1.0.33":{"tag":"1.0.33","author":"webhosting4ugr","date":"2026-07-03 11:54:47"},"1.0.34":{"tag":"1.0.34","author":"webhosting4ugr","date":"2026-07-07 13:13:25"}},"upgrade_notice":{"1.0.34":"<p>Aligns with Redirection Manual v3.1: Google Pay is accepted automatically (no configuration) on eligible devices and recorded on the order via the new PanCardType field. Also hardens failure-callback authentication (HashKey verified when the bank signs the response) and records recharge attempts on already-paid orders with a clear customer message. No payment-flow, database, or configuration change.<\/p>","1.0.33":"<p>Security release. Fixes a payment-bypass flaw where the transaction ticket (the HMAC key that authenticates the bank callback) was exposed in the browser redirect form, letting a shopper forge a paid-order callback. Update immediately; no configuration changes required.<\/p>","1.0.32":"<p>Docs-only release: adds a security-contact FAQ entry pointing to the Patchstack Vulnerability Disclosure Program. No code, database, or payment-flow change.<\/p>","1.0.31":"<p>Docs-only release. Readme Description trimmed to fit the wp.org 2,500-word limit (the 1.0.30 plugin page was truncated). No code or behaviour change \u2014 the in-admin WAF diagnostic, IRIS support, installments picker and tiered installments from 1.0.30 are all preserved.<\/p>","1.0.30":"<p>Adds IRIS payments support (auto-detected when Euronet enables IRIS on your account) and a customer-selectable installments dropdown on classic WC checkout with tiered max-installments by order amount. Existing installments config preserved. Blocks checkout customers default to one-time payment.<\/p>","1.0.28":"<p>Compatibility with WordPress 7.0 (Modern admin theme, iframed editor, PHP 7.4 minimum). No payment-flow, database, or callback-handler change.<\/p>","1.0.27":"<p>Settings screen reorganized: merchant credentials now sit above bank integration data, the bank-data card is collapsed by default, and the five callback URLs share one grey &quot;Copy&quot; block. No payment-flow, database, or callback-handler change.<\/p>","1.0.20":"<p>Text domain corrected to match plugin slug. Cloudflare IP fetch documented in External services. echo wrapped with wp_kses_post(). No payment-flow or database change.<\/p>","1.0.19":"<p>Plugin renamed to &quot;WebHosting4U Secure Card Gateway for ePay Paycenter (Piraeus Bank)&quot; with slug wh4u-* per Plugin Review Team feedback. External services fully documented with terms \/ privacy links. Deprecated libxml_disable_entity_loader() removed. No payment-flow change.<\/p>","1.0.18":"<p>Checkout icon changed from piraeus.svg to a responsive wp-cards.png image (400 px desktop, scales on mobile). Block checkout now shows card brands. Front-end CSS enqueued on checkout. Drop-in upgrade.<\/p>","1.0.17":"<p>Greek translation backfilled with all strings from 1.0.10-1.0.16: scenario labels, decline notices, admin notes, WAF self-test UI. POT regenerated. No PHP\/database\/payment-flow change.<\/p>","1.0.16":"<p>Fixes decline notice not appearing after bank redirect. Hook priority collision with WooCommerce core resolved (priority 5 vs core 10). Works on every theme. No database or payment-flow change.<\/p>","1.0.15":"<p>Aligns with Redirection Manual v2.9 section 5 scenario table. Fixes misleading ResultCode 1048 message, widens 50x matching to 500-599, adds AdminTool hint on 1045. Drop-in upgrade.<\/p>","1.0.14":"<p>Fixes decline message not appearing after bank redirect due to SameSite=Lax stripping the session cookie. Notices now queued as order-scoped transients. No database or payment-flow change.<\/p>","1.0.13":"<p>Fixes &quot;-1&quot; body when Success\/Failure URL is doubled in the Euronet portal. Malformed wc-api values normalised at parse_request. Please also correct the URL in the portal.<\/p>","1.0.12":"<p>Declined-transaction handling per Redirection Manual v2.9 section 5. Issuer decline shown to customer, failures redirect to pay-for-order URL. Fixes &quot;-1&quot; body via plugins_loaded binding.<\/p>","1.0.11":"<p>Adds &quot;Test callback URL&quot; button on the settings screen. Detects host WAF interception (cPFence, ModSec, Imunify360, BitNinja, LiteSpeed). No database or payment-flow change.<\/p>","1.0.10":"<p>Adds a &quot;Callback envelope&quot; forensic log line at every callback reach so\nhost-WAF-blocked transactions can be distinguished from plugin-rejected\nones, and refines the customer-facing wording per Paycenter ResultCode\nand ResponseCode. Safe drop-in upgrade, no database change.<\/p>","1.0.9":"<p>Greek translation rewritten in plain, merchant-friendly Greek. Banking\njargon replaced with everyday terms; field labels shortened so the\nWooCommerce settings layout is not stretched. Safe drop-in upgrade.<\/p>","1.0.8":"<p>Plugin Check compliance: adds the standard <code>defined( &amp;#039;ABSPATH&amp;#039; ) || exit;<\/code>\nguard at the top of the performant-translations <code>.l10n.php<\/code> file. No\nruntime or database change, safe drop-in upgrade.<\/p>","1.0.7":"<p>Plugin Review compliance: the bank redirect auto-submit helper is now\nloaded via wp_enqueue_script() from a standalone asset file instead of\nan inline `` block in the receipt template. Safe drop-in\nupgrade, no database or payment-flow change.<\/p>","1.0.6":"<p>Adds a complete Greek (el) translation, regenerates the POT catalog from\nthe live source, and ships WP 6.5+ performant-translations <code>.l10n.php<\/code>\nfiles next to every <code>.mo<\/code>. Safe drop-in upgrade, no database change.<\/p>","1.0.5":"<p>Plugin Check compliance: sanitizes $_SERVER input on the settings\nscreen, switches statistics queries to $wpdb-&gt;prepare() with the %i\nidentifier placeholder, and trims the 1.0.2 upgrade notice under the\n300-char limit. No functional change.<\/p>","1.0.4":"<p>Adds Cloudflare auto-detection and a help notice on the gateway\nsettings page instructing store owners to email Euronet Merchant\nServices to whitelist Cloudflare&#039;s IPv4 ranges. Safe drop-in upgrade.<\/p>","1.0.3":"<p>Stops the WC-API callback endpoint from spamming the WooCommerce error\nlog with &quot;Callback missing MerchantReference&quot; entries when hit by bots,\nscanners or direct browser visits. No functional or security change.<\/p>","1.0.2":"<p>Redesigned settings screen with status overview and an auto-generated\nBank integration data block listing the exact Website, Referrer,\nSuccess, Failure and Backlink URLs, server IP and response method\nasked for by Euronet Merchant Services. Safe drop-in upgrade.<\/p>","1.0.1":"<p>Compliance, security and packaging fixes. Recommended for all users;\nno database migration required.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3539821,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3539821,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3539821,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3539821,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.27","1.0.28","1.0.30","1.0.31","1.0.32","1.0.33","1.0.34"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3539821,"resolution":"1","location":"assets","locale":"","width":1883,"height":773},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3539821,"resolution":"2","location":"assets","locale":"","width":1888,"height":810}},"screenshots":{"1":"ePay Paycenter gateway entry in <strong>WooCommerce \u2192 Settings \u2192 Payments<\/strong> with editable title and description shown to the customer. \/ \u039a\u03b1\u03c4\u03b1\u03c7\u03ce\u03c1\u03b7\u03c3\u03b7 \u03c0\u03cd\u03bb\u03b7\u03c2 ePay Paycenter \u03c3\u03c4\u03bf <strong>WooCommerce \u2192 \u03a1\u03c5\u03b8\u03bc\u03af\u03c3\u03b5\u03b9\u03c2 \u2192 \u03a0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ad\u03c2<\/strong> \u03bc\u03b5 \u03b5\u03c0\u03b5\u03be\u03b5\u03c1\u03b3\u03ac\u03c3\u03b9\u03bc\u03bf \u03c4\u03af\u03c4\u03bb\u03bf \u03ba\u03b1\u03b9 \u03c0\u03b5\u03c1\u03b9\u03b3\u03c1\u03b1\u03c6\u03ae.","2":"Gateway settings page: <strong>Merchant credentials<\/strong> (AcquirerId, MerchantId, PosId, Username, Password) above <strong>Bank integration data<\/strong> with the Success \/ Failure \/ Backlink URLs grouped into a single grey block with a one-click Copy button. \/ \u03a3\u03b5\u03bb\u03af\u03b4\u03b1 \u03c1\u03c5\u03b8\u03bc\u03af\u03c3\u03b5\u03c9\u03bd \u03c0\u03cd\u03bb\u03b7\u03c2: <strong>\u03a3\u03c4\u03bf\u03b9\u03c7\u03b5\u03af\u03b1 \u03c0\u03c1\u03cc\u03c3\u03b2\u03b1\u03c3\u03b7\u03c2 \u03b5\u03bc\u03c0\u03cc\u03c1\u03bf\u03c5<\/strong> \u03c0\u03ac\u03bd\u03c9 \u03b1\u03c0\u03cc \u03c4\u03b1 <strong>\u03a3\u03c4\u03bf\u03b9\u03c7\u03b5\u03af\u03b1 \u03c3\u03cd\u03bd\u03b4\u03b5\u03c3\u03b7\u03c2 \u03bc\u03b5 \u03c4\u03b7\u03bd \u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1<\/strong>, \u03bc\u03b5 \u03c4\u03b1 Success \/ Failure \/ Backlink URLs \u03c3\u03b5 \u03b5\u03bd\u03b9\u03b1\u03af\u03bf \u03b3\u03ba\u03c1\u03b9 \u03c0\u03b5\u03b4\u03af\u03bf \u03ba\u03b1\u03b9 \u03ba\u03bf\u03c5\u03bc\u03c0\u03af \u03b1\u03bd\u03c4\u03b9\u03b3\u03c1\u03b1\u03c6\u03ae\u03c2 \u03bc\u03b5 \u03ad\u03bd\u03b1 \u03ba\u03bb\u03b9\u03ba."}},"plugin_section":[],"plugin_tags":[11475,207503,6593,263735,286],"plugin_category":[45],"plugin_contributors":[260181],"plugin_business_model":[],"class_list":["post-304109","plugin","type-plugin","status-publish","hentry","plugin_tags-credit-card","plugin_tags-greece","plugin_tags-payment-gateway","plugin_tags-piraeus-bank","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-webhosting4ugr","plugin_committers-webhosting4ugr"],"banners":{"banner":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/banner-772x250.png?rev=3539821","banner_2x":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/banner-1544x500.png?rev=3539821","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/icon-128x128.png?rev=3539821","icon_2x":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/icon-256x256.png?rev=3539821","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/screenshot-1.png?rev=3539821","caption":"ePay Paycenter gateway entry in <strong>WooCommerce \u2192 Settings \u2192 Payments<\/strong> with editable title and description shown to the customer. \/ \u039a\u03b1\u03c4\u03b1\u03c7\u03ce\u03c1\u03b7\u03c3\u03b7 \u03c0\u03cd\u03bb\u03b7\u03c2 ePay Paycenter \u03c3\u03c4\u03bf <strong>WooCommerce \u2192 \u03a1\u03c5\u03b8\u03bc\u03af\u03c3\u03b5\u03b9\u03c2 \u2192 \u03a0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ad\u03c2<\/strong> \u03bc\u03b5 \u03b5\u03c0\u03b5\u03be\u03b5\u03c1\u03b3\u03ac\u03c3\u03b9\u03bc\u03bf \u03c4\u03af\u03c4\u03bb\u03bf \u03ba\u03b1\u03b9 \u03c0\u03b5\u03c1\u03b9\u03b3\u03c1\u03b1\u03c6\u03ae."},{"src":"https:\/\/ps.w.org\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/assets\/screenshot-2.png?rev=3539821","caption":"Gateway settings page: <strong>Merchant credentials<\/strong> (AcquirerId, MerchantId, PosId, Username, Password) above <strong>Bank integration data<\/strong> with the Success \/ Failure \/ Backlink URLs grouped into a single grey block with a one-click Copy button. \/ \u03a3\u03b5\u03bb\u03af\u03b4\u03b1 \u03c1\u03c5\u03b8\u03bc\u03af\u03c3\u03b5\u03c9\u03bd \u03c0\u03cd\u03bb\u03b7\u03c2: <strong>\u03a3\u03c4\u03bf\u03b9\u03c7\u03b5\u03af\u03b1 \u03c0\u03c1\u03cc\u03c3\u03b2\u03b1\u03c3\u03b7\u03c2 \u03b5\u03bc\u03c0\u03cc\u03c1\u03bf\u03c5<\/strong> \u03c0\u03ac\u03bd\u03c9 \u03b1\u03c0\u03cc \u03c4\u03b1 <strong>\u03a3\u03c4\u03bf\u03b9\u03c7\u03b5\u03af\u03b1 \u03c3\u03cd\u03bd\u03b4\u03b5\u03c3\u03b7\u03c2 \u03bc\u03b5 \u03c4\u03b7\u03bd \u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1<\/strong>, \u03bc\u03b5 \u03c4\u03b1 Success \/ Failure \/ Backlink URLs \u03c3\u03b5 \u03b5\u03bd\u03b9\u03b1\u03af\u03bf \u03b3\u03ba\u03c1\u03b9 \u03c0\u03b5\u03b4\u03af\u03bf \u03ba\u03b1\u03b9 \u03ba\u03bf\u03c5\u03bc\u03c0\u03af \u03b1\u03bd\u03c4\u03b9\u03b3\u03c1\u03b1\u03c6\u03ae\u03c2 \u03bc\u03b5 \u03ad\u03bd\u03b1 \u03ba\u03bb\u03b9\u03ba."}],"raw_content":"<!--section=description-->\n<h4>What sets this plugin apart<\/h4>\n\n<ul>\n<li><p><strong>HPOS-native from day one.<\/strong> Built against WooCommerce's High-Performance Order Storage from the very first release. All order metadata uses the HPOS-aware <code>$order-&gt;update_meta_data()<\/code> \/ <code>get_meta()<\/code> API \u2014 never the legacy <code>update_post_meta()<\/code> \/ <code>get_post_meta()<\/code> calls that silently fail on HPOS-enabled stores (the WooCommerce default for new installs since 8.x). Your transaction IDs, support reference IDs, and approval codes are preserved whichever storage mode you run.<\/p><\/li>\n<li><p><strong>Cloudflare-aware.<\/strong> Automatically detects when your store is served through Cloudflare (via the <code>CF-Ray<\/code> \/ <code>CF-Connecting-IP<\/code> request headers) and surfaces the current Cloudflare IPv4 CIDR ranges right in the gateway settings page, ready to copy. You hand them to Euronet Merchant Services so the bank's callbacks are not blocked at their firewall when they arrive via Cloudflare edge IPs. Live list fetched from cloudflare.com\/ips-v4 and cached for 12 hours.<\/p><\/li>\n<li><p><strong>Built-in WAF \/ callback self-test.<\/strong> A diagnostic button in the gateway settings sends a realistic, <em>declined-transaction<\/em>-shaped POST to your own callback URL via loopback and reports whether your host's web-application firewall (cPFence, ModSecurity \/ OWASP CRS, Imunify360, BitNinja, LiteSpeed WAF) silently blocks it before PHP runs. No real order is created or modified \u2014 the synthetic payload carries a <code>WAFTEST-<\/code> merchant reference that cannot match any order in the database. Catches the class of <em>\"callbacks never arrive\"<\/em> problems before they cost you a sale.<\/p><\/li>\n<li><p><strong>Modern admin UI.<\/strong> Card-based layout, dashicons throughout, one-click Copy-to-clipboard for all callback URLs grouped in a single block, environment badge (Test \/ Live \/ Production) on the credentials section, collapsible Cloudflare details. Audited against WordPress 7.0's \"Modern\" admin theme.<\/p><\/li>\n<li><p><strong>Audited for WordPress 7.0 on release day.<\/strong> Reviewed against the full WordPress 7.0 Field Guide breaking-changes list on 2026-05-20. \"Tested up to: 7.0\" from the very first stable release. The plugin requires PHP 7.4 (the new WordPress 7.0 minimum) and uses no APIs deprecated in 7.0.<\/p><\/li>\n<li><p><strong>Fully bilingual (EN + EL).<\/strong> All 179 admin and customer-facing strings translated to Greek and shipped as both classic <code>.mo<\/code> and WordPress 6.5+ performant <code>.l10n.php<\/code> payloads. The wp.org page itself ships with an English <code>readme.txt<\/code> that opens with a Greek summary, plus a parallel full Greek <code>readme-el.txt<\/code> companion file inside the plugin folder for Greek-speaking merchants.<\/p><\/li>\n<\/ul>\n\n\n\n<p><strong>\u0395\u03bb\u03bb\u03b7\u03bd\u03b9\u03ba\u03ac:<\/strong><\/p>\n\n<p>\u0391\u03bd\u03b5\u03be\u03ac\u03c1\u03c4\u03b7\u03c4\u03bf \u03c0\u03c1\u03cc\u03c3\u03b8\u03b5\u03c4\u03bf \u03c0\u03cd\u03bb\u03b7\u03c2 \u03c0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ae\u03c2 WooCommerce \u03b1\u03c0\u03cc \u03c4\u03b7 WebHosting4U \u03b3\u03b9\u03b1\n\u03c4\u03b7\u03bd \u03c5\u03c0\u03b7\u03c1\u03b5\u03c3\u03af\u03b1 <em>ePay Paycenter Redirection<\/em> \u03c4\u03b7\u03c2 \u03a4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1\u03c2 \u03a0\u03b5\u03b9\u03c1\u03b1\u03b9\u03ce\u03c2 \/\nEuronet Merchant Services. \u03a5\u03bb\u03bf\u03c0\u03bf\u03b9\u03b5\u03af \u03c0\u03bb\u03ae\u03c1\u03c9\u03c2 \u03c4\u03b7\u03bd \u03b5\u03c0\u03af\u03c3\u03b7\u03bc\u03b7 \u03c0\u03c1\u03bf\u03b4\u03b9\u03b1\u03b3\u03c1\u03b1\u03c6\u03ae\n<em>Redirection v3.1<\/em>:<\/p>\n\n<ul>\n<li>\u0388\u03ba\u03b4\u03bf\u03c3\u03b7 \u03bc\u03bf\u03bd\u03b1\u03b4\u03b9\u03ba\u03bf\u03cd \u03b5\u03b9\u03c3\u03b9\u03c4\u03b7\u03c1\u03af\u03bf\u03c5 (TranTicket) \u03bc\u03ad\u03c3\u03c9 SOAP Ticketing Web\nService \u03bc\u03b5 \u03ba\u03c9\u03b4\u03b9\u03ba\u03bf\u03c0\u03bf\u03af\u03b7\u03c3\u03b7 UTF-8.<\/li>\n<li>\u0391\u03c5\u03c4\u03cc\u03bc\u03b1\u03c4\u03b7 \u03b1\u03bd\u03b1\u03ba\u03b1\u03c4\u03b5\u03cd\u03b8\u03c5\u03bd\u03c3\u03b7 POST \u03c3\u03c4\u03b7\u03bd \u03b1\u03c3\u03c6\u03b1\u03bb\u03ae \u03c3\u03b5\u03bb\u03af\u03b4\u03b1 \u03c0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ae\u03c2 \u03c4\u03b7\u03c2 \u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1\u03c2\n(<code>pay.aspx<\/code>) \u2014 \u03c4\u03b1 \u03b4\u03b5\u03b4\u03bf\u03bc\u03ad\u03bd\u03b1 \u03ba\u03ac\u03c1\u03c4\u03b1\u03c2 \u03b4\u03b5\u03bd \u03c0\u03b5\u03c1\u03bd\u03bf\u03cd\u03bd \u03c0\u03bf\u03c4\u03ad \u03b1\u03c0\u03cc \u03c4\u03bf\u03bd \u03b4\u03b9\u03b1\u03ba\u03bf\u03bc\u03b9\u03c3\u03c4\u03ae\n\u03c4\u03bf\u03c5 \u03ba\u03b1\u03c4\u03b1\u03c3\u03c4\u03ae\u03bc\u03b1\u03c4\u03bf\u03c2.<\/li>\n<li>\u03a0\u03bb\u03ae\u03c1\u03b7\u03c2 \u03b5\u03c0\u03b1\u03bb\u03ae\u03b8\u03b5\u03c5\u03c3\u03b7 HashKey HMAC-SHA256 \u03c3\u03b5 \u03ba\u03ac\u03b8\u03b5 \u03b5\u03c0\u03b9\u03c4\u03c5\u03c7\u03b7\u03bc\u03ad\u03bd\u03b7 \u03b1\u03c0\u03ac\u03bd\u03c4\u03b7\u03c3\u03b7\n\u03c0\u03c1\u03b9\u03bd \u03c7\u03b1\u03c1\u03b1\u03ba\u03c4\u03b7\u03c1\u03b9\u03c3\u03c4\u03b5\u03af \u03b7 \u03c0\u03b1\u03c1\u03b1\u03b3\u03b3\u03b5\u03bb\u03af\u03b1 \u03c9\u03c2 \u03b5\u03be\u03bf\u03c6\u03bb\u03b7\u03bc\u03ad\u03bd\u03b7.<\/li>\n<li>\u03a5\u03c0\u03bf\u03c3\u03c4\u03ae\u03c1\u03b9\u03be\u03b7 \u03c3\u03c5\u03bd\u03b1\u03bb\u03bb\u03b1\u03b3\u03ce\u03bd Sale \u03ba\u03b1\u03b9 \u03a0\u03c1\u03bf\u03ad\u03b3\u03ba\u03c1\u03b9\u03c3\u03b7\u03c2 (Preauthorization).<\/li>\n<li><strong>\u03a5\u03c0\u03bf\u03c3\u03c4\u03ae\u03c1\u03b9\u03be\u03b7 IRIS Payments<\/strong> (\u03ac\u03bc\u03b5\u03c3\u03b5\u03c2 \u03c0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ad\u03c2 \u03bc\u03ad\u03c3\u03c9 \u0394\u0399\u0391\u03a3). \u038c\u03c4\u03b1\u03bd \u03b7\nEuronet Merchant Services \u03b5\u03bd\u03b5\u03c1\u03b3\u03bf\u03c0\u03bf\u03b9\u03ae\u03c3\u03b5\u03b9 \u03c4\u03bf IRIS \u03c3\u03c4\u03b7 \u03c3\u03cd\u03bc\u03b2\u03b1\u03c3\u03ae \u03c3\u03b1\u03c2, \u03b7\n\u03c3\u03b5\u03bb\u03af\u03b4\u03b1 \u03c0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ae\u03c2 \u03c4\u03b7\u03c2 \u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1\u03c2 \u03b5\u03bc\u03c6\u03b1\u03bd\u03af\u03b6\u03b5\u03b9 \u03c3\u03c4\u03bf\u03bd \u03c0\u03b5\u03bb\u03ac\u03c4\u03b7 \u03ba\u03b1\u03b9 \u03c4\u03b9\u03c2 \u03b4\u03cd\u03bf\n\u03b5\u03c0\u03b9\u03bb\u03bf\u03b3\u03ad\u03c2 (\u03ba\u03ac\u03c1\u03c4\u03b1 \u03ae IRIS). \u03a4\u03bf \u03c0\u03c1\u03cc\u03c3\u03b8\u03b5\u03c4\u03bf \u03b1\u03bd\u03b1\u03b3\u03bd\u03c9\u03c1\u03af\u03b6\u03b5\u03b9 \u03c4\u03b9\u03c2 \u03b1\u03c0\u03b1\u03bd\u03c4\u03ae\u03c3\u03b5\u03b9\u03c2 IRIS,\n\u03b1\u03c0\u03bf\u03b8\u03b7\u03ba\u03b5\u03cd\u03b5\u03b9 \u03c4\u03bf \u03ba\u03b1\u03bd\u03ac\u03bb\u03b9 \u03c0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ae\u03c2 \u03c3\u03c4\u03b7\u03bd \u03c0\u03b1\u03c1\u03b1\u03b3\u03b3\u03b5\u03bb\u03af\u03b1, \u03ba\u03b1\u03b9 \u03b5\u03bc\u03c6\u03b1\u03bd\u03af\u03b6\u03b5\u03b9\n\u03bc\u03b7\u03bd\u03cd\u03bc\u03b1\u03c4\u03b1 \u03c0\u03c1\u03bf\u03c3\u03b1\u03c1\u03bc\u03bf\u03c3\u03bc\u03ad\u03bd\u03b1 \u03c3\u03c4\u03b1 IRIS \u03c3\u03b5\u03bd\u03ac\u03c1\u03b9\u03b1 (\u03b1\u03ba\u03cd\u03c1\u03c9\u03c3\u03b7 \u03b1\u03c0\u03cc \u03c4\u03b7\u03bd \u03b5\u03c6\u03b1\u03c1\u03bc\u03bf\u03b3\u03ae\n\u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1\u03c2, \u03bb\u03ae\u03be\u03b7 QR 5 \u03bb\u03b5\u03c0\u03c4\u03ce\u03bd, \u03c3\u03c6\u03ac\u03bb\u03bc\u03b1 \u03c5\u03c0\u03b7\u03c1\u03b5\u03c3\u03af\u03b1\u03c2 IRIS \u03ba.\u03bb\u03c0.).<\/li>\n<li><strong>\u03a0\u03bb\u03b7\u03c1\u03c9\u03bc\u03ad\u03c2 Google Pay\u2122<\/strong> (Redirection v3.1) \u2014 \u03b3\u03af\u03bd\u03bf\u03bd\u03c4\u03b1\u03b9 \u03b4\u03b5\u03ba\u03c4\u03ad\u03c2\n\u03b1\u03c5\u03c4\u03cc\u03bc\u03b1\u03c4\u03b1, \u03c7\u03c9\u03c1\u03af\u03c2 \u03ba\u03b1\u03bc\u03af\u03b1 \u03c1\u03cd\u03b8\u03bc\u03b9\u03c3\u03b7. \u0397 \u03c3\u03b5\u03bb\u03af\u03b4\u03b1 \u03c4\u03b7\u03c2 \u03c4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1\u03c2 \u03b5\u03bc\u03c6\u03b1\u03bd\u03af\u03b6\u03b5\u03b9 \u03c4\u03bf\nGoogle Pay \u03c3\u03b5 \u03c3\u03c5\u03bc\u03b2\u03b1\u03c4\u03ad\u03c2 \u03c3\u03c5\u03c3\u03ba\u03b5\u03c5\u03ad\u03c2 \u03b3\u03b9\u03b1 \u03c3\u03c5\u03bd\u03b1\u03bb\u03bb\u03b1\u03b3\u03ad\u03c2 \u03b1\u03b3\u03bf\u03c1\u03ac\u03c2 \u03ba\u03b1\u03b9 \u03c0\u03c1\u03bf\u03ad\u03b3\u03ba\u03c1\u03b9\u03c3\u03b7\u03c2.\n\u0395\u03c0\u03b5\u03b9\u03b4\u03ae \u03c4\u03bf Google Pay \u03b5\u03c0\u03b9\u03c3\u03c4\u03c1\u03ad\u03c6\u03b5\u03b9 \u03c4\u03b7\u03bd \u03c4\u03c5\u03c0\u03b9\u03ba\u03ae \u03b1\u03c0\u03ac\u03bd\u03c4\u03b7\u03c3\u03b7 \u03ba\u03ac\u03c1\u03c4\u03b1\u03c2,\n\u03b5\u03c0\u03b1\u03bb\u03b7\u03b8\u03b5\u03cd\u03b5\u03c4\u03b1\u03b9 \u03bc\u03b5 \u03c4\u03bf \u03af\u03b4\u03b9\u03bf HashKey HMAC-SHA256\u00b7 \u03c4\u03bf \u03c0\u03c1\u03cc\u03c3\u03b8\u03b5\u03c4\u03bf \u03ba\u03b1\u03c4\u03b1\u03b3\u03c1\u03ac\u03c6\u03b5\u03b9\n\u03b5\u03c0\u03b9\u03c0\u03bb\u03ad\u03bf\u03bd \u03c4\u03bf \u03c0\u03b5\u03b4\u03af\u03bf <code>PanCardType<\/code> (FPAN \u03c0\u03c1\u03b1\u03b3\u03bc\u03b1\u03c4\u03b9\u03ba\u03cc\u03c2 \u03b1\u03c1\u03b9\u03b8\u03bc\u03cc\u03c2 \u03ba\u03ac\u03c1\u03c4\u03b1\u03c2 \/\nDPAN token \u03c3\u03c5\u03c3\u03ba\u03b5\u03c5\u03ae\u03c2) \u03c3\u03c4\u03b7\u03bd \u03c0\u03b1\u03c1\u03b1\u03b3\u03b3\u03b5\u03bb\u03af\u03b1.<\/li>\n<li>\u03a3\u03c5\u03bc\u03c0\u03bb\u03ae\u03c1\u03c9\u03c3\u03b7 \u03c0\u03b5\u03b4\u03af\u03c9\u03bd 3-D Secure \u03b1\u03c0\u03cc \u03c4\u03b7 \u03b4\u03b9\u03b5\u03cd\u03b8\u03c5\u03bd\u03c3\u03b7 \u03c7\u03c1\u03ad\u03c9\u03c3\u03b7\u03c2 \/ \u03b1\u03c0\u03bf\u03c3\u03c4\u03bf\u03bb\u03ae\u03c2\n\u03c4\u03bf\u03c5 WooCommerce.<\/li>\n<li>\u03a3\u03c5\u03bc\u03b2\u03b1\u03c4\u03cc\u03c4\u03b7\u03c4\u03b1 \u03bc\u03b5 HPOS (Custom Order Tables) \u03ba\u03b1\u03b9 WooCommerce Blocks\ncheckout.<\/li>\n<\/ul>\n\n<p><strong>\u03a0\u03c1\u03bf\u03cb\u03c0\u03cc\u03b8\u03b5\u03c3\u03b7:<\/strong> \u03c0\u03c1\u03ad\u03c0\u03b5\u03b9 \u03bd\u03b1 \u03ad\u03c7\u03b5\u03c4\u03b5 \u03c5\u03c0\u03bf\u03b3\u03b5\u03b3\u03c1\u03b1\u03bc\u03bc\u03ad\u03bd\u03bf \u03c3\u03c5\u03bc\u03b2\u03cc\u03bb\u03b1\u03b9\u03bf \u03b1\u03c0\u03bf\u03b4\u03bf\u03c7\u03ae\u03c2 \u03bc\u03b5 \u03c4\u03b7\u03bd\nEuronet Merchant Services \/ \u03a4\u03c1\u03ac\u03c0\u03b5\u03b6\u03b1 \u03a0\u03b5\u03b9\u03c1\u03b1\u03b9\u03ce\u03c2 \u03ba\u03b1\u03b9 \u03bd\u03b1 \u03b4\u03b9\u03b1\u03b8\u03ad\u03c4\u03b5\u03c4\u03b5 \u03c4\u03b1\n\u03b4\u03b9\u03b1\u03c0\u03b9\u03c3\u03c4\u03b5\u03c5\u03c4\u03ae\u03c1\u03b9\u03b1 <code>AcquirerId<\/code>, <code>MerchantId<\/code>, <code>PosId<\/code>, <code>Username<\/code>,\n    Password. \u03a4\u03bf \u03c0\u03c1\u03cc\u03c3\u03b8\u03b5\u03c4\u03bf \u03b4\u03b5\u03bd \u03c0\u03b1\u03c1\u03ad\u03c7\u03b5\u03b9 \u03b4\u03b9\u03ba\u03bf\u03cd\u03c2 \u03c4\u03bf\u03c5 \u03b4\u03bf\u03ba\u03b9\u03bc\u03b1\u03c3\u03c4\u03b9\u03ba\u03bf\u03cd\u03c2\n\u03bb\u03bf\u03b3\u03b1\u03c1\u03b9\u03b1\u03c3\u03bc\u03bf\u03cd\u03c2.<\/p>\n\n<p>\u0397 \u03c0\u03bb\u03ae\u03c1\u03b7\u03c2 \u03b5\u03bb\u03bb\u03b7\u03bd\u03b9\u03ba\u03ae \u03bc\u03b5\u03c4\u03ac\u03c6\u03c1\u03b1\u03c3\u03b7 \u03c4\u03b7\u03c2 \u03c3\u03b5\u03bb\u03af\u03b4\u03b1\u03c2 \u03c4\u03bf\u03c5 \u03c0\u03c1\u03bf\u03c3\u03b8\u03ad\u03c4\u03bf\u03c5 \u03c3\u03c4\u03bf WordPress.org\n\u03b8\u03b1 \u03b5\u03af\u03bd\u03b1\u03b9 \u03b4\u03b9\u03b1\u03b8\u03ad\u03c3\u03b9\u03bc\u03b7 \u03bc\u03ad\u03c3\u03c9 \u03c4\u03bf\u03c5 <a href=\"https:\/\/translate.wordpress.org\/projects\/wp-plugins\/secure-card-gateway-for-epay-paycenter-piraeus-bank\/\">translate.wordpress.org<\/a>\n\u03bc\u03cc\u03bb\u03b9\u03c2 \u03b5\u03b3\u03ba\u03c1\u03b9\u03b8\u03b5\u03af \u03b1\u03c0\u03cc \u03c4\u03b7\u03bd \u03ba\u03bf\u03b9\u03bd\u03cc\u03c4\u03b7\u03c4\u03b1. \u0394\u03b5\u03af\u03c4\u03b5 \u03b5\u03c0\u03af\u03c3\u03b7\u03c2 \u03c4\u03bf \u03c3\u03c5\u03bd\u03bf\u03b4\u03b5\u03c5\u03c4\u03b9\u03ba\u03cc\n    readme-el.txt \u03b3\u03b9\u03b1 \u03c4\u03b7\u03bd \u03bf\u03bb\u03bf\u03ba\u03bb\u03b7\u03c1\u03c9\u03bc\u03ad\u03bd\u03b7 \u03b5\u03bb\u03bb\u03b7\u03bd\u03b9\u03ba\u03ae \u03c4\u03b5\u03ba\u03bc\u03b7\u03c1\u03af\u03c9\u03c3\u03b7.<\/p>\n\n\n\n<p><strong>English:<\/strong><\/p>\n\n<p>This plugin integrates WooCommerce with the ePay Paycenter Redirection\nservice operated by Piraeus Bank \/ Euronet Merchant Services. It implements\nthe official Redirection v3.1 specification end to end:<\/p>\n\n<ul>\n<li>SOAP Ticketing Web Service (<code>IssueNewTicket<\/code>) with UTF-8 payload.<\/li>\n<li>Auto-submitted HTML form POST redirection to the Paycenter secure\npayment page (<code>pay.aspx<\/code>) so card data never touches your server.<\/li>\n<li>Full HMAC-SHA256 HashKey verification for every successful callback\nbefore marking an order as paid.<\/li>\n<li>Support for Sale and Preauthorization transactions.<\/li>\n<li><strong>IRIS payments<\/strong> (Greek instant payment \/ DIAS) accepted transparently\nwhen enabled by Euronet Merchant Services on the merchant agreement.\nThe bank's hosted page presents card and IRIS as the two payment\noptions; the plugin recognises the IRIS-specific response payload\n(<code>CardType=15<\/code>, <code>PaymentMethod=IRIS<\/code>), surfaces IRIS-tailored decline\nmessages for the IRIS-only ResponseCodes (05 user-cancelled-in-bank-app,\n06 service error, 09 pending, 68 5-minute QR timeout, 70 IRIS service\nerror) and records the channel on the order so card vs IRIS settlements\nare distinguishable in your reports.<\/li>\n<li><strong>Google Pay\u2122<\/strong> (Redirection v3.1) accepted automatically \u2014 no\nconfiguration needed. The bank's hosted page shows Google Pay on\neligible devices\/browsers for purchase and pre-authorization\ntransactions (with or without installments). Because Google Pay\nreturns the standard card success payload, it is verified against the\nsame HMAC-SHA256 HashKey as any card; the plugin additionally records\nthe <code>PanCardType<\/code> (FPAN real card number \/ DPAN device token) on the\norder and notes \"Paid via Google Pay\" so wallet settlements are\ndistinguishable in your reports.<\/li>\n<li>3-D Secure auxiliary fields populated from the WooCommerce billing \/\nshipping address.<\/li>\n<li>HPOS (Custom Order Tables) and WooCommerce Blocks checkout support.<\/li>\n<\/ul>\n\n<p><strong>You must have signed an acquiring contract with Euronet Merchant\nServices \/ Piraeus Bank and obtained <code>AcquirerId<\/code>, <code>MerchantId<\/code>, <code>PosId<\/code>,\n    Username and <code>Password<\/code> credentials before using this plugin.<\/strong> The\nplugin does not provide test or sandbox accounts on its own; please\ncontact Euronet Merchant Services to request one.<\/p>\n\n<h4>Affiliation and trademark notice<\/h4>\n\n<p>This plugin is independent software published by <strong>WebHosting4U<\/strong> and is\n<strong>not affiliated with, endorsed by, sponsored by, or otherwise officially\nconnected to<\/strong> Piraeus Bank S.A., Euronet Merchant Services, or\nAutomattic Inc. The third-party names \"ePay\", \"Paycenter\", \"Piraeus Bank\"\nand \"WooCommerce\" are trademarks of their respective owners and are\nused here in good faith, after the unaffiliation marker \"for\", solely\nto describe the third-party service this plugin integrates with, in\nline with the WordPress.org Detailed Plugin Guidelines on third-party\ntrademarks. The bundled accepted card brands image\n(<code>assets\/img\/wp-cards.png<\/code>) is included with the rights-holder's\nauthorization for the merchant distribution scope of this plugin.<\/p>\n\n<h4>User tracking and consent<\/h4>\n\n<p>This plugin does <strong>not<\/strong> load any analytics, telemetry, advertising,\nfingerprinting, profiling or behavioural tracking code, neither on the\nstorefront nor in the WordPress admin. It does not set cookies on\nvisitor browsers, does not contact any first-party or third-party\nanalytics endpoint, and does not collect aggregated or individual\nusage statistics from the merchant's installation. The only outbound\nnetwork traffic the plugin generates is the strictly transactional\ntraffic documented in the <em>External services<\/em> section below, which\nis required to complete a payment the merchant has explicitly\nconfigured the plugin to perform. No user-tracking consent prompt is\ntherefore required by this plugin (Plugin Review Team Guidelines 7\nand 9).<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin reaches out to three external services. Two are operated\nby Euronet Merchant Services on behalf of Piraeus Bank S.A. for the\n\"ePay Paycenter\" payment redirection product (mandatory for the\nplugin's core function). The third is a publicly available Cloudflare\nendpoint used only in the admin panel to help store owners configure\nfirewall rules for payment callbacks.<\/p>\n\n<h4>1. ePay Paycenter Ticketing Web Service<\/h4>\n\n<ul>\n<li>What it is: a SOAP \/ ASMX endpoint published by Euronet Merchant\nServices that issues a single-use <code>TranTicket<\/code> for each card\npayment attempt. The ticket is kept server-side only (never exposed\nto the browser) and used solely to verify the HMAC-SHA256 HashKey on\nthe bank's callback; the customer's browser is redirected to the\nsecure payment page by a form carrying only non-secret fields, so\ncardholder data never touches the merchant server.<\/li>\n<li>Endpoint: <code>https:\/\/paycenter.piraeusbank.gr\/services\/tickets\/issuer.asmx<\/code><\/li>\n<li>What is sent: the merchant credentials provided by Euronet Merchant\nServices (AcquirerId, MerchantId, PosId, Username and an MD5 hash\nof the Password), the order's MerchantReference (numeric WooCommerce\norder id with a short random suffix), the transaction amount and\nISO 4217 numeric currency code, the request type (Sale or\nPreauthorization), and the 3-D Secure auxiliary fields populated\nfrom the WooCommerce order: billing email, cardholder name,\nbilling address (city \/ lines \/ post code \/ state \/ ISO 3166\nnumeric country code), shipping address when present, and the\ncustomer's mobile phone number formatted as <code>CC-Number<\/code>. No\ncardholder data, no PAN, no CVV, no expiry, and no analytics\nidentifier is ever transmitted; cardholder data is collected\nexclusively on the bank's secure payment page.<\/li>\n<li>When it is sent: once per successful checkout submission, at the\nmoment WooCommerce hands control to the gateway's\n<em>Pay for order<\/em> page, immediately before the customer is\nauto-redirected to the bank.<\/li>\n<\/ul>\n\n<h4>2. ePay Paycenter Redirection page<\/h4>\n\n<ul>\n<li>What it is: the bank-hosted secure payment page where the customer\nenters card details and completes the 3-D Secure challenge. The\nplugin renders an auto-submitted HTML form whose <code>action<\/code> attribute\nis the URL below.<\/li>\n<li>Endpoint: <code>https:\/\/paycenter.piraeusbank.gr\/redirection\/pay.aspx<\/code><\/li>\n<li>What is sent: the merchant identifiers (AcquirerId, MerchantId,\nPosId, User), the language code, the MerchantReference issued\nduring ticketing, and a per-order ParamBackLink so the bank's\nCancel button returns the customer to the correct WordPress\nendpoint. The TranTicket itself is read by the customer's\nbrowser from the hidden form field; the merchant server is not\nthe originator of the redirect POST.<\/li>\n<li>When it is sent: once per checkout, immediately after the\nTicketing call above succeeds.<\/li>\n<li>Inbound counterpart: Paycenter posts a signed transaction\nresponse (HMAC-SHA256 HashKey) back to the plugin's WC-API\ncallback URL on the merchant site\n(<code>https:\/\/&lt;merchant-site&gt;\/?wc-api=epay_paycenter<\/code>). This is the\nsame service - the merchant site is the Notification \/ Success \/\nFailure \/ Backlink target the merchant configures in the\nEuronet portal. No data leaves the merchant server on this\ninbound leg; the plugin only reads, verifies, and acts on the\nresponse.<\/li>\n<\/ul>\n\n<h4>Service operator and legal links<\/h4>\n\n<p>Both endpoints above are operated by Euronet Merchant Services\n(epay) for Piraeus Bank S.A.. Before activating the gateway,\nmerchants must review and agree to the operator's terms and\nprivacy policy:<\/p>\n\n<ul>\n<li>Service homepage: <a href=\"https:\/\/epayworldwide.com\/\">https:\/\/epayworldwide.com\/<\/a> (Euronet Merchant\nServices \/ epay corporate site)<\/li>\n<li>Greek market homepage: <a href=\"https:\/\/www.epaygreece.gr\/\">https:\/\/www.epaygreece.gr\/<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.epaygreece.gr\/oroi-xrisis\/\">https:\/\/www.epaygreece.gr\/oroi-xrisis\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.epaygreece.gr\/politiki-aporritou\/\">https:\/\/www.epaygreece.gr\/politiki-aporritou\/<\/a><\/li>\n<li>Piraeus Bank corporate site: <a href=\"https:\/\/www.piraeusbank.gr\/\">https:\/\/www.piraeusbank.gr\/<\/a><\/li>\n<li>Piraeus Bank Privacy Policy: <a href=\"https:\/\/www.piraeusbank.gr\/en\/idiwtes\/protection-of-personal-data\">https:\/\/www.piraeusbank.gr\/en\/idiwtes\/protection-of-personal-data<\/a><\/li>\n<\/ul>\n\n<p>If any of the above URLs change after publication, please consult\nthe live operator websites for the current version of the relevant\ndocument. The plugin's behaviour is not affected by such updates\nbecause the operator's terms apply to the merchant's relationship\nwith Euronet Merchant Services \/ Piraeus Bank, not to the plugin\nitself. Merchants remain responsible for keeping their own\nprivacy policy and terms aligned with the data flows documented\nabove (notably the transmission of billing \/ shipping address\nfields and customer email \/ phone to the bank for 3-D Secure\nauthentication).<\/p>\n\n<h4>3. Cloudflare IPv4 list<\/h4>\n\n<ul>\n<li>What it is: a publicly available plain-text file published by\nCloudflare, Inc. that lists the current IPv4 CIDR ranges used by\nCloudflare's edge network. The plugin fetches this file once every\n12 hours (or 15 minutes on failure) via <code>wp_safe_remote_get()<\/code> and\ncaches the result in a WordPress transient.<\/li>\n<li>Endpoint: <code>https:\/\/www.cloudflare.com\/ips-v4\/<\/code><\/li>\n<li>What is sent: a standard HTTP GET request with no personal data,\nno order information, no credentials, and no cookies. The only\nidentifying information in the request is the plugin's <code>User-Agent<\/code>\nstring (<code>secure-card-gateway-for-epay-paycenter-piraeus-bank\/VERSION<\/code>).<\/li>\n<li>Why: when the plugin's admin settings page detects that the\nWordPress site is served through Cloudflare (via the CF-Ray \/\nCF-Connecting-IP \/ CDN-Loop request headers), it displays the\ncurrent Cloudflare IPv4 ranges so the store owner can copy them\ninto an email to Euronet Merchant Services to whitelist them for\npayment callbacks. Without this list, callbacks routed through\nCloudflare edge IPs may be rejected by the bank's firewall.<\/li>\n<li>When: only when an administrator views the gateway's WooCommerce\nsettings page and Cloudflare is detected on the incoming request.\nIt is never triggered on the storefront or by guest\/customer visits.<\/li>\n<li>Cloudflare service homepage: <a href=\"https:\/\/www.cloudflare.com\/\">https:\/\/www.cloudflare.com\/<\/a><\/li>\n<li>Cloudflare Privacy Policy: <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">https:\/\/www.cloudflare.com\/privacypolicy\/<\/a><\/li>\n<li>Cloudflare Terms of Service: <a href=\"https:\/\/www.cloudflare.com\/terms\/\">https:\/\/www.cloudflare.com\/terms\/<\/a><\/li>\n<\/ul>\n\n<p>No data is sent to any third party other than the three endpoints\nlisted above.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP through <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>,\nor extract it into <code>wp-content\/plugins\/wh4u-secure-card-gateway-for-epay-paycenter-piraeus-bank\/<\/code>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>WooCommerce \u2192 Settings \u2192 Payments<\/strong> and enable\n<em>ePay Paycenter (Piraeus Bank)<\/em>.<\/li>\n<li>Enter your AcquirerId, MerchantId, PosId, Username and Password\nexactly as provided by Euronet Merchant Services.<\/li>\n<li>Set the environment (Test \/ Live), language, and transaction type.<\/li>\n<li>Provide Euronet Merchant Services with the following URLs for your\nmerchant record:\n\n<ul>\n<li>Referrer URL: your shop checkout page.<\/li>\n<li>Success URL:  <code>https:\/\/your-site.tld\/wc-api\/epay_paycenter\/<\/code><\/li>\n<li>Failure URL:  <code>https:\/\/your-site.tld\/wc-api\/epay_paycenter\/<\/code><\/li>\n<li>Backlink URL: <code>https:\/\/your-site.tld\/wc-api\/epay_paycenter\/<\/code><\/li>\n<li>IP address:   the outbound IP of your web server.<\/li>\n<li>Response method: <strong>POST<\/strong> (recommended).<\/li>\n<\/ul><\/li>\n<li>Execute the mandatory test cases documented in Section 7 of the\nRedirection v2.9 manual before requesting live credentials.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20cards%20are%20supported%3F\"><h3>Which cards are supported?<\/h3><\/dt>\n<dd><p>Visa, Mastercard, Maestro, and (subject to agreement with Euronet\nMerchant Services) Diners \/ Discover and American Express.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20support%20iris%20payments%3F\"><h3>Does the plugin support IRIS payments?<\/h3><\/dt>\n<dd><p>Yes. When IRIS is enabled on your merchant agreement by Euronet Merchant\nServices, customers can choose between card and IRIS directly on the\nbank's hosted payment page \u2014 the plugin does not need a separate setting\nto \"turn IRIS on\" because the choice is made server-side at the bank,\nnot in your checkout. The plugin recognises IRIS responses (CardType=15\nor PaymentMethod=IRIS in the bank's HMAC-verified callback), shows\nIRIS-tailored messages for the IRIS-only decline scenarios (user\ncancelled in their banking app, 5-minute QR timeout, IRIS service error,\netc.) and records the payment channel on the order so card and IRIS\ntransactions are distinguishable in your reports.<\/p>\n\n<p>Per Piraeus Bank policy, <strong>IRIS payments do not support installments<\/strong>\n(the full amount is charged) and <strong>refunds are not supported for IRIS\ntransactions<\/strong> (ResponseCode 9167). These restrictions are enforced by\nthe bank, not by the plugin.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20store%20any%20card%20data%3F\"><h3>Does the plugin store any card data?<\/h3><\/dt>\n<dd><p>No. Cardholder data is entered exclusively on the Paycenter secure\npayment page and never transits your server. The plugin stores only\nnon-sensitive metadata such as approval code, response code and\n    SupportReferenceID for reconciliation.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20hashkey%20cannot%20be%20verified%3F\"><h3>What happens if the HashKey cannot be verified?<\/h3><\/dt>\n<dd><p>The order is set to <em>On hold<\/em> and a notice is logged. Verification is\nmandatory before an order is marked paid; a mismatching HashKey is\ntreated as a potentially forged callback.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20gdpr-compatible%3F\"><h3>Is this plugin GDPR-compatible?<\/h3><\/dt>\n<dd><p>The plugin transmits only the minimum data required for the transaction\n(order total, currency, merchant reference, and 3-D Secure auxiliary\nfields such as billing email and address). No analytics or telemetry is\ncollected.<\/p><\/dd>\n<dt id=\"my%20host%27s%20waf%20%28cpfence%2C%20modsecurity%2C%20imunify360%2C%20bitninja%2C%20litespeed%29%20is%20blocking%20the%20bank%20callback.%20what%20do%20i%20do%3F\"><h3>My host's WAF (cPFence, ModSecurity, Imunify360, BitNinja, LiteSpeed) is blocking the bank callback. What do I do?<\/h3><\/dt>\n<dd><p>Shared-hosting firewalls sometimes flag Paycenter's decline-callback\npayload because it contains patterns (dash-only <code>TransactionDateTime<\/code>,\nempty <code>HashKey<\/code> on declined transactions, Greek <code>ResponseDescription<\/code>\ntext) that overlap with default attack signatures. Symptoms: callbacks\nfor failed transactions never arrive and orders get stuck in <em>pending\npayment<\/em>.<\/p>\n\n<p>The plugin's settings page includes a <strong>Test callback URL<\/strong> diagnostic\nthat POSTs a realistic declined-transaction payload to your own callback\nURL via loopback and reports whether a host WAF intercepts it. Run it\nonce before going live. If a WAF is intercepting, ask your hosting\nprovider to whitelist the URL <code>\/?wc-api=epay_paycenter<\/code> (callback-URL\nscope only \u2014 never disable rules server-wide). CDN-level WAFs\n(Cloudflare, Sucuri, Akamai) must be configured separately at the CDN \u2014\nthe in-admin diagnostic only exercises the origin server's WAF.<\/p><\/dd>\n<dt id=\"my%20customer%20sees%20only%20%22-1%22%20after%20the%20bank%20return.%20what%20happened%3F\"><h3>My customer sees only \"-1\" after the bank return. What happened?<\/h3><\/dt>\n<dd><p>The literal <code>-1<\/code> comes from WooCommerce core's <code>WC_API<\/code> handler. For\nthis plugin it usually means one of three things:<\/p>\n\n<ol>\n<li>The callback URL in the Euronet portal does not match the plugin's\nURL. Use exactly <code>https:\/\/&lt;your-site&gt;\/?wc-api=epay_paycenter<\/code> (no\ntrailing slash, no extra path). Copy it from the gateway settings\npage where the plugin displays the canonical form.<\/li>\n<li>A host WAF intercepted the callback before it reached PHP (see the\nWAF FAQ above).<\/li>\n<li>The plugin handled the callback but a downstream redirect target\nsuppressed the notice. Since 1.0.14 decline messages survive\ncross-origin redirect cookie stripping, so this is rare on current\nversions.<\/li>\n<\/ol>\n\n<p>Check <strong>WooCommerce \u2192 Status \u2192 Logs<\/strong> for <code>epay-paycenter-*<\/code> entries\naround the transaction timestamp. The <code>Callback envelope<\/code> INFO line is\nwritten on every callback that reaches PHP, so its presence or absence\ndistinguishes WAF-level blocks from plugin-level rejects.<\/p><\/dd>\n<dt id=\"where%20do%20i%20report%20security%20bugs%20found%20in%20this%20plugin%3F\"><h3>Where do I report security bugs found in this plugin?<\/h3><\/dt>\n<dd><p>Please report security bugs found in the source code of the Secure Card\nGateway for ePay Paycenter (Piraeus Bank) plugin through the <a href=\"https:\/\/patchstack.com\/database\/vdp\/cfd86dd3-29dd-411e-b5d7-731c76b719f0\">Patchstack\nVulnerability Disclosure Program<\/a>.\nThe Patchstack team will assist you with verification, CVE assignment, and\nnotify the developers of this plugin.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.34<\/h4>\n\n<ul>\n<li>Compatibility: aligned with Redirection Manual v3.1 (Google Pay\u2122 support). Google Pay needs no merchant configuration \u2014 the bank auto-offers it on eligible devices\/browsers for purchase and pre-authorization transactions and returns the standard card success payload, which the plugin already verifies against the unchanged HMAC-SHA256 HashKey. The plugin now also captures the new <code>PanCardType<\/code> response field (FPAN = real card number, DPAN = device token, returned only for Google Pay), storing it as <code>_epay_pan_card_type<\/code> order meta and noting \"Paid via Google Pay (FPAN\/DPAN)\" on the order when applicable so operators can tell wallet settlements apart. No change to the ticketing request, redirect form, or HashKey verification.<\/li>\n<li>Security (hardening): failure \/ decline callbacks are now authenticated before the order is touched. When Paycenter signs a non-success response (non-empty HashKey) the plugin verifies the HMAC-SHA256 HashKey and fails closed on any mismatch, leaving the order unchanged. When the bank sends the response with an empty HashKey (its documented behaviour for declined transactions \u2014 confirmed in Redirection Manual v3.1 \u00a75) the plugin continues to rely on the per-order MerchantReference secret (order id + CSPRNG suffix) already required to reach the handler. Previously the HashKey was only checked on the success path; a forged failure callback that supplied a bad HashKey is now rejected instead of flipping a pending order to \"failed\". The same check guards the recharge-attempt annotation on already-paid orders.<\/li>\n<li>Compliance: recharge attempts on an already-paid order (Redirection Manual v3.1 \u00a77 Test Case 3, ResultCode 1048 \u2014 e.g. the customer presses Back and the cached payment form re-submits after the transaction was approved) are no longer silently discarded by the duplicate-callback guard. The attempt is now recorded as an order note with the storage set the manual mandates (SupportReferenceID, MerchantReference, ResultCode, ResultDescription) under dedicated <code>_epay_recharge_attempt_*<\/code> meta keys, and the customer sees \"This order has already been paid. Your new payment attempt was not processed and no additional charge was made.\" on the order-received page instead of no message. Order status and the approved transaction's audit meta remain untouched.<\/li>\n<\/ul>\n\n<h4>1.0.33<\/h4>\n\n<ul>\n<li>Security: the Paycenter transaction ticket (<code>TranTicket<\/code>) is no longer emitted in the browser redirect form. Per Redirection Manual v2.9 \u00a74 the ticket must never be visible to the user, and the Annex 1 sample form omits it. Because the ticket is the HMAC-SHA256 secret key used to authenticate the bank's success\/failure callback, exposing it in the hidden form allowed a shopper to compute a valid HashKey and forge a paid-status callback for their own order. The ticket is now kept server-side only (in <code>_epay_tran_ticket<\/code> order meta) and used solely for callback verification; the redirect form now carries exactly the fields listed in the manual (AcquirerId, MerchantId, PosId, User, LanguageCode, MerchantReference, ParamBackLink). Stores should update immediately and review recent Paycenter orders for any marked paid without a matching bank settlement.<\/li>\n<\/ul>\n\n<h4>1.0.32<\/h4>\n\n<ul>\n<li>Docs: added a Patchstack Vulnerability Disclosure Program (VDP) security-contact entry to the FAQ, giving security researchers a coordinated channel to report vulnerabilities (verification, CVE assignment, developer notification). No code, database, or payment-flow change.<\/li>\n<\/ul>\n\n<h4>1.0.31<\/h4>\n\n<ul>\n<li>Docs: readme Description trimmed to fit the wp.org 2,500-word limit (the 1.0.30 release was truncated on the public plugin page). The standalone <code>== WAF compatibility ==<\/code> section was rolled into two FAQ entries that cover the same operator scenarios (WAF blocking callbacks, \"-1\" troubleshooting) without per-vendor configuration snippets \u2014 those move to support docs. No code change; the in-admin \"Test callback URL\" diagnostic, callback envelope logging and URL normalisation features previously documented in that section all remain.<\/li>\n<\/ul>\n\n<h4>1.0.30<\/h4>\n\n<ul>\n<li>Feature: <strong>IRIS payments support<\/strong> per Redirection Manual v2.9. When Euronet Merchant Services enables IRIS on your merchant account, the bank's hosted page lets customers pay by IRIS instead of card; the plugin now recognises the IRIS response payload (<code>CardType=15<\/code> \/ <code>PaymentMethod=IRIS<\/code>), stores the payment channel on the order, and surfaces IRIS-tailored messages for the IRIS-only ResponseCodes 05 (user cancelled in their bank app), 06 (service error), 09 (initiated but not confirmed), 68 (5-minute QR-code timeout) and 70 (IRIS service unexpected error). HMAC-SHA256 HashKey verification applies to IRIS callbacks identically (the empty AuthStatus \/ PackageNo \/ TraceID fields are concatenated as empty strings per the manual). No payment-flow or callback-handler change for existing card transactions.<\/li>\n<li>Feature: <strong>customer-selectable installments on the classic WooCommerce checkout<\/strong>. The gateway now renders an \"Installments (interest-free)\" dropdown when installments are enabled and the cart total qualifies; the picked value is captured at order creation, persisted as <code>_epay_installments<\/code> order meta, and sent as the <code>Installments<\/code> parameter in the Ticketing request to Piraeus Bank.<\/li>\n<li>Feature: <strong>tiered max-installments by amount<\/strong> via a new admin setting \"Tiered max installments by amount (interest-free)\". Format <code>amount:max,amount:max,...<\/code> (e.g. <code>50:3, 100:6, 200:12<\/code>). Overrides the flat \"Maximum installments\" when set. Per Piraeus Bank policy all installments via this gateway are interest-free for the customer; the merchant absorbs the bank commission.<\/li>\n<li>Security: the customer-side dropdown is treated as untrusted. <code>process_payment()<\/code> always re-clamps the picked value against the merchant's tier policy evaluated for the live order total, and the SOAP ticket request re-clamps a second time as defence-in-depth. Tier-string parsing uses a strict regex; malformed segments are silently dropped instead of throwing.<\/li>\n<li>Internal: the existing <code>installments<\/code> checkbox + <code>max_installments<\/code> + <code>min_amount_for_installments<\/code> settings, previously cosmetic (the Ticketing request was hard-coded to <code>Installments=0<\/code>), are now wired up. <code>_epay_installments<\/code> order meta carries the value through the bank round-trip. Success order note now branches by payment channel \u2014 IRIS rows omit the empty PackageNo \/ TraceID columns that have no analogue in the DIAS instant-payment flow.<\/li>\n<li>Docs: readme Description, FAQ and Greek <code>readme-el.txt<\/code> companion updated with IRIS coverage; new section \"What sets this plugin apart\" surfaces the technical differentiators (HPOS-native, Cloudflare detection, WAF self-test, WP 7.0 audit, bilingual readme).<\/li>\n<li>Known limitation: the installments customer picker ships for classic WC checkout only. WooCommerce Blocks Checkout customers default to one-time payment (<code>Installments=1<\/code>, the bank's canonical \"no installments\" per Redirection Manual v2.9 \u00a74); the Blocks picker is scheduled for a follow-up release.<\/li>\n<\/ul>\n\n<h4>1.0.28<\/h4>\n\n<ul>\n<li>Compatibility: tested with WordPress 7.0 (released 2026-05-20). Verified that the gateway works on the new Modern admin theme, the iframed post editor changes do not affect WooCommerce Blocks checkout integration, and PHP 7.4+ requirement already meets the new core minimum.<\/li>\n<li>Docs: screenshot captions in readme corrected to match the actual images (bilingual EN\/EL).<\/li>\n<\/ul>\n\n<h4>1.0.27<\/h4>\n\n<ul>\n<li>UX: settings screen reordered \u2014 the \"Merchant credentials\" section now appears above the \"Bank integration data\" section, matching the natural onboarding flow (enter the credentials from Euronet first, then send the technical data back).<\/li>\n<li>UX: \"Bank integration data\" card and its Cloudflare detection sub-block are now collapsible (closed by default) to keep the settings screen compact after onboarding.<\/li>\n<li>UX: the five callback URLs (Website, Referrer, Success, Failure, Backlink) are consolidated into a single grey block with one \"Copy\" button, replacing the per-URL row layout.<\/li>\n<li>i18n: Greek translation added for the new \"Copy callback URLs to clipboard\" aria-label.<\/li>\n<li>Internal: aligned EPAY_PAYCENTER_VERSION constant with the plugin header (was lagging at 1.0.25, used by asset cache-busting and outbound User-Agent strings).<\/li>\n<\/ul>\n\n<h4>1.0.26<\/h4>\n\n<ul>\n<li>Compliance: invalid Plugin URI header removed per Plugin Review Team feedback. The URI is an optional header (https:\/\/developer.wordpress.org\/plugins\/plugin-basics\/header-requirements\/) and the previously declared page was not public. Author URI (https:\/\/webhosting4u.gr\/) is unchanged and reachable.<\/li>\n<\/ul>\n\n<h4>1.0.22<\/h4>\n\n<ul>\n<li>Fix: plugin folder and main file renamed to secure-card-gateway-for-epay-paycenter-piraeus-bank to match WP.org slug; resolves Plugin Check TextDomainMismatch on all i18n calls.<\/li>\n<li>Fix: UTF-8 BOM properly stripped from all PHP files (previous fix re-encoded U+FEFF as a BOM on write; correct method skips the 3 BOM bytes before decoding).<\/li>\n<\/ul>\n\n<h4>1.0.21<\/h4>\n\n<ul>\n<li>Fix (critical): TranTicket was missing from the redirect form POST to pay.aspx \u2014 every payment attempt would be rejected by the bank. Added to form_fields in output_receipt_page().<\/li>\n<li>Fix: apply_filters( epay_paycenter_icon ) pre-escaped the default URL violating escape-late; escaping now happens only at output.<\/li>\n<li>Fix: printf() with HTML link replaced with echo wp_kses_post( sprintf() ).<\/li>\n<li>Fix: is_cloudflare_proxied() now uses isset() + is_scalar() guards on CF_RAY \/ CF_CONNECTING_IP.<\/li>\n<li>Fix: phpcs:ignore added to dbDelta() SQL interpolation in create_tables().<\/li>\n<li>Cleanup: removed orphaned docblock for deleted collect_attempt_stats().<\/li>\n<\/ul>\n\n<h4>1.0.20<\/h4>\n\n<ul>\n<li>Compliance: text domain corrected from wh4u-* to secure-card-gateway-for-epay-paycenter-piraeus-bank to match WP.org slug. All 179 i18n strings updated; language files renamed.<\/li>\n<li>Compliance: echo generate_settings_html() kept as phpcs:ignore with explanatory comment; wp_kses_post() wrap broke WooCommerce form attributes.<\/li>\n<li>Security: enqueue_admin_settings_assets() now checks current_user_can( manage_woocommerce ) before reading  args.<\/li>\n<li>External services: Cloudflare IPv4 fetch documented in readme with terms \/ privacy links.<\/li>\n<\/ul>\n\n<h4>1.0.19<\/h4>\n\n<ul>\n<li>Compliance: plugin renamed to WebHosting4U Secure Card Gateway for ePay Paycenter (Piraeus Bank); slug wh4u-* per Guideline 17. External services section fully documented with terms \/ privacy links. Deprecated libxml_disable_entity_loader() removed.<\/li>\n<\/ul>\n\n<h4>1.0.18<\/h4>\n\n<ul>\n<li>UI: checkout icon changed from piraeus.svg to responsive wp-cards.png. Block checkout now shows card brands. Front-end CSS enqueued on checkout.<\/li>\n<\/ul>\n\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>Localisation: Greek translation backfilled with all strings from 1.0.10-1.0.16. POT regenerated.<\/li>\n<\/ul>\n\n<h4>1.0.16<\/h4>\n\n<ul>\n<li>Fix: decline notice not appearing after bank redirect. Hook priority collision with WooCommerce core resolved (priority 5 vs core 10).<\/li>\n<\/ul>\n\n<h4>1.0.15<\/h4>\n\n<ul>\n<li>Compliance: failure handler aligned row-by-row with Redirection Manual v2.9 section 5 scenario table. Fixes misleading ResultCode 1048 message; widens 50x matching to 500-599.<\/li>\n<\/ul>\n\n<h4>1.0.14<\/h4>\n\n<ul>\n<li>Fix: decline message lost after bank redirect due to SameSite=Lax session-cookie stripping. Notices now queued as order-scoped transients (session-independent delivery).<\/li>\n<\/ul>\n\n<h4>1.0.13<\/h4>\n\n<ul>\n<li>Fix: -1 body when Success\/Failure URL is doubled in the Euronet portal. Malformed wc-api values normalised at parse_request.<\/li>\n<\/ul>\n\n<h4>1.0.12<\/h4>\n\n<ul>\n<li>Declined-transaction handling per Redirection Manual v2.9 section 5. Failure redirect now targets pay-for-order URL. Fixes -1 body via plugins_loaded binding.<\/li>\n<\/ul>\n\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Admin diagnostics: Test callback URL button detects host WAF interception before live payments.<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Logging: Callback envelope INFO line written on every callback reach for WAF\/plugin-reject disambiguation.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Independent WooCommerce gateway by WebHosting4U for the ePay Paycenter (Piraeus Bank \/ Euronet Merchant Services) Redirection service.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/304109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=304109"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/webhosting4ugr"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=304109"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=304109"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=304109"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=304109"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=304109"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=304109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}