{"id":353226,"date":"2026-08-25T04:55:48","date_gmt":"2026-08-25T04:55:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/agentops-review\/"},"modified":"2026-08-25T04:55:15","modified_gmt":"2026-08-25T04:55:15","slug":"hitlgate-order-review","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/hitlgate-order-review\/","author":23548532,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.4","requires":"6.9","requires_php":"8.1","requires_plugins":null,"header_name":"HitlGate Order Review for WooCommerce","header_author":"mike36292","header_description":"Human-in-the-loop order review for WooCommerce high-risk and high-AOV orders.","assets_banners_color":"637178","last_updated":"2026-08-25 04:55:15","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/github.com\/mikeliu7778","rating":0,"author_block_rating":0,"active_installs":0,"downloads":40,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"mike36292","date":"2026-08-25 04:55:15"}},"upgrade_notice":{"1.0.2":"<p>Natural-language settings now require an AI provider under Settings \u2192 Connectors. Direct LLM API key fields were removed.<\/p>","1.0.1":"<p>Plugin Check and review follow-up fixes. Safe to update from 1.0.0.<\/p>","1.0.0":"<p>Initial public release. Configure intake thresholds after activation.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3664561,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3664561,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3664561,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3664561,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3664561,"resolution":"1","location":"assets","locale":"","width":1280,"height":720},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3664561,"resolution":"2","location":"assets","locale":"","width":1280,"height":720},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3664561,"resolution":"3","location":"assets","locale":"","width":1280,"height":720},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3664561,"resolution":"4","location":"assets","locale":"","width":1280,"height":720},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3664561,"resolution":"5","location":"assets","locale":"","width":1280,"height":720}},"screenshots":{"1":"Review queue listing pending high-risk orders.","2":"Order metabox showing a masked evidence pack.","3":"Confirm gate flow for draft cancel or partial refund.","4":"Settings screen for intake thresholds and token TTL.","5":"Optional MCP \/ Abilities tool flow for agent-assisted review."}},"plugin_section":[],"plugin_tags":[132861,277346,242115,21473,286],"plugin_category":[45],"plugin_contributors":[277347],"plugin_business_model":[],"class_list":["post-353226","plugin","type-plugin","status-publish","hentry","plugin_tags-fraud-prevention","plugin_tags-human-in-the-loop","plugin_tags-mcp","plugin_tags-order-management","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-mike36292","plugin_committers-mike36292"],"banners":{"banner":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/banner-772x250.png?rev=3664561","banner_2x":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/banner-1544x500.png?rev=3664561","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/icon-128x128.png?rev=3664561","icon_2x":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/icon-256x256.png?rev=3664561","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/screenshot-1.png?rev=3664561","caption":"Review queue listing pending high-risk orders."},{"src":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/screenshot-2.png?rev=3664561","caption":"Order metabox showing a masked evidence pack."},{"src":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/screenshot-3.png?rev=3664561","caption":"Confirm gate flow for draft cancel or partial refund."},{"src":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/screenshot-4.png?rev=3664561","caption":"Settings screen for intake thresholds and token TTL."},{"src":"https:\/\/ps.w.org\/hitlgate-order-review\/assets\/screenshot-5.png?rev=3664561","caption":"Optional MCP \/ Abilities tool flow for agent-assisted review."}],"raw_content":"<!--section=description-->\n<p>HitlGate Order Review for WooCommerce helps store operators pause and review risky WooCommerce orders before fulfillment or money-moving actions.<\/p>\n\n<p>This plugin is not affiliated with AgentOps (agentops.ai), WordPress, WooCommerce, or Automattic.<\/p>\n\n<p><strong>Core HITL (works without any required external SaaS)<\/strong><\/p>\n\n<ul>\n<li>Intake thresholds enqueue orders (minimum amount, AOV spike, optional gateway risk meta, force meta).<\/li>\n<li>Masked evidence packs for reviewers (PII redacted where applicable).<\/li>\n<li>Admin queue under <strong>WooCommerce \u2192 HitlGate Order Review<\/strong>.<\/li>\n<li>Money-moving actions (cancel, partial refund) use a single-use confirm token and the <code>agentops_confirm_money<\/code> capability.<\/li>\n<li>Intake is fail-open: exceptions are logged and never block checkout.<\/li>\n<\/ul>\n\n<p><strong>Optional integrations<\/strong><\/p>\n\n<ul>\n<li><strong>WooCommerce MCP \/ WordPress Abilities<\/strong> \u2014 expose review tools to Cursor\/Claude when Woo MCP is enabled.<\/li>\n<li><strong>Natural-language settings<\/strong> \u2014 optional; uses the WordPress AI Client \/ Connectors (no direct third-party API keys in this plugin).<\/li>\n<li><strong>Readiness connector<\/strong> \u2014 optional inbound HMAC webhook to store a catalog readiness summary.<\/li>\n<li><strong>WooCommerce Subscriptions<\/strong> \u2014 soft dependency for failed renewal \/ on-hold enqueue and confirm-gated pause\/cancel.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin can optionally connect to third-party services. Core order review does <strong>not<\/strong> require any external service.<\/p>\n\n<h4>WordPress AI Client \/ Connectors (optional)<\/h4>\n\n<p>Used only if you use natural-language settings proposals.<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Turning a plain-language settings request into a proposed settings diff for you to preview and confirm.<\/li>\n<li><strong>What data is sent:<\/strong> The settings schema description and your natural-language prompt are sent through the WordPress AI Client to whichever AI provider you configured under <strong>Settings \u2192 Connectors<\/strong>. Order customer PII is not sent by this feature.<\/li>\n<li><strong>When:<\/strong> Only when an administrator submits a natural-language settings proposal.<\/li>\n<li><strong>Default:<\/strong> No AI provider is called until you configure a connector (for example OpenAI, Anthropic, or Google provider plugins) under Settings \u2192 Connectors. This plugin does <strong>not<\/strong> store third-party AI API keys or call provider endpoints directly.<\/li>\n<li>Follow the terms and privacy policy of the AI provider you connect via Connectors.<\/li>\n<\/ul>\n\n<h4>Optional readiness summary webhook (optional)<\/h4>\n\n<p>If you configure a webhook secret, an external readiness scanner you control may POST a catalog readiness summary into your site.<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Showing a readiness score in evidence packs and optionally influencing intake when you lower the critical-SKU threshold.<\/li>\n<li><strong>What data is sent:<\/strong> Your site does not initiate outbound catalog scans from this plugin. The external service (if you use one) may read public\/product data according to that service\u2019s own setup; this plugin only accepts an inbound signed summary.<\/li>\n<li><strong>When:<\/strong> When the configured service posts to <code>\/wp-json\/agentops\/v1\/readiness-summary<\/code>.<\/li>\n<li>Document the terms and privacy policy of whichever readiness service you connect. This plugin does not require a specific vendor.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>hitlgate-order-review<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install the zip via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>).<\/li>\n<li>The release zip already includes Composer autoload under <code>vendor\/<\/code> \u2014 you do <strong>not<\/strong> need to run <code>composer install<\/code> on the server.<\/li>\n<li>Activate <strong>WooCommerce<\/strong>, then activate <strong>HitlGate Order Review for WooCommerce<\/strong>.<\/li>\n<li>Administrators receive the <code>agentops_confirm_money<\/code> capability on activation.<\/li>\n<li>Open <strong>WooCommerce \u2192 HitlGate Order Review \u2192 Settings<\/strong> and set intake thresholds.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20require%20an%20external%20saas%3F\"><h3>Does this plugin require an external SaaS?<\/h3><\/dt>\n<dd><p>No. Core human-in-the-loop review works plugin-only. Natural-language settings use the WordPress AI Client if you configure a provider under Settings \u2192 Connectors. The readiness webhook is optional.<\/p><\/dd>\n<dt id=\"what%20are%20the%20requirements%3F\"><h3>What are the requirements?<\/h3><\/dt>\n<dd><p>WordPress 6.9+, PHP 8.1+, and WooCommerce 10.3+. WooCommerce Subscriptions is optional.<\/p><\/dd>\n<dt id=\"who%20can%20confirm%20cancel%20or%20refund%20actions%3F\"><h3>Who can confirm cancel or refund actions?<\/h3><\/dt>\n<dd><p>Users with the <code>agentops_confirm_money<\/code> capability (granted to administrators on activation).<\/p><\/dd>\n<dt id=\"does%20uninstall%20delete%20my%20data%3F\"><h3>Does uninstall delete my data?<\/h3><\/dt>\n<dd><p>By default, uninstall keeps plugin tables and options. To drop data on uninstall, set option <code>agentops_remove_data<\/code> to a truthy value first (example: <code>wp option update agentops_remove_data 1<\/code>).<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20my%20site%3F\"><h3>What data leaves my site?<\/h3><\/dt>\n<dd><p>By default, none for core HITL. If you use natural-language settings, prompts are sent via the WordPress AI Client to the provider configured under Settings \u2192 Connectors. See <strong>External services<\/strong>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20use%20mcp%20%2F%20cursor%3F\"><h3>How do I use MCP \/ Cursor?<\/h3><\/dt>\n<dd><p>Enable WooCommerce MCP per WooCommerce docs, point your MCP client at the store endpoint, then use the registered abilities (list queue, evidence, draft cancel\/refund, confirm-action, settings propose\/apply).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Natural-language settings now use the WordPress AI Client \/ Connectors instead of a direct third-party HTTP client.<\/li>\n<li>Removed plugin settings fields for LLM base URL, model, and API key.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Plugin Check fixes: output escaping, prepared SQL claim path, ABSPATH guard.<\/li>\n<li>WordPress.org review follow-up packaging.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First WordPress.org submission as HitlGate Order Review for WooCommerce.<\/li>\n<li>Human-in-the-loop intake, review queue, masked evidence packs, and Admin UI.<\/li>\n<li>Confirm-token gate for cancel and partial refund.<\/li>\n<li>Optional readiness HMAC webhook connector.<\/li>\n<li>Optional natural-language settings propose \u2192 apply.<\/li>\n<li>Optional WooCommerce Subscriptions HITL.<\/li>\n<li>Public abilities for WooCommerce MCP clients.<\/li>\n<\/ul>","raw_excerpt":"Human-in-the-loop review queue for WooCommerce high-risk and high-AOV orders.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353226"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mike36292"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353226"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353226"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353226"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353226"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353226"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}