{"id":366941,"date":"2026-09-16T06:09:18","date_gmt":"2026-09-16T06:09:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/passwordless-checkout-webequipe\/"},"modified":"2026-09-16T06:55:14","modified_gmt":"2026-09-16T06:55:14","slug":"webequipe-passwordless-checkout","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/webequipe-passwordless-checkout\/","author":23354821,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"WebEquipe Passwordless Checkout for WooCommerce","header_author":"WebEquipe","header_description":"WooCommerce passwordless checkout \u2014 no forced login, no duplicate accounts. Guest orders auto-link to customer accounts. Magic-link login included.","assets_banners_color":"ece4fb","last_updated":"2026-09-16 06:55:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/webequipe.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":48,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"webequipe","date":"2026-09-16 06:55:14","revision":3698029}},"upgrade_notice":{"1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697971,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697971,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697971,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697971,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3697971,"resolution":"1","location":"assets","locale":"","width":1440,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3697971,"resolution":"2","location":"assets","locale":"","width":1440,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3697971,"resolution":"3","location":"assets","locale":"","width":1440,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3697971,"resolution":"4","location":"assets","locale":"","width":1440,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3697971,"resolution":"5","location":"assets","locale":"","width":5760,"height":3200}},"screenshots":{"1":"My Account login screen \u2014 customers enter only their email and get a secure login link; no password fields.","2":"General settings \u2014 turn on auto-link\/auto-register, enable Blocks checkout support, choose login experience mode, and toggle logging.","3":"Magic Link settings \u2014 set login link expiry, payment-link access days, guest order-view days, and rate-limit rules.","4":"Merge Customer Accounts \u2014 search two accounts by email, review details, and merge the secondary account's orders into the primary account.","5":"Email Template settings \u2014 customize the magic-link email subject and body using placeholders like {magic_link} and {site_name}."}},"plugin_section":[],"plugin_tags":[3148,243450,185112,9223,286],"plugin_category":[45],"plugin_contributors":[259509,254575],"plugin_business_model":[],"class_list":["post-366941","plugin","type-plugin","status-publish","hentry","plugin_tags-checkout","plugin_tags-guest-checkout","plugin_tags-magic-link","plugin_tags-passwordless","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-bdsarwar","plugin_contributors-webequipe","plugin_committers-bdsarwar","plugin_committers-webequipe"],"banners":{"banner":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/banner-772x250.png?rev=3697971","banner_2x":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/banner-1544x500.png?rev=3697971","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/icon-128x128.png?rev=3697971","icon_2x":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/icon-256x256.png?rev=3697971","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/screenshot-1.png?rev=3697971","caption":"My Account login screen \u2014 customers enter only their email and get a secure login link; no password fields."},{"src":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/screenshot-2.png?rev=3697971","caption":"General settings \u2014 turn on auto-link\/auto-register, enable Blocks checkout support, choose login experience mode, and toggle logging."},{"src":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/screenshot-3.png?rev=3697971","caption":"Magic Link settings \u2014 set login link expiry, payment-link access days, guest order-view days, and rate-limit rules."},{"src":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/screenshot-4.png?rev=3697971","caption":"Merge Customer Accounts \u2014 search two accounts by email, review details, and merge the secondary account's orders into the primary account."},{"src":"https:\/\/ps.w.org\/webequipe-passwordless-checkout\/assets\/screenshot-5.png?rev=3697971","caption":"Email Template settings \u2014 customize the magic-link email subject and body using placeholders like {magic_link} and {site_name}."}],"raw_content":"<!--section=description-->\n<p><strong>Passwordless Checkout<\/strong> removes the two biggest sources of checkout drop-off: forced login and duplicate customer accounts.<\/p>\n\n<p>When a guest places an order, the plugin silently detects the billing email and links the order to the matching customer account \u2014 or creates one \u2014 <strong>without asking the customer to log in or set a password<\/strong>. Later, they access their account via a single-use, expiring <strong>magic login link<\/strong> sent to their email.<\/p>\n\n<p>No external services. No tracking. All tokens are generated with a cryptographically secure random generator, stored hashed, and expire automatically.<\/p>\n\n<h4>What it solves<\/h4>\n\n<p><strong>Problem 1 \u2014 Checkout drop-off from forced login.<\/strong>\nWooCommerce can require login before checkout. Customers abandon rather than remember a password. This plugin lets anyone check out as a guest while still creating (or linking to) a real customer account in the background.<\/p>\n\n<p><strong>Problem 2 \u2014 Duplicate customer accounts.<\/strong>\nWhen the same customer checks out multiple times with different guest sessions, WooCommerce can create a new account each time. This plugin detects the email and reuses the existing account \u2014 one email, one customer, always.<\/p>\n\n<p><strong>Problem 3 \u2014 Password friction on My Account.<\/strong>\nCustomers who can't remember their password hit a wall at login. This plugin replaces the WooCommerce login form with an email field + \"Send Login Link\" button. One click, no password.<\/p>\n\n<h4>Key features<\/h4>\n\n<ul>\n<li><strong>Auto order linking<\/strong> \u2014 guest orders linked to the matching account by billing email.<\/li>\n<li><strong>Auto registration<\/strong> \u2014 new accounts created silently; no password prompt, no credentials email.<\/li>\n<li><strong>Duplicate prevention<\/strong> \u2014 one email always maps to one customer account.<\/li>\n<li><strong>Magic link login<\/strong> \u2014 single-use, expiring links (default 30 min); rate-limited to prevent abuse.<\/li>\n<li><strong>Guest order view<\/strong> \u2014 expiring token links in order emails let guests view their order without logging in.<\/li>\n<li><strong>Invoice \/ payment link access<\/strong> \u2014 customers can pay custom orders without logging in (within a configurable window from order creation).<\/li>\n<li><strong>Passwordless login UI<\/strong> \u2014 choose how customers log in: passwordless only (email-only \"Send Login Link\" form), both (standard password form plus the login link), or password only.<\/li>\n<li><strong>Admin merge tool<\/strong> \u2014 WooCommerce \u2192 Passwordless Checkout \u2192 Merge Customer Accounts: find duplicates, preview, merge.<\/li>\n<li><strong>WooCommerce Blocks support<\/strong> \u2014 works with both classic shortcode and Block-based checkout.<\/li>\n<li><strong>HPOS compatible<\/strong> \u2014 fully supports High-Performance Order Storage.<\/li>\n<li><strong>Logging<\/strong> \u2014 optional, via the built-in WooCommerce logger (WooCommerce \u2192 Status \u2192 Logs).<\/li>\n<\/ul>\n\n<h4>Getting started (about 2 minutes)<\/h4>\n\n<ol>\n<li>Activate the plugin (WooCommerce must already be active).<\/li>\n<li>Open <strong>WooCommerce \u2192 Passwordless Checkout<\/strong>.<\/li>\n<li>Review the General tab (defaults are already enabled) and click <strong>Save Changes<\/strong>.<\/li>\n<li>Optionally adjust Magic Link expiry \/ rate limits and the email template.<\/li>\n<li>Place a test guest order \u2014 it should appear linked to a customer account under <strong>WooCommerce \u2192 Orders<\/strong>.<\/li>\n<li>Open My Account while logged out and request a login link to verify email delivery.<\/li>\n<\/ol>\n\n<h4>Privacy &amp; security<\/h4>\n\n<ul>\n<li>No external requests, tracking, or data sharing \u2014 everything runs on your own server.<\/li>\n<li>Tokens use <code>random_bytes()<\/code> (CSPRNG), are stored hashed with <code>wp_hash()<\/code>, are single-use, and expire automatically.<\/li>\n<li>Constant-time comparison (<code>hash_equals()<\/code>) prevents timing attacks.<\/li>\n<li>Nonces and capability checks protect every form and admin action.<\/li>\n<li>Magic link requests return a neutral response to prevent account enumeration.<\/li>\n<li>Optional logs mask email addresses and focus on order\/user IDs.<\/li>\n<li>A privacy-policy suggestion is registered under <strong>Settings \u2192 Privacy<\/strong> for store owners.<\/li>\n<\/ul>\n\n<p>This plugin does <strong>not<\/strong> connect to third-party APIs. Email is sent through your WordPress \/ WooCommerce mail configuration (<code>wp_mail()<\/code>).<\/p>\n\n<h3>Troubleshooting<\/h3>\n\n<h4>Magic login link returns 404<\/h4>\n\n<p>Go to <strong>Settings \u2192 Permalinks<\/strong> and click <strong>Save Changes<\/strong> once to flush rewrite rules, then try the link again.<\/p>\n\n<h4>Login link email never arrives<\/h4>\n\n<ol>\n<li>Confirm magic links are enabled (<strong>Login Experience<\/strong> is not set to \"Password only\").<\/li>\n<li>Check spam\/junk folders.<\/li>\n<li>Verify WordPress can send mail (use your existing SMTP \/ WooCommerce email setup).<\/li>\n<li>With logging enabled, check <strong>WooCommerce \u2192 Status \u2192 Logs<\/strong> for send success\/failure entries.<\/li>\n<\/ol>\n\n<h4>Guest order is still not linked to a customer<\/h4>\n\n<ol>\n<li>Confirm <strong>Auto-Link \/ Auto-Register<\/strong> is enabled.<\/li>\n<li>Confirm the order has a valid billing email.<\/li>\n<li>For block checkout, confirm <strong>Blocks Checkout Support<\/strong> is enabled.<\/li>\n<li>Review logs for resolution errors.<\/li>\n<\/ol>\n\n<h4>\"Too many login links\" message<\/h4>\n\n<p>Wait for the rate-limit window to expire, or raise the limits under <strong>Magic Link<\/strong> settings.<\/p>\n\n<h4>Uninstall cleanup<\/h4>\n\n<p>Deleting the plugin through the WordPress admin removes plugin options, related user meta, and related order meta. Short-lived hashed rate-limit transients expire on their own (their names cannot be listed without a direct database query). Customer accounts and orders themselves are never deleted by uninstall.<\/p>\n\n<!--section=installation-->\n<p><strong>From the WordPress admin:<\/strong><\/p>\n\n<ol>\n<li>Go to <strong>Plugins \u2192 Add New<\/strong>.<\/li>\n<li>Search for \"WebEquipe Passwordless Checkout\".<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<li>Go to <strong>WooCommerce \u2192 Passwordless Checkout<\/strong> and click <strong>Save Changes<\/strong>.<\/li>\n<\/ol>\n\n<p><strong>Manual installation:<\/strong><\/p>\n\n<ol>\n<li>Download the plugin zip.<\/li>\n<li>Go to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Upload the zip and activate.<\/li>\n<li>Go to <strong>WooCommerce \u2192 Passwordless Checkout<\/strong> and click <strong>Save Changes<\/strong>.<\/li>\n<\/ol>\n\n<p><strong>Requirements:<\/strong> WooCommerce must be installed and active.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20require%20woocommerce%3F\"><h3>Does this require WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. WooCommerce must be installed and active. The plugin will not activate without it.<\/p><\/dd>\n<dt id=\"will%20it%20interfere%20with%20my%20existing%20customers%20or%20orders%3F\"><h3>Will it interfere with my existing customers or orders?<\/h3><\/dt>\n<dd><p>No. Activating the plugin does not rewrite existing orders, customers, or settings. It acts at checkout, on My Account login, in order emails (guest order view and payment links), and via the admin merge tool.<\/p><\/dd>\n<dt id=\"are%20passwords%20ever%20sent%20to%20customers%3F\"><h3>Are passwords ever sent to customers?<\/h3><\/dt>\n<dd><p>Never. The plugin does not generate, display, or email passwords or credential setup links. Customers log in only via magic links (when enabled).<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20the%20block-based%20checkout%3F\"><h3>Does it work with the block-based checkout?<\/h3><\/dt>\n<dd><p>Yes. Both the classic (shortcode) checkout and the WooCommerce Blocks (Store API) checkout are fully supported.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20customer%20uses%20a%20different%20email%20address%3F\"><h3>What happens if a customer uses a different email address?<\/h3><\/dt>\n<dd><p>The plugin matches by billing email only. If a customer uses a different email at checkout, a new account is created for that email. You can merge accounts later using <strong>WooCommerce \u2192 Passwordless Checkout \u2192 Merge Customer Accounts<\/strong>.<\/p><\/dd>\n<dt id=\"how%20long%20do%20magic%20links%20last%3F\"><h3>How long do magic links last?<\/h3><\/dt>\n<dd><p>By default, 30 minutes. You can change this under <strong>WooCommerce \u2192 Passwordless Checkout \u2192 Magic Link<\/strong>. Links are single-use \u2014 clicking them a second time will show an expired message.<\/p><\/dd>\n<dt id=\"what%20is%20the%20rate%20limit%20on%20magic%20link%20requests%3F\"><h3>What is the rate limit on magic link requests?<\/h3><\/dt>\n<dd><p>By default, a maximum of 3 requests per 15-minute window per email address. Both values are configurable in the settings.<\/p><\/dd>\n<dt id=\"where%20do%20i%20find%20the%20logs%3F\"><h3>Where do I find the logs?<\/h3><\/dt>\n<dd><p>Enable logging under <strong>WooCommerce \u2192 Passwordless Checkout \u2192 General<\/strong>, then find entries under <strong>WooCommerce \u2192 Status \u2192 Logs<\/strong> with the source <code>webequipe-passwordless-checkout<\/code>.<\/p><\/dd>\n<dt id=\"does%20the%20guest%20order-view%20link%20expire%3F\"><h3>Does the guest order-view link expire?<\/h3><\/dt>\n<dd><p>Yes. By default, the \"View your order\" link included in order emails expires after 7 days. After expiry, the page shows an expired message and a link to My Account. The expiry duration is configurable.<\/p><\/dd>\n<dt id=\"is%20it%20hpos%20compatible%3F\"><h3>Is it HPOS compatible?<\/h3><\/dt>\n<dd><p>Yes. The plugin declares High-Performance Order Storage compatibility and stores order meta through the WooCommerce order APIs (HPOS-aware).<\/p><\/dd>\n<dt id=\"will%20this%20cause%20issues%20with%20caching%20plugins%3F\"><h3>Will this cause issues with caching plugins?<\/h3><\/dt>\n<dd><p>Magic link URLs and order-view URLs use query parameters, which most page caching plugins bypass by default. If you experience issues, exclude URLs containing <code>weplc_magic_login<\/code> and <code>weplc_order_view<\/code> from your cache.<\/p><\/dd>\n<dt id=\"how%20does%20the%20admin%20merge%20tool%20work%3F\"><h3>How does the admin merge tool work?<\/h3><\/dt>\n<dd><p>Go to <strong>WooCommerce \u2192 Passwordless Checkout \u2192 Merge Customer Accounts<\/strong>. Search two email addresses, preview both accounts (name, order count, registration date), confirm, and the plugin moves all orders from the secondary account to the primary, backfills any missing address data, and deletes the secondary user. The action requires <code>manage_woocommerce<\/code> capability and a nonce confirmation.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20use%20shortcodes%20or%20blocks%3F\"><h3>Does this plugin use shortcodes or blocks?<\/h3><\/dt>\n<dd><p>No shortcodes are registered. The plugin integrates with WooCommerce checkout (classic and Blocks) and the My Account login form automatically.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release.<\/li>\n<li>Email-based customer detection at checkout (case-insensitive, classic + Blocks).<\/li>\n<li>Auto order linking to existing customer accounts by billing email.<\/li>\n<li>Auto registration of new customers \u2014 no password shown, no credentials emailed.<\/li>\n<li>Duplicate account prevention \u2014 one email always maps to one account.<\/li>\n<li>WooCommerce Blocks (Store API) support via <code>woocommerce_store_api_checkout_order_processed<\/code>.<\/li>\n<li>HPOS (High-Performance Order Storage) compatibility declared.<\/li>\n<li>Passwordless magic link login \u2014 single-use, expiring tokens (default 30 min), CSPRNG + hashed storage.<\/li>\n<li>Rate limiting for magic link requests \u2014 configurable per-email window and max count.<\/li>\n<li>Guest order-view tokens in order emails \u2014 read-only order page, no login required.<\/li>\n<li>Password-free access for custom order \/ invoice payment links (order key authorization, no login session).<\/li>\n<li>Passwordless login UI \u2014 selectable login experience (passwordless only, both, or password only) on the My Account login form.<\/li>\n<li>Customizable magic link email \u2014 subject, body, and placeholders (<code>{magic_link}<\/code>, <code>{site_name}<\/code>, <code>{customer_name}<\/code>).<\/li>\n<li>Admin merge accounts tool \u2014 search, preview, confirm, merge, with nonce and capability protection.<\/li>\n<li>Admin tabbed settings \u2014 General \/ Magic Link \/ Merge Customer Accounts \/ Email Template.<\/li>\n<li>Logging via the WooCommerce logger \u2014 activity log for detection, linking, registration, and magic link lifecycle.<\/li>\n<li>Daily cron cleanup of expired tokens.<\/li>\n<li>Full uninstall cleanup \u2014 all plugin options, user meta, and order meta removed on uninstall.<\/li>\n<\/ul>","raw_excerpt":"WooCommerce passwordless checkout \u2014 no forced login, no duplicate accounts. Guest orders auto-link to customer accounts. Magic-link login included.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/366941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=366941"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/webequipe"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=366941"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=366941"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=366941"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=366941"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=366941"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=366941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}