{"id":374572,"date":"2026-09-25T17:30:18","date_gmt":"2026-09-25T17:30:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/quick-cod-order-confirmation-for-woocommerce\/"},"modified":"2026-09-25T17:30:05","modified_gmt":"2026-09-25T17:30:05","slug":"sazcod-order-confirmation-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sazcod-order-confirmation-for-woocommerce\/","author":23561562,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.1.2","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"SazCOD \u2013 COD Order Confirmation for WooCommerce","header_author":"Sazonov Studio","header_description":"Intercepts Cash on Delivery orders, places them in \"Awaiting Confirmation\", and lets customers confirm via a secure bearer link before warehouse dispatch.","assets_banners_color":"0b181d","last_updated":"2026-09-25 17:30:05","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":56,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"alexsazonov","date":"2026-09-25 17:30:05","revision":3713381}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3713381,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3713381,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3713381,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3713381,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3713381,"resolution":"1","location":"assets","locale":"","width":1024,"height":440},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3713381,"resolution":"2","location":"assets","locale":"","width":1024,"height":440},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3713381,"resolution":"3","location":"assets","locale":"","width":1024,"height":440},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3713381,"resolution":"4","location":"assets","locale":"","width":1024,"height":440},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3713381,"resolution":"5","location":"assets","locale":"","width":1024,"height":440}},"screenshots":{"1":"Cash on Delivery confirmation banner on the Order Received page.","2":"Dedicated secure customer confirmation screen.","3":"Confirmation success screen with single-use opaque result token.","4":"Real-time order status transition to Processing in WooCommerce admin.","5":"Chronological order audit trail in WooCommerce order notes."}},"plugin_section":[],"plugin_tags":[31179,31178,278208,226324,286],"plugin_category":[45],"plugin_contributors":[281453],"plugin_business_model":[],"class_list":["post-374572","plugin","type-plugin","status-publish","hentry","plugin_tags-cash-on-delivery","plugin_tags-cod","plugin_tags-fake-order-protection","plugin_tags-order-confirmation","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-alexsazonov","plugin_committers-alexsazonov"],"banners":{"banner":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/banner-772x250.png?rev=3713381","banner_2x":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/banner-1544x500.png?rev=3713381","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/icon-128x128.png?rev=3713381","icon_2x":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/icon-256x256.png?rev=3713381","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/screenshot-1.png?rev=3713381","caption":"Cash on Delivery confirmation banner on the Order Received page."},{"src":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/screenshot-2.png?rev=3713381","caption":"Dedicated secure customer confirmation screen."},{"src":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/screenshot-3.png?rev=3713381","caption":"Confirmation success screen with single-use opaque result token."},{"src":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/screenshot-4.png?rev=3713381","caption":"Real-time order status transition to Processing in WooCommerce admin."},{"src":"https:\/\/ps.w.org\/sazcod-order-confirmation-for-woocommerce\/assets\/screenshot-5.png?rev=3713381","caption":"Chronological order audit trail in WooCommerce order notes."}],"raw_content":"<!--section=description-->\n<p>Cash on Delivery (COD) is essential for e-commerce growth in many regions, but fraudulent orders, impulsive checkouts, and wrong delivery addresses cost merchants substantial fulfillment and return shipping fees.<\/p>\n\n<p><strong>SazCOD \u2013 COD Order Confirmation for WooCommerce<\/strong> is a lightweight, 100% self-hosted plugin that automatically intercepts COD orders containing physical goods and places them into a custom status: <strong>Awaiting Confirmation<\/strong>.<\/p>\n\n<p>The buyer receives an actionable confirmation block in their order email. Clicking the link takes the customer to a secure verification screen where they explicitly confirm their order. Once confirmed, the order instantly transitions to <strong>Processing<\/strong> so your warehouse can safely begin packing.<\/p>\n\n<h3>Key Features<\/h3>\n\n<ul>\n<li><strong>Zero External Dependencies<\/strong>: 100% self-hosted. No external APIs, SMS gateways, or recurring subscriptions.<\/li>\n<li><strong>WooCommerce HPOS Compatible<\/strong>: Fully compatible with High-Performance Order Storage (<code>custom_order_tables<\/code>).<\/li>\n<li><strong>Block Checkout &amp; Classic Checkout Support<\/strong>: Intercepts COD orders across both WooCommerce Checkout Block (Store API) and classic shortcode checkouts.<\/li>\n<li><strong>Smart Physical Goods Detection<\/strong>: Only intercepts orders requiring physical shipping; virtual and digital orders pass through normally.<\/li>\n<li><strong>Hardened Token Security Architecture<\/strong>:\n\n<ul>\n<li>Cryptographically random, SHA-256 hashed tokens bound to the unique order.<\/li>\n<li>Encrypted at rest using AEAD AES-256-GCM with order-bound additional authenticated data (<code>v1:{order_id}<\/code>).<\/li>\n<li>Strict anti-cache headers (<code>Cache-Control: no-store, no-cache<\/code>) to prevent intermediate caching of confirmation screens.<\/li>\n<li>Synchronized 48-hour WordPress nonce lifetime matching the token TTL.<\/li>\n<li>Pre-commit business guards verifying COD payment method, awaiting-confirm status, and token hash.<\/li>\n<li>Sequential token revocation and native WooCommerce order state machine transitions to eliminate double-confirmation races.<\/li>\n<li>Post\/Redirect\/Get (PRG) flow with single-use opaque result tokens to eliminate order status enumeration.<\/li>\n<li>Strict Content Security Policy (<code>default-src 'none'<\/code>), Referrer-Policy, and anti-tampering checks.<\/li>\n<\/ul><\/li>\n<li><strong>Responsive, Clean UI<\/strong>: Mobile-friendly confirmation screen rendered using native styles without heavy frontend libraries.<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<p>The plugin does not transmit customer order data to external services or third-party servers. It stores only confirmation-related metadata (<code>_qcoc_confirmed_at<\/code>) in the local WooCommerce order. Customer information displayed on the self-hosted confirmation screen is retrieved directly from the merchant's local WordPress database.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/sazcod-order-confirmation-for-woocommerce<\/code> directory, or install the plugin directly through the WordPress plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Ensure Cash on Delivery (COD) is enabled in <strong>WooCommerce &gt; Settings &gt; Payments<\/strong>.<\/li>\n<li>Test with a physical product checkout using Cash on Delivery.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20require%20an%20external%20service%20or%20api%20key%3F\"><h3>Does this plugin require an external service or API key?<\/h3><\/dt>\n<dd><p>No. The plugin is 100% self-hosted on your WordPress server. No third-party accounts, APIs, or ongoing fees are required.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20virtual%20or%20downloadable%20orders%3F\"><h3>What happens to virtual or downloadable orders?<\/h3><\/dt>\n<dd><p>Orders containing only virtual or downloadable items bypass the confirmation flow automatically and proceed to standard processing.<\/p><\/dd>\n<dt id=\"how%20long%20is%20a%20confirmation%20link%20valid%3F\"><h3>How long is a confirmation link valid?<\/h3><\/dt>\n<dd><p>By default, confirmation tokens remain valid for 48 hours.<\/p><\/dd>\n<dt id=\"does%20it%20support%20woocommerce%20high-performance%20order%20storage%20%28hpos%29%3F\"><h3>Does it support WooCommerce High-Performance Order Storage (HPOS)?<\/h3><\/dt>\n<dd><p>Yes, HPOS compatibility is declared and fully supported.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20rotate%20the%20wordpress%20security%20keys%20%28auth_key%20%2F%20auth_salt%29%3F\"><h3>What happens if I rotate the WordPress security keys (AUTH_KEY \/ AUTH_SALT)?<\/h3><\/dt>\n<dd><p>Since unconfirmed order tokens are encrypted at rest using keys derived from your WordPress secret salts, rotating AUTH_KEY or AUTH_SALT in wp-config.php will invalidate existing pending confirmation links. Newly placed orders after key rotation will work normally.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Added strict anti-cache headers (<code>Cache-Control: no-store, no-cache, must-revalidate<\/code>) on confirmation preview and result screens.<\/li>\n<li>Registered custom order status as non-public (<code>public =&gt; false<\/code>, <code>exclude_from_search =&gt; true<\/code>).<\/li>\n<li>Implemented immediate pre-commit business guards verifying COD payment method, status, and active token hash.<\/li>\n<li>Synchronized WordPress nonce lifetime to 48 hours for confirmation actions to prevent premature session expiry.<\/li>\n<li>Scoped plain-text email confirmation links with the customer email ID whitelist.<\/li>\n<li>Added explicit operator order note when token generation fails.<\/li>\n<li>Bundled official WordPress.org screenshot assets into release archive.<\/li>\n<li>Documented dual-layer cryptographic threat model in source code.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Hardened token encryption using AEAD AES-256-GCM with order-bound additional authenticated data.<\/li>\n<li>Implemented database-backed lock with owner tokens and pre-commit fencing.<\/li>\n<li>Added single-use opaque result tokens to PRG flow to prevent result status enumeration.<\/li>\n<li>Added Store API checkout interception hook for WooCommerce Checkout Block compatibility.<\/li>\n<li>Corrected physical product shipping check for mixed carts.<\/li>\n<li>Scoped customer email notifications with dedicated ID whitelist and rel=\"noopener noreferrer\".<\/li>\n<li>Standardized clean POT localization template without fuzzy flags.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Reduce fake Cash on Delivery orders. Holds COD orders in Awaiting Confirmation until the buyer verifies via a secure 1-click confirmation link.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/374572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=374572"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/alexsazonov"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=374572"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=374572"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=374572"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=374572"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=374572"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=374572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}