• Resolved wrapyourbaby

    (@wrapyourbaby)


    I am switching my online store from an html website to Woocommerce and I have a question about the setup on your plugin. On my current site, I use Payflow and there’s no SSL required as Paypal handles the transactions even though they appear to the customer to take place in my store. I called Paypal to ask how to achieve the same set up for my new site and was told to look for a plugin with hosted checkout. He said I could tell if the plugin was using hosted checkout if it asked for user, partner, vendor and password, which yours does, but after entering that info I found out that it also requires SSL to work.
    I do have a domain validated SSL certificate, so that my customer’s address info is secure when they create a log-in on my website, but I wasn’t intending to use it for processing credit card info. Does your plug-in require a higher level of security than that or since Paypal is processing the credit cards, will the domain validated SSL certificate be fine?
    Thank you very much!

    https://wordpress.org/plugins/paypal-for-woocommerce/

Viewing 12 replies - 1 through 12 (of 12 total)
  • Plugin Contributor angelleye

    (@angelleye)

    It sounds like you’re talking about “PayPal Advanced” or “PayPal Pro Hosted”. Our plugin currently supports “PayPal Payments Pro” which is direct credit card processing, not an iframe, and would require an SSL on the server.

    Our 1.2.0 update that we’re just about to release includes PayPal Advanced, so you could use that if that’s what you’ve got setup. Unfortunately, we won’t have Pro Hosted done for a little while longer.

    Honestly, though, I prefer the full Payments Pro. The user experience is typically better and results in higher conversion rates.

    The SSL is only around $75/year with your web host, and as long as you’re not saving any credit card details on your server (which our plugin does not) then you would be PCI compliant.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Are you able to tell me about when you’ll be releasing the 1.2 update? I called Paypal and they told me that what I’m currently using is Paypal Advanced. They also recommended that I use Paypal Pro instead but it looks like my host (Hostgator) wants $269 a year for extended validated SSL, so I’d rather stick with Paypal Advanced if possible.
    Thank you!

    Plugin Contributor angelleye

    (@angelleye)

    You can get an SSL certificate from anybody. It doesn’t have to be directly from your host. I often use Rapid SSL, and in fact many times when you get it through a host they’re using Rapid SSL anyway.

    Looks like they’re selling standard SSL certs for $49/year right now.

    I would double check with HostGator, though. It sounds like they’re trying to sell you a wildcard SSL which is not what you need (unless you plan on running a bunch of subdomains that you want to secure with SSL).

    For PayPal Advanced we have that done in the release branch on GitHub right now, so you could go ahead and grab that early if you want to. You can download it here: https://github.com/angelleye/paypal-woocommerce/archive/release.zip

    You’ll just need to extract it and update the files manually overriding the current plugin files on the server.

    Once that’s done you’ll want to clear any cache/CDN services if you have them running, and then you’ll see PayPal Advanced included in your payment gateway setup options.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    I will see if I can figure that out – thank you! The person I talked to at Paypal seemed to think using Paypal Advanced without SSL would be less secure for my customers than Paypal Pro with SSL as they are still on my Woocommerce page – does that seem correct? I couldn’t tell if he knew for certain or not.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Also I just was told by Hostgator that my domain validated SSL would be compliant with Paypal’s requirements, so it sounds like I’m okay to just set it up with Paypal Pro. If you have any feedback on this or on my previous post that would be great – it’s all pretty new to me. Otherwise I’ll go ahead and start getting it set up. Thank you!

    Plugin Contributor angelleye

    (@angelleye)

    PayPal Advanced without an SSL should be pretty secure. That’s the point of it really. It’s a PayPal hosted iframe embedded on your page, but that’s exactly why I don’t like it. I don’t like embedded iframes.

    Since it sounds like it’ll work out I would really recommend going with Pro and an SSL. Keep in mind that Pro is going to cost $30/mo where-as Advanced is $15 if I remember correctly..?? So you’ll be paying a little more but I think the advantages are well worth it.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Thanks very much for all your help! I plan to go with PayPal Advanced for the launch and once my website is transferred over to the address with SSL, I will look at switching to Pro. I tried to install the 1.2 version of your plugin but I’m afraid I didn’t know exactly what I was doing and got locked out of my website temporarily (that’s fixed now). Do you happen to know about when your version 1.2 will be released? Thank you!

    Plugin Contributor angelleye

    (@angelleye)

    We should have it officially released within a week or two at the most.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Okay, thanks!

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Is there any update on when you will release version 1.2? Thanks!

    Plugin Contributor angelleye

    (@angelleye)

    It’s essentially done. I just need to tie up a few loose ends with the readme file and some verbiage in settings pages. If you want to grab it early you can download it here.

    Thread Starter wrapyourbaby

    (@wrapyourbaby)

    Thank you!

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘domain validated SSL’ is closed to new replies.