| 开发者 | marto46 |
|---|---|
| 更新时间 | 2026年9月30日 04:27 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/marupurupu-checkout-for-mpesa/api.safaricom.co.ke, or sandbox.safaricom.co.ke when Test Mode is on) — the service that actually takes the M-Pesa payment.
telemetry.billtoolbox.com) — optional and off by default; used only if you tick "Help improve this plugin by sharing anonymous usage data" in the gateway settings. Exactly what is sent, and when, is listed field by field under "Privacy Policy" below. Operated by the plugin author. It has no separate terms document: the complete disclosure of what it receives, stores and for how long is the "Privacy Policy" section below.api.wordpress.org/secret-key/1.1/salt/) — only a link in an admin notice shown when your site's security keys are missing. The plugin sends nothing to it; your browser opens it only if you click the link.
Yes! Version 1.1.0 adds full support for WooCommerce block-based checkout while maintaining backward compatibility with classic checkout.
Yes, M-Pesa STK Push requires your site to have a valid SSL certificate (HTTPS).
A Till Number is your M-Pesa Buy Goods business number. This plugin currently supports Till (Buy Goods) payments only; Paybill numbers are not supported.
Yes! Enable "Test Mode" in settings and use the test credentials from Daraja Portal.
Go to WooCommerce > M-Pesa Transactions to view all payment transactions.
The plugin includes comprehensive error logging. Enable debug mode and check wp-content/debug.log for details.
Currently supports KES (Kenyan Shillings) only, as required by M-Pesa.
The plugin automatically generates a callback URL, including a secret token unique to your site. M-Pesa sends payment confirmations to this URL; the plugin verifies the token before updating order status automatically.
Requires Plugins: woocommerce.fail, which WooCommerce Blocks does not recognise; it now returns failure).=, +, - or @ so spreadsheet programs cannot run it as a formula.WC tested up to raised to 11.1; the amount shown on the order-received page is escaped.CREATE TABLE form that WordPress's dbDelta() expects (it previously read IF NOT EXISTS as the table name, so future column changes could never be applied).Author URI now points to the author's WordPress.org profile.section query argument before comparing it.marupurupu_ / Marupurupu_ / MARUPURUPU_ instead of the generic mpesa (which could collide with other M-Pesa plugins). The custom transactions table is now {prefix}marupurupu_transactions.RENAME TABLE; no rows are copied or lost), saved options and dismissed notices are carried over, and leftover scheduled events are cleared. Your gateway settings, saved credentials and payment history are unchanged, and no action is needed. The migration retries by itself if it cannot finish, and never overwrites newer data.mpesa_till), your saved gateway settings, and the Safaricom callback URL (/wc-api/wc_mpesa_till_callback/) — orders, settings and Safaricom callbacks depend on them.composer test) covering credential encryption, the payment webhook, the STK Push request, the migration and the order-state guard.cart_checkout_blocks), so WooCommerce no longer lists the gateway as incompatible with block checkout.config-sample.php, which described a constants-based credential mechanism that the plugin never implemented. Credentials are entered on the gateway settings screen and stored encrypted.marupurupu-checkout-for-mpesa), following WordPress.org Plugin Review Team feedback that the previous name led with a third-party trademark. "Marupurupu" is a Swahili word meaning "allowances". No functional change: internal identifiers, the database table (wp_mpesa_till_transactions), the option keys, and the Daraja callback URL (/wc-api/wc_mpesa_till_callback/) are all unchanged. Existing installs need a manual reinstall to pick up the new folder name (WordPress cannot rename an installed plugin's folder in an update); stored settings are unaffected.Plugin URI and the readme's source-code link now point to the renamed public repository, github.com/marto-karanja/marupurupu-checkout-for-mpesa (the previous repository name led with a third-party trademark).admin.css) was referenced but not shipped, so the page's styles came only from an inline block. It is now a real, enqueued stylesheet.1.0.0.sanitize_text_field) before it is logged, stored, or shown in order notes; nonces are sanitized before verification; the callback secret is sanitized before comparison; the bulk-export IN (...) list now goes through $wpdb->prepare().<script>/<style> blocks and onclick handlers moved to properly enqueued files (wp_enqueue_script/wp_enqueue_style, with report data passed via wp_localize_script).wc_price, paginate_links, wpautop), and wp_die() messages now use esc_html__().mpesa-blocks-improved.js (never loaded by the plugin).Plugin URI and Author URI in the plugin header were identical (https://billtoolbox.com) — flagged during WordPress.org submission review (both must be different, or one omitted). Plugin URI now points to the public GitHub source; Author URI stays https://billtoolbox.com.mpesa-till-gateway to mpesa-payment-gateway, matching the v1.5.1 display-name change and made ahead of first WordPress.org submission (self-service slug changes go away once review starts). No functional change — internal identifiers, the database table (wp_mpesa_till_transactions), the WC_Mpesa_Till_Gateway class name, and the Daraja callback URL (/wc-api/wc_mpesa_till_callback/) are all unchanged, matching the same precedent as the earlier wc-mpesa-till-payment → mpesa-till-gateway rename. Existing installs on bonbargains.com/nairobistalls.com need a manual reinstall to pick this up — WordPress cannot rename an installed plugin's folder via a normal update; deactivate, delete the old mpesa-till-gateway folder, install this version fresh, then reactivate. Stored settings are unaffected (kept under a WooCommerce option key, not tied to the folder name).mpesa-till-gateway at the time; renamed again in 1.5.2, see above), text domain, folder name, main file name, database table, and the Daraja callback URL were all unchanged by this specific release; existing installs were unaffected.wc-mpesa-till-payment to mpesa-till-gateway (slug, folder, main file, text domain) — see the 1.5.2 and 1.5.5 entries above for the further renames, most recently to marupurupu-checkout-for-mpesa. WordPress.org restricts the term "wc" in plugin slugs — the previous name could never have been submitted. No functional change; internal identifiers, the database table, and the M-Pesa/Daraja callback URL are all unchanged, so existing installs keep working exactly as before once updated.wp_remote_get()/wp_remote_post()) instead of calling cURL directly — same behavior (timeouts, SSL verification), but works correctly on hosts that restrict direct cURL usage and follows WordPress.org coding standards.date() calls affected by server timezone changed to gmdate(), superglobal reads missing wp_unslash(), wp_redirect() changed to wp_safe_redirect() for two admin actions added in 1.4.x, and a stale "Tested up to" header.do_action('woocommerce_payment_complete', ...) call that passed a raw database string instead of an integer order ID, which crashes WooCommerce core's own stock-reduction code (get_stock_reduced()) on this WooCommerce version. WC_Order::payment_complete(), called immediately before it, already fires this same hook correctly — the duplicate call is removed rather than just type-fixed, since it was firing every other plugin's payment-complete listeners twice per order. Found live on a production install 2026-08-28; confirmed via WooCommerce core source that the fix doesn't lose any behavior.class-mpesa-blocks-support-v2.php (superseded by the active blocks support class)