Receipt Uploader for WooCommerce
The receipt arrives on the order, not in someone's inbox.
For shops paid by bank transfer, cheque or cash on delivery. The customer uploads a photo or PDF of the receipt on the thank-you page or in their account, the order moves to Awaiting Approval, and the shop approves or rejects it from the order screen. Each step sends the right email and sets the right status.
Free, GPL-2.0 or later. Published by Pepro Dev; I am its lead developer. Figures from the WordPress.org and GitHub APIs, 30 September 2026.
What it does
One receipt per order, a status for every stage, and the admin never leaves the order screen.
Upload where they already are
A form on the thank-you page and in My Account order details, for any payment method you choose. JPG, PNG, WEBP, HEIC, PDF and more, with a size limit.
Approve or reject
From the order screen, with an admin note. Three extra order statuses: Awaiting Receipt Upload, Awaiting Receipt Approval, Receipt Rejected.
Six emails
Uploaded, approved and rejected, each for the customer and for the shop, as ordinary WooCommerce emails.
For developers
Nine actions, four filters and four jQuery events, plus [receipt-form] and [receipt-preview] shortcodes. HPOS compatible.
Why it exists
For many shops a bank transfer is how customers pay. WooCommerce ships the payment method, and nothing that happens after it.
Without a plugin, the customer sends a screenshot by message or email, someone matches it to an order by hand, and the order sits in On hold with no record of why. Receipt Uploader puts the file on the order it belongs to, and gives the order a status that says exactly what it is waiting for.
It has been on WordPress.org since October 2020, and it is the second most installed plugin I work on, after Ultimate Invoice. For a newer take built at Pigment Dev, with review from Telegram, see Easy Receipt.
A receipt is private data
It shows a customer's name, bank and amount. In September 2026 the plugin went through seven versions in one day to treat it that way.
Two researchers reported the same class of bug, an insecure direct object reference: with the right request, someone could attach a receipt to another customer's order, or view another customer's receipt. Both are credited in the changelog of 2.14.0.
The fixes, from 2.9.0 to 2.14.0: uploads check that the visitor owns the order, as the logged-in customer or a guest with the order key, instead of trusting a public nonce. Previews are served only through signed links bound to their order. Files get random names in a folder with deny rules, and are validated by their real content, not their extension.
# Nginx ignores .htaccess, so the plugin checks, # and the Help & Tools tab suggests this rule: location ~* ^/wp-content/uploads/receipt_upload/ { deny all; return 403; }
Getting started
WordPress 6.0+, WooCommerce 7.0+, PHP 7.4+.
Install
Plugins, Add New, search for "PeproDev Receipt Uploader", then Install and Activate.
Choose the payment methods
WooCommerce, Settings, Receipt Upload. Pick which gateways ask for a receipt, the file types and the size limit.
Set the statuses
Under Order Status Automation, choose what an order becomes when it is placed, when a receipt arrives, and when you approve or reject it.
On Nginx, protect the folder
Help and Tools checks whether receipts can be opened directly, and shows the rule above if they can.
Releases
WordPress.org keeps four tagged versions of this plugin; the changelog lists every one since 2020.
| Version | Released | What changed |
|---|---|---|
| 2.15.0 | 26 Sep 2026 | Receipt status on block-theme thank-you pages. |
| 2.9 to 2.14 | 26 Sep 2026 | The security work above, a settings tab of its own, a file-type picker, the rename to PeproDev Receipt Uploader, Plugin Check compliance. |
| 2.8.0 | 31 Mar 2025 | Receipt data saved before the email goes out; WordPress 6.7 text-domain notice fixed. |
| 2.7.0 | 22 Nov 2024 | A security fix reported through Patchstack and Wordfence. |
| 2.6.x | 2024 | Full HPOS compatibility; receipts moved to their own folder. |
| 1.8.0 | 15 Aug 2022 | Oldest version WordPress.org still keeps. |
| first release | 13 Oct 2020 | Listed on WordPress.org. |
2.15.0, 2.8.0, 2.7.0 and 1.8.0 are dated by their downloads on WordPress.org; the rest by the changelog.
Hindsight
What I would do from the first release.
// open-source/
More open source
The other projects with a page of their own. The rest, 56 in all, are in the explorer, each with its status and where the numbers come from.
- Receipt Uploader for WooCommerce1,000+ installs, rated 5.0 from 14
- upload-url-to-serverOne PHP file, 32 releases since 2020
- Justify It and Lorem SazAdobe XD plugins, 11,015 downloads, archived
- CF7 DatabaseContact Form 7 submissions, kept and exported
- Gravity Forms OTP VerificationA one-time code before the entry is saved
- Block External RequestWordPress's outbound calls, under control
- Slipnet for macOSA Mac client for a DNS-tunnelling VPN
- BDM, BlackSwan Download ManagerSegmented downloads on the Mac, with browser extensions
- Firefox add-onsFive published, 4.6 average rating