Amirhossein Hosseinpouramirhp
CV
Active WordPress plugin · WooCommerce

Receipt Uploader for WooCommerce

The receipt arrives on the order, not in someone's inbox.

For shops paid by bank transfer, cheque or cash on delivery. The customer uploads a photo or PDF of the receipt on the thank-you page or in their account, the order moves to Awaiting Approval, and the shop approves or rejects it from the order screen. Each step sends the right email and sets the right status.

Get it on WordPress.org Source on GitHub

Free, GPL-2.0 or later. Published by Pepro Dev; I am its lead developer. Figures from the WordPress.org and GitHub APIs, 30 September 2026.

On WordPress.org2020 to today

What it does

One receipt per order, a status for every stage, and the admin never leaves the order screen.

Upload where they already are

A form on the thank-you page and in My Account order details, for any payment method you choose. JPG, PNG, WEBP, HEIC, PDF and more, with a size limit.

Approve or reject

From the order screen, with an admin note. Three extra order statuses: Awaiting Receipt Upload, Awaiting Receipt Approval, Receipt Rejected.

Six emails

Uploaded, approved and rejected, each for the customer and for the shop, as ordinary WooCommerce emails.

For developers

Nine actions, four filters and four jQuery events, plus [receipt-form] and [receipt-preview] shortcodes. HPOS compatible.

Why it exists

For many shops a bank transfer is how customers pay. WooCommerce ships the payment method, and nothing that happens after it.

Without a plugin, the customer sends a screenshot by message or email, someone matches it to an order by hand, and the order sits in On hold with no record of why. Receipt Uploader puts the file on the order it belongs to, and gives the order a status that says exactly what it is waiting for.

It has been on WordPress.org since October 2020, and it is the second most installed plugin I work on, after Ultimate Invoice. For a newer take built at Pigment Dev, with review from Telegram, see Easy Receipt.

A receipt is private data

It shows a customer's name, bank and amount. In September 2026 the plugin went through seven versions in one day to treat it that way.

Two researchers reported the same class of bug, an insecure direct object reference: with the right request, someone could attach a receipt to another customer's order, or view another customer's receipt. Both are credited in the changelog of 2.14.0.

The fixes, from 2.9.0 to 2.14.0: uploads check that the visitor owns the order, as the logged-in customer or a guest with the order key, instead of trusting a public nonce. Previews are served only through signed links bound to their order. Files get random names in a folder with deny rules, and are validated by their real content, not their extension.

# Nginx ignores .htaccess, so the plugin checks,
# and the Help & Tools tab suggests this rule:
location ~* ^/wp-content/uploads/receipt_upload/ {
  deny all;
  return 403;
}
From the plugin's README, version 2.15.0.

Getting started

WordPress 6.0+, WooCommerce 7.0+, PHP 7.4+.

  1. Install

    Plugins, Add New, search for "PeproDev Receipt Uploader", then Install and Activate.

  2. Choose the payment methods

    WooCommerce, Settings, Receipt Upload. Pick which gateways ask for a receipt, the file types and the size limit.

  3. Set the statuses

    Under Order Status Automation, choose what an order becomes when it is placed, when a receipt arrives, and when you approve or reject it.

  4. On Nginx, protect the folder

    Help and Tools checks whether receipts can be opened directly, and shows the rule above if they can.

Releases

WordPress.org keeps four tagged versions of this plugin; the changelog lists every one since 2020.

VersionReleasedWhat changed
2.15.026 Sep 2026Receipt status on block-theme thank-you pages.
2.9 to 2.1426 Sep 2026The security work above, a settings tab of its own, a file-type picker, the rename to PeproDev Receipt Uploader, Plugin Check compliance.
2.8.031 Mar 2025Receipt data saved before the email goes out; WordPress 6.7 text-domain notice fixed.
2.7.022 Nov 2024A security fix reported through Patchstack and Wordfence.
2.6.x2024Full HPOS compatibility; receipts moved to their own folder.
1.8.015 Aug 2022Oldest version WordPress.org still keeps.
first release13 Oct 2020Listed on WordPress.org.

2.15.0, 2.8.0, 2.7.0 and 1.8.0 are dated by their downloads on WordPress.org; the rest by the changelog.

Hindsight

What I would do from the first release.

branch main 6 active projects ↑ 113 releases open-source/receipt-uploader.md Sari --:-- UTC+3:30 its@amirhp.com