KISS Checkout Password Protection
Password-protects WooCommerce checkout on non-production environments. Fails open — production domains are never protected. Admins bypass automatically.
by KISS Plugins | Hypercart · github.com/kissplugins/kiss-checkout-password-protection
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/kissplugins/kiss-checkout-password-protection/archive/refs/heads/main.zipReadme
KISS Checkout Password Protection
Lightweight WooCommerce checkout protection for non-production WordPress environments.
What it does
This plugin blocks access to the WooCommerce checkout page on non-production domains until a visitor enters a shared password. It is designed for cloned, staging, and development environments where checkout should stay hidden from normal visitors.
The plugin intentionally fails open on production. If the current host matches a configured production domain, checkout is not protected.
Features
- Protects the WooCommerce checkout page with a password gate
- Automatically bypasses protection on configured production domains
- Automatically bypasses protection for logged-in administrators
- Skips WooCommerce
order-receivedandorder-payendpoints - Uses a WordPress password hash instead of storing a plaintext password
- Uses a nonce on form submission and hardened cookie flags
Requirements
- WordPress
- WooCommerce
Configuration
Edit these constants in checkout-password-protection.php:
CPP_PASSWORD_HASH— awp_hash_password()hash for the checkout passwordCPP_PRODUCTION_DOMAINS— comma-separated production domains that should never be protected
Example hash generation:
echo wp_hash_password( 'your-chosen-password' );
Replace the placeholder value in CPP_PASSWORD_HASH with the generated hash before using the plugin.
Behavior summary
Checkout protection is skipped when:
- The current request is not for checkout
- The request is for
order-receivedororder-pay - The current host matches a configured production domain
- The current user can
manage_options
Otherwise, visitors must enter the configured password to continue to checkout.
Emergency disable
- Deactivate the plugin in WordPress admin
- Run
wp plugin deactivate checkout-password-protection - Rename the plugin folder over SFTP/SSH
Version
Current version: 1.0.1
License
Licensed under GNU General Public License v2.0. See LICENSE or license.txt.