Changelog
Complete release history for the Login for Stripe Customer Portal WordPress plugin, including the v1.0.6 security and privacy hardening pass.
Version 1.0.6 — May 24, 2026#
Security & privacy
- Fix: Redirect URL setting now persists correctly. The 1.0.5 form emitted the input under a corrupted name attribute, so saving silently failed and customers were always returned to the default endpoint.
- Fix: Magic-link URLs now use the configured Customer Portal slug instead of a hardcoded
/customer-portalpath. Renaming the endpoint no longer breaks outstanding login emails. - Fix: Namespaced
catch (Exception $e)clauses around Stripe SDK calls resolved to the nonexistent classLSCP\Exceptionand never matched. Any Stripe failure now surfaces a graceful “Please try again later” message instead of a WSOD. - Hardening: Stored magic-link tokens are now SHA-256 hashed at rest. A database snapshot no longer exposes unredeemed login links.
- Hardening: Per-email + per-IP rate limiter (5 requests / 10 minutes) on the magic-link form prevents the page from being abused as a mail relay or as an email-enumeration oracle against your Stripe customer list.
- Hardening: The form response is now constant for valid, invalid, and unknown email addresses, and the wording is mode-aware. When “Only allow existing Stripe customers to login” is unchecked (default) the message is “A login link is on its way” — no longer the misleading “If your email address is registered…” wording, which implied gatekeeping that did not exist in that mode.
- Hardening: Settings page now explicitly checks
manage_optionsbefore rendering, and everywp_die()message is HTML-escaped. - Hardening: Stripe Secret Key input renders a fixed-length mask (12 characters). The field no longer leaks the real key length via “view source”.
- Hardening: Customer Portal Slug is length-capped (max 64 chars) so a pasted megabyte string can’t bloat the rewrite engine.
- Hardening: Shortcode forms now render with per-instance unique
idattributes. Embedding the shortcode multiple times on the same page no longer produces duplicate IDs that break<label for>binding, HTML5 validation, and screen-reader navigation. - Privacy: Plugin uninstall now cleans up every option and transient. The Stripe Secret Key no longer lingers in
wp_optionsafter the plugin is uninstalled. - Privacy: GDPR personal-data exporter and eraser are registered with WordPress Privacy Tools (Tools → Export Personal Data / Erase Personal Data).
UX
- Settings page description for the “Only allow existing Stripe customers to login” toggle now explicitly notes that unchecking it (the default) auto-creates a Stripe customer the first time a magic link is redeemed for a new email.
- Magic-link form input now uses
<label for>,autocomplete="email", andrequiredattributes for screen-reader and password-manager compatibility.
Reliability & ops
- New daily WP-Cron sweep removes expired magic-link tokens and rate-limit counters. WordPress’s built-in transient GC is lazy and can leave expired rows in
wp_optionsindefinitely on low-traffic sites. - New WP-CLI commands:
wp lscp purge-tokens,wp lscp limiter-reset <email>,wp lscp send <email>,wp lscp config. - Full payments-grade test suite — 250 PHPUnit tests, 18,690 assertions, property-based fuzz on the token store, token-entropy distribution check, concurrent-redemption race test, slug path-traversal hardening, email-header injection hardening, multi-instance shortcode ID uniqueness, mode-aware confirmation message.
Compatibility & internal
- Bumps minimum PHP from 7.0 to 7.4 (PHP 7.0/7.1/7.2/7.3 are end-of-life).
- Backwards-compatible public class surface — every public method on
LSCP\Pluginfrom 1.0.x is preserved. - Plugin refactored into focused units (
Settings,TokenStore,TokenGC,StripeGateway,Mailer,RateLimiter,PortalController,FormRenderer,RewriteEndpoint,Shortcode,Privacy,Cli,Uninstall,DocsHelper).
Version 1.0.5 — May 24, 2026#
- Added contextual documentation links on the Stripe Portal settings page.
Version 1.0.4 — Dec 16, 2025#
- Updated Freemius SDK.
Version 1.0.3 — Jan 27, 2025#
- Updated Freemius SDK.
Version 1.0.2 — Nov 17, 2024#
- Added shortcode to embed login form anywhere on your site.
Version 1.0.1 — Nov 12, 2024#
- Added email login link functionality.
- Added Freemius SDK.
Version 1.0 — Nov 12, 2024#
- Initial release with Stripe API integration and customizable login endpoint.
- Secure login form for customers to access their Stripe Customer Portal.