=== COD Anti-Fraud for WooCommerce ===
Contributors: beralabs
Donate link: https://beralabs.it
Tags: woocommerce, cash on delivery, anti fraud, otp, whatsapp
Requires at least: 6.0
Tested up to: 7.1
WC requires at least: 5.0
WC tested up to: 11.1
Requires PHP: 7.4
Stable tag: 1.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Protect WooCommerce Cash on Delivery (COD) orders against fraud by requiring WhatsApp OTP verification and calculating dynamic risk scores.

== Description ==

**COD Anti-Fraud for WooCommerce** protects WooCommerce online stores from non-delivered or fraudulent Cash on Delivery (COD) orders by combining dynamic risk evaluation with mandatory WhatsApp OTP verification.

### Key Features
* **Dynamic Risk Engine:** Calculates a 0-100 risk score based on guest checkout status, cart total, and past failed/cancelled COD history.
* **WhatsApp OTP Verification:** Automatically sends a 6-digit verification code to the customer's phone via WhatsApp before confirming COD orders.
* **Smart Thresholds & Gateways:** Configure minimum/maximum cart amounts for COD, blacklist fraudulent phone numbers or emails, and whitelist trusted VIP customers.
* **Rate Limiting & Anti-Brute-Force:** Built-in rate limiter by phone number and IP address to prevent SMS/WhatsApp flooding.
* **Multiple Gateway Support:** Out-of-the-box integration with UltraMsg API, extensible for Twilio and custom WhatsApp gateways.
* **Seamless Checkout UX:** Modern inline UI and responsive modal overlay integrated smoothly with WooCommerce checkout (both Classic and Block checkout).
* **Order Meta & Admin Details:** Transparent risk scores and verification timestamps displayed directly inside WooCommerce order details.
* **HPOS Compatible:** Fully compatible with WooCommerce High-Performance Order Storage (HPOS).

== External services ==

This plugin connects to the **UltraMsg WhatsApp API** to send One-Time Password (OTP) verification messages via WhatsApp to customers choosing the Cash on Delivery (COD) payment method.

* **Service Provider:** UltraMsg (UltraMsg Inc.)
* **Service Website:** [https://ultramsg.com/](https://ultramsg.com/)
* **Terms of Service:** [https://ultramsg.com/terms-conditions.php](https://ultramsg.com/terms-conditions.php)
* **Privacy Policy:** [https://ultramsg.com/privacy-policy.php](https://ultramsg.com/privacy-policy.php)

**What data is sent to UltraMsg?**
* The customer's mobile telephone number entered during checkout.
* The dynamically generated 6-digit OTP verification code text.

No customer passwords, credit card numbers, billing addresses, or purchase history details are shared with UltraMsg. API requests are triggered exclusively when a customer requests an OTP code to verify a Cash on Delivery order.

== Installation ==

1. Upload the `cod-anti-fraud-for-woocommerce` directory to your `/wp-content/plugins/` directory.
2. Activate the plugin through the **Plugins** menu in WordPress.
3. Go to **WooCommerce > Settings > COD Anti-Fraud** to configure settings and your WhatsApp API credentials.

== Frequently Asked Questions ==

= Is this plugin compatible with High-Performance Order Storage (HPOS)? =
Yes, COD Anti-Fraud for WooCommerce is fully compatible with HPOS (Custom Order Tables).

= What WhatsApp gateway is supported? =
The plugin natively supports UltraMsg API and can be easily extended for Twilio and custom API gateways.

= What happens if the customer does not verify the OTP? =
If OTP verification is required based on settings or risk score, checkout submission is prevented until valid OTP verification is completed.

= Does this plugin work with guest checkout? =
Yes, guest checkout is fully supported and analyzed with higher risk evaluation weights.

== Screenshots ==

1. Plugin settings page in WooCommerce Admin (`/assets/screenshot-1.png`).
2. WhatsApp OTP verification box in WooCommerce checkout (`/assets/screenshot-2.png`).
3. Anti-Fraud Risk Engine meta box in WooCommerce order details (`/assets/screenshot-3.png`).

== Changelog ==

= 1.1.2 =
* WordPress.org standards compliance: sanitized superglobals, nonces validation, and output escaping.
* Unified settings option keys across all modules.

= 1.1.1 =
* Maintenance release: version bump and compatibility verification.

= 1.1.0 =
* Added HPOS compatibility.
* Added customizable message templates for WhatsApp OTP.
* Enhanced risk engine algorithms and order history lookup.
* Added rate limiting and IP abuse protection.
* Added whitelist and blacklist management.

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.1.2 =
Upgrade to version 1.1.2 for security hardening and full WordPress.org standards compliance.

= 1.1.1 =
Upgrade to version 1.1.1 for maintenance updates and latest compatibility verification.

= 1.1.0 =
Upgrade to version 1.1.0 for WooCommerce HPOS support and enhanced security features.
