The Companion plugin’s public hooks use the rsc_ prefix. A few older ones from the plugin boilerplate use
retail_store_compaion_ or retail-store-compaion_. Put customisations in a small must-use plugin or a site plugin, never in the
Companion’s own files, so updates don’t overwrite them. File paths are relative to the plugin root.
Filter
Arguments → returns
Default
Purpose
File
rsc_require_email_verification
bool $required
true (false when RSC_DISABLE_EMAIL_VERIFICATION is true)
Whether a new account must verify its email before it can sign in
includes/REST/AbstractController.php
rsc_frontend_verify_email_path
string $path
/verify-email
Storefront path the verification email links to
includes/REST/AuthController.php
rsc_email_verification_url
string $url, string $token
Storefront URL plus that path and ?token=; falls back to the REST route when no storefront URL is set
Override the whole verification link
includes/REST/AuthController.php
rsc_frontend_reset_password_path
string $path
/reset-password
Storefront path the password-reset email links to
includes/REST/AuthController.php
rsc_password_reset_url
string $url, string $token
Storefront URL plus that path and ?token=
Override the whole reset link. The REST fallback is POST-only, so set the storefront URL.
includes/REST/AuthController.php
rsc_social_login_rate_limit
int
60 per minute per client
Social sign-in attempts; 0 turns the limit off
includes/REST/AuthController.php
Filter
Arguments → returns
Default
Purpose
File
rsc_protected_rest_namespaces
array $namespaces
The API Access setting; built-in default ['wc/v3']
Namespaces that require a valid JWT, or a wp-admin cookie plus nonce
includes/RestGuardSettings.php
rsc_public_rest_routes
array $routes, each a method and a path glob
The API Access setting; built-in default empty
Routes inside protected namespaces that stay public
includes/RestGuardSettings.php
Filter
Arguments → returns
Default
Purpose
File
rsc_checkout_rate_limit
int
5 per minute per customer or Shopper address
Store API checkout limit, applied only while the shared secret is set
includes/Payment/CheckoutProtection.php
rsc_paypal_order_rate_limit
int
10 per minute per cart
/payment/paypal/order per-cart limit
includes/Payment/PayPalOrderPreparation.php
rsc_paypal_order_ip_rate_limit
int
60 per minute per Shopper address
/payment/paypal/order per-address limit
includes/Payment/PayPalOrderPreparation.php
rsc_placed_order_rate_limit
int
10 per minute per cart
/payment/placed-order per-cart limit
includes/Payment/PlacedOrderRecord.php
rsc_placed_order_ip_rate_limit
int
60 per minute per Shopper address
/payment/placed-order per-address limit
includes/Payment/PlacedOrderRecord.php
rsc_storefront_shared_secret
string $secret
RSC_STOREFRONT_SHARED_SECRET, or ''
Supply the storefront-to-backend HMAC secret from elsewhere, such as a secrets manager
includes/Payment/ShopperAddress.php
Filter
Arguments → returns
Default
Purpose
File
rsc_newsletter_providers
AbstractProvider[]
[ BrevoProvider ]
Register more newsletter providers (each has a slug())
includes/Newsletter/NewsletterProviders.php
rsc_newsletter_available
bool
Whether the subscribers table is installed
Whether newsletter storage is available
includes/Newsletter/NewsletterService.php
rsc_newsletter_ip_rate_limit
int
20 per minute per IP
Newsletter sign-ups per address
includes/REST/NewsletterController.php
rsc_wishlist_available
bool
Tables installed and wishlist enabled
Whether wishlist storage is available
includes/Wishlist/WishlistService.php
rsc_stock_notifications_enabled
bool
The stored master switch
Force back-in-stock alerts on or off
includes/StockNotifications/StockNotificationsSettings.php
rsc_stock_notifications_batch_size
int
50
Emails sent per back-in-stock batch job
includes/StockNotifications/NotificationsProcessor.php
rsc_stock_notifications_retry_cooldown
int seconds
900
Wait before a failed alert is retried
includes/StockNotifications/NotificationRepository.php
Filter
Arguments → returns
Default
Purpose
File
rsc_seo_redirect_product
bool $redirect, WP_Post $product
true
Return false to stop a published product’s WordPress page from 301-redirecting to the storefront
includes/Seo/ProductRedirect.php
rsc_storefront_page_languages
string[] $languages
['en']
Languages the Static Pages and SEO settings keep a value for (default language first). There is no admin UI for this.
includes/Storefront/StaticPages.php
retail-store-compaion_template
string $path, string $name
The plugin’s templates/ path
Override a plugin template file
includes/RetailStoreCompaion.php
Action
Arguments
Fires when
File
retail_store_compaion_loaded
none
The plugin has booted (plugins_loaded)
includes/RetailStoreCompaion.php
retail_store_compaion_before_template_part, retail_store_compaion_after_template_part
$template_name, $args
Around every plugin template include
includes/RetailStoreCompaion.php
rsc_newsletter_subscribed
string $email, string $source
A new newsletter subscriber is stored
includes/Newsletter/NewsletterService.php
rsc_stock_notification_created
Notification $n
A back-in-stock sign-up is created
includes/StockNotifications/SignupService.php
rsc_back_in_stock_notification
Notification $n, WC_Product $p
A restock alert is about to be emailed (the Back in stock email listens)
includes/StockNotifications/NotificationsProcessor.php
rsc_back_in_stock_notification_sent
Notification $n
The mailer accepted the restock email
includes/Emails/BackInStockEmail.php
rsc_back_in_stock_notification_failed
Notification $n, $failure
A restock email failed
includes/StockNotifications/NotificationsProcessor.php
rsc_stock_notifications_sent
int $product_id, int $sent
A product’s send batch finished
includes/StockNotifications/NotificationsProcessor.php
rsc_payment_failure
string $where, Throwable $failure
A call into Stripe, PayPal or the WooCommerce session failed. Also written to the WooCommerce log, source retail-store-companion-payment.
includes/Payment/PaymentLog.php
rsc_seo_plugin_values_changed
'post' or 'term', int $id
Values edited in Yoast SEO or Rank Math were mirrored into the plugin’s SEO copy
includes/Seo/Mirroring.php
Each of these fires the matching WooCommerce email (WooCommerce → Settings → Emails). You can listen to them, or fire them yourself:
rsc_email_verification_notification, rsc_password_reset_notification, rsc_security_alert_notification,
rsc_stock_notification_verify, rsc_stock_notification_confirmed, rsc_back_in_stock_notification.
Not the plugin’s own, but useful when debugging or when another plugin hooks the same place:
Hook
What the Companion does there
determine_current_user (priority 20)
Sets the user from a valid Bearer JWT on WooCommerce REST routes
rest_authentication_errors (priority 20)
Hard-gates the protected namespaces
rest_request_after_callbacks
Adds its fields to Store API responses; restores its 409 payment refusals over the Store API’s generic 400
woocommerce_rest_checkout_process_payment_with_context
The express amount guard (priority 20) and the PayPal amount guard (priority 998)
woocommerce_store_api_checkout_order_processed
Records the placed order in the cart’s session; re-mirrors the Address Book
woocommerce_email_classes
Registers the plugin’s six emails
wp_rest_cache/allowed_endpoints, wp_rest_cache/disallowed_endpoints
Tells WP REST Cache what it may and may not cache
sib_form_submission_info
Applied when building Brevo form submissions
These are illustrative; adapt them to your site.
// Illustrative: the storefront serves its verification page at /account/verify.
add_filter ( 'rsc_frontend_verify_email_path' , function () {
return '/account/verify' ;
// Illustrative: keep policy pages and SEO patterns in English and Arabic.
add_filter ( 'rsc_storefront_page_languages' , function () {
return array ( 'en' , 'ar' );
// Illustrative: read the shared secret from the environment instead of wp-config.php.
add_filter ( 'rsc_storefront_shared_secret' , function ( $secret ) {
$from_env = getenv ( 'RSC_STOREFRONT_SHARED_SECRET' );
return $from_env ? $from_env : $secret;
// Illustrative: alert an on-call channel when a payment call fails.
add_action ( 'rsc_payment_failure' , function ( $where, $failure ) {
error_log ( sprintf ( '[payments] %s failed: %s' , $where, $failure -> getMessage () ) );
// Illustrative: keep product pages on WordPress for one product.
add_filter ( 'rsc_seo_redirect_product' , function ( $redirect, $product ) {
return 123 === $product -> ID ? false : $redirect;
REST API The endpoints and limits these filters tune.