5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download
Kitsuly Commerce 1.44.11 – WordPress Plugin

Kitsuly Commerce

v1.44.11 Updated 2 days ago
Download Kitsuly Commerce 1.44.11
Free download · version 1.44.11

Description

At a glance

Looking for Kitsuly Commerce v1.44.11? It is available here as a free GPL download for WordPress — updated September 28, 2026 · requires WordPress 6.6+ & PHP 8.1+.

Kitsuly Commerce is a commerce-native WordPress ecommerce platform with native store building, catalogue, checkout, shipping, tax, accounting, fulfilment and Stripe Connect payments.

Kitsuly platform fees are controlled by the private T1K1 controller. Merchant plugin code never receives T1K1 Stripe secret keys.

Privacy and local analytics

Kitsuly’s built-in Site SEO analytics is disabled by default. It begins collecting local visit/engagement statistics only after a site administrator deliberately enables that feature in Kitsuly settings. The built-in analytics records are stored in the site’s own WordPress database and are not sent to Kitsuly, T1K1 or another analytics provider by that feature. Administrators can configure retention and exclude administrators.

Features that contact external providers are separately disclosed below and are used only when the merchant connects, enables or invokes the relevant integration.

External Services

Kitsuly Commerce connects to external services only when the merchant enables or uses the relevant feature. Credentials are stored in WordPress and sensitive integration values are encrypted where supported. External setup/help links opened from Kitsuly launch in a new browser tab.

Kitsuly Support requests

If a site administrator deliberately submits the Kitsuly Support form, WordPress sends the administrator-provided name, email address, support area, subject, message and any optional screenshot to [email protected] using the site’s configured WordPress mail transport. The message also includes the site’s URL plus the installed Kitsuly Commerce, WordPress and PHP versions so the reported installation can be identified and diagnosed. This data is sent only when the administrator presses the support-form submit button.

Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/

Kitsuly Platform Controller and Stripe

Kitsuly uses the private Kitsuly Platform Controller hosted at https://t1k1.com for controller-backed payment and merchant social-integration features. When a controller-backed feature first needs registration, the plugin sends a generated installation identifier, site URL, Kitsuly admin return URL, signed-callback URL, Kitsuly edition and plugin version so that installation can be registered and authenticated.

For payments and invoice payments, the controller receives the authenticated installation context plus the amount, currency, checkout/order/invoice reference, requested payment methods and Stripe payment identifiers required to connect the merchant account, create or retrieve payment intents, reconcile payments, process refunds and record transaction costs. Stripe.js is loaded from https://js.stripe.com/v3/. Card and wallet credentials are entered into Stripe-hosted Elements and are not stored by Kitsuly Commerce. Stripe webhook handling is controller-managed: individual merchant WordPress installations do not require or store a Stripe webhook signing secret (whsec_...), and the controller sends signed Kitsuly callbacks to the registered store for payment/refund reconciliation.

For supported brokered social connections (Facebook, Instagram, Pinterest, X, LinkedIn and TikTok), the controller can receive the selected provider, return URL, site URL, store name and administrator email when the merchant deliberately starts a connection. When the merchant deliberately publishes through a brokered provider, it can also receive the selected provider plus the post title/text, public link, public media URL and provider-specific publishing choices required for that post. Provider app secrets and controller-held social refresh tokens are not stored in the merchant WordPress installation.

Kitsuly Platform Controller: https://t1k1.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/
Stripe terms: https://stripe.com/legal
Stripe privacy: https://stripe.com/privacy

Kitsuly Licensing API

When a merchant activates, validates or requests a domain change for an official Kitsuly Pro or Business licence, the plugin communicates with the Kitsuly Licensing API hosted at https://api.kitsuly.com. The service receives the licence key, normalised production domain, installation identifier and site URL required to verify the entitlement and enforce the approved one-domain licence. On the private Kitsuly owner store, authorised licence-management requests may also include customer email, company, plan and expiry details. Payment card credentials are not sent to the licensing API.

Kitsuly Licensing API: https://api.kitsuly.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/

Kitsuly Signature Theme Catalogue

When the merchant opens the Signature Edition theme catalogue, Kitsuly may request up to four promoted theme-pack records from Kitsuly/T1K1 endpoints. The catalogue request sends normal HTTP request metadata plus the Kitsuly plugin version in the User-Agent so compatible theme metadata can be returned. If the merchant deliberately chooses Install, Kitsuly downloads only that selected Kitsuly-native theme pack from the same validated HTTPS host and imports its layout/JSON/media assets into the local store. These are Kitsuly theme packs, not WordPress themes, and the plugin does not activate a WordPress theme.

Kitsuly: https://kitsuly.com/
T1K1: https://t1k1.com/
Kitsuly terms: https://kitsuly.com/terms/
Kitsuly privacy: https://kitsuly.com/privacy/

Google services

If Google Analytics or Google Search Console integrations are configured, Kitsuly sends the merchant-configured credentials, property/site identifiers and report/query parameters to the applicable Google APIs so aggregate analytics or search-performance information can be retrieved. Google OAuth endpoints are contacted only when the merchant explicitly connects or refreshes a Google integration.

When a merchant explicitly runs the Site SEO performance analyser, Kitsuly sends the tested public page URL and selected mobile/desktop strategy to Google’s PageSpeed Insights API so Google can return performance diagnostics.

Google privacy: https://policies.google.com/privacy
Google API terms: https://developers.google.com/terms
Google PageSpeed Insights documentation: https://developers.google.com/speed/docs/insights/v5/get-started

AI providers

Kitsuly can optionally connect to OpenAI, Google Gemini and Anthropic Claude for merchant-invoked content generation, marketing automation and the Kit dashboard assistant. For ordinary content/marketing actions, the selected provider receives the merchant’s API credential plus the prompt and relevant source copy or product/content context required for that request. When Kit AI is connected, Kit sends only the merchant’s question, the current Kitsuly screen, the installed Kitsuly version and the most relevant built-in Kitsuly help snippets needed to answer the question. Kit’s local navigation/component help works without sending a request to an external AI provider.

OpenAI privacy: https://openai.com/policies/privacy-policy/
OpenAI terms: https://openai.com/policies/terms-of-use/
Google privacy: https://policies.google.com/privacy
Gemini API terms: https://ai.google.dev/gemini-api/terms
Anthropic privacy: https://www.anthropic.com/legal/privacy
Anthropic commercial terms: https://www.anthropic.com/legal/commercial-terms

Shopify

When Shopify transfer tools are enabled, Kitsuly sends the configured Shopify store domain and Admin API token together with catalogue/import query data to Shopify’s Admin API so merchant-authorised store content can be read for transfer.

Shopify privacy: https://www.shopify.com/legal/privacy
Shopify API terms: https://www.shopify.com/legal/api-terms

Australia Post

When Australia Post live shipping is enabled, Kitsuly sends the configured API/account credentials and the origin/destination and parcel data required for the selected quote request, such as postcode, weight and dimensions, to Australia Post.

Australia Post developer information: https://auspost.com.au/developers/
Australia Post terms: https://auspost.com.au/terms-conditions
Australia Post privacy: https://auspost.com.au/privacy

DHL Express

When DHL Express live shipping is enabled, Kitsuly sends the merchant’s DHL API credentials plus the origin, destination and parcel details needed to request shipping rates from the DHL MyDHL API. This occurs only when a customer or merchant requests a live shipping quote.

DHL developer information: https://developer.dhl.com/
DHL terms: https://www.dhl.com/global-en/home/footer/terms-of-use.html
DHL privacy: https://www.dhl.com/global-en/home/footer/privacy-notice.html

Sendle

When Sendle live shipping is enabled, Kitsuly sends the merchant’s Sendle credentials and the origin, destination and parcel details required for a shipping quote to the Sendle API. This occurs only when a live Sendle quote is requested.

Sendle developer information: https://developers.sendle.com/
Sendle terms: https://support.sendle.com/hc/en-au/articles/205800148-Terms-and-Conditions
Sendle privacy: https://support.sendle.com/hc/en-au/articles/206525557-Privacy-Policy

FedEx

When FedEx live shipping is enabled, Kitsuly sends the merchant’s FedEx OAuth credentials/account number and the origin, destination and parcel details required to authenticate and request shipping rates from FedEx. This occurs only when a live FedEx quote is requested.

FedEx developer information: https://developer.fedex.com/
FedEx terms: https://www.fedex.com/en-us/terms-of-use.html
FedEx privacy: https://www.fedex.com/en-us/trust-center/privacy.html

UPS

When UPS live shipping is enabled, Kitsuly sends the merchant’s UPS OAuth credentials and the origin, destination and parcel details required to authenticate and request shipping rates from UPS. This occurs only when a live UPS quote is requested.

UPS developer information: https://developer.ups.com/
UPS terms: https://www.ups.com/us/en/support/shipping-support/legal-terms-conditions.page
UPS privacy: https://www.ups.com/us/en/support/shipping-support/legal-terms-conditions/privacy-notice.page

BigCommerce

When the optional BigCommerce transfer connection is configured, Kitsuly stores the merchant-provided store hash, client ID and access token so the merchant can stage a migration of catalogue, customer and order information. When transfer requests are performed, the credential and the requested resource/query information are sent to the merchant’s BigCommerce store API. The connection is not used unless the merchant configures and starts the transfer feature.

BigCommerce developer information: https://developer.bigcommerce.com/docs/start/authentication/api-accounts
BigCommerce terms: https://www.bigcommerce.com/terms/
BigCommerce privacy: https://www.bigcommerce.com/privacy/

Social publishing services

When a merchant connects a supported social account and deliberately publishes from Kitsuly Marketing, the applicable provider receives the account identifiers/authorisation held for that connection plus the post content required by the selected network, such as title or message text, public destination link, public media URL and network-specific publishing choices. Facebook, Instagram, Pinterest, X, LinkedIn and TikTok can use the Kitsuly Platform Controller broker described above where the connected merchant account and provider permissions allow it. GitHub publishing uses the merchant-provided GitHub access token and repository directly from the WordPress installation. Dribbble and DeviantArt currently use connection/setup or manual-handoff states when their required publishing/upload flow is unavailable rather than reporting an external post as successful.

Meta privacy: https://www.facebook.com/privacy/policy/
Meta Platform terms: https://developers.facebook.com/terms/
Pinterest privacy: https://policy.pinterest.com/privacy-policy
Pinterest developer terms: https://developers.pinterest.com/terms/
X privacy: https://x.com/en/privacy
X developer agreement: https://developer.x.com/en/developer-terms/agreement-and-policy
LinkedIn privacy: https://www.linkedin.com/legal/privacy-policy
LinkedIn API terms: https://www.linkedin.com/legal/l/api-terms-of-use
TikTok privacy: https://www.tiktok.com/legal/page/row/privacy-policy/en
TikTok developer terms: https://www.tiktok.com/legal/page/global/tik-tok-developer-terms-of-service/en
GitHub privacy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
GitHub terms for developer features: https://docs.github.com/en/site-policy/github-terms/github-terms-for-additional-products-and-features

Merchant-configured remote digital files

For a digital product, a merchant can optionally configure a remote source URL instead of storing the downloadable file in the local WordPress uploads directory. When an authorised customer uses a valid Kitsuly download token, the WordPress server requests that merchant-configured URL, temporarily streams the returned file through the store and then removes the temporary copy. Kitsuly does not choose or operate that remote host; the merchant is responsible for the terms, privacy policy and permission to use whichever remote storage/provider URL they configure.

Optional media, map and font resources

Kitsuly Builder can render merchant-selected YouTube or Vimeo video embeds and Google Maps embeds. When a merchant places one of these elements on a public page, the visitor’s browser connects to the selected provider to load that media or map; the provider may receive normal web-request information such as the visitor’s IP address, browser headers and the requested embed URL. Kitsuly uses YouTube’s privacy-enhanced youtube-nocookie.com embed domain where supported. Kitsuly can also load Google Fonts selected by the merchant, which causes the visitor’s browser to request the chosen font resources from Google.

YouTube terms: https://www.youtube.com/static?template=terms
Google privacy: https://policies.google.com/privacy
Google Maps terms: https://maps.google.com/help/terms_maps/
Vimeo terms: https://vimeo.com/terms
Vimeo privacy: https://vimeo.com/privacy
Google Fonts information: https://developers.google.com/fonts/faq/privacy

QR discount tickets

The merchant-only QR discount ticket maker requests a QR-code PNG from QRServer (api.qrserver.com) when a store administrator opens or generates a coupon ticket. The request contains the public store promotion URL and selected coupon code so the QR image can be created. No customer, order, payment or account data is sent by this feature. If the QR service is unavailable, the ticket image cannot be generated until it becomes available again.

QRServer / goQR.me API information: https://goqr.me/api/
QRServer API privacy statement: https://goqr.me/de/rechtliches/datenschutz-api.html
QRServer API terms of service: https://goqr.me/legal/tos-api.html

Kitsuly.com owner-site documentation compatibility

When the plugin is running on kitsuly.com itself, it can render Kitsuly’s own documentation library from cover images and PDF files already stored in that site’s local WordPress uploads folders. This compatibility component is disabled on third-party/customer sites and does not contact kitsuly.com from those installations.

Source Code

This plugin ZIP is the source distribution. The PHP under src/ and includes/, the JavaScript under assets/js/ and assets/seo/, and the CSS under assets/css/ and assets/seo/ are the human-readable maintained source files loaded by WordPress.

Kitsuly Commerce does not use npm, webpack, Rollup, Vite, Babel, Sass or another compilation/minification pipeline for the distributed first-party assets. There is no separate unpublished source tree or build command needed to recreate the JavaScript/CSS included in this ZIP. The distributed files are intentionally readable and are edited directly.

A concise source-layout note is also included as SOURCE-CODE.txt. Third-party components and their licences are documented in THIRD-PARTY-LICENSES.txt.

Frequently asked questions

What is Kitsuly Commerce?

Kitsuly Commerce is a free WordPress plugin available under the GPL license. The current version is 1.44.11.

Is Kitsuly Commerce free to download?

Yes — Kitsuly Commerce 1.44.11 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.

How do I install Kitsuly Commerce 1.44.11?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for Kitsuly Commerce?

Kitsuly Commerce 1.44.11 requires WordPress 6.6 or higher and PHP 8.1 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was Kitsuly Commerce last updated?

Version 1.44.11 was last updated on September 28, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the Kitsuly Commerce download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.44.11
Updated: October 1, 2026

Technical details

Version1.44.11
Last updatedSeptember 28, 2026
Requires WordPress6.6 or higher
Requires PHP8.1 or higher
AuthorKITSULY
Tagscheckout, commerce, ecommerce, store, stripe

Download Kitsuly Commerce

Download Kitsuly Commerce WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment