CashuPayServer v0.5.5-alpha is out.
If you switched your store to a different mint on 0.5.4, payments could get stuck in "Processing". This release fixes it, and those payments are credited once you upgrade. It also runs on PHP 8.1 and 8.2 now, and a standalone install sitting inside a WordPress site's folder no longer answers 403.
WooCommerce shops can save the BTCPay plugin settings without the key being rejected, and a customer who retries paying an order gets the payment page instead of a 404.
The QR libraries used to load from CDNs, including on the admin page that can show your seed phrase. They ship with the app now.
There's also a signed emergency shutdown. If we ever find a hole that lets strangers take your money, we can publish a notice signed with a Nostr key, and installs on the affected versions stop until they're upgraded. Nothing moves your funds. If you'd rather not have it, turning off the update check in Settings turns it off too.
Reasoning for doing this in this blog:
https://juraj.bednar.io/en/blog-en/2026/09/18/ten-ai-models-vs-embargoed-core-lightning-a-case-study-of-ai-for-auditing/ (Section "Signed kill switch"). I wish other Bitcoin projects included something like this.
Upload it over your old install and keep the data folder.
https://github.com/jooray/cashupayserver/releases/tag/v0.5.5-alpha