Turn it on
Go to WooCommerce → Powerups and switch on Order meta inspector in the Developer group. Open any order: the Order meta box starts collapsed until you open it once. The box loads its content when you open it (“Loading order meta…”). Big orders (more than 50 items) always load on open, so the order page stays fast.The Order meta box on an order page, with the Line items tab open
Use it
- The box has tabs for Order, Line items, Shipping, Coupons and Fees, with counts. Item tabs group by item, for example “Hoodie × 2 · Item #177”.
- Type in Search keys and values to search across all tabs. The counts show where the matches are. Press Esc to clear.
- Each row has Copy key, Copy value and Copy JSON. Copy tab as JSON copies what’s shown; items keep their structure.
The whole order as JSON
Use the Meta | JSON switch at the top of the box to see the whole order as JSON: the order, customer, line items, tax, shipping, fee and coupon lines, refunds and meta. The JSON loads only the first time you click JSON (“Loading the order as JSON…”).- Copy all copies the whole order. Copy section copies one part, such as
line_items. - Long JSON shows the first 200 lines; click Show all for the rest.
- Sensitive values show as
[masked]in the JSON, even for people allowed to reveal them in the meta view, so a copy never leaks secrets.
- how the order is stored (for example “Stored in the order tables (HPOS).”)
- how many sensitive values were masked
- what was cut: more than 250 items of one type (“Line items: showing the first 250 of 300.”), or very long values (over 10,000 characters), which end in
…[truncated: N chars]
The Order meta box in JSON view, with the note above the JSON and the Copy all button
Masked values
Fields that look sensitive (tokens, secrets, passwords, card and bank data, API keys, signatures) show as••••••. Allowed users can click Show to reveal one value.
- Masked values are never in the page source.
- Copying a masked row copies the mask.
- Masking ignores case, accents and look-alike characters in the key. For example
_access_tokén, full-width letters and zero-width characters are masked like_access_token. - A value that holds a sensitive key anywhere inside it, such as an access token inside a payment gateway’s saved response, is masked as a whole, in the box and in the JSON view. Values saved as JSON text count too.
- If you can’t reveal masked values, the order key, payment link, customer IP address and transaction ID are masked for you too, in the JSON view and in meta keys that look like them.
Settings
Data
Known limitations
- On orders with hundreds of items, the content loaded when you open the box can be several MB.