WooCommerce Checkout Field Validation Generator

Add server-side checkout validation to WooCommerce: pattern, length and range rules per field, with error messages that name the field.

Live output

Enable JavaScript to customise; default output below.

Rules
  1. For pattern, a PHP regex including its delimiters, such as /^[A-Z]{2}[0-9]{4}$/. For blocked words, a comma separated list.

Each rule runs after WooCommerce's own validation, so required and email checks are already done.

Live preview checkout-validation.php
<?php
/**
 * Checkout validation.
 *
 * Server side, because anything in the browser can be skipped. This runs
 * after WooCommerce's own validation, so required and email checks are done.
 */

/**
 * Checks the submitted fields.
 *
 * @param array    $data   Posted checkout data.
 * @param WP_Error $errors Errors to add to.
 */
function my_store_validate_checkout( $data, $errors ) {

	if ( ! empty( $data['billing_phone'] ) ) {
		$digits = preg_replace( '/[^0-9]/', '', $data['billing_phone'] );

		if ( strlen( $digits ) < 7 || strlen( $digits ) > 15 ) {
			$errors->add( 'validation', esc_html__( 'Enter a phone number we can reach you on, digits only.', 'my-store' ) );
		}
	}
}
add_action( 'woocommerce_after_checkout_validation', 'my_store_validate_checkout', 10, 2 );

Output is valid and updates as you type.

Add server-side checkout validation to WooCommerce: per-field rules, a minimum order value, and messages that tell the customer what to do rather than that something is wrong.

How to use

  1. Write rules against the field key, not the label. billing_phone, not “Phone”.
  2. Let WooCommerce do the basics. This runs after its own validation, so required and email format are already checked.
  3. Write messages a customer can act on. “Enter a phone number we can reach you on” beats “Invalid phone number”.
  4. Check the minimum order on the cart as well as at checkout, which is what the generated code does. Telling someone at the payment step is how a basket is abandoned.
  5. Test with the browser’s validation disabled. Anything enforced only in the browser is not enforced.

Example

function acme_validate_checkout( $data, $errors ) {
	if ( ! empty( $data['billing_phone'] ) ) {
		$digits = preg_replace( '/[^0-9]/', '', $data['billing_phone'] );

		if ( strlen( $digits ) < 7 || strlen( $digits ) > 15 ) {
			$errors->add( 'validation', esc_html__( 'Enter a phone number we can reach you on.', 'acme' ) );
		}
	}
}
add_action( 'woocommerce_after_checkout_validation', 'acme_validate_checkout', 10, 2 );

Stripping non-digits before counting is deliberate: +44 20 7946 0000 and 02079460000 are the same number, and a length check on the raw string rejects the first.

Pitfalls

  • Browser validation is a convenience, not a control. Everything real happens on the server, which is what this hook is for.
  • woocommerce_after_checkout_validation passes $errors as a WP_Error. Adding a notice with wc_add_notice() inside it double-reports the problem in some themes.
  • Phone number formats vary enormously by country. A strict pattern written for one market rejects real customers in another.
  • A user-supplied regex can be catastrophically slow on a crafted input. Keep patterns simple and anchored.
  • PO box matching catches the common spellings and misses the rest. Treat it as a filter, not a guarantee.
  • The minimum order check should look at the subtotal, not the total, or a coupon or a shipping charge changes whether the rule fires.
  • The Checkout block does not use this hook. Blocks validate through their own API and the Store API.
  • Validation that fires only at checkout lets someone fill a basket they can never buy. Check the cart too.

Compatibility

woocommerce_after_checkout_validation has been available since WooCommerce 3.0 with the $errors argument, and woocommerce_check_cart_items since 2.x. Both apply to the classic shortcode checkout in WooCommerce 8 and 9. The Checkout block validates through the Store API, so these rules do not run there. The generated code targets PHP 7.0 and up, and the tool runs entirely in your browser.

Frequently asked questions

Why is my validation not firing?
The store is probably using the Checkout block, which validates through the Store API rather than this hook.
Should I validate phone numbers strictly?
Only if you know your market. Digits and a length range is usually as strict as is safe.
Where does the error appear?
At the top of the checkout form, in the standard WooCommerce notice area.
Can I validate a custom field?
Yes. Use its key in $data, exactly as it appears in the posted form.
How do I stop a specific product being ordered below a quantity?
Hook woocommerce_check_cart_items and inspect the cart contents. The minimum order option here shows the shape.

From the people who built this tool

WP Adminify

The WordPress admin, rebuilt: a dashboard worth looking at, menu and column control, a real file manager and the login page your client sees.

See WP Adminify Free version on WordPress.org

Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.