Currently, WHMCS does Auth+Capture via the Authorize.Net API. A rash of skilled credit card thieves recently plowed through WHMCS and got past both of the anti-fraud modules. These must have been particularly skilled criminals with a large database of working stolen cards. Not capturing payments immediately would be helpful to hosting companies who are less lucky than others.
I second this request but not only for Authorize.net. We use PayFlow Pro and would like to perform authorizations only at the time of order and then have the payment captured when we process the order. Using the sale transaction type which does the auth and immediate capture is bad practice for merchants.
1 Comment
Login to post a comment.