PWA Guest Checkout 5.3 - Security / Compatibility Fixes

Applied in this package:

1. Guest-order reflected XSS
   - Normalize order_id to an integer in guest_order.php.
   - Use the normalized value everywhere in the guest-order page/template.

2. Guest-order token security
   - Guest tokens are now 32 random characters.
   - Only SHA-256 hashes are stored in orders.reviews_key.
   - Existing plaintext 12-character tokens are migrated to SHA-256 hashes during install.
   - Token lifetime is configurable; default is 365 days.
   - Token validation is applied consistently to guest_order.php and guest review access.
   - Admin status-update emails rotate the guest token so the plaintext token does not need to be recoverable from the database.

3. Admin guest-account deletion
   - Destructive deletion changed from GET to POST.
   - Session token is required and checked with hash_equals().
   - Browser confirmation is added.
   - GROUP_CONCAT() was removed; IDs are collected as integers in PHP.
   - Empty guest sets are handled without generating IN ().
   - Child records are deleted before the customer record.

4. cd_matc hook
   - Installation no longer deletes the checkout_confirmation/cd_matc hook.

5. Guest reviews
   - Guest review endpoint now registers Phoenix's reviewable pipeline, matching Phoenix 1.1.0.7's official review endpoint.
   - Token validation is applied before review access.

6. zz_redirect.php
   - $db and $Linker are explicitly brought into method scope.
   - Guest review token validation uses the hashed token and lifetime check.

7. Checkout redirect / uninstall
   - Installation no longer overwrites CHECKOUT_REDIRECT.
   - Uninstall no longer forcibly changes CHECKOUT_REDIRECT.
   - Optional column removal checks INFORMATION_SCHEMA before dropping columns.

8. Version / headers / markup
   - Admin version changed from 4.6.4 to 5.3.
   - Stale 4.6.0 template header updated.
   - phoenixcartaddonsaddons.com references corrected.
   - Duplicate <tbody> corrected to </tbody>.
   - Malformed textarea placeholder array corrected.
   - PHP files were syntax checked after modification.

Still requires a separate implementation decision:

- PAYMENT_MODULES is still only a configuration setting. It needs to be connected to the Phoenix checkout/payment pipeline for the intended virtual-guest-order filtering. I have deliberately not guessed the hook point.

Documentation PDF has not been rewritten in this pass.

ADDITIONAL FILE RESTORED
------------------------
- Restored the PWA payment class override at:
  templates/override/includes/classes/payment.php
- This override applies MODULE_CONTENT_PWA_LOGIN_PAYMENT_MODULES to the
  installed payment module list for guest customers.
- The payment-module filtering was therefore restored as functional runtime
  code rather than merely leaving the configuration setting defined.
- The selected-module filename comparison was normalized to use <module>.php,
  matching the installed-module list.
