| 开发者 | pay4all |
|---|---|
| 更新时间 | 2026年7月23日 00:56 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPL-2.0-or-later |
| 版权网址: | 版权信息 |
Pay4All AGE > Paramètres) drives both integrations — a merchant running Pay4All Shop AND WooCommerce configures the verification once, gets consistent behaviour everywhere.
Drag-drop step order
The two capture steps (ID card front/back and selfies) can be reordered by drag-and-drop from Pay4All AGE > Paramètres > Documents à demander > Ordre d'affichage. The chosen order applies to both Pay4All Shop and WooCommerce checkouts.
WooCommerce support
The WooCommerce integration (product-level "Requires age verification" checkbox, QR-code checkout panel, order-screen photo viewer) is provided by the paid Pay4All Pro add-on, distributed through pay4all.ch. Pay4All Age itself remains free ; Pay4All Pro simply wires it into WooCommerce.
How it works
edit_users capability./wp-content/plugins/pay4all-age-verification/ or install via Plugins > Add New.Yes. Pay4All Age Verification is a companion plugin — it plugs into either Pay4All Shop (free, ships the form-based checkout) or WooCommerce (via the paid Pay4All Pro add-on). On a bare WordPress install without either, the plugin stays dormant and shows an admin notice on the Plugins screen.
AES-256-GCM with a per-order (or per-user) subkey derived via HMAC-SHA256 from a master key. The master key is generated once and stored in wp-content/uploads/p4all-age-secure/age.key (mode 0600). Ciphertexts live in the same private folder, guarded by .htaccess, index.php and web.config so they are never web-servable — a direct URL always returns 403 / 404. See the Security section above for the full threat model.
Outside the database, in wp-content/uploads/p4all-age-secure/age.key. This means a stolen SQL dump alone is not enough to decrypt the photos — the attacker would also need read access to that specific file. Please make sure your backup strategy either encrypts wp-content/uploads/p4all-age-secure/ or excludes it entirely from the backup archive.
They are auto-purged. Both the WooCommerce order lifecycle (woocommerce_delete_order hook) and Pay4All Shop order deletion trigger KycStorage::purge_order(), which removes every encrypted blob and the order-scoped directory. A daily cron also purges session-scoped buckets older than the configured TTL (default 24 h).
The delete_user hook fires KycStorage::purge_user() — every stored user photo (recto / verso / selfie_1 / selfie_2) is removed together with the user record. GDPR-friendly by default.
The page uses the native <input type="file" accept="image/*" capture="…"> API — supported by Safari (iOS 6+), Chrome, Firefox, Edge on both Android and iOS. On the desktop side, the QR code is generated with a pure-JS library (no external service call) and the pairing is polled every 4 seconds via a REST endpoint scoped to the session token.
Yes. When a product's Requires age verification flag is ticked on a source-language product, every translation is treated as age-restricted too — even if the flag hasn't been mirrored to the translation post. Same behaviour on WooCommerce products via Pay4All Pro.
French (fr_FR), German (de_DE), Italian (it_IT) and English (en_US). Every customer-facing string is also overridable per-language from the settings page — merchants can rewrite the KYC panel copy without touching a .po file.
No. Photo capture, encryption, storage and admin decryption are all local — nothing leaves the site. The QR code is generated client-side ; the mobile page polls only your own WordPress REST API.
get_edit_post_link() returns an empty string when called from the customer's public REST upload (no edit_post cap). URL is now built manually.Pay4All AGE > Paramètres > Textes > Renvoi, with placeholders {customer_firstname}, {customer_lastname}, {order_number}, {slots_list}, {link}, {admin_order_url}, {site_name}, {shop_name}. Sensible FR / DE / IT / EN defaults ship out of the box.Pay4All AGE > Paramètres > Documents à demander > Ordre d'affichage. The chosen order applies to both Pay4All Shop and WooCommerce checkouts (single source of truth). Keyboard fallback (up/down arrows) included for accessibility.<details> markup.