Linux 软件免费装
Banner图

Pay4All Age Verification for WooCommerce & Pay4All Shop

开发者 pay4all
更新时间 2026年7月23日 00:56
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

age verification age gate adult selfie id verification

下载

1.1.0 1.0.0 1.1.1 1.1.2 1.3.1

详情介绍:

Pay4All Age Verification blocks any order containing age-restricted products until the customer has uploaded a valid ID (recto + verso) and/or two selfies. Photos are captured either directly on the customer's desktop or, more commonly, through a QR code that hands off to their smartphone. The plugin plugs into Pay4All Shop (pay4all-form) and WooCommerce. Install it alongside either storefront and it will only surface where a product is flagged as age-restricted. The same setting screen (Pay4All AGE > Paramètres) drives both integrations — a merchant running Pay4All Shop AND WooCommerce configures the verification once, gets consistent behaviour everywhere. Drag-drop step order The two capture steps (ID card front/back and selfies) can be reordered by drag-and-drop from Pay4All AGE > Paramètres > Documents à demander > Ordre d'affichage. The chosen order applies to both Pay4All Shop and WooCommerce checkouts. WooCommerce support The WooCommerce integration (product-level "Requires age verification" checkbox, QR-code checkout panel, order-screen photo viewer) is provided by the paid Pay4All Pro add-on, distributed through pay4all.ch. Pay4All Age itself remains free ; Pay4All Pro simply wires it into WooCommerce. How it works
  1. Merchant ticks Requires age verification on any product edit screen (Pay4All Shop product).
  2. When a customer adds such a product to their form, a panel appears in the KYC step showing a QR code.
  3. Customer scans the QR with their phone -> the mobile capture page opens -> they take the required photos with their phone camera.
  4. The desktop form polls the server every 4 seconds and unlocks automatically when every required slot is filled — no page refresh needed.
  5. On order submit, the encrypted photos are moved from the session bucket to the order-scoped bucket, and are only decrypted on demand by an admin from the order edit screen.
Security WPML / Polylang Multilingual-aware : when the Requires age verification flag is set on a source product, every translation is treated as age-restricted too — even if the flag hasn't been mirrored to the translation. Available languages Français (fr_FR), Deutsch (de_DE), Italiano (it_IT), English (en_US).

安装:

  1. Upload the plugin to /wp-content/plugins/pay4all-age-verification/ or install via Plugins > Add New.
  2. Activate it from the Plugins menu.
  3. Open Pay4All AGE > Paramètres to tune what documents you require and to override the customer-facing texts if needed.
  4. On each product that requires an age check, tick the Requires age verification checkbox on the product edit screen (Pay4All Shop product).

屏幕截图:

  • Customer checkout with an age-restricted product in the cart : the KYC panel appears in the « Vérification d'âge » step with the QR code + status of each photo slot.
  • Mobile capture page (loaded from the QR) : native camera capture for ID recto / verso and selfies, live upload progress, encrypted at rest before storage.
  • Admin lightbox : merchant clicks the shield icon on the order edit screen — the encrypted photos are streamed, decrypted on-the-fly, and displayed side-by-side without being written back to disk.
  • Settings page : merchant chooses required documents (ID / selfies / both), OR / AND mode, purge delay, and can override the customer-facing texts in each activated language.

升级注意事项:

1.0.0 Initial release.

常见问题:

Do I need Pay4All Shop or WooCommerce?

Yes. Pay4All Age Verification is a companion plugin — it plugs into either Pay4All Shop (free, ships the form-based checkout) or WooCommerce (via the paid Pay4All Pro add-on). On a bare WordPress install without either, the plugin stays dormant and shows an admin notice on the Plugins screen.

How are photos encrypted?

AES-256-GCM with a per-order (or per-user) subkey derived via HMAC-SHA256 from a master key. The master key is generated once and stored in wp-content/uploads/p4all-age-secure/age.key (mode 0600). Ciphertexts live in the same private folder, guarded by .htaccess, index.php and web.config so they are never web-servable — a direct URL always returns 403 / 404. See the Security section above for the full threat model.

Where is the master encryption key stored?

Outside the database, in wp-content/uploads/p4all-age-secure/age.key. This means a stolen SQL dump alone is not enough to decrypt the photos — the attacker would also need read access to that specific file. Please make sure your backup strategy either encrypts wp-content/uploads/p4all-age-secure/ or excludes it entirely from the backup archive.

What happens to the photos when an order is deleted?

They are auto-purged. Both the WooCommerce order lifecycle (woocommerce_delete_order hook) and Pay4All Shop order deletion trigger KycStorage::purge_order(), which removes every encrypted blob and the order-scoped directory. A daily cron also purges session-scoped buckets older than the configured TTL (default 24 h).

What happens if a user account is deleted?

The delete_user hook fires KycStorage::purge_user() — every stored user photo (recto / verso / selfie_1 / selfie_2) is removed together with the user record. GDPR-friendly by default.

Does the mobile capture page work on all phones?

The page uses the native <input type="file" accept="image/*" capture="…"> API — supported by Safari (iOS 6+), Chrome, Firefox, Edge on both Android and iOS. On the desktop side, the QR code is generated with a pure-JS library (no external service call) and the pairing is polled every 4 seconds via a REST endpoint scoped to the session token.

Does it work with WPML / Polylang?

Yes. When a product's Requires age verification flag is ticked on a source-language product, every translation is treated as age-restricted too — even if the flag hasn't been mirrored to the translation post. Same behaviour on WooCommerce products via Pay4All Pro.

Which languages ship out of the box?

French (fr_FR), German (de_DE), Italian (it_IT) and English (en_US). Every customer-facing string is also overridable per-language from the settings page — merchants can rewrite the KYC panel copy without touching a .po file.

Does the plugin contact any external service?

No. Photo capture, encryption, storage and admin decryption are all local — nothing leaves the site. The QR code is generated client-side ; the mobile page polls only your own WordPress REST API.

更新日志:

1.3.1 1.3.0 1.2.0 1.1.2 1.1.1 1.1.0 1.0.0