plugin-icon

Pay4All Age Verification for WooCommerce & Pay4All Shop

Von pay4all·
Age verification for WooCommerce and Pay4All Shop. ID + selfie capture, cross-device QR, AES-256-GCM encryption. 100% local.
Version
1.4.1
Zuletzt aktualisiert
Jul 27, 2026
Pay4All Age Verification for WooCommerce & Pay4All Shop

Pay4All Age Verification blocks any order containing age-restricted products until the customer has uploaded a valid ID (recto + verso) and/or two selfies. Photos are captured either directly on the customer’s desktop or, more commonly, through a QR code that hands off to their smartphone.

The plugin plugs into Pay4All Shop (pay4all-form) and WooCommerce. Install it alongside either storefront and it will only surface where a product is flagged as age-restricted. The same setting screen (Pay4All AGE > Paramètres) drives both integrations — a merchant running Pay4All Shop AND WooCommerce configures the verification once, gets consistent behaviour everywhere.

Drag-drop step order

The two capture steps (ID card front/back and selfies) can be reordered by drag-and-drop from Pay4All AGE > Paramètres > Documents à demander > Ordre d'affichage. The chosen order applies to both Pay4All Shop and WooCommerce checkouts.

WooCommerce support

The WooCommerce integration (product-level „Requires age verification“ checkbox, QR-code checkout panel, order-screen photo viewer) is provided by the paid Pay4All Pro add-on, distributed through pay4all.ch. Pay4All Age itself remains free ; Pay4All Pro simply wires it into WooCommerce.

How it works

  1. Merchant ticks Requires age verification on any product edit screen (Pay4All Shop product).
  2. When a customer adds such a product to their form, a panel appears in the KYC step showing a QR code.
  3. Customer scans the QR with their phone -> the mobile capture page opens -> they take the required photos with their phone camera.
  4. The desktop form polls the server every 4 seconds and unlocks automatically when every required slot is filled — no page refresh needed.
  5. On order submit, the encrypted photos are moved from the session bucket to the order-scoped bucket, and are only decrypted on demand by an admin from the order edit screen.

Security

  • Photos are encrypted with AES-256-GCM using a per-order (or per-user) subkey derived via HMAC-SHA256 from a master key.
  • Ciphertexts live in a private folder guarded, so they are never web-servable.
  • Admin decryption endpoint is nonce-protected and requires the edit_users capability.
  • Photos are auto-purged when the order (or user) is permanently deleted.

WPML / Polylang

Multilingual-aware : when the Requires age verification flag is set on a source product, every translation is treated as age-restricted too — even if the flag hasn’t been mirrored to the translation.

Available languages

Français (fr_FR), Deutsch (de_DE), Italiano (it_IT), English (en_US).

External services

This plugin does not connect to any external service. Everything runs on the site: photo capture, encryption, storage and admin decryption are all local. No data is sent to any third-party server.

Source code

The complete, non-minified source of this plugin is bundled inside the ZIP itself. Every PHP, CSS and JavaScript file is human-readable and directly editable. No compiler, transpiler or bundler is required to work on this plugin.

Kostenlosmit kostenpflichtigen Tarifen
Mit deiner Installation stimmst du den Geschäftsbedingungen von WordPress.com sowie den Bedingungen für Drittanbieter-Plugins zu.
Getestet bis
WordPress 7.0.2
Dieses Plugin steht für deine -Website zum Download zur Verfügung.