xpay✦ Commerce
Directory
WooCommerce plugins
Pay4All Age Verification – For WooCommerce & Pay4All Shop
Pay4All Age Verification – For WooCommerce & Pay4All Shop
Age verification by scanning a QR code (ID document and/or video selfie) when ordering products subject to a legal age restriction from WooCommerce.
Will this break my store?
What the WordPress.org registry says about keeping Pay4All Age Verification – For WooCommerce & Pay4All Shop running.
Tested to 7.0.2
Tested against the WordPress branch in use today.4 days ago
7.4
Your host must be running at least this version.5.9
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how Pay4All Age Verification – For WooCommerce & Pay4All Shop is looked after — not on how many stores run it.
Maintenance
35 / 35WordPress compatibility
20 / 20Support responsiveness
Not enough dataMerchant satisfaction
Not enough dataListing transparency
7 / 10Ratings
No one has rated this plugin on WordPress.org yet. That is a statement about the ratings page, not about the plugin — plenty of well-kept plugins never collect them.
Pay4All Age Verification blocks any order containing age-restricted products until the customer has submitted a 5-second video selfie and/or valid proof of identity, including the front and back of the document. The video selfie and identity document photos are captured by scanning a QR code, allowing the customer to continue the verification process on their smartphone.
The plugin integrates with WooCommerce and Pay4All Shop (pay4all-form). Install it alongside either e-commerce solution, and it will only appear when a product is marked as requiring age verification. The same settings page (Pay4All AGE > Settings) manages both integrations. A merchant using both Pay4All Shop and WooCommerce therefore only needs to configure the verification process once and will benefit from consistent behaviour across both platforms.
Identity document photos and/or video selfie
The merchant can choose to require either verification method or both, depending on the applicable legislation.
WooCommerce support
Simply select the Requires age verification option on the product page to trigger QR-code age verification during checkout. The customer’s age verification status can be reviewed directly from the order.
Pay4All Pro provides the WooCommerce integration. Pay4All Age remains completely free when used with Pay4All Shop.
How it works
- The merchant selects the Requires age verification option on the product edit screen.
- When a customer adds the product to their order form, a panel containing a QR code appears.
- The customer scans the QR code with their smartphone. The mobile capture page opens and allows them to take the required identity document photos or record the video selfie using their phone’s camera.
- The form displayed on the customer’s computer automatically unlocks once all required photos and/or the video selfie have been submitted.
- When the order is submitted, the encrypted photos and videos are stored with the order. They are only decrypted on demand by an administrator from the order edit screen.
Security
- Photos are encrypted with AES-256-GCM using a per-order (or per-user) subkey derived via HMAC-SHA256 from a master key.
- Ciphertexts live in a private folder guarded, so they are never web-servable.
- Admin decryption endpoint is nonce-protected and requires the
edit_userscapability. - Photos are auto-purged when the order (or user) is permanently deleted.
WPML / Polylang
Multilingual-aware : when the Requires age verification flag is set on a source product, every translation is treated as age-restricted too — even if the flag hasn’t been mirrored to the translation.
Available languages
Français (fr_FR), Deutsch (de_DE), Italiano (it_IT), English (en_US).
External services
This plugin does not connect to any external service. Everything runs on the site: photo capture, encryption, storage and admin decryption are all local. No data is sent to any third-party server.
Source code
The complete, non-minified source of this plugin is bundled inside the ZIP itself. Every PHP, CSS and JavaScript file is human-readable and directly editable. No compiler, transpiler or bundler is required to work on this plugin.
Yes. Pay4All Age Verification is a companion plugin — it plugs into either Pay4All Shop (free, ships the form-based checkout) or WooCommerce (via the paid Pay4All Pro add-on). On a bare WordPress install without either, the plugin stays dormant and shows an admin notice on the Plugins screen.
AES-256-GCM with a per-order (or per-user) subkey derived via HMAC-SHA256 from a master key. The master key is generated once and stored in wp-content/uploads/p4all-age-secure/age.key (mode 0600). Ciphertexts live in the same private folder, guarded by .htaccess, index.php and web.config so they are never web-servable — a direct URL always returns 403 / 404. See the Security section above for the full threat model.
Outside the database, in wp-content/uploads/p4all-age-secure/age.key. This means a stolen SQL dump alone is not enough to decrypt the photos — the attacker would also need read access to that specific file. Please make sure your backup strategy either encrypts wp-content/uploads/p4all-age-secure/ or excludes it entirely from the backup archive.
They are auto-purged. Both the WooCommerce order lifecycle (woocommerce_delete_order hook) and Pay4All Shop order deletion trigger KycStorage::purge_order(), which removes every encrypted blob and the order-scoped directory. A daily cron also purges session-scoped buckets older than the configured TTL (default 24 h).
The delete_user hook fires KycStorage::purge_user() — every stored user photo (recto / verso / selfie_1 / selfie_2) is removed together with the user record. GDPR-friendly by default.
The page uses the native <input type="file" accept="image/*" capture="…"> API — supported by Safari (iOS 6+), Chrome, Firefox, Edge on both Android and iOS. On the desktop side, the QR code is generated with a pure-JS library (no external service call) and the pairing is polled every 4 seconds via a REST endpoint scoped to the session token.
Yes. When a product’s Requires age verification flag is ticked on a source-language product, every translation is treated as age-restricted too — even if the flag hasn’t been mirrored to the translation post. Same behaviour on WooCommerce products via Pay4All Pro.
French (fr_FR), German (de_DE), Italian (it_IT) and English (en_US). Every customer-facing string is also overridable per-language from the settings page — merchants can rewrite the KYC panel copy without touching a .po file.
No. Photo capture, encryption, storage and admin decryption are all local — nothing leaves the site. The QR code is generated client-side ; the mobile page polls only your own WordPress REST API.
Categories
Plugin details
Tags on WordPress.org
