[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqNGFyTL3e39hpCk9GFPtuGLAAv_Ye525JoJOo30teAU":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"mredodos","Edoardo G.","https:\u002F\u002Fprofiles.wordpress.org\u002Fmredodos\u002F",1,100,30,94,"2026-08-28T21:48:11.191Z",[13],{"slug":14,"name":15,"version":16,"author":5,"author_profile":6,"description":17,"short_description":18,"active_installs":8,"downloaded":19,"rating":20,"num_ratings":20,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":8,"vuln_count":20,"unpatched_count":20,"last_vuln_date":33,"fetched_at":34},"wwu-withdrawal-button","WWU Right of Withdrawal for Popular Ecommerce Platforms","1.4.0","\u003Cp>Product page & docs: \u003Ca href=\"https:\u002F\u002Fwebwakeup.it\u002Fwwu-withdrawal-button\u002F\" rel=\"nofollow ugc\">webwakeup.it\u002Fwwu-withdrawal-button\u003C\u002Fa> | source code, issues & contributions: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAn-Idea-For-Business\u002Fwwu-withdrawal-button\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>From 19 June 2026, EU law (Directive (EU) 2023\u002F2673, new Art. 11a of the Consumer Rights Directive; Italy: Art. 54-bis Codice del Consumo) requires online stores to provide a \u003Cstrong>withdrawal function\u003C\u002Fstrong> that lets consumers withdraw from a distance contract as easily as they concluded it. WWU Withdrawal Button adds that function — and everything around it you need to run it and to prove you did it right — to WooCommerce, FluentCart and Easy Digital Downloads.\u003C\u002Fp>\n\u003Ch4>How it works (in plain terms)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>An eligible customer opens their order and clicks the statutory \u003Cstrong>“Withdraw from contract here”\u003C\u002Fstrong> button — in their account, from a link in the order e-mail, or on a public page (no account needed: they look the order up with its number + e-mail).\u003C\u002Fli>\n\u003Cli>A simple \u003Cstrong>two-step form\u003C\u002Fstrong> appears: they review what they are withdrawing from (optionally ticking only some items — partial withdrawal is allowed), then confirm. No reason required, no hoops.\u003C\u002Fli>\n\u003Cli>The instant they confirm, the customer receives an \u003Cstrong>acknowledgement of receipt on a durable medium\u003C\u002Fstrong> — an e-mail, a PDF copy and a permanent verifiable link — showing exactly what was withdrawn and the precise date and time. The order is flagged “withdrawal requested”.\u003C\u002Fli>\n\u003Cli>Every step is written to a \u003Cstrong>tamper-evident, append-only log\u003C\u002Fstrong> (hash-chained and timestamped) so you can prove what happened and when. You then handle the refund as usual — the plugin records that too.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>That is the whole customer experience. Everything below exists to make it correct, easy to run, and defensible.\u003C\u002Fp>\n\u003Ch4>For your customers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>A prominently displayed, legible button with the \u003Cstrong>exact statutory wording per language\u003C\u002Fstrong> (IT, EN, DE, FR, ES, SV — extensible).\u003C\u002Fli>\n\u003Cli>The button appears where customers actually look: the \u003Cstrong>account area\u003C\u002Fstrong> (order list, order detail, a dedicated “Right of withdrawal” tab), a \u003Cstrong>link inside order e-mails\u003C\u002Fstrong>, a \u003Cstrong>public self-service page\u003C\u002Fstrong> with guest lookup, and anywhere via \u003Cstrong>shortcodes\u003C\u002Fstrong> or the \u003Cstrong>Gutenberg block\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>A short, reassuring \u003Cstrong>step-by-step guide\u003C\u002Fstrong> during the flow (timing, refund, returns); the wording and the withdrawal window (≥14 days — you may grant more) are editable.\u003C\u002Fli>\n\u003Cli>When an order is genuinely exempt, a clear \u003Cstrong>“why is the button not here” note\u003C\u002Fstrong> explains the specific legal exception, instead of leaving the customer confused.\u003C\u002Fli>\n\u003Cli>A human-readable \u003Cstrong>verification certificate\u003C\u002Fstrong> for the receipt (integrity, order, date, hash) — not raw code.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>For you (the merchant)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>An onboarding \u003Cstrong>Dashboard\u003C\u002Fstrong> with a setup checklist (one-click fixes), a plain “how it works” walkthrough, and a “where the button appears \u002F why it might not” explainer.\u003C\u002Fli>\n\u003Cli>A one-click \u003Cstrong>e-mail delivery test\u003C\u002Fstrong> that detects your SMTP plugin and proves the receipt actually reaches the inbox — the #1 cause of “nothing happened”.\u003C\u002Fli>\n\u003Cli>A \u003Cstrong>Requests dashboard\u003C\u002Fstrong> to manage every withdrawal: status (open \u002F processed \u002F refunded), a chain-integrity badge, and one-click \u003Cstrong>mark processed\u003C\u002Fstrong>, \u003Cstrong>resend receipt\u003C\u002Fstrong> and \u003Cstrong>open the order to refund\u003C\u002Fstrong> (the refund is logged as proof you met the 14 days). Subscription and partial-withdrawal requests are flagged.\u003C\u002Fli>\n\u003Cli>A \u003Cstrong>Compliance page\u003C\u002Fstrong>: a go-live countdown, the statutory labels in use, the document checklist with ready-to-paste clauses, and environment warnings (Complianz \u002F cache \u002F multilingual) to fix.\u003C\u002Fli>\n\u003Cli>Receipts are \u003Cstrong>real WooCommerce e-mails\u003C\u002Fstrong> (your logo, colours, header) with a preview. The withdrawal button and form \u003Cstrong>inherit your theme’s typography and colour presets\u003C\u002Fstrong> out of the box, so they blend in automatically; for finer control, restyle every part from \u003Cstrong>Appearance \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Customize \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Additional CSS\u003C\u002Fstrong> (built into WordPress), targeting the plugin’s documented CSS variables and classes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Smart legal handling (so you don’t have to think about it)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Subscriptions\u003C\u002Fstrong> — the law gives one 14-day right per contract, so the button shows on the \u003Cstrong>initial order only\u003C\u002Fstrong> and is hidden on renewals (WooCommerce Subscriptions, FluentCart, EDD Recurring). Fail-safe, with opt-in overrides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Partial withdrawal\u003C\u002Fstrong> — customers can withdraw from only some items of an order.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Art. 59 exemptions\u003C\u002Fstrong> — tag products or categories by the specific statutory reason (events on a fixed date, digital content with immediate access, a service fully performed…). For the conditional reasons the plugin captures the customer’s \u003Cstrong>express consent at checkout\u003C\u002Fstrong> (WooCommerce classic + block, FluentCart, EDD), stores it as evidence, sends the required durable-medium confirmation, and only then hides the button. \u003Cstrong>Physical products always keep the right\u003C\u002Fstrong> — never hidden by mistake.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Applicability by country\u003C\u002Fstrong> — EU\u002FEEA consumers only (default) or always; B2B (VAT) orders can be treated as out of scope.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Evidence, timestamps & integrity\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The immutable log is \u003Cstrong>append-only and hash-chained\u003C\u002Fstrong> (HMAC-keyed with your site secret), so tampering is detectable.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recommended\u003C\u002Fstrong> trusted timestamping (off by default — one click to enable): free, independently-verifiable \u003Cstrong>OpenTimestamps\u003C\u002Fstrong> (Bitcoin) anchoring, or a \u003Cstrong>qualified eIDAS RFC 3161\u003C\u002Fstrong> timestamp (a free Sectigo endpoint, or your national authority — Aruba, InfoCert, D-Trust, Universign, FNMT, SwissSign), for an independent \u003Cstrong>“data certa”\u003C\u002Fstrong> of when each withdrawal was received. The hash chain is the baseline evidence on its own; once you enable a provider, failed stamps retry automatically and any not-yet-anchored records are surfaced in the admin. (It is off by default only because WordPress.org requires external calls to be opt-in — the plugin prompts you to switch it on.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy & GDPR\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The log commits to an \u003Cstrong>anonymised IP\u003C\u002Fstrong>; the full IP lives separately and is \u003Cstrong>erased after a configurable retention\u003C\u002Fstrong> (10 years by default).\u003C\u002Fli>\n\u003Cli>A \u003Cstrong>Consent records\u003C\u002Fstrong> screen lists and exports the exemption consents (CSV). Two ready-to-paste privacy clauses are generated (withdrawal log + exemption-consent), on a legitimate-interest basis. The uninstaller keeps the evidence log by default (legal hold) unless you opt to erase it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Documents & compliance\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Generates the \u003Cstrong>Annex I-B model withdrawal form\u003C\u002Fstrong> — with its “To …” recipient line filled from your \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Seller details\u003C\u002Fstrong> (business name, geographical address, contact e-mail) — and ready clauses for \u003Cstrong>pre-contractual information, Terms & Conditions and Privacy\u003C\u002Fstrong> — and reminds you, clearly, that installing the button is \u003Cstrong>not enough\u003C\u002Fstrong>: your Terms and pre-contractual withdrawal article must be updated to describe the new button modality (the plugin gives you the exact text to paste).\u003C\u002Fli>\n\u003Cli>A single \u003Cstrong>consolidated “Right of withdrawal” notice\u003C\u002Fstrong>, assembled live from your settings and the Art. 59 exceptions you selected, published three ways: the \u003Cstrong>\u003Ccode>[webwakeupwdb_policy]\u003C\u002Fcode> shortcode\u003C\u002Fstrong>, an \u003Cstrong>auto-created page\u003C\u002Fstrong> (one click to recreate it if you delete it) or a downloadable \u003Cstrong>PDF\u003C\u002Fstrong> — all managed from \u003Cstrong>Compliance \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Informativa sul diritto di recesso”\u003C\u002Fstrong> (preview \u002F create \u002F open \u002F \u003Cstrong>freeze\u003C\u002Fstrong> to static HTML \u002F download). Optionally, two opt-in toggles append the same clauses to your \u003Cstrong>Complianz\u003C\u002Fstrong> Privacy Policy and Terms & Conditions (EU-only, off by default, with a live preview). It complements — it does \u003Cstrong>not\u003C\u002Fstrong> replace — your own legal texts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Integrations & automation\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>A \u003Cstrong>read-only REST API\u003C\u002Fstrong> (authenticated with a standard Application Password) to list requests and check an order’s withdrawal status, plus an optional \u003Cstrong>signed webhook\u003C\u002Fstrong> (HMAC-SHA256) fired the moment a withdrawal is confirmed — for Zapier, Make, n8n, a CRM or a helpdesk. Privacy-first: the consumer’s IP is never exposed. \u003Cstrong>33 documented hooks\u002Ffilters\u003C\u002Fstrong> for developers.\u003C\u002Fli>\n\u003Cli>Plays nicely with \u003Cstrong>Complianz\u003C\u002Fstrong>, \u003Cstrong>TranslatePress\u003C\u002Fstrong> and page-cache plugins (WP Rocket \u002F LiteSpeed \u002F W3TC).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Platforms & licence\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WooCommerce (HPOS + legacy), FluentCart and Easy Digital Downloads (3.0+)\u003C\u002Fstrong> through a common adapter — one plugin for all three. On FluentCart it can step aside automatically if FluentCart ships its own native withdrawal add-on, so customers never see two buttons.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free and open source\u003C\u002Fstrong> (GPLv3) — no upsell, no tracking, no remote scripts or fonts loaded on your site. Passed a full multi-dimension security audit (0 critical \u002F 0 high).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is a technical aid to compliance and is \u003Cstrong>not legal advice\u003C\u002Fstrong>. Have your own counsel review your store’s documents.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin makes \u003Cstrong>no external calls by default\u003C\u002Fstrong>. Every outbound connection listed below is \u003Cstrong>opt-in\u003C\u002Fstrong> and stays \u003Cstrong>off\u003C\u002Fstrong> until you explicitly enable it in the settings. The tamper-evident log works fully offline — it is append-only and hash-chained with your site secret — so timestamping only \u003Cem>adds\u003C\u002Fem> an extra, independently-verifiable anchor; it is never required for the plugin to function.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OpenTimestamps\u003C\u002Fstrong> (opt-in, off by default) — only if you set the timestamp provider to “OpenTimestamps” (Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Receipt & evidence) does the plugin connect to the OpenTimestamps public calendar servers to obtain a free, trusted timestamp (a “data certa”) for the log.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What is sent:\u003C\u002Fstrong> only a SHA-256 hash (a one-way digest) of the immutable-log record, plus a random privacy nonce. No personal data, order content, names, emails or IP addresses are ever sent — only an opaque hash that cannot be reversed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> only while the provider is enabled — once when a withdrawal is confirmed (to submit the hash) and periodically via WP-Cron (to retrieve the Bitcoin-anchored proof). Nothing is ever sent while the provider is “None” (the default).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Where:\u003C\u002Fstrong> the OpenTimestamps public calendars (a.pool.opentimestamps.org, b.pool.opentimestamps.org, a.pool.eternitywall.com, ots.btc.catallaxy.com).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service info \u002F privacy:\u003C\u002Fstrong> https:\u002F\u002Fopentimestamps.org\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>RFC 3161 \u002F eIDAS timestamp authority\u003C\u002Fstrong> (opt-in, off by default) — if you instead set the provider to an RFC 3161 authority, the same one-way SHA-256 hash (no personal data) is sent to the authority URL \u003Cstrong>you\u003C\u002Fstrong> configure. This is a provider you choose and contract with directly (examples: a free Sectigo endpoint, or a national authority such as Aruba, InfoCert, D-Trust, Universign, FNMT, SwissSign); please review that provider’s own terms of service and privacy policy. No such call is made until you enable it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Outbound webhook\u003C\u002Fstrong> (opt-in, off by default — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations) — if enabled, the plugin sends a signed POST to the endpoint URL \u003Cstrong>you\u003C\u002Fstrong> specify whenever a withdrawal is confirmed. The payload carries a verification hash and contract reference, never the consumer’s IP address.\u003C\u002Fp>\n\u003Cp>No other external services are used. The plugin does not load remote scripts, fonts or trackers on your site.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>The plugin records withdrawal declarations (name, identified contract, email, IP address, date and time) in an append-only, tamper-evident log on \u003Cstrong>your own server\u003C\u002Fstrong>, because Art. 54-bis requires this as legal evidence (GDPR Art. 6(1)(c)\u002F(f)). It generates a ready-to-paste privacy clause for your policy. Data is retained for a configurable period (10 years by default), and the uninstaller keeps the evidence log by default (legal hold) unless you opt to erase it.\u003C\u002Fp>\n\u003Cp>For the conditional Art. 59 exemptions, the plugin also stores the consumer’s checkout consent + acknowledgement (the agreed wording, a hash, the date\u002Ftime and — unless you turn it off — the IP) as evidence to prove the exemption is valid. The lawful basis is \u003Cstrong>legitimate interest\u003C\u002Fstrong> (GDPR Art. 6(1)(f); defence of legal claims), \u003Cstrong>not\u003C\u002Fstrong> GDPR consent. The IP lives only on the order (never in the immutable log) and is automatically anonymised once the retention period lapses. A second ready-to-paste privacy clause is generated for this processing.\u003C\u002Fp>\n","EU statutory withdrawal button (Art. 11a) for WooCommerce, FluentCart & EDD: two-step flow, durable-medium receipt, tamper-evident log.",501,0,"2026-07-02T21:42:00.000Z","7.0.2","5.8","8.1",[26,27,28,29,30],"fluentcart","gdpr","recesso","right-of-withdrawal","woocommerce","https:\u002F\u002Fwebwakeup.it\u002Fwwu-withdrawal-button\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwwu-withdrawal-button.1.4.0.zip",null,"2026-07-22T17:31:50.256Z"]