Effective June 19, 2026

Documentation

WWU Withdrawal Button brings WooCommerce, FluentCart, and Easy Digital Downloads into compliance with the online cancellation button Required by EU Directive 2023/2673 (Art. 54-bis of the Consumer Code). Statutory button, two-step form, receipt on a durable medium, tamper-proof log, and timestamp. Free and open source (GPLv3).

How It Works (in Practice)

It's very simple for the customer—just four steps:

  1. Click the button. The customer opens their order and clicks «Cancel the contract here»—from the account area, from the link in the order email, or from the public page (without an account: search for the order using the order number and email address). The wording is as follows: exact amount prescribed by law for each language.
  2. Two-step form. Review what you're canceling (you can only select certain products — partial withdrawal), then confirm. No mandatory reason, no dark pattern.
  3. Receipt on a durable medium. As soon as they confirm, they receive email + PDF + verifiable permanent link the reason for the cancellation and the exact date and time. The order status changes to «cancellation requested,» and you receive a notification.
  4. Unalterable evidence. Each step is logged append-only with a hash chain and timestamp (certified date). You then manage the refund as always — also recorded as proof of compliance with the 14-day requirement.

The rest of the plugin is designed to make this workflow correct, easy to manage, and defensible. In summary, here's what it includes (each item has its own section below):

Free and open source (GPLv3): no upsells, no tracking, and no remote scripts or fonts loaded on your site. It has passed a comprehensive security audit (0 critical / 0 high).

Requirements

WordPress5.6+ (6.x recommended)
PHP8.1+ (WordPress.org directory build, with Dompdf 3.x). Still on PHP 7.4–8.0? In the GitHub release There is a build compatible with PHP 7.4 (same features, Dompdf 2.x): it is a temporary workaround and It won't last forever — PHP 7.4 reached end-of-life in November 2022; it's best to upgrade to PHP 8.1+ (which is faster and more secure).
E-commerceWooCommerce (HPOS + legacy), FluentCart or Easy Digital Downloads (3.0+)
EmailAn SMTP plugin (e.g., FluentSMTP) for sending receipts

Installation

  1. From the WordPress.org directory (recommended): In WordPress, go to Plugins → Add New, search «WWU Right of Withdrawal»Install Now. From here, you'll receive the automatic updates. Page on WordPress.org →
  2. Alternatively (manual zip): download wwu-withdrawal-button.zip from GitHub release (includes the PDF library), then Plugins → Add New → Upload Plugin → Select the ZIP file → Install Now (If it already exists, select «Replace the current one with the uploaded one»).
  3. Active. The plugin automatically creates the «Right of Withdrawal» public page and the log tables.
Important: Configure an SMTP plugin; otherwise, receipts won't be sent (this is the #1 cause for «the email isn't arriving»). Use the button «Send a test email» on the dashboard to check.

Configuration

Go to Withdrawal Button → Settings and work from top to bottom. The Dashboard It has a checklist that turns completely green when you're all set.

  1. Enable the right of withdrawal.
  2. Where it applies — «EU/EEA only» (legal minimum) or «Always show»; optional B2B exclusion (VAT ID).
  3. Consumer Guidance — a cancellation window in days (minimum 14; you can allow more) and, if you wish, a custom message.
  4. Receipt & Evidence — attach PDF, notification email, timestamp (Free OpenTimestamps, or RFC 3161), retention, account card slug.
  5. Email Delivery — Configure SMTP, run a test, then «Preview the acknowledgment email».

All Settings

SettingsWhat does it do?
Enable the withdrawal featureShow the button to eligible consumers.
Applicability ModeEU/EEA only · Always · Custom country list. + B2B toggle.
Withdrawal period (days)Window displayed to the customer. Minimum 14, expandable.
Custom guidance textReplaces the default guide text (basic HTML). Merchant's responsibility.
Legal Provisions 1.2.1Edit the text of the clauses (pre-contractual / Terms and Conditions / Privacy / Consent and Exemptions) using your own words — they will replace the default template everywhere, including the shortcode [webwakeupwdb_info], and remove the note «sample text.» Empty field = the default template remains.
Attach PDF receiptAttach a PDF copy to the receipt (the email itself serves as the durable medium).
Notification emailWhere to receive notifications about new requests. You can enter multiple addresses separated by commas to notify multiple people; the first one is also the one shown to the customer as the store's contact.
Trusted timestampOpenTimestamps · RFC 3161 (endpoint + credentials) · None.
Evidence retention (years)How long to keep the log (default: 10).
"My Account" tab slugSlug for the «Right of Withdrawal» page in the customer area.
CSS CustomizationCustomize every graphic element from the WordPress Customizer → Additional CSS, using the plugin's documented classes/variables (reference included in the settings).
FluentCartCars (default) · Always · Off. In Auto mode, the plugin displays the button but automatically hides it if it detects a native FluentCart checkout add-on, so the customer never sees two buttons. This applies only to FluentCart's consumer-facing interfaces; the requests dashboard and log remain unchanged.

Install the button That's not enough to comply with the law. The Consumer Rights Directive (Art. 6) requires that consumers be informed about how Exercise your right of withdrawal: With the introduction of the button, your Terms and Conditions of Sale and the Pre-contractual information must be updated in the'article on withdrawal to enable the new button-based mode. The plugin adds the button, but It does not modify your published documents.

To put it simply, the plugin generates ready-to-paste clauses — you can find them in Withdrawal Button → Compliance (and via shortcode [webwakeupwdb_info type="precontractual|terms|privacy"]):

From the 1.2.1 you can edit these texts directly from the admin panel, without code: Withdrawal Button → Settings → «Legal Terms». Type your text and save: your text will replace the template everywhere (Compliance page + shortcode [webwakeupwdb_info]) and the «sample text» note disappears. Leave a blank field to keep the default template (there's also a «Show default» option so you can copy it as a starting point). For developers, there's also the filter webwakeupwdb_clause_text.

From the 1.3.0, in addition to the individual clauses, the plugin automatically generates an'«Full Notice on the Right of Withdrawal» based on your settings and the exceptions you selected under Art. 59. You can manage this from Compliance → «Notice Regarding the Right of Withdrawal»: preview, Create/open the page (can be recreated with a single click), «freeze» in static HTML, or download it at PDF. You can also publish it using the shortcode [webwakeupwdb_policy]. Optional: two toggles in Settings → Compliance Documents They attach the same clauses to the Privacy Policy and to the Terms and Conditions Managed by Complianz (EU only, opt-in, off by default, with preview). Here as well: complements — does not replace your lyrics.

From the 1.4.0, the Standard Form (Annex I-B) automatically fills in the «Recipient» field with the your business data — name, physical address, and email address — that you enter in Withdrawal button → Settings → «Seller details». The rest of the form consists of the official text of the law, which cannot be modified. If you leave a field blank, the line will default to the website name and the administrator's email address; the physical address must be entered (as required by the law governing the form).

This is not legal advice: use the clauses as a starting point and Always have your legal counsel review your documents, adapting them to your business.

Where the button appears

It does not appear when there is no actual right of withdrawal: country outside the scope, order not in a contractual status, excluded items (Art. 59), or B2B, Subscription Renewal Order, or the feature is disabled. The dashboard explains «why it might not appear.».

Shortcode & Block

ShortcodeUsage
[webwakeupwdb_form]The two-step form / order selector.
[webwakeupwdb_button order_id="…"]Just one button to place an order.
[webwakeupwdb_status order_id="…"]The status of an order request.
[webwakeupwdb_model_form lang="…"]The form in Annex I-B (with the «Recipient» line filled in with your seller information — Settings → Seller Details).
[webwakeupwdb_info type="precontractual|terms|privacy"]Ready-made legal clauses.
[webwakeupwdb_policy]The complete information on the right of withdrawal (compiled from the general provisions and exceptions under Article 59).

Editor block: «Withdrawal — Self-Service» (dynamic, server-rendered) to place the surface anywhere in the block editor.

Customer Experience

  1. The customer opens their order and clicks the status button. In the first step of the form, a Optional checklist Order items: You may select only the products to be returned (partial withdrawal, permitted under EU law — Annex I-B: «the following goods»). If you leave the selection blank, the withdrawal applies to the entire order. This choice never prevents you from withdrawing from the order.
  2. Two-step form (review → confirmation), no dark patterns, no reason required.
  3. Upon confirmation, you will immediately receive an acknowledgment of receipt via email (including a PDF and a verifiable link), along with a list of the selected items; the order status will change to «return requested.».
The selection of products (all or some) appears on the receipt in a durable medium and in the dashboard Requests. Refunds—whether full or partial—are always processed manually by the merchant.

Request Management

In Withdrawal Button → Requests: each request with status (Open / Processed / Refunded), blockchain integrity badge, and actions:

Legal Notice: The right of withdrawal is a unilateral right—it does not require «approval.» Once exercised within the specified timeframe, the refund must be issued within 14 days using the same payment method. The «What to do» box on this page summarizes this.

Time Stamps

Choose from Receipt & evidence → Trusted timestamp:

ProviderNotes
OpenTimestampsFree, pegged to Bitcoin, no account required (default).
Sectigo /qualifiedRFC 3161 eIDAS-certified, free, no account required.
National QTSPsAruba/InfoCert (IT), D-Trust (DE), Universign (FR), FNMT (ES), SwissSign (CH) — endpoints + credentials.

Exemptions (Art. 59)

Certain products/services are not eligible for return (custom-made items, perishable goods, opened sealed items, tickets for events with a set date, digital content available immediately upon consent, services already performed…). In Settings → Exemptions Tag products/categories by specific statutory ground, each with a legal reference and an explanation in plain language. The right of withdrawal remains the default (including digital products).

When an order is fully exempt, the cancellation button does not appear—but the customer is not left without an explanation. From the 1.0.0-alpha.43, a a brief and accurate note It lists the specific exception applied along with the relevant legal reference (e.g., «Digital content with immediate access — Art. 16(1)(m) CRD / Art. 59(1)(o) Consumer Code»). The note is displayed on the withdrawal form, on the WooCommerce and EDD account pages, and in the FluentCart portal. The text can be edited in Settings → Consumer Guide. Appears only on orders that are actually exempt, never on ordinary orders; the button's visibility does not change.

For cases air-conditioned (immediate digital, service completed) the exemption applies only if you have obtained the customer's express consent and acknowledgment. From the 1.0.0-alpha.28 The WooCommerce checkout automatically displays the required acknowledgment checkbox and stores its text (along with the hash, date, and IP address) on the order as proof; the button is hidden for those items only after Consent. The text can be customized using the filter webwakeupwdb_consent_text. Consent collection is now active on WooCommerce (Classic + Block-based), FluentCart, and Easy Digital Downloads, with exemptions as well by category. If capture is not available, the button remains active (fail-safe). Never hide the button unless these conditions are met.

Subscriptions

EU law provides for just one 14-day right of withdrawal by contract, which begins upon the conclusion of the contract (Art. 9 of Directive 2011/83/EU = Art. 52 of the Consumer Code). A Renewal won't get it going again: This is a continuation of the same contract, not a new distance contract. Therefore:

In Settings → Subscriptions There are two switches, both disabled By default:

SettingsWhat does it do?
See also: Contract RenewalsNot recommended. Enable this only if a legal opinion states that a specific renewal restarts the right.
Cancel the subscription (right of withdrawal)Off. If enabled, it stops future renewals upon confirmation of cancellation. The refund and any pro rata For the service that has already been used, the following always remain: manuals.
Withdrawal ≠ cancellation. «Cancel subscription» stops future renewals; the withdrawal It is the 14-day statutory right that also entitles the refund. Simply offering cancellation is not enough during the initial 14-day period. In the requests dashboard, subscription orders have a «Subscription» badge with the following reminder: pause renewals, apply any pro-rata adjustments, then issue a refund.

FAQ

Is installing the button enough to comply with regulations? No. You need to update it. also Your Terms of Sale and pre-contractual information in the section on withdrawal, to include the new button-based procedure (Article 6 of the Consumer Rights Directive). The plugin generates ready-to-paste clauses — see Update your legal documents.

Can I give more than 14 days? Yes — set the «Withdrawal period» to your desired value (≥14). The text displayed will update.

How do subscriptions work? The button appears on the'initial order and disappears into the renewals (only one 14-day right per contract). Withdrawal is not the same as cancellation: the customer can always stop future renewals from their account, but withdrawal is the 14-day right to a refund. See the section Subscriptions.

Is the email not sending? Set up an SMTP plugin and use «Send test email.» It’s not the PDF library.

Does it work with block-based themes / FSE? Yes: The WooCommerce "My Account" page is still rendered using the classic shortcode, the hooks work, and there's also a Gutenberg block.

Does the law apply to digital products (plugins, software, downloads)? Yes. The button requirement applies to the professional that sells online to EU consumers—not just individual products—even a store selling plugins or digital content falls within the scope. Digital products are subject to the 14-day right of withdrawal by default; the right is revoked only with express consent + acknowledgment + confirmation on a durable medium (Art. 59(o)), which the plugin captures at checkout. Sales B2B (with a VAT number) and to consumers non-EU They're out of scope.

Is this legal advice? No, it's a technical tool to help ensure compliance. Have a lawyer review your documents.

For Developers

The plugin exposes 34 documented public hooks (action and filter) to customize the cancellation workflow, the text, the button's visibility logic, the receipt, and the log—without modifying the plugin's core.

Full reference: wwu-wb-hooks-filters-REFERENCE.md on GitHub — each hook with its signature, description, parameters, and usage example.

REST API & Webhooks (Automation)

From the 1.0.0-alpha.44 The plugin offers a'Read-Only REST API (namespace webwakeupwdb/v1, authentication with Application Password (from WordPress) to list return requests and check the status of an order, plus a Signed Outbound Webhook (HMAC-SHA256) that notifies your endpoint as soon as a cancellation is confirmed—ready for Zapier, Make, n8n, a CRM, or a help desk. Privacy-first: the customer's IP address is not never exposed (only a row hash for integrity verification). By design, there is no endpoint for create a withdrawal (which is the consumer's legal declaration). Once a dedicated security check before release.

API Reference: wwu-wb-rest-api-REFERENCE.md — endpoints, authentication, response formats, webhook payloads, and examples of signature verification (PHP + Node).

Change Log

Keep this section aligned with the docs/changelog/wwu-wb-CHANGELOG.md from the repository.

1.3.1 2026-06-26
  • Notice Regarding the Right of Withdrawal + Compliance with WordPress.org Guidelines. New «Notice Regarding the Right of Withdrawal» Consolidated, compiled from settings + exceptions under Art. 59: shortcode [webwakeupwdb_policy], automatically generated page (can be regenerated with one click), PDF, and injection opt-in in Complianz documents (Privacy + Terms, EU only, disabled by default). Translations: it/de/es/fr/sv. At the request of the WordPress.org team, Each internal identifier has been changed from the short prefix "wwu" to "webwakeupwdb" (constants, options, hooks, shortcodes, namespaces, REST): Existing installations are automatically migrated (settings, consent checks, log/timestamp tables, and pages are preserved); new installations are not affected. Developers: the code that uses the old names (wwu_wb_*, [wwu_wb_*]) needs to be updated to reflect the new webwakeupwdb_*.
1.2.12 2026-06-25
  • WordPress.org Compliance: opt-in timestamping, no custom CSS field, PHP 8.1 + Dompdf 3.1.5. The «Custom CSS» field has been removed: to customize the layout, use the WordPress Customizer → Additional CSS (with reference to the classes/variables in the settings). The guarantee timestamp (OpenTimestamps / RFC 3161) is now opt-in and disabled by default: The plugin doesn't none external call unless you enable it — the hash chain log remains the primary proof and works offline. The directory build switches to PHP 8.1 + Dompdf 3.1.5; a build compatible with PHP 7.4 (Dompdf 2.x) is still available on GitHub. Release Notes →
1.2.11 2026-06-23
  • The «Consent Records» page is now cross-platform (resolves #41). The consent admin page (and the CSV export) only read WooCommerce orders, so on an Easy Digital Downloads or FluentCart store, it displayed «WooCommerce not active» even though consent had been captured. Now it pulls data from the immutable, cross-platform test log (where WooCommerce—both Classic and Block-based—EDD, and FluentCart all write data at the time of capture), so the consents for each platform appear; complete entries (with IP addresses) are re-read from the order when it exists, and remain as PII-free records if the order has been canceled. New «Platform» column. Read-only modification: the tamper-proof log is never altered. Release Notes →
1.2.10 2026-06-23
  • WordPress.org Compliance (Plugin Check) — only real fixes. Added wp_unslash() to the settings-saving inputs (the values had already been sanitized: this is the standard procedure expected by the Plugin Check tool) and suppressed a false positive «unprepared query» during the integrity check (no user input: table name from $wpdb->prefix, LIMIT with integer cast). Shorten some update statements that are too long. No change in behavior. Release Notes →
1.2.9 2026-06-19
  • «Type-aware» cancellation window (digital = order date, physical = delivery date). The 14-day countdown shown to the customer is now calculated based on the product type: orders all digital start from the order date (conclusion of the contract, Art. 9 of Directive 2011/83 / Art. 52 of the Consumer Code), while orders for products physicists remain unchanged (delivery date / «completed»). This is for informational purposes only: the button is never hidden based on this value. No changes for physical products. Release Notes →
1.2.8 2026-06-19
  • Guest check-out has been processed correctly across all platforms. Completes version 1.2.7: the shortcode as well [webwakeupwdb_button] and the «order actions» link (which some themes display on the order confirmation page) now takes guests to the public cancellation page, rather than the login screen. A shared helper constructs the URL the same way everywhere. Logged-in customers remain unaffected. Release Notes →
1.2.7 2026-06-19
  • The cancellation button no longer requires guests to log in. In the order summary, the button directed customers without an account to the login screen because it linked to the «My Account» section. Now guests are directed to the public cancellation page (with the order reference and key—the same pre-authenticated link from the order email), so they can cancel without an account. Logged-in customers remain unaffected. Release Notes →
1.2.6 2026-06-19
  • Complete translations for all languages included. Some admin strings in the latest releases (the «Legal Terms» editor, the «Notification Email» field, reminders about legal texts on the Compliance page, and the FluentCart email helper) appeared in English because they had not yet been translated. The five language files (Italian, German, French, Spanish, Swedish) are now complete for these strings. (The Swedish file is machine-translated and awaiting review by a native speaker.) Release Notes →
1.2.5 2026-06-19
  • PHP 7.4 compatibility restored + notifications to multiple recipients + automatic FluentCart coexistence. The PDF library (Dompdf) had been updated to a version that requires PHP 8.1, causing a Composer «platform» error related to the PDF option on sites running PHP 7.4: It has now been reverted to the 2.x line, which is compatible with 7.4 (PDFs remain unchanged; verified via render audit). The field Settings → Notification Emails Accept Now multiple addresses separated by commas (The first one is also the contact information shown to the customer.) And with FluentCart management on Cars, the plugin automatically detects the FluentCart «Customer Rights» add-on and deactivates itself—no duplicate button. Release Notes →
  • PHP 7.4 compatibility restored + notifications to multiple recipients + automatic FluentCart coexistence. The PDF library (Dompdf) had been updated to a version that requires PHP 8.1, causing a Composer «platform» error related to the PDF option on sites running PHP 7.4: It has now been reverted to the 2.x line, which is compatible with 7.4 (PDFs remain unchanged; verified via render audit). The field Settings → Notification Emails Accept Now multiple addresses separated by commas (The first one is also the contact information shown to the customer.) And with FluentCart management on Cars, the plugin automatically detects the FluentCart «Customer Rights» add-on and deactivates itself—no duplicate button. Release Notes →
1.2.4 2026-06-19
  • WordPress.org Compliance and Basic Security Measures. The plugin name has been made more distinctive and free of third-party trademarks; additional sanitization has been added to the rate-limiter input; URLs in plain-text emails have been escaped; explicit REST permission callbacks have been added to public endpoints; and the translation loader, which is no longer needed (WordPress loads translations on its own starting with version 4.6), has been removed. No changes to the cancellation process or your data. Release Notes →
  • WordPress.org Compliance and Basic Security Measures. The plugin name has been made more distinctive and free of third-party trademarks; additional sanitization has been added to the rate-limiter input; URLs in plain-text emails have been escaped; explicit REST permission callbacks have been added to public endpoints; and the translation loader, which is no longer needed (WordPress loads translations on its own starting with version 4.6), has been removed. No changes to the cancellation process or your data. Release Notes →
1.2.3 2026-06-19
  • The email sending error now shows the exact reason, rather than a generic message. Continuation of 1.2.2: If the confirmation email fails to send, the plugin captures the specific reason from the sending system—the SMTP plugin error (e.g., «Could not authenticate» or «Could not connect to host…») or the exception message—and displays it in the «email not sent» admin notification and in the tamper-proof log, instead of a generic «email failed.» Diagnosing an incorrect SMTP configuration (WP Mail SMTP, FluentSMTP) becomes straightforward, without having to dig through the PHP log. The submission is always logged, and the customer is always redirected to the confirmation page. Release Notes →
  • The email sending error now shows the exact reason, rather than a generic message. Continuation of 1.2.2: If the confirmation email fails to send, the plugin captures the specific reason from the sending system—the SMTP plugin error (e.g., «Could not authenticate» or «Could not connect to host…») or the exception message—and displays it in the «email not sent» admin notification and in the tamper-proof log, instead of a generic «email failed.» Diagnosing an incorrect SMTP configuration (WP Mail SMTP, FluentSMTP) becomes straightforward, without having to dig through the PHP log. The submission is always logged, and the customer is always redirected to the confirmation page. Release Notes →
1.2.2 2026-06-18
  • Critical fix: No more «critical error» when sending the confirmation email. On some sites (as reported by WP Mail SMTP), an exception is thrown when confirming the cancellation and clicking «Resend Email.» inside wp_mail() An issue with the SMTP plugin—or a PDF error on PHP 8—could have gone unnoticed and caused the page to display a «critical error,» even though the cancellation had already been recorded. Now the entire sending process is exception-proof (mailer, WooCommerce emails, and optional PDFs): a failed send is flagged, and you can resend it without causing the page to crash. In addition: A Guide to Living Together Now That FluentCart 1.4.2 It includes its own built-in cancellation form (Settings → FluentCart: set it to «Off» if you’re using FluentCart’s form). Release Notes →
  • Critical fix: No more «critical error» when sending the confirmation email. On some sites (as reported by WP Mail SMTP), an exception is thrown when confirming the cancellation and clicking «Resend Email.» inside wp_mail() An issue with the SMTP plugin—or a PDF error on PHP 8—could have gone unnoticed and caused the page to display a «critical error,» even though the cancellation had already been recorded. Now the entire sending process is exception-proof (mailer, WooCommerce emails, and optional PDFs): a failed send is flagged, and you can resend it without causing the page to crash. In addition: A Guide to Living Together Now That FluentCart 1.4.2 It includes its own built-in cancellation form (Settings → FluentCart: set it to «Off» if you’re using FluentCart’s form). Release Notes →
1.2.1 2026-06-18
  • Fix: The «Right of Withdrawal» tab no longer returns a 404 error on a new installation + legal clauses that can be edited by the admin. The tab in the WooCommerce customer area is a endpoint (not a page): The rewrite rules were not regenerated upon activation, resulting in 404 errors until the permalinks were saved again. Now the plugin regenerates them automatically on the first load after activation (manual workaround: Settings → Permalinks → Save). In addition, a new section Settings → «Legal Terms» allows you to edit the text of the clauses (pre-contractual / Terms and Conditions / Privacy Policy / Consent) using your own words, without a code — replace the template everywhere, including in the shortcode [webwakeupwdb_info] (plus the filter webwakeupwdb_clause_text (for developers). Release Notes →
  • Fix: The «Right of Withdrawal» tab no longer returns a 404 error on a new installation + legal clauses that can be edited by the admin. The tab in the WooCommerce customer area is a endpoint (not a page): The rewrite rules were not regenerated upon activation, resulting in 404 errors until the permalinks were saved again. Now the plugin regenerates them automatically on the first load after activation (manual workaround: Settings → Permalinks → Save). In addition, a new section Settings → «Legal Terms» allows you to edit the text of the clauses (pre-contractual / Terms and Conditions / Privacy Policy / Consent) using your own words, without a code — replace the template everywhere, including in the shortcode [webwakeupwdb_info] (plus the filter wwu_wb_clause_text (for developers). Release Notes →
1.2.0 2026-06-18
  • Reminder: Be sure to update your legal documents as well. Installing the button does not update your store's documents. The law (Article 6 of the Consumer Rights Directive) requires that the Terms and Conditions of Sale and the Pre-contractual information describe how The consumer cancels — and this now includes the new online button. The plugin now clearly indicates this in the Dashboard and on the page Compliance, opens the two clauses to be pasted (pre-contractual + terms and conditions) by default, and the «Withdrawal Procedure» clause now explicitly names the button. No changes to the withdrawal process. See Update your legal documents.
  • Reminder: Be sure to update your legal documents as well. Installing the button does not update your store's documents. The law (Article 6 of the Consumer Rights Directive) requires that the Terms and Conditions of Sale and the Pre-contractual information describe how The consumer cancels — and this now includes the new online button. The plugin now clearly indicates this in the Dashboard and on the page Compliance, opens the two clauses to be pasted (pre-contractual + terms and conditions) by default, and the «Withdrawal Procedure» clause now explicitly names the button. No changes to the withdrawal process. See Update your legal documents.
1.0.0-alpha.45 2026-06-16
  • Unsubscribe links in order emails — on all platforms. The link is added automatically to WooCommerce customer emails and the Easy Digital Downloads receipt email (so that the customer can access the cancellation form directly from the email, as suggested in Recital 37). FluentCart does not allow plugins to automatically add content to its emails: therefore Settings → FluentCart Now displays a brief optional guide (3 steps) for inserting the shortcode {{wwu.recesso_url}} in the receipt template. Nothing intrusive and nothing mandatory: the cancellation option is always accessible from the customer area/portal and the public page. Release Notes →
  • Unsubscribe links in order emails — on all platforms. The link is added automatically to WooCommerce customer emails and the Easy Digital Downloads receipt email (so that the customer can access the cancellation form directly from the email, as suggested in Recital 37). FluentCart does not allow plugins to automatically add content to its emails: therefore Settings → FluentCart Now displays a brief optional guide (3 steps) for inserting the shortcode {{wwu.recesso_url}} in the receipt template. Nothing intrusive and nothing mandatory: the cancellation option is always accessible from the customer area/portal and the public page. Release Notes →
1.0.0-alpha.44 2026-06-16
  • Automation: Read-only REST API + signed webhook. New Section Settings → Integrations to connect cancellation requests to external systems (Zapier, Make, n8n, CRM, helpdesk). (1) A'Read-Only REST API (webwakeupwdb/v1) to view your requests and check the status of an order, after logging in with a Application Password by WordPress. (2) A webhook an optional feature that sends a notification signed with HMAC-SHA256 to your endpoint when a cancellation is confirmed. Privacy-first: The consumer's IP address is not never exposed (only a checksum). No endpoint for create A withdrawal, by legal choice. Following a dedicated security review. No changes to the withdrawal process. Release Notes →
  • Automation: Read-only REST API + signed webhook. New Section Settings → Integrations to connect cancellation requests to external systems (Zapier, Make, n8n, CRM, helpdesk). (1) A'Read-Only REST API (wwu-wb/v1) to view your requests and check the status of an order, after logging in with a Application Password by WordPress. (2) A webhook an optional feature that sends a notification signed with HMAC-SHA256 to your endpoint when a cancellation is confirmed. Privacy-first: The consumer's IP address is not never exposed (only a checksum). No endpoint for create A withdrawal, by legal choice. Following a dedicated security review. No changes to the withdrawal process. Release Notes →
1.0.0-alpha.43 2026-06-16
  • Note: «because it is exempt» from the consumer’s perspective. When all items in an order fall under an exception under Article 59 (e.g., digital content with immediate access or a service that has been fully performed, both with consent obtained at checkout), the withdrawal button is not displayed. The customer now sees a brief and accurate note stating the specific exception along with the relevant legal reference (e.g., «Digital content with immediate access — Art. 16(1)(m) CRD / Art. 59(1)(o) Consumer Code»). Displayed on the withdrawal form, on the WooCommerce and EDD account pages, and in the FluentCart portal. Editable text in Settings → Consumer Guide. It appears only on orders that are actually exempt—never on regular orders; the button's visibility does not change. Release Notes →
  • Note: «because it is exempt» from the consumer’s perspective. When all items in an order fall under an exception under Article 59 (e.g., digital content with immediate access or a service that has been fully performed, both with consent obtained at checkout), the withdrawal button is not displayed. The customer now sees a brief and accurate note stating the specific exception along with the relevant legal reference (e.g., «Digital content with immediate access — Art. 16(1)(m) CRD / Art. 59(1)(o) Consumer Code»). Displayed on the withdrawal form, on the WooCommerce and EDD account pages, and in the FluentCart portal. Editable text in Settings → Consumer Guide. It appears only on orders that are actually exempt—never on regular orders; the button's visibility does not change. Release Notes →
1.0.0-alpha.42 2026-06-16
  • Partial return by product (consumer-facing). EU law also allows you to cancel individual items in an order (Annex I-B: «the following goods»). The first step of the form now displays a Optional checklist: The consumer selects the products to be returned; if left blank, the entire order is canceled. The selection appears on the receipt in a durable medium and in the "Requests" dashboard. Refunds (full or partial) are always processed manually. The cancellation is never blocked. Release Notes →
  • Partial return by product (consumer-facing). EU law also allows you to cancel individual items in an order (Annex I-B: «the following goods»). The first step of the form now displays a Optional checklist: The consumer selects the products to be returned; if left blank, the entire order is canceled. The selection appears on the receipt in a durable medium and in the "Requests" dashboard. Refunds (full or partial) are always processed manually. The cancellation is never blocked. Release Notes →
1.0.0-alpha.41 2026-06-16
  • Configurable FluentCart management. New Approach Settings → FluentCart with three modes: Cars (default) — displays the button but automatically hides it if it detects FluentCart's native checkout add-on, so the customer never sees two buttons; Always — always keeps our button; Off — Disables FluentCart management. This applies only to consumer-facing interfaces; admin interfaces and existing requests remain unchanged. Release Notes →
  • Configurable FluentCart management. New Approach Settings → FluentCart with three modes: Cars (default) — displays the button but automatically hides it if it detects FluentCart's native checkout add-on, so the customer never sees two buttons; Always — always keeps our button; Off — Disables FluentCart management. This applies only to consumer-facing interfaces; admin interfaces and existing requests remain unchanged. Release Notes →
1.0.0-alpha.38 2026-06-15
  • Properly managed subscriptions (WooCommerce Subscriptions, FluentCart, EDD Recurring). EU law provides for a single 14-day right of withdrawal by contract, in conclusion: refreshing the page won't fix it. The button now appears only on the initial order and is hidden in the renewal orders (a single check covers all surfaces). Two opt-in switches in Settings → Subscriptions (also shows renewals · cancel subscription upon termination), both off by default — refunds and pro-rata adjustments remain manual. The requests dashboard flags subscription orders with a reminder. Conservative and fail-safe renewal detection (if uncertain, the button remains). To be tested with an active subscription plugin. See Subscriptions.
  • Properly managed subscriptions (WooCommerce Subscriptions, FluentCart, EDD Recurring). EU law provides for a single 14-day right of withdrawal by contract, in conclusion: refreshing the page won't fix it. The button now appears only on the initial order and is hidden in the renewal orders (a single check covers all surfaces). Two opt-in switches in Settings → Subscriptions (also shows renewals · cancel subscription upon termination), both off by default — refunds and pro-rata adjustments remain manual. The requests dashboard flags subscription orders with a reminder. Conservative and fail-safe renewal detection (if uncertain, the button remains). To be tested with an active subscription plugin. See Subscriptions.
1.0.0-alpha.37 2026-06-15
  • FluentCart email merge tags. . Include the cancellation link for each individual order in transactional emails native from FluentCart (e.g., order receipt). The FluentCart team has confirmed the hook implementation; the tag is registered in the email editor selector and resolves correctly (empty if there is no order in the context). To be tested on a live FluentCart instance. Note: FluentCart has announced that a native EU right of withdrawal feature is coming soon.
  • FluentCart Email Merge Tags {{wwu.recesso_url}}. Include the cancellation link for each individual order in transactional emails native from FluentCart (e.g., order receipt). The FluentCart team has confirmed the hook implementation; the tag is registered in the email editor selector and resolves correctly (empty if there is no order in the context). To be tested on a live FluentCart instance. Note: FluentCart has announced that a native EU right of withdrawal feature is coming soon.
1.0.0-alpha.36 2026-06-15
  • Comprehensive security audit of the entire plugin — 0 critical, 0 high. SQLi, XSS, CSRF, access control/IDOR, file/deserialization, encryption/integrity checks, and Dompdf dependency—all fixed. Fix: SSRF protection on the configurable RFC 3161 endpoint (blocks internal targets / cloud-metadata / IPv6-loopback / CGNAT), rate limiting on withdrawal endpoints, input length limits, stricter debug masking, and cron cleanup upon uninstallation. No changes for the client.
  • Comprehensive security audit of the entire plugin — 0 critical, 0 high. SQLi, XSS, CSRF, access control/IDOR, file/deserialization, encryption/integrity checks, and Dompdf dependency—all fixed. Fix: SSRF protection on the configurable RFC 3161 endpoint (blocks internal targets / cloud-metadata / IPv6-loopback / CGNAT), rate limiting on withdrawal endpoints, input length limits, stricter debug masking, and cron cleanup upon uninstallation. No changes for the client.
1.0.0-alpha.35 2026-06-15
  • EDD: The cancellation button now appears on the customer pages. In Easy Digital Downloads, the button appears on the sales receipt and in every line of the purchase history, and the link is added to the'EDD receipt email — Fully compatible with WooCommerce and FluentCart (previously, EDD only used the public page). Built using EDD 3.x hooks verified against the official source code. To be tested on a live EDD store.
  • EDD: The cancellation button now appears on the customer pages. In Easy Digital Downloads, the button appears on the sales receipt and in every line of the purchase history, and the link is added to the'EDD receipt email — Fully compatible with WooCommerce and FluentCart (previously, EDD only used the public page). Built using EDD 3.x hooks verified against the official source code. To be tested on a live EDD store.
1.0.0-alpha.34 2026-06-15
  • FluentCart improvements reviewed with the team. The consent checkbox now appears on before_payment_methods (covers standard checkout, modal) and in blocks); FluentCart's exemptions are by category (taxonomy product-categories, such as WooCommerce and EDD); the return/refund policies appear in the Activity Timeline from the FluentCart order.
  • FluentCart improvements reviewed with the team. The consent checkbox now appears on before_payment_methods (covers standard checkout, modal) and in blocks); FluentCart's exemptions are by category (taxonomy product-categories, such as WooCommerce and EDD); the return/refund policies appear in the Activity Timeline from the FluentCart order.
1.0.0-alpha.33 2026-06-15
  • Easy Digital Downloads (EDD 3.0+) is supported. Third platform after WooCommerce and FluentCart: the opt-out button, trial flow, and exemptions with consent capture work on EDD stores, with exemptions by category (download_category). To be tested on a live EDD store.
  • Easy Digital Downloads (EDD 3.0+) is supported. Third platform after WooCommerce and FluentCart: the opt-out button, trial flow, and exemptions with consent capture work on EDD stores, with exemptions by category (download_category). To be tested on a live EDD store.
1.0.0-alpha.32 2026-06-15
  • Capturing Consent Even at the WooCommerce Block-Based Checkout (via the official Additional Checkout Fields API, WooCommerce 9.9+), on par with the classic checkout and FluentCart. Pure PHP, no build required. + SPEC for future EDD integration.
  • Capturing Consent Even at the WooCommerce Block-Based Checkout (via the official Additional Checkout Fields API, WooCommerce 9.9+), on par with the classic checkout and FluentCart. Pure PHP, no build required. + SPEC for future EDD integration.
1.0.0-alpha.31 2026-06-15
  • Redesigned Exemption Settings (WWU UI Kit): grouped patterns (conditional / unconditional / seal) with tooltips, examples, the «What are you selling?» helper, a preview of what the customer sees (text box + email), and a status panel. The IT/FR/ES/DE translations are complete, including the exemption labels that previously appeared in English.
  • Redesigned Exemption Settings (WWU UI Kit): grouped patterns (conditional / unconditional / seal) with tooltips, examples, the «What are you selling?» helper, a preview of what the customer sees (text box + email), and a status panel. The IT/FR/ES/DE translations are complete, including the exemption labels that previously appeared in English.
1.0.0-alpha.30 2026-06-14
  • Capturing Consent on FluentCart. Conditional exemptions (immediate digital / service performed) now also collect consent at the FluentCart checkout, with a confirmation email sent via a durable medium—built using hooks verified against the official documentation. The «open order» link for admins uses the native FluentCart URL.
  • Capturing Consent on FluentCart. Conditional exemptions (immediate digital / service performed) now also collect consent at the FluentCart checkout, with a confirmation email sent via a durable medium—built using hooks verified against the official documentation. The «open order» link for admins uses the native FluentCart URL.
1.0.0-alpha.29 2026-06-14
  • Exemptions (Art. 59) — Confirmation on a durable medium + evidence, retention, GDPR. For conditional cases, the plugin now sends the customer a confirmation email on a durable medium that reproduces the text of the accepted consent (which is binding for digital consent, Art. 59(1)(o)) and records the sending of the email separately. Stored consents have a configurable retention period (default 10 years) with a daily routine that subsequently anonymizes the IP address; the IP address is configurable and is never included in the unalterable log. A GDPR-compliant privacy clause (legitimate interest) and a "Consent Records" page with CSV export have been added. Clearer copy throughout: physical products never require consent; the button is hidden only after consent is captured (fail-safe).
  • Exemptions (Art. 59) — Confirmation on a durable medium + evidence, retention, GDPR. For conditional cases, the plugin now sends the customer a confirmation email on a durable medium that reproduces the text of the accepted consent (which is binding for digital consent, Art. 59(1)(o)) and records the sending of the email separately. Stored consents have a configurable retention period (default 10 years) with a daily routine that subsequently anonymizes the IP address; the IP address is configurable and is never included in the unalterable log. A GDPR-compliant privacy clause (legitimate interest) and a "Consent Records" page with CSV export have been added. Clearer copy throughout: physical products never require consent; the button is hidden only after consent is captured (fail-safe).
1.0.0-alpha.28 2026-06-14
  • Exemptions (Art. 59) — obtaining consent at checkout. For the two conditional cases (digital content with immediate access; service already performed), the WooCommerce checkout displays a mandatory acknowledgment checkbox and saves the accepted text (with SHA-256 hash, date/time, and IP) on the order as proof: the button is hidden for those items only after valid consent has been given. Text can be customized via webwakeupwdb_consent_text. Classic WooCommerce checkout; block-based checkout and FluentCart coming soon.
  • Exemptions (Art. 59) — obtaining consent at checkout. For the two conditional cases (digital content with immediate access; service already performed), the WooCommerce checkout displays a mandatory acknowledgment checkbox and saves the accepted text (with SHA-256 hash, date/time, and IP) on the order as proof: the button is hidden for those items only after valid consent has been given. Text can be customized via webwakeupwdb_consent_text. Classic WooCommerce checkout; block-based checkout and FluentCart coming soon.
1.0.0-alpha.27 2026-06-14
  • Exemptions (Art. 59) — tagging by reason. Mark products or categories as exempt for a specific statutory reason (custom-made, perishable, hygienically sealed, fixed-date services, immediate digital delivery, services already performed…), each with a legal reference and guidance in plain language. The right of withdrawal remains the default—including for digital products—and the conditional grounds retain the button until consent is obtained.
  • Exemptions (Art. 59) — tagging by reason. Mark products or categories as exempt for a specific statutory reason (custom-made, perishable, hygienically sealed, fixed-date services, immediate digital delivery, services already performed…), each with a legal reference and guidance in plain language. The right of withdrawal remains the default—including for digital products—and the conditional grounds retain the button until consent is obtained.
1.0.0-alpha.19 2026-06-14
  • Customer Portal FluentCart Functional: «Right of Withdrawal» page in the account, side menu item, button on the individual order page, and banner. Each hook has been updated to match the official FluentCart contract (verified on dev.fluentcart.com), and the order list now retrieves data using the correct relationships (customer, address). This resolves the blank page and missing button issues observed during live testing.
  • Customer Portal FluentCart Functional: «Right of Withdrawal» page in the account, side menu item, button on the individual order page, and banner. Each hook has been updated to match the official FluentCart contract (verified on dev.fluentcart.com), and the order list now retrieves data using the correct relationships (customer, address). This resolves the blank page and missing button issues observed during live testing.
1.0.0-alpha.18 2026-06-14
  • Initial integration of the FluentCart customer portal + list of eligible orders valid for both WooCommerce and FluentCart.
  • Initial integration of the FluentCart customer portal + list of eligible orders valid for both WooCommerce and FluentCart.
1.0.0-alpha.17 2026-06-14
  • Consumer Guide (step-by-step, anywhere) + timestamp provider reference in the settings.
  • Consumer Guide (step-by-step, anywhere) + timestamp provider reference in the settings.
1.0.0-alpha.16 2026-06-14
  • Time-stamp provider RFC 3161 / eIDAS (Qualified free Sectigo certificates + national QTSPs).
  • Time-stamp provider RFC 3161 / eIDAS (Qualified free Sectigo certificates + national QTSPs).
1.0.0-alpha.15 2026-06-14
  • Refund recorded in the log as proof; see the «What to Do After a Request» guide.
  • Refund recorded in the log as proof; see the «What to Do After a Request» guide.
1.0.0-alpha.14 2026-06-14
  • Request management workflow (status, mark as processed, resend, refund) + CSS list fix.
  • Request management workflow (status, mark as processed, resend, refund) + CSS list fix.
1.0.0-alpha.13 2026-06-14
  • List of eligible orders, readable verification page, email preview, Gutenberg block.
  • List of eligible orders, readable verification page, email preview, Gutenberg block.
1.0.0-alpha.10–.12 2026-06-13/14
  • Onboarding dashboard, WooCommerce email integration, email delivery diagnostics, rendering bug fixes.
  • Onboarding dashboard, WooCommerce email integration, email delivery diagnostics, rendering bug fixes.
1.0.0-alpha.1–.9 2026-06-13
  • MVP: statutory button, two-step form, durable receipt, tamper-proof log + OpenTimestamps, country-specific applicability, multilingual support (IT/EN/DE/FR/ES), legal documents, customizable CSS.
  • MVP: statutory button, two-step form, durable receipt, tamper-proof log + OpenTimestamps, country-specific applicability, multilingual support (IT/EN/DE/FR/ES), legal documents, customizable CSS.