BuddyPilot Withdrawal – Easy Returns for WooCommerce

Beschrijving

BuddyPilot Withdrawal – Easy Returns for WooCommerce adds a complete returns and withdrawal workflow to your store: the mandatory EU withdrawal button required by Article 11a of EU Directive 2023/2673, an online return form for customers, and a declarations dashboard for the operator.

Vanaf 19 juni 2026 moet elke WooCommerce winkel met EU-klanten een duidelijk zichtbare en gemakkelijk toegankelijke herroepingsfunctie (knop “Contract hier herroepen”) bieden, naast de bestaande informatievereisten inzake het herroepingsrecht.

The plugin works alongside your return policy: the customer withdraws from the contract online during the cooling-off period (14 days by default, configurable), and you process the WooCommerce return and refund with native tools.

Wat de plugin doet

Voor de klant

  • Knop “Contract hier herroepen” conform artikel 11a op de bestellingsdetailpagina in Mijn account
  • Tweestaps herroepingsformulier: artikelselectie, verklaringsvoorbeeld, bevestigen met een klik
  • Ondersteuning voor variabele producten: elke variant (maat, kleur, enz.) verschijnt met volledige attribuutlabels als afzonderlijke regel in het herroepingsformulier
  • Ondersteuning voor afrekenen als gast via directe verificatiestroom (e-mail en bestelnummer, inloggen niet vereist)
  • Herroepingsgeschiedenis in Mijn account: lijst en detailpagina van de verklaring
  • Vastleggen van toestemming conform artikel 16(m) bij het afrekenen voor digitale en virtuele goederen (instelbaar: verplicht, optioneel of verborgen)
  • E-mail met verklaring voor de klant als bevestiging op een duurzame drager vereist door artikel 11a lid 3
  • Withdrawal resolved email sent to the customer after the operator closes the declaration; includes the EU ODR platform link (ec.europa.eu/consumers/odr) when any item is rejected
  • Per-item resolution status visible in the withdrawal form after a declaration is closed: each item shows an “accepted” or “rejected” badge with the rejection reason and ODR link, so the customer understands the outcome without contacting support

Voor de ondernemer

  • Metabox voor bestellingbewerking voor het registreren van verklaringen ontvangen via telefoon, post of persoonlijk
  • Zelfstandige pagina “Nieuwe verklaring toevoegen” voor ondernemers met grote hoeveelheden verklaringen, zonder de verklaringenlijst te verlaten
  • Verklaringenlijst met zoeken, filteren en sorteren in het WooCommerce beheer
  • Declaration detail page with full audit trail and resolution workflow: accept all, reject all, or partial resolution with per-item decisions and individual rejection reasons
  • E-mail beheerdermelding onmiddellijk verzonden wanneer een klant een herroeping indient

Juridisch en naleving

  • Custom order status wc-withdrawal (optional, plugin-registered) with a full change history logged as WooCommerce order notes
  • Pagina met herroepingsinformatie van Bijlage I(A) beschikbaar om met een klik te genereren vanuit instellingen
  • Annex I(B) model withdrawal form page available to generate with one click from Settings, published as a WordPress page and auto-linked from order emails and My Account
  • Configurable refund period (default 14 days, matches your contract terms)
  • Instelbare “geleverd” statussen die de herroepingstermijn starten
  • Toewijzing van retourkosten (consument betaalt of ondernemer betaalt, conform vereisten van Bijlage I(A))
  • AVG export en anonimisering van persoonsgegevens, compatibel met WordPress privacytools
  • HPOS compatibility (High-Performance Order Storage) and legacy post-meta mode
  • Naleving van WCAG 2.2 AA-toegankelijkheid op alle formulieren voor klanten
  • Poolse en Engelse vertalingen inbegrepen

Pro add-on

Uitgebreide functionaliteit is beschikbaar via de BuddyPilot Withdrawal Pro add-on:

  • Door de ondernemer goedgekeurde automatische terugbetaling op basis van gedeclareerde artikelen (een klik vanuit het verklaringsscherm)
  • Verificatie van het downloadaantal: herstelt het herroepingsrecht wanneer een digitaal product nooit daadwerkelijk is gedownload, waarmee ongerechtvaardigde weigering van terugbetalingen wordt verminderd
  • Ondersteuning voor WooCommerce Subscriptions: annuleert toekomstige verlengingen, berekent de huidige factureringsperiode naar rato conform artikel 9 lid 2 sub b punt iii
  • Ondersteuning voor WooCommerce Product Bundles: automatische verwerking op bundeltype; voor per-artikel-bundels met een geconfigureerde korting: kies of gedeeltelijke retouren het betaalde bedrag behouden of de gehele bundelkorting vervalt
  • PDF export van de juridische herroepingsverklaring
  • Landspecifieke generatie van formulier Bijlage I(B)

Installatie

  1. Upload de pluginmap naar /wp-content/plugins/ of installeer via Plugins > Nieuw toevoegen.
  2. Activeer de plugin via het menu Plugins in WordPress.
  3. Ga naar WooCommerce > Instellingen > Herroeping en configureer:
    • Algemeen: herroepingstermijn, respijtperiode, statussen “geleverd”
    • Gegevens ondernemer: naam, adres, retouradres, verantwoordelijkheid voor retourkosten
    • Klantervaring: toestemmingsmodus voor digitale goederen, pagina met herroepingsinformatie
  4. In the Customer experience section click “Create withdrawal information page” to publish an EU-compliant Annex I(A) notice and Annex I(B) model form. The page URL is auto-linked from order emails and the My Account view-order screen.
  5. Customers eligible to withdraw will see a “Withdraw from contract here” call-to-action on their order page. The form works without JavaScript.

FAQ

Werkt de plugin bij afrekenen als gast?

Yes. Create a dedicated withdrawal form page from WooCommerce > Settings > Withdrawal > Customer (one click). Place the [buddypilot_withdrawal_guest_form] shortcode on that page. Guest customers enter their order number and billing email; a secure magic-link is sent to the billing address. Clicking the link opens the full interactive withdrawal form without requiring an account.

Verwerkt de plugin terugbetalingen automatisch?

The free version records the withdrawal declaration and changes the order status to wc-withdrawal. The operator processes the refund using native WooCommerce tools. One-click automatic refund built from declared items is available in the Pro addon.

Wat doet de plugin NIET?

De plugin registreert herroepingsverklaringen als juridische documenten en stelt zowel de klant als de ondernemer op de hoogte. De plugin verwerkt geen automatische terugbetalingen, verifieert geen retourzendingen, handhaaft geen terugbetalingstermijnen en verwerkt geen boekhouding en btw. De shopbeheerder is verantwoordelijk voor het verwerken van de terugbetaling binnen de wettelijk vereiste termijn (standaard 14 dagen, instelbaar onder WooCommerce > Instellingen > Herroeping > Algemeen).

Is this a returns plugin for WooCommerce?

Yes, in the legal sense: it handles WooCommerce returns as EU consumer withdrawals. The customer submits a return request (a withdrawal declaration) through the online return form, and the operator resolves it from the declarations list. It is not a courier or RMA logistics tool: it does not generate shipping labels or track return parcels.

Does it replace my return policy page?

No, it complements it. The plugin generates the legally required withdrawal information page (Annex I(A)) and the model withdrawal form (Annex I(B)) with one click; your return policy and terms of service remain your own documents. Together they cover both the legal minimum and your store’s practical rules.

Ondersteunt de plugin variabele producten?

Ja, zonder extra configuratie. Variabele producten (verschillende maten, kleuren, enz.) worden volledig ondersteund in de gratis versie. Elke variant verschijnt in het herroepingsformulier als een afzonderlijke regel met volledige attribuutlabels (bijv. T-shirt, Maat: L, Kleur: Zwart), zodat de klant precies aangeeft wat hij retourneert en de ondernemer dezelfde details ziet op de verklaringenlijst en de detailpagina van de verklaring.

Werkt de plugin met WooCommerce Subscriptions of Product Bundles?

Subscription, bundle and composite product handling (cancel renewals, proration, bundle refund modes) is part of the Pro addon. The free version treats them as standard products.

Dekt de plugin de toestemming van artikel 16(m) voor digitale goederen?

Yes. The plugin adds an explicit consent checkbox at checkout when the cart contains downloadable or virtual products. The operator can choose between “required before purchase”, “optional” or “hidden” (trader waives the exclusion). Consent is recorded on the order and displayed in the withdrawal form.

When does the cooling-off period (withdrawal clock) start?

The clock starts from the exact moment the order status changes to one of the “delivered” statuses configured under WooCommerce > Settings > Withdrawal > General. The plugin records the precise timestamp of that status change. As long as the deadline has not passed, the customer sees how many days remain in the withdrawal form; once the deadline passes, the withdrawal button is no longer shown. Any built-in or custom WooCommerce order status can be mapped as a “delivered” trigger (e.g. “Completed”, a custom “Shipped” status, etc.). Leaving the list empty means the clock never starts, which is useful during testing or when you want withdrawal to be available indefinitely.

Is de plugin HPOS compatibel?

Yes. The plugin is fully compatible with WooCommerce High-Performance Order Storage (HPOS) and falls back to legacy post-meta mode automatically.

Beoordelingen

19 juni 2026 1 reactie
I tried many solutions out there before to choose this plugin but I have to say that this is the most complete and best overall. It covers many aspects that other ignores so this has been an easy choice
17 juni 2026 1 reactie
Swietna i prosta wtyczka zapewniajaca zgodnosc z dyrektywa. Doskonaly kontakt z devem i reakcja na bledy/poprawki. Wtyczka praktycznie plug&play. Zainstaluj, aktywuj, sprawdz usatwienia gdybys chcial cos niestandarowego, podepnij shortcode i tyle… Bardzo polecam!
29 mei 2026 1 reactie
Bardzo dobra wtyczka. Rozwiązuje problem, który wiele sklepów będzie miało już niebawem. Dobry kontakt z autorem. Będę ją polecał moim klientom.
Lees alle 4 beoordelingen

Bijdragers & ontwikkelaars

“BuddyPilot Withdrawal – Easy Returns for WooCommerce” is open source software. De volgende personen hebben bijgedragen aan deze plugin.

Bijdragers

“BuddyPilot Withdrawal – Easy Returns for WooCommerce” is vertaald in 7 talen. Dank voor de vertalers voor hun bijdragen.

Vertaal “BuddyPilot Withdrawal – Easy Returns for WooCommerce” naar jouw taal.

Interesse in de ontwikkeling?

Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.

Changelog

1.0.21

  • Oplossing: de herroepingslink staat weer in de footer van je WooCommerce e-mails bij winkels waar deze e-mails worden gegenereerd door een plugin die de WooCommerce e-mail templates vervangt. MailPoet doet dit wanneer de eigen WooCommerce e-mailaanpassing is ingeschakeld, waardoor de link stilletjes uit elke e-mail verdween. De link is wettelijk vereist en wordt daarom nu toegevoegd aan de afgeronde e-mail, telkens wanneer hij de template niet overleefde.
  • Fix: The “Submit withdrawal form online” button on the withdrawal information page could be unreadable on themes that colour links inside page content with the same shade as the button background: the label took the link colour and vanished into the button. The same fix covers the Back buttons on the confirmation page and in My Account.
  • Nieuw: een ‘e-mail link’ instelling schakelt de automatische herroeping link in WooCommerce e-mails uit. Gebruik het als je de link zelf toevoegt aan je e-mails, bijvoorbeeld in een e-mail ontwerper plugin, en wil niet dat het twee keer verschijnt.

1.0.20

  • New: Site-wide withdrawal link. A discreet link in the footer of every page (plus an optional sticky button) leads customers to the withdrawal function from anywhere on the store, not only from My Account, in the spirit of Article 11a of EU Directive 2023/2673. A [buddypilot_withdrawal_link] shortcode is available for manual placement. The footer link is on for new installs and stays off on existing sites until you enable it.
  • New: Optional direct guest access. You can now let guests reach the withdrawal form immediately after entering their order number and email, without the emailed access link. The access link stays required by default.
  • Fix: Pro-only options on the settings screen now appear unchecked in the free plugin, so they no longer look enabled.
  • Developer: Refreshed the translation template (.pot) and the Polish translation.

1.0.19

  • Fix: Recently added strings no longer appear in English on sites without an up-to-date language pack. The bundled translations were refreshed and expanded so every supported EU language now ships at the current plugin version. Community translations from the translate.wordpress.org language pack still take priority; the bundled copy only fills what the pack is missing.
  • Developer: The translation template (.pot) is now included in the package, so you can translate the plugin yourself (for example with Loco Translate) and keep a multilingual site consistent. No code or database changes, safe to update.

1.0.18

  • Feature: The original delivery cost is now refunded when the customer withdraws from every shipped item in an order (Article 13). The amount is shown to the customer on the confirmation step and in My Account, and is added to the Pro one-click refund. Delivery is still included when only virtual or downloadable items remain in the order; it is not added on a partial return of the physical goods. A new “Refund the original delivery cost” setting (on by default) controls this.
  • Improved: Customer-facing amounts are now shown gross (tax inclusive). The confirmation step and the My Account declaration view now show a refund summary: items, delivery, and the total to refund.
  • Improved: After submitting a withdrawal that includes physical goods, the customer is now reminded on the confirmation page to send the goods back to the seller.
  • Improved: The operator declaration screens now show the withdrawn items in WooCommerce’s familiar order-items layout (Product, Price, Quantity, Total, tax) with a totals summary (items subtotal, shipping, tax, total to refund).
  • Improved: The “Cost of returning the goods” setting was renamed to “Who pays to return the goods” and reworded to make clear it concerns the cost of sending the goods back, not the refund of the original delivery.
  • Developer: New buddypilot_withdrawal_shipping_refund_snapshot filter to adjust or suppress the delivery refund amount (for example to cap an express-delivery supplement). The public API version is now 1.1.

1.0.17

  • Improved: The My Account order page now lists every item with its withdrawal status, eligible, already withdrawn, or not eligible, above the withdrawal button. Digital items the customer consented to receive immediately (Article 16(m)) are shown with a “not eligible for withdrawal” badge instead of being silently omitted, and orders where no item is eligible now show the item list with that explanation instead of a generic message.
  • Improved: The withdrawal form shows the same read-only item list with badges when an order has no items eligible for withdrawal.
  • Improved: Bundled translations now fill any strings the translate.wordpress.org language pack is still missing, so strings added in a release appear in the site language immediately without waiting for the language pack to be updated. Community translations from the language pack keep priority.
  • Fixed: The rejection / partial-resolution email no longer shows two near-identical ADR / EU Online Dispute Resolution notices. The notice with the clickable link is kept; the duplicate default text was removed.

1.0.16

  • Fixed: The “right of withdrawal” link in the WooCommerce email footer and the My Account call-to-action now resolve to the correct language version of the information page on Polylang and WPML sites. Previously the stored page ID was used verbatim, so on multilingual stores the link could be missing or point to the wrong language.
  • Fixed: The withdrawal period and the refund deadline are now shown consistently across all screens. The My Account order button now reflects the configured withdrawal period instead of a hardcoded 14 days, the declaration preview and the post-submission confirmation now reflect the configured refund deadline instead of a hardcoded value or the wrong setting.
  • Fixed: The guest withdrawal flow now stays in the language the visitor is using on multilingual sites. Previously, after requesting an access link on a non-default language page, the form action, every following step and the e-mails fell back to the site default language. The form now recognises translated page variants, keeps each step on the current-language page, and sends both the magic-link e-mail and the withdrawal-confirmation e-mail in the visitor’s language (Polylang, WPML). The confirmation e-mail now also follows the customer’s language for logged-in My Account submissions; operator-registered declarations keep the site language.
  • Improved: The refund deadline option is now seeded on activation, so fresh installations report a consistent value before the operator visits the settings screen.

1.0.15

  • Feature: Guest magic-link emails now point to the correct language version of the withdrawal form on multilingual sites. Polylang, WPML, TranslatePress, Weglot, and qTranslate-XT are all supported automatically; the order language meta stored by each plugin is used to resolve the translated page URL.
  • Improved: Translation .mo files for all 24 EU official languages are now bundled in the plugin ZIP as a fallback. Users on sites where translate.wordpress.org has not yet published a language pack receive translated strings from the bundled .mo files instead of falling back to English.
  • Improved: Czech (cs_CZ), Croatian (hr), Dutch Belgium (nl_BE), Dutch Netherlands (nl_NL), and Romanian (ro_RO) translations synchronised with GlotPress (translate.wordpress.org); GlotPress-approved strings are now authoritative.

1.0.14

  • Feature: New buddypilot_withdrawal_has_consent filter allows third-party plugins to integrate their own Article 16(m) consent checkbox. Return true from the filter to record consent for all digital items in the order; the plugin handles the internal storage. No knowledge of internal meta keys is required.
  • Improved: When the plugin’s own consent checkbox is set to “Hidden” in settings, the new filter still fires. External consent can therefore be recorded even when the built-in checkbox is disabled.

1.0.13

  • Feature: Operators can now close a declaration as “Reject all items” or “Partial resolution” directly from the declaration detail page. Previously only full acceptance was available from that screen.
  • Feature: Partial resolution mode allows a per-item accept/reject decision with a mandatory rejection reason for each rejected item, so the customer receives an itemised outcome rather than a single blanket decision.
  • Feature: Rejection and partial resolution emails now include the EU ODR (Online Dispute Resolution) platform link (ec.europa.eu/consumers/odr) as required for cross-border dispute notifications under Article 11a.
  • Feature: The customer-facing withdrawal form now shows per-item resolution badges for fully-resolved declarations: accepted items display a confirmation badge, rejected items display the rejection reason and an ODR platform link. Previously the form showed a generic “order not eligible” message.
  • Improved: Reopening a declaration now resets the resolution type and operator note to null, so the operator starts with a clean slate when correcting an erroneous decision.
  • Security: Financial snapshot fields in the declaration record (item total, subtotal, tax) are immutable; they cannot be overwritten by POST manipulation during the resolution step.
  • Security: Resolution type is validated against a strict server-side whitelist (accepted / rejected / partial); arbitrary values are rejected before reaching the database.
  • Security: Already-closed declarations reject stale resolution attempts with an explicit error, preventing accidental overwrites in concurrent operator sessions.

1.0.12

  • Fixed: Article 16(m) consent checkbox was not displayed at checkout on stores using WooCommerce 8.6 or later with a classic shortcode-based checkout (e.g. Blocksy theme). The plugin now correctly detects whether the block checkout is in use before routing consent collection through the Additional Checkout Fields API.
  • Improved: Guest withdrawal session is now time-limited to 15 minutes after clicking the magic link, reducing the window in which a shared or inactive browser session could be misused.
  • Improved: Magic link redemption endpoint now applies rate limiting per order per IP, consistent with the email verification endpoint.
  • Improved: Declaration detail and status toggle in the admin panel now verify that the current user has access to the linked order, providing correct access control on multi-vendor setups.
  • Improved: Operator-customised consent label text is sanitised when saved, so stored option value is always clean HTML.
  • Improved: Plugin no longer collects or stores the browser user-agent string with withdrawal declarations. The field served no active purpose and its removal reduces the personal data footprint. Existing installations will have the column dropped automatically on first load after updating (no data loss; the legal declaration record is preserved in full).

1.0.11

  • Reparatie: Pluginemailklassregistratie is nu geïsoleerd per klasse. Een constructorfout in één klasse verspreidt zich niet meer in de e-mailverzending van WooCommerce en blokkeert niet langer alle transactionele e-mails van WooCommerce (nieuwe bestelling, klantverwerking, enz.).

1.0.10

  • Fixed: Attempting to bulk-change orders in withdrawal status to Completed or Processing now triggers an admin notice informing the operator how many orders were skipped because the status change is not permitted for them, and that those orders must be handled individually.

1.0.9

  • Feature: Guest verification form now accepts custom order numbers from third-party renumbering plugins (e.g. WebToffee Advanced Order Numbers, Custom Order Numbers for WooCommerce by Tyche Softwares). Guests can enter the formatted number shown in their confirmation email instead of the internal numeric order ID.
  • Feature: Order number input on the guest verification form no longer forces a numeric-only keyboard on mobile devices, allowing guests to type prefixed order numbers such as ORD-2024-1042.
  • Security: Input length on the guest verification form is now capped before order resolution, preventing crafted requests from triggering full-table database scans on stores with custom order number plugins installed.

1.0.8

  • Feature: Withdrawal information page is now created as native WordPress blocks, allowing the operator to freely edit the legal wording directly in the block editor.
  • Feature: New [buddypilot_withdrawal_info_block] shortcode renders the dynamic sections (trader contact details, return address, CTA button) independently so they always reflect current settings, even after manual edits to the surrounding text.
  • Feature: New “Overwrite information page content” button in WooCommerce > Settings > Withdrawal > Customer refreshes the page with the latest model notice wording at any time.
  • Fixed: Orders imported via the WooCommerce REST API (e.g. BaseLinker) were being re-imported in a loop because the plugin was writing unnecessary consent meta to every new order. The plugin no longer writes any meta to API-created orders that contain no digital items.

1.0.7

  • Improved: Delivery tracking now uses a dedicated database table instead of order meta, preventing third-party order-sync integrations (e.g. BaseLinker) from re-importing orders on every delivery status update.
  • Improved: Confirmation screen now reads the configured withdrawal period dynamically instead of using a hardcoded value.
  • Improved: Rate limiting is now handled with a single atomic database operation.
  • Improved: Reduced database queries on the withdrawals list page.
  • Fixed: Several coding standards issues and minor security hardening.

1.0.6

  • Feature: guest (non-logged-in) customers can now submit a withdrawal declaration directly from a dedicated form page. After entering their order number and billing email, a secure one-time magic-link is sent to the billing address; clicking it opens the full interactive withdrawal form with no account required.
  • Functie: nieuwe shortcode [buddypilot_withdrawal_guest_form] voor de gastherroepingsformulierpagina. De pagina en shortcode kunnen met een enkele klik worden gemaakt vanuit WooCommerce > Instellingen > Herroeping > Klant.
  • Feature: [buddypilot_withdrawal_information] shortcode now shows an optional “Submit withdrawal form online” call-to-action button linking to the guest form page when the form page is configured. Existing information pages are not modified.
  • Feature: new “Withdrawal form access link (guest)” transactional email containing the magic-link; configurable under WooCommerce > Settings > Emails.

1.0.5

  • Plugin renamed to BuddyPilot Withdrawal (Easy Returns) for better discoverability.
  • Volledige vertalingen toegevoegd voor alle 24 officiële EU-talen: bg, cs, da, de (de_DE, de_AT, de_CH), el, es, et, fi, fr (fr_FR, fr_BE, fr_CH), ga, hr, hu, it, lt, lv, mt, nl (nl_NL, nl_BE), pl, pt, ro, sk, sl, sv.
  • Vertaalkwaliteit: alle 24 EU-taalbestanden gecontroleerd over drie ronden; juridische terminologie geverifieerd aan officiële nationale gazetten (EU-richtlijn 2011/83/EU Bijlage I), diakritische markeringen hersteld, formeel register overal afgedwongen, meervoudige vormen gecorrigeerd en interne consistentie verbeterd.

1.0.4

  • Functie: gebroken producthoeveelheden worden nu gedetecteerd en gemeld in de herroepingsverklaring. Volledige verwerking van gebroken hoeveelheden (correcte naar-rato-berekening, berekening van terugbetaling) is beschikbaar in BuddyPilot Herroeping Pro.
  • Feature: added “Upgrade to Pro” action link in the Plugins list, shown only when the Pro version is not active.

1.0.3

  • Getest en compatibiliteit met WordPress 7.0 bevestigd.
  • Beveiliging: nonce wordt nu geverifieerd voor het innemen van een rate-limit slot, zodat CSRF sondes het uurbudget van een gebruiker niet kunnen uitputten.
  • Beveiliging: anonieme (gast) rate-limit buckets zijn nu per gehashed IP-adres gescheiden in plaats van een gedeelde user_id=0 bucket.
  • Beveiliging: sealed_map en GET voorverzegelde ID’s worden gevalideerd tegen de bestelling voor gebruik, zodat geconstrueerde verzoeken geen verzegelde bevestigingen kunnen koppelen aan gewone artikelen.
  • Beveiliging: de uitvoer van apply_filters('buddypilot_withdrawal_declaration_items_payload') wordt opnieuw gevalideerd: vermeldingen met item_id=0, negatieve hoeveelheden of niet-array-waarden worden verwijderd.
  • Beveiliging: PermissionChecker blokkeert nu expliciet user_id=0 ongeacht de customer_id van de bestelling.
  • Beveiliging: OperatorRegistration controleert EXCLUDED_STATUSES bij het betreden van de handler en wist de rechtencode na het opslaan van de bestelling.
  • Security: DeclarationRepository validates filing_date format and rejects zero-date strings.
  • Beveiliging: RateLimit::tally() geeft PHP_INT_MAX terug wanneer de rate-limittabel ontbreekt, zodat de begrenzer niet stilzwijgend inactief wordt.
  • Correctie: round(qty, 10) in get_declared_quantities() voorkomt IEEE-754-epsilonaccumulatie bij gebroken producthoeveelheden.
  • Fix: removed spurious user_register hook from Privacy Manager; only woocommerce_created_customer is used.

1.0.2

  • Code: renamed all short bpw_ / bpw- identifiers to the full buddypilot_withdrawal_ / buddypilot-withdrawal- prefix throughout (affects AJAX/admin-post action names, script handles, localized JS object, metabox ID, WooCommerce field type, nonce field names, lock keys and GET parameters). Resolves WordPress.org unique-prefix review requirement.

1.0.1

  • Beveiliging: alle handlers voor beheerder en AJAX verzoeken verifiëren nu eerst gebruikersrechten voor nonce verificatie, conform de beveiligingsrichtlijnen van WordPress.
  • Beveiliging: het AJAX pad in de registratiehandler van de ondernemer gebruikt nu check_ajax_referer() in plaats van check_admin_referer(), wat een correcte AJAX foutreactie geeft bij een nonce-fout.
  • Beveiliging: toegevoegd current_user_can() poort naar de beheerdernoticehandler voor status van het maken van infopagina’s.
  • Beveiliging: valutasymbool en scheidingsteken waarden uit gelokaliseerde prijsformaatgegevens worden nu aan de JavaScript-kant ge-escaped voor invoeging in de DOM.
  • Code: verplaatste inline JavaScript van de handelsregistratiesjabloon naar een geplaatst bestand (assets/js/admin/operator-registration.js); strings doorgegeven via wp_localize_script().
  • Code: aanroep van load_plugin_textdomain() verwijderd; WordPress 4.6 en hoger laadt vertalingen automatisch voor plugins op WordPress.org.

1.0.0

  • Eerste stabiele release. Volledige implementatie van de herroepingsfunctie van artikel 11a: tweestapsformulier, gastverificatie, handmatige registratie door de ondernemer, beheerderslijst met verklaringen, instelbare termijn en statussen “geleverd”, vastleggen van toestemming conform artikel 16(m), paginagenerator voor Bijlage I(A)/(B), e-mails voor klant en beheerder, herroepingsgeschiedenis in Mijn account, HPOS-ondersteuning, AVG-hooks, naleving van WCAG 2.2 AA, Poolse en Engelse vertalingen.