Description
ARDOIZA gives a restaurant the three things guests ask for on its website, without any account or subscription:
A simple table reservation. Set your opening hours for each day, the slot length, the number of guests per slot and how far ahead guests may book. The “ARDOIZA Reservation” block or the [ardoiza_reservation] shortcode shows a form (date, time, guests, seating preference when your venue has a terrace, name, phone, email, comment, consent box). Slots that are full or in the past are not offered. The restaurant receives the request by email, the guest receives an acknowledgement, and you confirm or refuse each request from the dashboard; the guest is notified by email. Requests can also be confirmed automatically when the slot has room.
An online menu with allergens. Create your sections (starters, mains, desserts) and your dishes with a name, a description, a photo, a price in euros, the 14 allergens of Regulation (EU) No 1169/2011 (cereals containing gluten, crustaceans, eggs, fish, peanuts, soybeans, milk, nuts, celery, mustard, sesame seeds, sulphur dioxide and sulphites, lupin, molluscs), and the vegetarian and vegan mentions. Mark a dish as unavailable in one click. Display the menu with the “ARDOIZA Menu” block or the [ardoiza_carte] shortcode. The layout is sober, readable on a phone, accessible (headings, lists, visible focus) and every colour is a CSS custom property your theme can override.
A QR code of your menu. From the dashboard, download the QR code that opens your menu page, as PNG (for printers) or SVG (for designers). The code is generated on your own site by a small encoder included in the plugin: nothing is sent to any third-party service.
Personal data. Reservations are the only personal data handled. They are stored in your own database, never shared, and exported or erased with the WordPress privacy tools (Tools, Export Personal Data / Erase Personal Data). A retention period deletes old reservations automatically, and a suggested paragraph is added to the privacy policy guide. Light anti-spam protection is built in (security token, hidden trap field, minimum fill time, limits per address and per guest); no CAPTCHA and no external service.
What this plugin does not do. No online payment, no takeaway ordering, no deposit, no automatic reminders, no multi-restaurant management, no mobile notification. The paid ARDOIZA offers, described at https://ardoiza.fr/, are separate products: this free plugin works fully on its own, does not require them, does not connect to them and does not show any advertising for them beyond one sentence and one link on its settings page.
Privacy and independence. The plugin makes no request to any external server: no licence check, no telemetry, no update from outside WordPress.org, no font or script loaded from a third party. Emails are sent with the standard WordPress mail function.
Privacy
The plugin stores reservation requests (date, time, party size, seating preference, name, phone, email, comment, consent time) in your database. It sends them by email to the restaurant address set in the settings and an acknowledgement to the guest. It registers a personal data exporter and eraser with the WordPress privacy tools, adds suggested text to the privacy policy guide and applies a configurable retention period. Anti-abuse counters keep only salted hashes of the visitor address, email and phone, for one hour to one day. It does not set cookies, does not use third-party services and does not send any data outside your site.
Third-party code and licences
The QR code encoder (includes/class-ardoiza-qr.php) was written for this plugin and is released under the GPLv2 or later, like the rest of the plugin. No other third-party library is bundled. The plugin uses the WordPress block editor packages provided by WordPress itself. The full text of the GPLv2 is in LICENSE.txt.
Screenshots






Blocks
This plugin provides 2 blocks.
- ARDOIZA Menu Your dishes by section, with prices, allergens, vegetarian and vegan mentions.
- ARDOIZA Reservation A simple table reservation form: date, time, guests and contact details.
Installation
- Install the plugin from the WordPress plugin directory (Plugins, Add New, search “ARDOIZA PRO”) or upload the
ardoiza-profolder to/wp-content/plugins/. - Activate it.
- In the ARDOIZA menu, create your sections and your dishes.
- Create a page and add the “ARDOIZA Menu” block (or the
[ardoiza_carte]shortcode). - In ARDOIZA, Settings, select that page as the menu page, fill in your opening hours, slot length and capacity, then save.
- Add the “ARDOIZA Reservation” block (or
[ardoiza_reservation]) to the page of your choice. - In ARDOIZA, QR code, download the code and print it.
FAQ
-
Is an account or a subscription required?
-
No. Everything runs on your WordPress site. The plugin never contacts ARDOIZA servers.
-
Which allergens are covered?
-
The 14 substances or products causing allergies or intolerances listed in Annex II of Regulation (EU) No 1169/2011, which apply to non-prepacked food in the European Union. You remain responsible for the accuracy of the information shown to your guests.
-
Can I change the colours?
-
Yes. The public styles use CSS custom properties (
--ardoiza-accent,--ardoiza-ink,--ardoiza-cream,--ardoiza-sand, and so on) that your theme or the Customizer’s additional CSS can redefine on.ardoiza-menuand.ardoiza-form-wrap. -
How are slots computed?
-
For each day the opening hours are cut into slots of the chosen length; the last slot starts before closing time. A slot is offered when the sum of guests of pending and confirmed reservations plus the requested party fits within the capacity per slot. Past slots and dates beyond the booking horizon are excluded.
-
Does the reservation form work without JavaScript?
-
Yes. The form posts to the server, which validates the slot again. When JavaScript is available, the list of times is refined as soon as a date and a party size are chosen; a time already chosen stays selected if it is still free, otherwise a message next to the field asks for another one.
-
How is spam handled?
-
Several checks: a security token tied to the form, a hidden trap field, a minimum fill time measured from a timestamp signed by your site for the visitor’s address, a limit of five attempts per hour and per address, a limit of three reservations per hour and ten per day for the same email address or phone number, and a limit of 40 reservations per hour for the whole site (filter
ardoiza_site_requests_per_hour). Every attempt counts towards the limit per address, including the ones that fail; a request without a valid address is refused. The list of free times can be looked up 30 times per ten minutes from one address. Addresses, emails and phone numbers are only hashed, with the secret salt of your site, for these short-lived counters and are never stored with the reservation. This stops most bots without CAPTCHA or external service.If your pages are served from a cache, the token and the timestamp are refreshed by the plugin’s own script when the visitor picks a date; the page holding the form also asks shared caches not to keep it. Should a visitor still send an out of date page, the form says so and asks them to reload.
-
Where are reservations stored, and for how long?
-
In a dedicated table of your WordPress database. The retention period (365 days by default, 0 to keep forever) deletes older reservations once a day. Guests can also ask you to export or erase their data through the WordPress privacy tools.
-
Does the plugin delete its data when uninstalled?
-
Only if you tick “Delete dishes, sections, reservations and settings when the plugin is uninstalled” in the settings. Otherwise your data is kept.
-
Can I offer takeaway ordering or a mobile app that rings for each order?
-
Not with this plugin. The paid ARDOIZA offers are described at https://ardoiza.fr/. They are separate products and are not needed to use this plugin.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“ARDOIZA PRO : réservation de table pour restaurant” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “ARDOIZA PRO : réservation de table pour restaurant” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.6
- Dashboard: the Reservations, QR code and Settings screens are styled again (status badges, framed QR code, compact opening hours table); the price field of a dish is wider.
- Readme: table reservation now comes first in the description and the screenshots.
1.0.5
- Reservations: new setting “My venue has a terrace”. When it is checked, the form offers a seating preference (no preference, indoors or terrace), shown as a wish in the reservations list, the emails and the personal data export.
1.0.4
- Published as “ARDOIZA PRO” (slug
ardoiza-pro, text domainardoiza-pro): the plugin folder and its main file are renamed accordingly. Nothing changes in the data, the shortcodes, the blocks or the CSS classes. - Settings page: one link to the ARDOIZA space, where the paid modules (takeaway ordering, full reservation management, mobile app) are subscribed and downloaded, then installed as separate plugins.
1.0.3
- Translation files are no longer bundled; translations come from translate.wordpress.org.
- Anti-spam: the hidden timestamp of the reservation form is signed by the site (HMAC-SHA-256 with a secret of the site), so a script can no longer send an old timestamp of its own to skip the minimal delay. A page displayed before the update asks to be reloaded.
- Anti-spam: the limits per address count an IPv6 address by its /64 prefix, so changing address inside the same /64 no longer resets them.
- Anti-spam: the signed timestamp only holds from the address (IPv6: the /64) that loaded the page, so a page read once can no longer be posted from many addresses. A page served by a cache still works: the form script takes a fresh timestamp from the availability route, and the page and that route ask shared caches not to keep them.
- Anti-spam: at most 40 reservations recorded per hour for the whole site, whatever the address (filter
ardoiza_site_requests_per_hour, 0 turns it off). Beyond that, guests are asked to try again a few minutes later or to call. - Reservation form: a note under the comment field asks guests not to enter any health information there. The restaurant still sees the comment.
1.0.2
- Reservation form: changing the date or the number of guests reloads the list of times without silently dropping the time already chosen. If it is still free it stays selected; otherwise the field is emptied and a message next to it asks for another time. A late answer is ignored, and if the lookup fails the full list comes back (the server checks the slot anyway).
- Reservation form: after a refused request, the message is also shown next to the field in cause, which is marked as invalid for screen readers (aria-invalid, aria-describedby).
- Anti-spam: limit of three reservations per hour and ten per day for the same email address or phone number; a request without a valid visitor address is refused instead of escaping the limit; the availability lookup is limited to 30 calls per ten minutes and per address. Its errors name the field in cause in
data.params. - Dates: validation, today, booking horizon, day of the week and retention are computed with DateTimeImmutable in the time zone of the site. Dates in emails and in the dashboard no longer shift by one day in time zones far from UTC.
- Emails: the subject of a new request uses the singular for one guest.
- Dish editing: the price is shown with the decimal separator of the dashboard language.
- Database: table names are passed to prepared queries as identifiers.
- Translations: WordPress loads them itself (language packs from translate.wordpress.org); the French catalog shipped in the plugin, now also covering the block editor labels, is only used when no language pack is installed.
- Readme: the paid ARDOIZA offers are only pointed to, without describing their features.
1.0.1
- Dishes list in the dashboard: an empty price or allergen column now reads “No price” or “None” instead of a dash.
- Readme: the description of the paid ARDOIZA offers is corrected, and the allergen list uses the exact names of Annex II.
1.0.0
- First release: menu with sections, dishes, prices, 14 EU allergens, vegetarian and vegan mentions, availability; “ARDOIZA Menu” block and
[ardoiza_carte]shortcode. - QR code of the menu page, PNG and SVG, generated locally.
- Simple table reservation: opening hours, slot length, capacity, booking horizon, public form, emails to the restaurant and the guest, confirmation and refusal from the dashboard, automatic confirmation option.
- Privacy: exporter, eraser, suggested policy text, retention period, optional deletion on uninstall.
- French translation included.
