Shoplex – EU Compliance for WooCommerce

Description

Selling to consumers in the European Union requires specific information across the product page, the shopping cart, the checkout flow, and post-purchase order management. Requirements differ across EU member states: German courts mandate specific button labels under the Button-Lösung rule, French law penalizes missing payment warnings, Spanish law requires a three-year statutory warranty rather than the standard two-year period, and packaging laws require specific register numbers (LUCID in Germany, EPR in France, BDO in Poland).

Shoplex implements these legal requirements as seventeen distinct, independent modules. Each module can be switched on or off individually under WooCommerce > Shoplex. The administration interface explicitly references the corresponding EU directive or national statute for each requirement.

The Seventeen Modules

  1. Unit Price (Price per Reference Unit)
    Directive 98/6/EC requires showing the price per standard unit (such as per kilogram, 100 grams, litre, or metre) alongside the final selling price for packaged goods sold by weight or volume. Shoplex calculates this ratio automatically from the product’s net content and chosen reference unit. Works across simple and variable products, and supports archive catalogue loops.

  2. Lowest Price in the Last 30 Days (Omnibus Directive)
    Directive 2019/2161 (the Enforcement and Modernisation Directive, commonly called Omnibus) dictates that any price reduction announcement must state the lowest price applied during a period of at least 30 days prior to the reduction. Shoplex maintains a local database log of every price update across regular, sale, and variation prices. Unscheduled sales calculate against historical records, and daily scheduled cleanup retains the window without deleting the active base price.

  3. VAT Notice (Tax Display Indication)
    Directive 98/6/EC and Directive 2011/83/EU require informing the consumer whether the price includes applicable VAT. Shoplex prints the rate applied to each product (e.g. “incl. 19% VAT” or “excl. VAT” for net display). For merchants qualifying for the small business scheme (Article 284 of Directive 2006/112/EC, such as § 19 UStG in Germany), a dedicated exemption notice replaces standard tax percentages.

  4. Shipping Costs Notice & PAngV Link
    Directive 2011/83/EU art. 6(1)(e) requires that when shipping costs cannot be calculated in advance, the fact that such costs are payable must be stated. Under the German Price Indication Ordinance (PAngV § 6), the words “plus shipping” (“zzgl. Versandkosten”) must provide a direct hyperlink to the merchant’s payment and shipping conditions page rather than a generic catalogue archive. Shoplex allows designating a specific shipping page or falls back cleanly to the shop’s legal terms page.

  5. From-Price for Variable Products
    Directive 98/6/EC restricts deceptive price ranges. When product variants carry different prices, displaying wide ranges (“€10.00 – €90.00”) can mislead buyers regarding initial availability. Shoplex replaces ranges with a clean “from €10.00” label reflecting the lowest currently purchasable variation.

  6. Delivery Time Indication
    Directive 2011/83/EU art. 6(1)(g) mandates providing the arrangements for payment, delivery, and performance, including the time by which the trader undertakes to deliver the goods. In countries like Germany, vague estimates like “promptly” or “usually within a few days” are legally non-compliant. Shoplex registers a dedicated delivery time taxonomy allowing unified terms (“2 – 4 business days”, “ready to ship in 24h”) applied per product, per variation, or shop-wide.

  7. Legal Guarantee of Conformity and Durability
    Directive (EU) 2019/771 on consumer sales of goods and Directive (EU) 2019/770 on digital content require informing consumers of their statutory conformity guarantee. For Spain, where Real Decreto-ley 7/2021 amended the LGDCU to require a 3-year statutory warranty (36 months) starting January 1, 2022, Shoplex automatically provides the 3-year warranty statement when resolving customers in Spain. Also supports displaying commercial guarantees of durability, digital software update periods, and repair information.

  8. Country-Specific EU Rules (Button-Lösung & Packaging Registers)
    National transpositions of Article 8(2) of the Consumer Rights Directive require the order confirmation button to be clearly labelled with an unambiguous statement indicating that placing the order entails an obligation to pay:

– Germany & Austria (§ 312j Abs. 3 BGB / § 8 FAGG): Zahlungspflichtig bestellen
– France (Art. L. 221-14 Code de la consommation): Commande avec obligation de paiement
– Italy (Art. 51 comma 2 Codice del Consumo): Ordina e paga
– Spain (Art. 98.2 LGDCU): Pedido con obligación de pago
– Poland (Art. 17 ust. 3 Ustawy o prawach konsumenta): Zamówienie z obowiązkiem zapłaty
Works on both the classic checkout and the WooCommerce Block Checkout via client-side registration filters. Also displays packaging and environmental registry numbers (LUCID register number for Germany under VerpackG, Identifiant Unique REP / EPR for France under AGEC, and Numer BDO for Poland under the Waste Act).

  1. 14-Day Statutory Right of Withdrawal
    Directive 2011/83/EU Annex I(B) guarantees consumers a 14-day cancellation window. Shoplex provides an out-of-the-box workflow:

– Public shortcode [shoplex_withdrawal_form] allowing guest lookups with anti-enumeration protection and rate limiting.
– Secure single-use magic links sent directly to the customer’s billing email with a 30-minute expiry.
– Authenticated declaration form listing remaining withdrawable items with clamped quantities to prevent returning more units than ordered.
– Direct High-Performance Order Storage (HPOS) metadata storage (_shoplex_withdrawals), audit trails in WooCommerce order notes, and automated confirmation emails to both customer and store administrator.

  1. General Product Safety Regulation (GPSR)
    Regulation (EU) 2023/988 (GPSR), in effect since December 13, 2024, requires online listings to publish manufacturer identity details, postal address, electronic address, the EU responsible person (for manufacturers outside the EU), and required safety warnings or instructions. Shoplex provides dedicated per-product and default fields for all required GPSR disclosures.

  2. Checkout Consents & Consent Recording
    Directive 2011/83/EU art. 8 and GDPR art. 7 demand unambiguous, affirmative agreement for specific contractual conditions, particularly waiving withdrawal rights for immediate access to digital downloads. Shoplex renders terms, privacy policy, right of withdrawal acknowledgment, digital content waivers, newsletter consents, and carrier delivery updates. Each recorded consent captures the verbatim text displayed, the customer decision, and the exact timestamp stored in HPOS order meta. Compatible with classic and block checkouts.

  3. Trader Identity (Impressum / Legal Notice)
    Directive 2000/31/EC art. 5 and national legislation (such as § 5 DDG in Germany) require commercial websites to provide permanent, immediate access to commercial registry numbers, corporate entity names, physical addresses, electronic mail, telephone contact, and VAT identification numbers. Shoplex renders these through the [shoplex_business_info] shortcode or the native block.

  4. Dispute Resolution (ODR Notice)
    Regulation (EU) 524/2013 and Directive 2013/11/EU require e-commerce platforms to link to consumer alternative dispute resolution bodies. Shoplex provides the statutory notice for inclusion in store footers or legal pages.

  5. Intra-EU B2B VAT Validation (VIES REST API)
    Under Directive 2006/112/EC art. 138, exempting cross-border intra-EU B2B supplies at 0% VAT requires verifying that the customer is a taxable person with a valid VAT number in another member state. Shoplex queries the European Commission’s official VIES REST endpoint in real time across all 27 member states and Northern Ireland (XI). When configured with your own VAT ID, it performs a qualified check and stores the official consultation number (requestIdentifier) directly in the order meta and order notes as audit-proof evidence for tax authorities.

  6. Statutory Complaint Form Template (Formularz Reklamacyjny)
    Under Directive (EU) 2019/771, consumers are entitled to remedies (repair, replacement, price reduction, contract termination) for non-conforming goods. Shoplex provides a ready-to-print or embed complaint form via shortcode [shoplex_complaint_template] and an administrative preview with one-click standalone HTML download, automatically populated with the merchant’s company details.

  7. Cyber Resilience Act Disclosure (CRA / RFC 9116 security.txt)
    In alignment with European cybersecurity standards and the Cyber Resilience Act (Regulation EU 2024/2847), Shoplex serves a standard security disclosure policy at /.well-known/security.txt (RFC 9116). Merchandisers can specify their designated security contact email, vulnerability disclosure policy URL, and expiration date.

  8. Digital Services Act Notice & Action Mechanism (DSA Reporting)
    Under Article 16 of Regulation (EU) 2022/2065 (Digital Services Act), online intermediaries and shops must provide an easily accessible mechanism for individuals and entities to notify them of illegal content or non-compliant products. Shoplex provides the public notice form via [shoplex_dsa_report] with structured reason selection, validation, rate limiting, and instant email dispatch to store administrators.

Multilingual and Translation Compatibility

Shoplex includes comprehensive multilingual support:
* WPML & Polylang: Includes an official wpml-config.xml mapping configuration keys from shoplex_* options directly into string translation tables.
* TranslatePress & Loco Translate: Built with standard gettext functions across all frontend templates, notices, and checkout buttons.
* Autonomous Resolution: Destination country rules resolve based on billing address, shipping address, or geolocation independently of the front-end language chosen by the buyer.

Technical Architecture

  • HPOS Native: Full support for WooCommerce High-Performance Order Storage (Custom Order Tables).
  • Block Checkout Compatible: Integrates with WooCommerce Cart and Checkout Blocks via Store API and Blocks JavaScript filter registries.
  • Zero External Dependencies: Runs locally on your server. No calls home, no API keys, and no monthly service fees.
  • Minimal Overhead: Built without heavy JavaScript frameworks or unnecessary database tables.

Screenshots

Installation

  1. Ensure your store runs WordPress 6.5 or newer and WooCommerce 8.0 or newer.
  2. Upload the shoplex folder to your /wp-content/plugins/ directory or install via the WordPress Plugins menu.
  3. Activate the plugin through the ‘Plugins’ menu in WordPress.
  4. Navigate to WooCommerce > Shoplex to review and toggle individual compliance modules.
  5. Navigate to WooCommerce > Shoplex settings to customize store identity, notices, registry numbers, and country rules.
  6. For statutory withdrawal, create a returns page and insert the shortcode [shoplex_withdrawal_form].

FAQ

Does Shoplex cover statutory rules across all 27 EU member states?

Yes. Under Directive 2011/83/EU (Consumer Rights Directive) Art. 8(2), orders placed online must explicitly state that placing the order entails an obligation to pay. Shoplex includes verified statutory checkout button labels for all 27 EU countries (such as Germany and Austria: “Zahlungspflichtig bestellen”, France and Luxembourg: “Commande avec obligation de paiement”, Italy: “Ordina e paga”, Spain: “Pedido con obligación de pago”, Netherlands and Belgium: “Bestelling met betalingsverplichting”, Poland: “Zamówienie z obowiązkiem zapłaty”, Sweden: “Beställning med betalningsförpliktelse”, etc.). It also adapts consumer conformity warranties (such as the Spanish 3-year requirement under RDL 7/2021) and packaging register numbers.

How does customer country detection work at checkout?

Shoplex determines the destination country using a five-tier hierarchy:
1. Active form submission during checkout or AJAX updates (billing_country).
2. Customer billing country stored in the active WooCommerce session.
3. Customer shipping country stored in the active WooCommerce session.
4. IP-based geolocation via WC_Geolocation::geolocate_ip().
5. Store base country configured in WooCommerce settings.

When a customer changes their billing or shipping country in the checkout dropdown, the order button label updates immediately to match the statutory requirement of that destination.

What are the German and Austrian Button-Lösung and PAngV requirements?

In Germany (§ 312j Abs. 3 BGB) and Austria (§ 8 FAGG), failure to label the final purchase button with an unequivocal payment notice (“Zahlungspflichtig bestellen” or equivalent) renders the purchase contract void. Furthermore, the German Price Indication Ordinance (PAngV § 6) requires stating whether prices include VAT and providing a direct, accessible link to your shipping costs page (“inkl. MwSt., zzgl. Versandkosten”). Shoplex provides dedicated settings to link directly to your shipping information page.

How does the Spanish 3-year statutory guarantee work?

Under Spain’s Real Decreto-ley 7/2021 amending the General Consumer Protection Law (LGDCU), the statutory conformity warranty for tangible goods was extended from two years to three years (36 months). When Shoplex detects a customer in Spain (ES), it automatically serves the 3-year legal guarantee notice instead of the standard 2-year European baseline.

Which packaging and environmental register numbers are supported?

Shoplex allows you to configure:
* Germany: LUCID registration number under the Packaging Act (VerpackG § 9).
* France: Unique Identification Number (Identifiant Unique REP / IDU) under the AGEC law and Article L. 541-10-13 of the Environmental Code.
* Poland: BDO register number (Baza Danych o Odpadach) under the Waste Act.
These numbers automatically attach to your trader identity blocks and impressum footers.

How does the 14-day statutory right of withdrawal work?

Directive 2011/83/EU Annex I(B) requires providing consumers with a standardized withdrawal declaration model. Shoplex implements this via the shortcode [shoplex_withdrawal_form]. Logged-in customers can select an eligible order, pick individual items and quantities, and submit their declaration. For guest customers, an anti-enumeration lookup sends a secure, single-use 30-minute magic link to their billing email. Declarations are stored in HPOS order meta (_shoplex_withdrawals), noted in order history, and emailed to both the buyer and the store owner.

How does the VIES VAT validation module work for intra-EU B2B sales?

Under Directive 2006/112/EC Art. 138, cross-border B2B sales within the EU can be zero-rated (0% VAT) only when the buyer has an active, verified VAT number in their member state. Shoplex checks customer VAT IDs in real time against the European Commission’s official VIES REST API. If you configure your own VAT ID in the settings, Shoplex performs a qualified request and records the official consultation identifier (requestIdentifier) in the order notes as audit-proof evidence for tax authorities.

What is the Digital Services Act (DSA) reporting form?

Under Article 16 of Regulation (EU) 2022/2065 (Digital Services Act), online intermediaries and e-commerce stores must provide an easily accessible electronic notice mechanism for reporting illegal content, counterfeit items, or non-compliant goods. Shoplex provides the public notice form via [shoplex_dsa_report], complete with structured reason selection, spam rate limiting, and administrative notifications.

Does Shoplex generate a RFC 9116 security.txt for the Cyber Resilience Act?

Yes. In accordance with European cybersecurity standards and the Cyber Resilience Act (Regulation EU 2024/2847), Shoplex serves a compliant /.well-known/security.txt endpoint. Store owners can configure their designated security contact email, vulnerability disclosure policy URL, and expiration date under WooCommerce > Shoplex settings > CRA security.txt.

Does it support the WooCommerce Block Checkout?

Yes. Checkout consents, button labels, and terms links hook both classic shortcode checkouts and modern block checkouts (wc-blocks-checkout).

Does Shoplex replace country-specific plugins like Germanized or Polski?

Shoplex implements the harmonized EU-wide consumer protections and key destination rules (Button-Lösung across all 27 countries, PAngV shipping links, packaging register numbers, Spanish 3-year warranty, VIES validation, statutory withdrawal, and GPSR). It does not handle national fiscal cash register drivers, local invoice numbering sequences, or national postal locker APIs. For domestic Poland integrations, plugins like Polski cover local carriers and KSeF; for stores selling across the European Union, Shoplex provides the complete cross-border legal compliance stack.

How does the Omnibus lowest-price tracker handle scheduled sales?

When a product enters a sale, Shoplex determines the comparison window (30 days by default). It inspects recorded prices in the shop currency, looks for the lowest price active before the promotion commenced, and prints the result according to your chosen template. Daily cleanup prunes obsolete historical records while preserving the active base price.

Is Shoplex compatible with multilingual plugins?

Yes. Shoplex includes a native wpml-config.xml file that registers all options, button texts, and notice templates for translation in WPML and Polylang. It also supports TranslatePress, Loco Translate, and standard gettext localization.

Reviews

wow

September 23, 2026
I’m impressed with how well this integrates with my existing theme.
Read all 1 review

Contributors & Developers

“Shoplex – EU Compliance for WooCommerce” is open source software. The following people have contributed to this plugin.

Contributors

“Shoplex – EU Compliance for WooCommerce” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “Shoplex – EU Compliance for WooCommerce” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.3.0

  • Feature: Country-specific compliance module implementing the Button-Lösung checkout button rules (§ 312j BGB for DE/AT: “Zahlungspflichtig bestellen”, France: “Commande avec obligation de paiement”, Italy: “Ordina e paga”, Spain: “Pedido con obligación de pago”, Poland: “Zamówienie z obowiązkiem zapłaty”).
  • Feature: Spanish 3-year statutory guarantee compliance under Real Decreto-ley 7/2021 (automatically serves 36-month conformity notice to Spanish buyers).
  • Feature: Packaging and environmental register number support for German LUCID (VerpackG), French REP / EPR Identifiant Unique (AGEC), and Polish BDO.
  • Feature: Statutory 14-day consumer right of withdrawal module with public shortcode [shoplex_withdrawal_form], guest order lookup via magic links, anti-enumeration protections, HPOS order meta logging, and automated notification emails.
  • Feature: Intra-EU B2B VAT number validation via official European Commission VIES REST API with audit-proof consultation number (requestIdentifier) storage in order meta (Directive 2006/112/EC).
  • Feature: Statutory consumer warranty complaint form template ([shoplex_complaint_template]) with printable HTML export for non-conforming goods (Directive EU 2019/771).
  • Feature: Cyber Resilience Act security disclosure policy endpoint at /.well-known/security.txt (RFC 9116 / Regulation EU 2024/2847).
  • Feature: Digital Services Act notice & action mechanism ([shoplex_dsa_report]) for illegal content reporting (Article 16 of Regulation EU 2022/2065).
  • Feature: Comprehensive multilingual support with native wpml-config.xml for WPML and Polylang, plus runtime translation fallbacks.
  • Enhancement: PAngV compliant shipping page link settings for German and Austrian store requirements.
  • Verified: Full compatibility with WooCommerce 11.1 and WordPress 7.1.

1.2.4

  • Fixed: the lowest price of the last 30 days could state the sale price itself. A sale without a start date compared against its own price, and only the first price change of a day was recorded, so a later change that day was missing from the history. Every change is now recorded, an unscheduled sale is measured from the moment it was first recorded, and the price already in force when the window opens counts.
  • Fixed: price history was never pruned, because nothing scheduled the daily cleanup. It now runs daily, never deletes inside the comparison window, and keeps the record of the price still in force. Variation prices changed through the REST API, WP-CLI or an import are recorded too.
  • Fixed: saving a settings tab flattened multi-line fields and stripped the links from the checkout consent wording, so the terms link disappeared after any save of the Checkout consent tab.
  • Fixed: the shipping cost notice, the dispute resolution notice and the small business VAT notice rendered nothing until their settings tab had been saved once. Unsaved settings now use their packaged defaults.
  • Fixed: “Displayed prices: net” changed nothing, so the VAT notice kept saying the price included VAT. It now uses its own “excl.” wording.
  • Fixed: on the classic checkout the consent note was written before the order existed and was lost. The block checkout already had it.
  • Fixed: the terms and withdrawal links in the consent wording pointed at “#”. They now use the WooCommerce terms page and the refund and returns page.
  • Fixed: the Trader identity block could not be inserted in the editor. It now can on WordPress 7.0 and newer.
  • Addresses, warnings and repair information keep their line breaks on the product page and in the trader details.

1.2.3

  • The Plugin URI pointed at the site root rather than this plugin page, because the page did not exist yet. It does now.

1.2.2

  • Fixed: the unit price stated the unit but not the reference amount, so a product priced per 1000 g read “EUR 67.50 / g” while costing EUR 13.50. The product panel invites a reference amount other than 1, and price indication is the one thing this module exists for, so the amount is now part of the line: “EUR 67.50 / 1000 g”.

1.2.1

  • Fixed: the consent fields for the block checkout are registered on init, and building them read the cart, which WooCommerce only has from wp_loaded. Every front-end load logged “get_cart was called incorrectly” with debugging on. The cart is read only once it exists.
  • Changed: a consent box limited to certain products, countries or payment methods is shown on the classic checkout only. A block checkout field is registered once for the whole shop, so the digital-content waiver would otherwise appear for someone buying a chair.

1.2.0

  • The checkout consent module now reaches the checkout. Both checkouts are wired, the classic one and the block one, which share no hooks, and the order stores what was agreed in the wording that was shown plus the time it was given. The order screen shows that record.
  • Renamed to Shoplex.

1.1.0

  • Product fields. Unit price, delivery time, guarantee of durability, update period, repair information and the twelve GPSR fields are now filled in on an Shoplex tab of the product.
  • Settings screen. Trader details and every notice wording are now editable under WooCommerce, Shoplex settings.
  • Delivery times are a real taxonomy, edited under Products, so a shop states the same wording across its catalogue.
  • Prices displayed net can be chosen again.
  • The VAT rate follows the site language.

1.0.0

  • First release: unit price, lowest price in the last 30 days, VAT and shipping notices, from-price, delivery time, legal guarantee and durability, product safety information, checkout consent, trader identity and dispute resolution notice.