EquaShop

Description

EquaShop turns WordPress into a clean subscription storefront. You define products, billing plans (monthly / every 6 months / yearly), and rich multilingual marketing content, then sell them through Stripe.

It ships a complete selling engine: a multilingual catalogue admin, a public storefront via shortcodes, a Stripe-powered checkout tunnel (subscriptions and one-off), a self-owned versioned consent referential, and native order management. The product catalogue is always unlimited and the ability to sell is never limited.

Two-layer internationalisation

  • Admin strings — standard WordPress gettext (text domain equashop), driven by the admin’s WordPress locale. The admin ships in English (source); a translation template (languages/equashop.pot) is included, and community translations are served through translate.wordpress.org.
  • Storefront content & strings — fully translatable by you in the five shipped languages (English, French, Spanish, German, Portuguese). Strings resolve in three steps: your admin override a built-in default for the shipped languages fall back to your default shop language.

Admin

  • Products — multilingual catalogue: non-translatable fields (slug, logo, reference price), billing plans, and per-language label / description / features / benefits.
  • Languages — configure your shop languages among the five shipped ones and pick exactly one default (fallback).
  • Storefront translations — override every storefront string per language.
  • Settings — Stripe keys, cart & storefront behaviour, demo data management.

Standalone, with optional companions

EquaShop requires no other plugin to run — it works as a generic shop for any vendor. It is part of the EquaSuite range: when the optional EquaFulfil companion plugin is installed, EquaShop delegates order fulfilment to it. It can also, entirely optionally and off by default, display content from the EquaMarket service — a remote HTTPS service, not an installed plugin (see External services). Neither is required; without them the shop stays fully functional.

Fonts

The storefront embeds the open-source fonts Plus Jakarta Sans and Inter (SIL Open Font License 1.1), so it never depends on a theme or a CDN.

External services

Stripe (payment processing — required to sell). EquaShop uses Stripe (api.stripe.com) for everything money-related. It contacts Stripe:

  • at checkout, to create the Stripe customer and the subscription or one-off payment (sending the buyer’s name and e-mail, the cart contents and amount);
  • to read prices, on demand and on a scheduled WP-Cron price sync you configure in Settings › Stripe sync (refreshing the cached amounts of your tariffs);
  • during product import, to list your Stripe products and to download each product’s image into your Media Library;
  • on the “Test connection” button in Settings › Stripe keys, to query your Stripe account.

Stripe also notifies your site by webhook (Stripe your site) to record paid orders and renewals. Stripe Terms: https://stripe.com/legal — Stripe Privacy: https://stripe.com/privacy

EquaMarket content service — marketing.equadev.fr (optional, opt-in — OFF by default). EquaShop can display EquaSuite news and offers as an admin banner and an “EquaSuite” page inside the WordPress admin. This feature is off by default and only makes a request if you explicitly authorise it in Settings › EquaSuite — a technical server-call authorisation, distinct from any marketing consent, revocable at any time. When enabled, and only while viewing an EquaShop admin screen, the plugin requests this content over HTTPS from https://marketing.equadev.fr. It sends the technical values needed to serve the right content: the plugin identifier (equashop), the content edition it runs (free), and the language of the plugin’s admin display. In addition, WordPress’s own HTTP user-agent carries your site’s URL and WordPress version, and — as with any request — your server’s IP address is visible to the server it contacts; none of these transport values is used. No personal data is collected for marketing or prospecting when querying the marketing.equadev.fr server. The content is display-only (admin-only, never on the storefront). Terms of use for this service are the EquaShop End-User Licence Agreement — https://equasuite.equadev.fr/contrat-de-licence/ .

For developers

EquaShop exposes a small, stable set of public extension points so other code can react to its lifecycle and integrate with it. None of them are required to run the shop; each is simply a documented moment (a hook or a method) you may use.

Payment signal

  • equashop_payment_processed (action) — fires once a paid order has been recorded, on both the subscription and the one-off checkout paths. Listeners receive one associative-array payload with a fixed, versioned key shape (the payment hook, contract v4). Use it to react to a completed sale — fulfilment, CRM, accounting, and so on.

PHP API façade

  • EquaShop_Api (class) — a read-mostly, static-method integration surface for in-process consumers; always call it under your own class_exists( 'EquaShop_Api' ) guard. Catalogue identity: enumerate(), get_product(), count(). Availability verdict: set_availability() (a binary in-stock / out-of-stock verdict). Order read and sync: get_order(), get_orders_by_ids(), orders_cursor(), orders_delta(), set_order_status(), update_order_field(). Method names and return shapes are kept stable (contract version 3).

Lifecycle & data hooks

  • equashop_after_create_tables (action; args: table prefix, charset/collate) — fires after the base tables are created or upgraded, on both fresh install and upgrade. A moment to create your own related tables.
  • equashop_after_seed (action) — fires after the base seed data is written. A moment to seed your own related data.
  • equashop_before_product_delete (action; arg: product id) — fires just before a product (and its i18n and price rows) is deleted.
  • equashop_before_price_delete (action; args: product id, months) — fires just before a single tariff row is deleted.
  • equashop_product_save_columns (filter; args: columns map, submitted data) — filter the column/value map written when a product is saved. With no listener the map is unchanged.
  • equashop_product_price_saved (action; args: tariff row id, tariff data) — fires after each tariff row is upserted during a product save.
  • equashop_demo_installed (action; arg: array of product ids) — fires after the demo products are installed.
  • equashop_demo_removed (action) — fires after the demo data is removed.
  • equashop_fulfilment_active (filter; default false) — return true to take over the native Orders screen; used by a fulfilment companion plugin (returns false when none is present).
  • equashop_checkout_finalize_error (action; args: stage, product slug, WP_Error or null) — fires when a checkout line cannot be finalised (coupon or subscription), for logging or alerting.
  • equashop_content_slot (filter; default free) — the opaque content-set key sent to the EquaMarket content service (see External services); it names which content set the server should return. Return a different key to request another content set.

Screenshots

FAQ

Can I sell already?

Yes. On first activation you review and accept the End-User Licence Agreement and the liability limits on a one-time screen (EquaShop’s own admin pages wait behind it; your site and storefront are unaffected). Then publish the storefront with the shortcodes, add your Stripe keys in Settings › Stripe keys, and buyers can subscribe or buy through the Stripe checkout tunnel; paid orders are recorded and shown in the Orders screen.

How are Stripe keys protected?

The publishable key is stored as-is (it is public). The secret key and webhook secret are encrypted at rest with a key (EQUASHOP_KEK) kept only in wp-config.php, never in the database. From Settings › Stripe keys you generate this key with one click and the plugin writes it to wp-config.php for you (through WordPress’s file API); when the file is not writable, the same screen shows the exact line to add by hand. Nothing is written at activation, and until a key is set the admin warns you that the secrets are stored in plain text. On uninstall the line is left in place — remove it by hand if you wish.

Does uninstalling delete my data?

Only if you tick “Delete data on uninstall” in the settings (OFF by default).

Reviews

There are no reviews for this plugin.

Contributors & Developers

“EquaShop” is open source software. The following people have contributed to this plugin.

Contributors

Translate “EquaShop” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.4.0

  • Maintenance and refinement release — no change to how your shop sells, and no database change. Internal source clean-up (comments and identifiers) for a tidy submission. On the Withdrawal notice screen, switching the behaviour (blocking waiver / display-only notice) now fills each language with the wording that matches the chosen mode, and never overwrites text you have already edited. The encryption key (EQUASHOP_KEK) is generated and written to wp-config.php from the Stripe settings screen with one click, through WordPress’s file API (WP_Filesystem); nothing is written at activation. It never overwrites an existing key, is staged through a private temporary file in the same directory as wp-config.php that is always removed, shows the exact line to add by hand when wp-config.php is read-only, and never stores the key in the database; the line is left in place on uninstall. The payment hook (v4) keeps its byte-identical contract.

1.0.4

  • Maintenance release: internal comment and admin-label tidy-up only — no change to how your shop works, and no database change. The payment hook (v4) keeps its byte-identical contract.

1.0.3

  • Documentation and refinement release — no change to how your shop sells, and no database change. The in-product help was corrected to match the plugin exactly (out-of-stock behaviour, consents and the delivery-mode field). The payment hook (v4) keeps its byte-identical contract.

1.0.2

  • Refinement and non-destructive-downgrade release — no change to how your shop sells. New products now default to the “Immediate execution” withdrawal regime, so a product is compliant out of the box (fully editable afterwards). Order management is now driven by a single “Physical order management” setting, and its help was rewritten to match. The in-product help was tidied and de-duplicated. No database change; the payment hook (v4) keeps its byte-identical contract.

1.0.1

  • Security and refinement release — no change to how your shop works. Values submitted on the product form are sanitised before they are stored. This release also leaves wp-config.php untouched, adding the encryption key by hand from the settings screen (the automatic, writable-only write with a manual fallback is reinstated in 1.4.0). Fixed a broken documentation link in this readme. No database change; the payment hook (v4) keeps its byte-identical contract.

1.0.0

  • First public WordPress.org release. The complete selling engine: an unlimited multilingual catalogue, storefront shortcodes, and Stripe checkout for both subscriptions and one-time products. A self-owned, versioned consent referential (marketing and transactional texts, each edit archived and transmitted with the order) and a single, editable withdrawal notice (blocking waiver or informational) shown at the cart. Native order management with manual handling statuses. The storefront and the dedicated product page render inside your active theme on both classic and block themes (with an accessibility skip-link on block themes). English is the source language; community translations are served through translate.wordpress.org. Hardened for the directory: consistent input sanitisation and output escaping, and capability + nonce checks on every admin action; fixed a fatal error that could occur when refreshing a product’s Stripe prices. No database change; the payment hook (v4) and PHP API façade keep byte-identical contracts.