Description
JAZ-X Product Recall Manager for WooCommerce gives store owners a structured workflow for product safety recalls.
Free 1.0.0 includes:
- Manual product recall cases.
- Recall reference, source, date, brand, model, identifier, batch/lot, hazard, customer action and remedy fields.
- Link recalls to WooCommerce products.
- Batch-safe scanning of WooCommerce orders using WooCommerce order APIs.
- HPOS compatibility declaration.
- Affected order/customer list.
- Quantity counts.
- Resolution tracking: open, refund, replacement, repair or closed.
- Public product recall notice pages.
-
Internal audit log foundation.
-
Provider-agnostic Purchase Source Adapter API for verified external buyers.
- Built-in WooCommerce order source plus optional hook/callback adapters.
- Adapter records are normalized before storage and quarantine locks are enforced centrally.
-
Purchase Sources admin screen shows only registered verified sources, without requiring provider-specific branding.
-
Deep Transaction Discovery using exact product title, slug, SKU or product URL; numeric-only IDs are ignored.
- Read-only discovery across transaction/customer-capable custom tables and transaction-like custom record types.
- Strict external product identity verification and quarantine of legacy false-positive matches.
JAZ-X Product Recall Manager does not determine whether a product is legally subject to a recall. Store owners remain responsible for verifying recall information and legal obligations.
Adapter API Example
Integrations may register a callback-backed verified purchase source:
add_action( 'recallsafe_register_purchase_sources', function ( $registry ) {
$registry->register_callback_source(
'my_external_source',
'External verified purchase source',
function ( $context ) {
// Query your own system and return only independently verified buyers.
return array();
}
);
} );
Or use the generic hook-backed adapter:
add_filter( 'recallsafe_external_verified_matches', function ( $records, $context ) {
// Return only provider-verified records for the supplied product fingerprints.
return $records;
}, 10, 2 );
A verified record requires source_record_id and customer_email. Optional fields are customer_id, customer_name, quantity, purchased_at, verification_method, and product_reference.
Adapter SDK v2 Example
add_action( 'recallsafe_register_purchase_sources', function ( $registry ) {
$registry->register_callback_source(
'verified_external_commerce',
'External verified purchase source',
function ( $context ) {
$records = array();
foreach ( RecallSafe_Adapter_SDK::products_from_context( $context ) as $product ) {
// Query your own trusted system using the product fingerprint.
// Only return a row after your integration has verified ownership.
}
return $records;
}
);
} );
Build records with RecallSafe_Adapter_SDK::verified_record(). Required fields remain source_record_id and customer_email. Recommended fields are verification_method, product_reference, purchased_at, and, for access-based products, entitlement_status and entitlement_expires. Provider-specific API credentials, webhook secrets and private implementation details must stay in the integrating system.
Installation
- Upload the
jaz-x-product-recall-manager-for-woocommercefolder to/wp-content/plugins/or install the ZIP from Plugins > Add New > Upload Plugin. - Ensure WooCommerce is installed and active.
- Activate JAZ-X Product Recall Manager for WooCommerce.
- Go to JAZ-X Recalls > Add Product Recall.
- Add recall details and link the affected WooCommerce products.
- Go to JAZ-X Recalls > Affected Customers and run Scan / Rescan Orders.
FAQ
-
Does JAZ-X Product Recall Manager automatically contact government recall databases?
-
Not in Free 1.0.0. This release focuses on the store-side recall workflow, manual verified recall records, and provider-neutral purchase-source adapters.
-
Does it support WooCommerce HPOS?
-
The plugin declares HPOS compatibility and uses WooCommerce order APIs rather than directly querying legacy order post tables.
-
Can another checkout, licensing, membership, marketplace, or download system integrate with JAZ-X Product Recall Manager?
-
Yes. Version 0.4.0 adds a provider-agnostic Purchase Source Adapter API. Integrations can register an object implementing
RecallSafe_Purchase_Source_Interface, register a callback source through the registry, or supply verified rows through therecallsafe_external_verified_matchesfilter. JAZ-X Product Recall Manager core does not need to know the provider implementation. -
What must an external adapter return?
-
Each verified row must include a stable
source_record_idand a validcustomer_email. Optional fields includecustomer_id,customer_name,quantity,purchased_at,verification_method, andproduct_reference. The adapter is responsible for verifying that the buyer belongs to one of the product fingerprints supplied in the scan context. -
Does it automatically email customers?
-
JAZ-X Product Recall Manager can send a manual safety notification to a verified affected customer and includes a no-send preview. Draft and Reviewing recalls cannot send live notifications.
-
Does uninstalling delete recall records?
-
No. Safety and audit-related data is intentionally not automatically deleted on uninstall.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“JAZ-X Product Recall Manager for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “JAZ-X Product Recall Manager for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.4
- Documented the activation-only SHOW INDEX query as using a trusted schema identifier derived only from $wpdb->prefix and a fixed suffix.
- No functional behavior changed from 1.0.3.
1.0.3
- Marked activation-only schema verification queries as intentional direct database checks for WordPress coding standards.
- No functional behavior changed from 1.0.2.
1.0.2
- Renamed the public plugin identity to JAZ-X Product Recall Manager for WooCommerce and updated the WordPress.org text domain/package slug.
- Moved admin JavaScript out of inline script tags and into a properly enqueued admin asset.
- Passed scan runtime data to JavaScript through WordPress localization instead of interpolating PHP values into a script block.
- Reduced the composite unique-index prefix lengths for compatibility with older WordPress-supported MySQL/InnoDB index limits.
- Database version is now recorded only after the required tables and unique index are verified.
- Existing RecallSafe database/meta keys and developer hooks are intentionally preserved for backward compatibility and existing data.
1.0.1
- Removed the duplicate Plugin URI header so Plugin URI and Author URI no longer conflict during WordPress.org validation.
1.0.0
- First stable Free release.
- Finalized the professional Add/Edit Recall, Product Recalls, Affected Customers, Purchase Sources, audit, and quarantine interfaces.
- Includes provider-neutral purchase-source adapters, strict external-buyer verification, quarantine safeguards, manual safety notifications, no-send email preview, and resolution tracking.
- Reworked the quarantined-record removal control for reliable visible rendering.
- Declares WooCommerce HPOS compatibility and uses WooCommerce order APIs for order scanning.
- Preserves recall, affected-customer, quarantine, and audit data on uninstall; safety records are not deleted automatically.
- Release packaging, readme, version, stable-tag, translation-domain, and Plugin Check cleanup completed.
0.5.10
- Made the quarantined-record removal action render as a plain, reliable text button.
- Added explicit spacing between the Recent Audit Activity title and event-count badge.
0.5.9
- Added direct-access protection to the provider-neutral adapter example.
- Documented and scoped Plugin Check handling for validated dynamic database identifiers used by external-source discovery.
- Kept value parameters prepared and existing strict source-validation safeguards unchanged.
0.5.8
- Reworked bounded post-meta discovery to use fixed prepared statements and remove dynamic IN-clause prepare warnings.
0.5.7
- Fixed the remaining Plugin Check translators-comment error in payment evidence diagnostics.
- Corrected the plugin header version to match the runtime version.
0.5.6
- Added the two remaining translator comments for payment-evidence placeholder strings reported by Plugin Check.
0.5.4
- Polished Affected Customers audit and quarantine panels.
- Improved audit event badge spacing and card consistency.
- Restored a prominent, reliable Remove permanently quarantine action.
0.5.3
- Redesigned Add/Edit Recall screen with professional card layout, summary metrics, responsive sections, numbered product selection, and checkboxes.
- Added serial numbers and selection checkboxes to the Product Recalls list.
0.5.0
- Professional admin UI/UX polish across recall management screens.
- Added scan summary metric cards for orders, affected units, external signals, and verified external buyers.
- Moved technical scan output into a collapsed Advanced diagnostics panel.
- Improved responsive layout, spacing, typography, cards, toolbars, tables, empty states, and audit presentation.
- Kept provider-neutral purchase-source architecture and quarantine safeguards unchanged.
0.4.8
- Improved Recent Audit Activity with meaningful scan summaries.
- Collapsed Scan Started/Completed pairs into a single scan event in the UI.
- Added reliable actor labels (admin, system, or user ID fallback).
- Added clearer audit cards for notifications, resolution changes, quarantine and recall updates.
0.4.5
- Added no-send safety email preview.
- Added meaningful empty state for audit activity and filters malformed legacy audit rows.
- Reused the exact notification builder for preview and live sends.
0.4.4
- Expands Purchase Sources into an adapter operations screen with health, capabilities, last verification, last test, and non-destructive source tests.
- Adds optional Adapter SDK v2 methods: get_capabilities(), get_health_status(), and test_connection() without breaking the original interface.
- Records source runtime health/verification timestamps and clean adapter failure diagnostics.
- Keeps WooCommerce on the same common purchase-source contract and adds health/capability reporting.
- Updates the provider-neutral developer example and keeps provider-specific implementation outside JAZ-X Product Recall Manager core.
0.4.2
- Packaging fix: restored the canonical plugin directory used by that release so uploaded ZIPs replaced the existing plugin instead of installing as a duplicate.
- Keeps the v0.4.1 Adapter SDK v2 functionality unchanged.
0.4.1
- Adds Adapter SDK v2 while preserving the v1 interface for backward compatibility.
- Adds a richer provider-neutral scan context with a normalized
productsarray. - Adds standardized verification methods for webhook, provider API, entitlement, subscription, download and license integrations.
- Adds optional entitlement status/expiry and source type fields to normalized adapter records.
- Keeps provider-specific implementation outside JAZ-X Product Recall Manager core.
0.4.0
- Adds the provider-agnostic Purchase Source Adapter API.
- Adds registration through
recallsafe_register_purchase_sources, callback-backed sources, and a generic verified-match filter. - Adds centralized verified-record normalization before external buyers can enter the affected-customer table.
- Enforces external quarantine locks for adapter-provided matches.
- Adds a Purchase Sources admin screen for connected verified sources.
- Keeps provider-specific implementation details outside JAZ-X Product Recall Manager core.
0.3.3
- Fixes the unique-bridge discovery-to-correlation hand-off.
- Carries catalog-unique bridge fingerprints on exact external source rows instead of re-deriving them later.
- Deduplicates multiple bridge hits on the same external row.
- Correlation diagnostics now use the already-proven unique bridge discovery as authoritative evidence.
- Allows human-review buyer candidates when a catalog-unique bridge, customer identity, and entitlement/access evidence are present without requiring a transaction reference.
0.3.1
- Preserve catalog-unique bridge fingerprints through row-level buyer correlation.
- Deduplicate multiple bridge hits that refer to the same external source row.
- Align in-memory bridge matching with common case-insensitive database collations.
- Treat unique bridge + customer identity + entitlement evidence as a valid human-review path when no transaction reference exists.
0.3.0
- Adds Unique Bridge Buyer Verification for external download/access stores.
- Allows a catalog-unique product bridge to verify a buyer without requiring a transaction reference when entitlement/access evidence is present.
- Resolves opaque same-source customer references to customer identity rows before presenting a human-review candidate.
- Keeps human approval mandatory and preserves quarantine for older false-positive external matches.
0.2.9
- Added catalog-wide bridge identifier uniqueness validation.
- Shared/global bridge identifiers are rejected for buyer promotion.
- Added catalog-unique bridge + customer identity + entitlement verification when no transaction reference exists.
- Added uniqueness diagnostics to the External Identifier Bridge Discovery UI.
0.2.8
- Adds related-row bridge correlation inside the same external source.
- Follows exact transaction/reference values from bridge-matched seed rows to customer and entitlement/history rows.
- Keeps correlation bounded and read-only; private provider, bridge and transaction values are never displayed.
- Deduplicates multiple related history rows into one human-reviewed buyer candidate.
0.2.6
- Adds Bridge-Correlated Buyer Verification for opaque external catalog identifiers.
- Correlates exact linked-product bridge identifiers with customer identity, transaction evidence and download/access entitlement evidence in the same external source.
- Deduplicates history/event rows by source and customer identity before human review.
- Shows masked buyer candidates with bridge-correlation confidence; raw provider, table, bridge and transaction values remain private.
- Keeps promotion human-reviewed and revalidates promoted external buyers against current bridge evidence on later scans.
0.2.5
- Adds External Identifier Bridge Discovery for opaque external catalog/product/price references.
- Reads only safe, non-sensitive linked-product metadata and displays identifier fingerprints instead of raw values.
- Correlates exact bridge identifiers with transaction/customer-capable external sources without exposing provider names or private values.
- Numeric WooCommerce product IDs alone remain insufficient for external customer promotion.
0.2.3
- Quarantines legacy external matches that fail strict product-identity revalidation.
- Excludes quarantined rows from active affected-customer counts.
- Adds a dedicated Actions column with a visible Remove button for external rows.
- Adds a quarantined-records review panel with permanent removal.
- Keeps deep transaction discovery read-only and provider-agnostic.
0.2.2
- Strict external product identity verification: numeric IDs alone can no longer be promoted.
- Added false-positive removal for external affected-customer records.
- Added deeper read-only transaction discovery using exact text identifiers.
0.2.1
- Adds human-reviewed promotion of exact-product external download/access entitlement candidates into Affected Customers.
- Deduplicates entitlement history by customer identity and keeps provider/table names private.
- Uses generic external entitlement source labels and masked candidate identities before approval.
0.2.0
- Added entitlement-aware external record classification for digital products that grant direct downloads or time-limited access without issuing a license.
- Separates purchase/transaction, download/access entitlement, license/supporting, fulfillment and access-period evidence.
- Treats subscription/access/download fields as entitlement evidence instead of assuming they are license records.
- Reports access-period/expiry evidence so time-limited download access can be distinguished from licensing.
- Expands safe source discovery to entitlement, download, access, fulfillment and delivery storage signals.
- External candidate mapping remains read-only and diagnostic; raw customer, payment, entitlement and license values are not displayed or auto-enrolled.
0.1.9
- Added privacy-preserving Safe Candidate Mapping for strong external purchase/license sources.
- Reads only exact affected-product candidate rows in bounded read-only queries and never displays raw customer, transaction or license values.
- Reports customer evidence, transaction evidence, license evidence, anonymized unique identity counts, likely record role and mapping confidence.
- Fixed external-source labels so verification/mapping uses the same source letter shown by Source Inspector.
- External candidates remain diagnostic only and are not auto-enrolled as affected customers.
0.1.8
- Added a read-only Candidate Verification Engine for strong unknown external purchase/license sources.
- Runs exact affected-product reference checks without displaying customer identity or transaction values.
- Reports anonymized candidate-record counts, match method and confidence.
- Candidate evidence never auto-marks customers as affected; a compatible adapter or safely mapped source is still required.
0.1.7
- Added anonymized Source Inspector for possible non-WooCommerce purchase/license storage.
- Inspects schema metadata only; unknown customer and transaction rows are never read.
- Classifies generic source capabilities such as customer identity, product reference, transaction/license reference, status/date and quantity/amount.
- Adds adapter-readiness guidance without exposing provider names in the plugin UI.
0.1.6
- Added provider-agnostic purchase-source registry and safe external source discovery signals.
- Prepared affected-customer storage for verified non-WooCommerce purchase sources.
- Unknown external schemas are never read automatically and cannot create affected-customer matches without an adapter.
0.1.4
- Improved affected-order scanner diagnostics.
- Normalize WooCommerce order statuses before querying orders.
- Match recalled products by product ID, variation ID, parent product ID and SKU fallback.
- Show scan totals, line-item totals, match method counts and linked product identifiers after each scan.
- Keep matching conservative: product-name-only matching is intentionally not used.
0.1.3
- Block Draft and Reviewing recall URLs for all frontend visitors, including logged-in managers.
- Add linked WooCommerce product names, SKUs and product image to public recall notices.
- Improve the public recall notice with an official safety-alert layout and clearer status presentation.
0.1.1
- Fix public recall URLs returning 404 after activation by flushing rewrite rules safely after post type registration.
0.1.2
- Replaced the generic WordPress post editor with a dedicated product-recall management interface.
- Added searchable WooCommerce product selection.
- Unified recall status handling so Draft/Reviewing notices are not public.
- Added structured admin sections and improved public recall notice formatting.
- Redirected legacy recall edit links into the product-recall management interface.
0.1.0
- Initial free release.
- Manual recall case management.
- WooCommerce product linking.
- Batch order scan and affected customer detection.
- Resolution tracking.
- Public recall notice.
- HPOS compatibility declaration.