- 2026-10-03
- by LethaldiranMX
- Trends
- 0 Comments

LethaldiranMX Insight
The FDesign Withdrawal Button for WooCommerce addresses a critical compliance requirement for e-commerce merchants operating within the European Union under Directive 2023/2673. By automating the mandatory two-step electronic withdrawal process for both registered users and guests, it bridges a significant gap in standard WooCommerce functionality without requiring custom development. The plugin’s inclusion of timestamped acknowledgements on a durable medium and structured audit trails provides merchants with the necessary technical infrastructure to handle consumer contract cancellations systematically.
Best Fit & Operational Role: This plugin is an essential addition to the WordPress stack for any WooCommerce merchant selling physical or digital goods to consumers in the EU. Operationally, it streamlines customer service workflows by allowing partial-quantity withdrawals directly from the front-end, automatically updating orders with administrative notes, and providing a centralized request list with status filters to manage returns efficiently.
Potential Limitations & Pitfalls: While the plugin provides the technical framework for compliance, it is not a turnkey legal solution; merchants must still manually align their terms of service and returns policies. Additionally, because the guest withdrawal flow relies on a time-sensitive, 30-minute email verification link, merchants must ensure a highly reliable transactional email setup (such as dedicated SMTP or API-based delivery) to prevent customer frustration and potential compliance bottlenecks due to delayed or spam-filtered emails.
Helps your WooCommerce shop meet EU Directive 2023/2673: a two step withdrawal form guests use without an account, and a timestamped acknowledgement.
Since 19 June 2026, shops selling online to consumers in the EU have had to offer an electronic withdrawal function under Article 11a of the Consumer Rights Directive, added by Directive (EU) 2023/2673. The function must be clearly labelled, easy to find and available for the whole withdrawal period. The customer gives their name, the contract and an email address, confirms in a separate step, and receives an acknowledgement on a durable medium stating what was declared and when.
This plugin builds that function into WooCommerce. It is a technical tool, not legal advice, and installing it does not by itself make a shop compliant. The wording on your terms and returns pages, and how your team handles returns when they arrive, remain yours. Confirm both against the law as it applies in your country.
What it does
- Adds a clearly labelled withdrawal link to the footer of every page of the shop, on by default.
- Lets guests withdraw without an account. The customer enters the order number and the email used for the order; when both match, a link valid for thirty minutes is sent to that address.
- Puts the same link on each order in My Account, where the customer is already looking, and only on orders that can still be withdrawn from.
- Offers the
[fdwb_button]shortcode to place the link on any other page. - Runs a genuine two step flow: the customer reviews exactly what they are declaring, then confirms as a separate action.
- Supports withdrawing from part of an order, per item and per quantity, and counts refunds already issued.
- Sends a timestamped acknowledgement of receipt on a durable medium, carrying an integrity code, then tells the customer what you decided.
- Gives the shop a request list with status filters, a full audit trail, and accept or reject with a note that goes to the customer.
- Lets you reword every email: the closing paragraph of each customer email is a setting, and all five carry WooCommerce’s standard Additional content box.
- Writes the declared items onto the order as an order note, so the merchant sees the request where the money is.
- Lets you exclude product categories, and virtual or downloadable products, that carry no right of withdrawal.
- Asks for nothing beyond a name, an order number and a contact email. No IBAN, no mandatory reason.
- Ready for translation. Greek and Polish translations are complete and submitted to translate.wordpress.org, from where WordPress installs them automatically once approved.
- Works with Loco Translate, WPML and Polylang, including a separate withdrawal page for each language.
Built to survive a real shop
The parts nobody sees until they go wrong:
- Access links are stored only as hashes, never in readable form, work for one purpose only, and expire after thirty minutes. A leaked database backup contains nothing usable.
- Every form carries a WordPress nonce, so a form submitted from another website is refused before anything is recorded or sent.
- The lookup form is rate limited per email address and per visitor, with a hidden field for bots and a signed timing check, so it cannot be used to search for other people’s orders. A wrong order number and a wrong email produce exactly the same message as a correct pair.
- Refunds you have already issued reduce what is left to withdraw. Withdraw one of three, refund another through WooCommerce, and the customer is offered one, not two.
- The withdrawal page excludes itself from caching, using the signal WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache and WP Fastest Cache all respect. A cached withdrawal page would show one customer another customer’s session.
- A double click cannot file two declarations. The session is claimed before anything is written, so one submission is recorded and the other lands on the same confirmation.
- Nothing is stored that would be wrong later. No monetary amount, because what you owe depends on delivery costs, discounts spread across several items and the condition of the goods.
Setup and support
The plugin’s page on fdesign.com.gr describes every part of the plugin and its settings in detail: FDesign Withdrawal Button for WooCommerce.
FDesign, the author of the plugin, also offers installation, a review of the email wording against your returns process, and monthly care. These services are optional. The plugin is free and complete without them.
For questions and bug reports, use the support forum on WordPress.org.
Privacy and GDPR
The plugin registers a personal data exporter and eraser, so withdrawal declarations appear in the tools under Tools, Export Personal Data and Tools, Erase Personal Data, and it contributes suggested wording to your privacy policy draft.
Erasure is off by default, and says so in the report rather than failing quietly. A withdrawal declaration is the record of a legal act and your evidence that you honoured it, which is a recognised ground for keeping it. WooCommerce treats orders the same way. Switch it on under Withdrawal, Advanced and the name, address and free text are replaced while the declaration itself survives, so you keep the proof without keeping the personal data.
What it deliberately does not do
The plugin records the legal declaration and timestamps it. It does not issue refunds. Refunds stay in your normal WooCommerce flow, through your existing gateway, decided by you after you have inspected the returned goods. The rules on return shipping, inspection and refund deadlines are unchanged by the directive and unchanged by this plugin.
It also stores no monetary amount against a request. What a shop owes depends on delivery costs, discounts spread across several items and the condition of the goods. A figure stored at declaration time would look authoritative and be wrong.
A note on sealed goods
Sealed health, hygiene and cosmetic products lose the right of withdrawal only once the customer has opened them. An unopened item can still be withdrawn. The plugin therefore does not let you exclude such products automatically, because no software can tell whether a package has been opened. That check belongs to your team when the return arrives.
What is stored
The name, email address and order reference a customer submits, the items declared, the time of receipt, and anything the customer chose to write. Visitor IP addresses are used only for rate limiting, kept as a salted hash, and never stored against a declaration.
The plugin contacts no external server. Nothing is sent anywhere, no usage is tracked, and no data leaves your site.
Editorial note: This overview combines WordPress.org official plugin metadata with an AI-assisted LethaldiranMX editorial review. Plugin data should be verified on the official WordPress.org listing before installation.

