=== BFSG Accessibility for WooCommerce ===
Contributors: catcode
Tags: accessibility, bfsg, barrierefreiheit, wcag, woocommerce
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
WC requires at least: 7.0
WC tested up to: 11.1
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Prepare the accessibility information a German online shop has to publish under the BFSG, and check cart, checkout and product pages against WCAG with axe-core and WooCommerce-specific rules.

== Description ==

Since 28 June 2025 the German Barrierefreiheitsstärkungsgesetz (BFSG) applies to e-commerce services provided to consumers (§ 1 (3) no. 5 BFSG). A service provider has to provide information on how the service meets the accessibility requirements — in its terms and conditions or in another clearly perceivable way, and in an accessible form (§ 14 (1) no. 2 BFSG with Annex 3).

This plugin helps with two jobs:

1. **Write and publish that information** — a guided form that follows Annex 3 no. 1 a) to d): general description of the service, how the service is carried out (prefilled from your WooCommerce settings: guest checkout, active payment methods), how the requirements are met (benchmark, result of your evaluation, method and date, accessibility features, known limitations, alternatives), contact for accessibility questions and the market surveillance authority (prefilled with the joint authority of the German federal states, MLBF, as published on its website). The page is created for you with a shortcode, in German or English.
2. **Check the shop** — the cart, the checkout, a product page and the information page are opened in your browser from the admin and checked with [axe-core](https://github.com/dequelabs/axe-core) against WCAG 2.1 or 2.2 Level A and AA, plus rules written for WooCommerce: autocomplete tokens of the address fields (WCAG 1.3.5), required fields exposed to assistive technology, shop messages outside a live region, controls without a visible focus change, missing "same address" option (WCAG 2.2 3.3.7), CAPTCHAs (3.3.8) and payment-provider frames the automated check cannot enter. Every finding is mapped to its WCAG success criterion and EN 301 549 clause. A WooCommerce checklist covers what automation cannot judge: keyboard-only purchase, error handling, dialogs, payment widgets, zoom and reflow.

A failing checklist item can carry a public explanation that goes straight into the "known limitations" of your accessibility information, so the published page stays in step with what you actually tested.

= What this plugin does not do =

* It does not make a shop accessible. It adds no overlay, no toolbar and no script to your storefront. The fixes belong in your theme and plugins; the check shows where.
* It does not decide whether the BFSG applies to you (for example the micro-enterprise exemption in § 3 (3) BFSG) and it is not legal advice.
* Automated rules find only part of the possible barriers. The result of your evaluation is your own statement.

= Free =

* Accessibility information in one language (German or English), page creation, optional footer link
* Automated check of checkout, cart, product page and the information page, desktop and 320 px (WCAG 1.4.10 Reflow)
* WCAG 2.1 or 2.2 depending on the benchmark you name (EN 301 549 V3.2.1 = WCAG 2.1 AA, EN 301 549 V4.1.1 = WCAG 2.2 AA)
* WooCommerce checklist with 23 items (20 when the benchmark is WCAG 2.1), linked to WCAG criteria and EN 301 549 clauses
* Warnings when the status "meets the requirements" contradicts your checklist or the check results
* Change log of theme and plugin updates since the last review and a review reminder in the admin

= Pro =

* The information in German and English at the same time — visitors see their language
* One-click check of the page sample from BFSG Annex 1: home, login, search, contact, legal pages, category, product, cart, checkout, the information page and the barrier report form
* Check history with new and fixed issues
* Printable audit report and CSV export for an authority request (§ 14 (5) BFSG)
* Accessible barrier report form with inbox, statuses and e-mail notification
* E-mail reminders and change digests to several recipients
* Export and import of settings, information and checklist for agencies

Pro is licensed per shop for 1 to 5 years; a 7-day trial starts only when you click the button on the Licence tab.

= Sources =

* BFSG: https://www.gesetze-im-internet.de/bfsg/ (§§ 1, 2, 3, 14, 16, 17, 32, Annexes 1 and 3)
* BFSGV: https://www.gesetze-im-internet.de/bfsgv/ (§§ 12, 19)
* EN 301 549 V3.2.1 and V4.1.1: https://www.etsi.org/deliver/etsi_en/301500_301599/301549/
* WCAG 2.2: https://www.w3.org/TR/WCAG22/
* Market surveillance authority (MLBF): https://www.mlbf-barrierefrei.de/

== Privacy ==

* The automated check runs in the administrator's browser. The page and the result never leave your site.
* For cart and checkout the check puts one product in the administrator's own cart when it is empty and removes it afterwards.
* The barrier report form (Pro) stores name, e-mail, page and message in your database and sends a notification e-mail from your site.
* The only external request is the licence check against catcode.com.ua when a licence key or the trial is used.

== Third-party code ==

axe-core 4.13.0 by Deque Systems, Inc. is bundled unmodified in `vendor/axe-core/` under the Mozilla Public License 2.0. The file carries no "Incompatible With Secondary Licenses" notice, so section 3.3 of the MPL 2.0 allows it to be distributed as part of this GPL-licensed plugin. The source code of this version is available at https://github.com/dequelabs/axe-core (tag v4.13.0).

== Frequently Asked Questions ==

= Where do I put the shortcode? =

`[bfsg_accessibility_statement]` on any page; the plugin can create the page for you. Optional attributes: `lang="de"` or `lang="en"`, `heading="2"`. The barrier report form (Pro) is `[bfsg_feedback_form]`.

= The check says the page did not answer in time =

A security plugin or the server may forbid showing your shop in a frame (X-Frame-Options, Content-Security-Policy frame-ancestors). Use "Run in a new tab" — the result is the same.

= Which standard should I name? =

The one you actually evaluated against. EN 301 549 V3.2.1 corresponds to WCAG 2.1 AA; V4.1.1 (published September 2026) to WCAG 2.2 AA. The choice also switches the WCAG version of the check and the checklist.

= What happens to my data when I delete the plugin? =

Nothing, unless `define( 'CCBF_DELETE_DATA', true );` is set in wp-config.php — then the tables and options are removed. The statement page is never deleted.

== Changelog ==

= 1.0.0 =
* First release.
