
Verifactu for WooCommerce — AEAT invoicing records and the tax QR
VERI*FACTU records with a SHA-256 chain, submission to the AEAT and the tax QR in e-mails. Pro — full invoices with a NIF, corrective invoices, voiding, PDF, export.
- Compatibility
- WooCommerce 7.0+ · WordPress 6.2+ · PHP 7.4+
- Licence
- one site, annual
- Trial
- 7 days, no card, one per site
- Updated
- September 2026
What Free has,
and what Pro adds
The free version works with no time limit. Pro adds the rest of the features in the table.
What it looks like

The trial starts when you ask
A fresh install is the free version, nothing switches on by itself. The “Try Pro for 7 days” button → e-mail → the key right in the window and by e-mail.

One key — one site
Moving the store? Unbind the licence on the old domain and activate it on the new one yourself. If our server is unreachable, Pro keeps working for 14 more days. For studios — keys for 5 or 25 sites, or unlimited.
Technical requirements
WooCommerce 7.0+ with the classic or block checkout, HPOS compatible
WordPress 6.2+ · PHP 7.4+ with the openssl and curl extensions
An electronic certificate of the issuer, of an authorised representative, or an electronic seal (sello) certificate in .p12 / .pfx format. The same certificate works with the AEAT test portal.
A shop taxed in Spain: VAT rates configured in WooCommerce, currency in euro.
Software producer. RD 1007/2023 requires every record to identify the producer of the software, and the producer to hold a “declaración responsable”. In this build the production environment unlocks once the producer identification is set through constants in wp-config.php; until then the plugin stays on the AEAT test portal and says so in the settings. Write to us and we will help you set this up for your case.
Version history
RegistroAlta records for every paid order, simplified F2 invoices with their own series, the SHA-256 chain per the AEAT specification, SOAP submission with an electronic certificate, a…
Frequently bought with Verifactu for WooCommerce
4 modules in one order — 40% cheaper than separately


Nova Poshta Premium — a Nova Poshta module for OpenCart 2.3, 3.x and 4.x

LiqPay — Card Payments for OpenCart 2.3, 3.x and 4.x

Telegram notifications and Viber/SMS for customers for OpenCart
Full module description
Verifactu for WooCommerce turns a WooCommerce shop into a VERI*FACTU invoicing system under the Spanish anti-fraud rules. For every paid order the plugin creates an invoicing record (registro de alta), chains it to the previous one with a SHA-256 hash, submits it to the web service of the Spanish Tax Agency (AEAT) with your electronic certificate, and puts the tax QR code with the “VERI*FACTU” legend into the customer e-mail, the thank-you page and the account area.
Spain’s anti-fraud invoicing rules (Real Decreto 1007/2023, Orden HAC/1177/2024) require invoicing software to create a tamper-evident record for every invoice. In VERI*FACTU mode each record goes to the AEAT right away, and the customer can check the invoice from the QR code on the AEAT site. The obligation applies from 1 January 2027 to companies and from 1 July 2027 to everyone else (Real Decreto-ley 15/2025).
What the shop owner gets
- Order metabox — invoice number, AEAT status and the actions: send, correct, void (Pro).
- Order notes — the plugin writes into the order history which invoice was issued and what the AEAT answered, including the error code.
- “Check connection” — a separate button that proves the AEAT accepts your certificate while registering nothing.
- Test and production kept apart — separate record chains and separate invoice counters, so test invoices never disturb live numbering.
How it works, step by step
- An order reaches the status you chose (Completed or Processing).
- The plugin issues the invoice: it takes the next number from its own series (e.g.
T2027-000001) and builds aRegistroAltarecord — simplified (F2) or, with Pro, full (F1) with the customer’s NIF. - The tax breakdown comes from what WooCommerce actually charged: Spanish VAT (S1), exports with no tax (exempt, regime 02), EU distance sales through OSS (N2, regime 17), zero-rated domestic lines. For the Canary Islands the tax type is switched to IGIC in the settings.
- The record is chained with a SHA-256 hash to the shop’s previous record, exactly as the AEAT specifies. The chain is guarded by a lock, so two simultaneous orders cannot break the order of records.
- The record goes to the AEAT over SOAP with your electronic certificate. The plugin respects the waiting time between submissions that the AEAT itself returns.
- The answer is split per record: accepted, accepted with errors, rejected — with the AEAT error code in the log and in the order notes.
- If the AEAT is unreachable, the record stays queued and is retried with increasing delays (2, 4, 8 minutes… up to 256 minutes). The invoice and its QR code are valid from the moment the record is created.
- A rejected record is corrected in one click: the plugin creates a new chained record with the
SubsanacionandRechazoPrevioflags set the way the AEAT expects. Records are never edited after the fact — a correction is always a new record.
Under the hood
- The hash follows the AEAT specification (huella document, v0.1.2) exactly: field order, amount formatting, uppercase SHA-256. All three examples from the AEAT document are reproduced byte for byte.
- The chain is locked: the number and the previous hash are taken under a database-level lock, so parallel orders cannot leave gaps or duplicates in the chain.
- Records are immutable: no record is edited after it is created. A correction, a corrective invoice and a voiding are always new records in the chain.
- The QR follows the AEAT document (v0.5.0): an own ISO 18004 encoder with no external service, the ValidarQR URL for the chosen environment, and the image in e-mails served through a signed URL — someone else’s invoice cannot be opened from the link.
- The certificate: the private key is re-encrypted with a key derived from your site salts and kept in a randomly named folder. The safer option is constants in
wp-config.phpwith files outside the web root; the plugin supports both. - A queue that does not lose records: up to 1,000 records per submission, retries with increasing delays, and a separate admin banner if delivery keeps failing.
- An AEAT mock for staging: the
CCVF_AEAT_MOCKconstant returns answers that follow the AEAT schema and nothing leaves the site. It is ignored in production. - Uninstalling does not erase tax data: records stay unless you deliberately define
CCVF_DELETE_DATA.
Installation
- Plugins → Add New → Upload Plugin: choose
catcode-verifactu-for-woocommerce-1.0.0.zipand activate it. - WooCommerce → Verifactu → Settings: the issuer NIF and name exactly as registered at the AEAT, the order status that issues the invoice, and the invoice series.
- Upload the .p12/.pfx certificate with its password, or define
CCVF_CERT_FILE,CCVF_KEY_FILEandCCVF_CERT_PASSWORDinwp-config.php. - Staying on “Test portal”, press “Check connection”, switch “Generate Verifactu records” on and place a test order.
- When the test records are accepted, move to production.
- For Pro: paste the licence key from the e-mail you got after payment into the Licence tab, or start the 7-day trial.
Questions
about the module
Didn't find the answer? Message us on Telegram and we'll reply within a business day.
Which certificate do I need?
An electronic certificate of the issuer (company or self-employed person), of an authorised representative, or an electronic seal (sello) certificate. The same certificate works for the AEAT test portal.
Can I test without a certificate?
Yes, on a staging site: define CCVF_AEAT_MOCK in wp-config.php. Nothing leaves the site and the answers follow the AEAT response schema. It is ignored in production.
What happens if the AEAT is down?
Records stay in the queue and are retried automatically with increasing delays. The invoice and its QR code are valid from the moment the record is created, not from the moment the tax agency answers.
The AEAT rejected a record — what now?
Open WooCommerce → Verifactu, read the AEAT error, fix the order data or the settings and press “Correct & resend”. A new record with the same invoice number is chained and sent.
Does it replace my accountant's software?
No. It creates and submits the invoicing records of your web shop. The tax defaults fit a typical shop in mainland Spain; confirm the settings with your tax adviser.
Is the certificate safe on the server?
The private key is re-encrypted and stored in a randomly named folder under uploads. On nginx add a rule that denies wp-content/uploads/ccvf-*, or keep the files outside the web root with the wp-config.php constants.
What if I do not want to pay for Pro?
Simplified F2 invoices, the chain, submission to the AEAT, correction of rejected records and the QR code stay free with no time limit.
No reviews yet. Be the first.
No questions yet. Ask one — we answer within 24 hours.
Not quite what you are looking for?
We build custom modules for WordPress, WooCommerce, OpenCart and Shopify. Tell us about the task and we'll prepare an estimate.
Order a custom module
Buying the module
—