Questions, answered.
The questions stores, IT teams and procurement ask us, answered plainly. If yours isn't here, ask us.
Licensing and setup
Who can use it?
Any business with a WooCommerce store and a license. A gift shop, a café, a bookstore, a box office or a museum front desk all work the same way. Nothing in the register is tied to one kind of business, and it shows your store's own name.
How much does it cost, and how is it licensed?
It's a paid plugin, licensed per location. Contact us for pricing. A license covers one location, and while it's active you get every update and every new feature as it's released, for the current release of WordPress and WooCommerce.
We don't add a transaction fee. You pay Stripe's card processing fees directly to Stripe, and you'll need your own WordPress hosting and card readers.
Sources
Is setup self-service?
Yes. You install the plugin, connect your Stripe account and set up your location and registers from wp-admin. If you get stuck, send us a message through the contact form.
Which versions of WordPress and WooCommerce does it support?
The latest releases, and we keep pace with new ones as part of your license. The minimums are WordPress 6.5, WooCommerce 9.0 and PHP 8.1. It supports WooCommerce's high-performance order storage (HPOS).
Accessibility
Is it accessible?
Yes, and that's why it exists. It's designed from the start for blind and low-vision staff, so a cashier can run the whole register, from the first scan to closing the drawer, without a sighted colleague.
The standard is WCAG 2.2 AA at minimum, with AAA contrast wherever it's practical. It works fully from the keyboard, announces every change in plain words, reflows at 200% text, and has light, dark and high contrast themes.
Which screen readers is it designed for?
It's designed for the screen readers cashiers actually use: JAWS and NVDA on Windows, and VoiceOver on iPad and Mac. It's built on standard, well-labeled controls rather than tricks for one screen reader, so every flow, from the first scan to the receipt, follows the same rules. That includes split payments, returns and exchanges, and the supervisor's PIN pad.
Do my staff need to use a screen reader to benefit?
No. The things that make it work without the screen also make it faster with one: big totals you can read across the counter, a single key (F2) to get back to scanning, and plain answers to "how much" and "is it paid". Staff can choose light, dark or high contrast, and set their own text size.
What standard does it meet?
WCAG 2.2 AA at minimum, with AAA contrast wherever it's practical. Every screen and dialog is scanned automatically, including in high contrast at 200% text, and it supports Windows forced colors and reduced motion.
Security and privacy
How is it secured?
The server decides, not the screen. Your WordPress site prices every sale, checks every approval and confirms every card payment with Stripe before taking it, so nothing a browser sends can set a price, choose a register or approve a refund.
Approvals are single-use and tied to exactly what the supervisor was shown. Each device is bound to its register by a secure cookie. Orders, payments, refunds and approvals are rate limited. The register page loads none of your theme's or other plugins' scripts, under a strict content security policy.
Does it touch cardholder data, or change our PCI compliance?
Card numbers never pass through it. The card is read by the Stripe reader, which sends it straight to Stripe, a PCI Service Provider Level 1, which Stripe describes as the most stringent level of certification in the payments industry. Your website only asks Stripe to take the payment and gets the result back, and Stripe's messages to your site never include sensitive card data.
The register itself holds no card data. For the receipt, the WooCommerce order keeps what Stripe returns: the card brand, the last four digits and the chip details printed on card receipts. Stripe's guidance is that the card brand and last four digits aren't subject to PCI compliance, and that anything its API returns can be stored. The full card number and security codes never reach the register, your website or WooCommerce.
PCI compliance is a shared responsibility: every business that takes cards confirms its own compliance each year, and Stripe's Dashboard shows which form applies to you. Ask your payment or compliance advisor how that applies to your organization.
How do staff sign in, and who can do what?
Staff sign in with their own WordPress account through your normal WordPress login. The plugin adds two roles, POS Cashier and POS Supervisor, and shop managers and administrators can do everything. Cashiers can't open wp-admin.
Price changes, discounts, refunds, tax-exempt sales, cash paid out and no sale need a supervisor, who approves them with a six-digit PIN on the cashier's register. You can change any role, and upgrades never undo your changes.
Two-factor authentication isn't handled by the register. Staff sign in through your normal WordPress login, so two-factor is the job of the WordPress security plugin you prefer. Register accounts can't sign in with application passwords or other tokens.
How is data encrypted?
In transit, everything goes over HTTPS: the register and receipt printers refuse plain HTTP. Once your whole site is on HTTPS, we recommend turning on HSTS at your web server or CDN.
At rest, the register's data lives in your WordPress database next to your WooCommerce data, so it has the same protection as the rest of your site, including any disk or database encryption your host provides. Supervisor PINs, store credit codes and printer passwords are stored only as one-way hashes, and full card numbers are never stored.
Where is it hosted?
On your own WordPress site. It's a plugin, so it runs on the server and hosting you already have. Prolific Digital doesn't host it, and the register doesn't depend on any service of ours to work.
It adds the register page and its own routes to your site's REST API. They need a signed-in register user, except the Stripe webhook, which must be signed by Stripe, and the receipt printer routes, which need each printer's own password.
Is there an audit log of who did what?
Yes. It records who did what, on which register and when: price changes, discounts, voided sales, refunds, approvals and refusals, PIN changes and lockouts, cash movements, failed card attempts and settings changes. Entries can't be edited.
Managers read it in wp-admin, under Point of Sale, Audit log. Entries are kept for a year by default.
How is it security tested?
With automated tests that run on every change. Playwright browser tests drive the real register through sales, payments, returns, approvals and cash, and server-side test scripts check the same rules directly, including attempts to tamper with prices, approvals and requests. The code is also checked against the WordPress coding standards, which include security rules.
How are API keys and credentials stored?
The Stripe secret key comes from a constant in wp-config, an environment variable or the WooCommerce Stripe Gateway's settings, in that order. The webhook secret comes only from wp-config or an environment variable. The plugin never stores them itself and never sends them to the browser.
Extensions that connect to other systems run on the same server-side API, so their credentials can stay on the server too.
Hardware, payments and connection
What hardware do I need?
An iPad, Android tablet or computer with a current browser. For cards, a Stripe Terminal smart reader such as the Stripe Reader S700 or S710. The hardware page lists every reader that works. Optionally, a USB or Bluetooth barcode scanner, and a Star CloudPRNT or Epson receipt printer, which also opens the cash drawer.
Do I need Stripe?
For card payments, yes. Today the register works only with Stripe Terminal, and support for more payment providers will come later. You can also take cash, record a payment taken on a separate terminal, and split one sale across card, cash and store credit.
Does it work offline, or on a poor connection?
It needs a connection to your website for every sale, because the server checks every price and payment. There's no offline mode yet, and Stripe's server-driven readers, the kind the register uses, can't take cards offline either.
If the connection drops, the register says so on screen and out loud, and nothing is lost: a sale in progress is kept, and a request that didn't get through is retried without ever making the sale twice. If your site can't reach Stripe, or a card reader goes offline, staff can take cash, pick another reader, or record a payment from a separate card terminal with a supervisor's approval.
Switching from FooSales
We use FooSales today. Can we switch?
Yes. Your products, stock, orders and customers are already WooCommerce data, so there's nothing to migrate for the register itself. You keep your Stripe Terminal readers.
Why look beyond FooSales?
FooSales does a lot well. Both registers run on WooCommerce and take cards on Stripe Terminal readers, so switching doesn't change your store or your card hardware. What sets this one apart is that it's designed from the start for blind and low-vision staff to run on their own, from the first scan to closing the drawer, and it's built to be extended with WordPress hooks.
If neither matters to you, FooSales may suit you well.
Can we switch back if it doesn't work out?
Yes, and there's little to undo. Your products, stock, customers and orders, including every register sale, are ordinary WooCommerce data, so they stay where they are whichever point of sale you use.
Deactivating or deleting the plugin keeps its own data unless you turn on Delete all Point of Sale data, and it never deletes orders, products or customers. Your card readers stay in your Stripe account.
What's the backup plan if the register is down?
The same as for any online register: keep a way to take payment without it. Cash and the drawer key work for any sale, and if you have one, a separate card terminal. Note those sales and enter them when the register is back.
If the plugin itself had to come out, your store and its data are untouched, as above.
Running the counter
Can new staff practice without affecting real sales?
Yes. Turn on training mode for a register or a person. Practice sales are kept out of reports, cash drawers and stock, can't take real money, and are cleared after seven days.
Who can change prices or give refunds?
You decide. Cashiers can sell and nothing more. Price changes, discounts, returns and tax exemptions need a supervisor, who can approve them with a PIN on the cashier's register, without logging the cashier out.
Can developers extend it?
Yes. Other plugins can add screens and register features through a public PHP and JavaScript API, and the register's security rules apply to them too.
Ring up a sale yourself.
Talk to us about your store, or try the live demo first: the real register, running in your browser with nothing to install. Bring your screen reader.