=== Ebook Store ===
Contributors: motov.net
Tags: ebook, sell ebooks, digital downloads, ebook watermarking, woocommerce
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 6.25
License: GPLv2 or later
License URI: http://www.gnu.org/licenses/gpl-2.0.html

Sell ebooks and digital downloads on WordPress. Upload, drop a shortcode, get paid with PayPal. Pro watermarks every PDF and ePub to its buyer.

== Description ==

You wrote it. You should get paid for it.

You spent months on your ebook. Then one buyer emails the file to ten friends, someone drops it in a group chat, and it spreads for free while you never see another sale. Ebook Store fixes both halves of that problem on your own WordPress site: it gets you paid, and — with Pro — it stamps every copy you sell, PDF or ePub, with the buyer it was sold to, so a leaked file points straight back to the person who shared it.

No separate storefront. No marketplace skimming a cut of every sale. You keep the payment, the customer, and the file.

= Sell your first ebook this afternoon =

Upload a book, set a price, drop a shortcode on any page — that page is now a working order form, with the cover, description, price and a buy button. Add an optional 3D book preview and a free sample chapter if you like. When someone buys, they get a checkout, a thank-you page with their download links, and an optional delivery email with the file attached or linked. Would you rather they didn't download at all? Let them read it in the browser instead.

PayPal is built in — PayPal balance, card, eCheck and bank transfer — so you can take money the moment you're set up. A store-readiness panel walks you through exactly what's left before your first sale and links straight to the screen that fixes each item. Several order-form designs let the form match your site.

That's the free version, and it is a complete store: sell ebooks and other digital downloads, take payment, and deliver — for real, not a crippled demo.

= The free version sells and delivers. Pro protects and scales. =

When casual sharing starts eating your sales, or you outgrow PayPal-only checkout, Ebook Store Pro adds the protection and reach a growing store needs. Everything below is what you gain — Pro adds capabilities, it never switches off anything the free version already does.

= New in 6.20 — watermark every ePub to its buyer (social DRM) =

An ePub is a website in a box: unlike a PDF, it cannot be password-locked without breaking the e-readers your customers use. So Ebook Store doesn't lock it — it stamps it. Every ePub you sell is watermarked with the buyer's identity right in the pages, recorded again in the file's hidden metadata, and can carry a scannable QR verification code. You decide where the watermark and QR go: the opening page, the start of every chapter, or a dedicated licence page at the end; top or bottom; a subtle line or a boxed notice.

This is ePub DRM the customer-friendly way — social DRM, not a lock. The delivered file stays a fully valid ePub that opens in Apple Books, Kindle, Kobo, calibre and the rest, with no apps and no logins. It works in any language, and books that already carry DRM or font obfuscation pass through untouched. And a paid download is never blocked, even if watermarking can't run. The reader you sold to is never punished; the copy is simply traceable.

= Lock down your PDFs: PDF DRM that prints in any language =

For PDFs, Pro adds full PDF DRM. Encrypt the file, set an open password (a fixed one, a fresh random one per order, the buyer's own email, or leave it open but restricted), and disable printing, copying, editing and annotations. Every page can be stamped with a per-buyer watermark carrying their name, email and order, alongside a QR verification code. The watermarking engine, rebuilt on TCPDF, renders buyer watermarks and QR codes in any language — Cyrillic, Hebrew and Arabic included, with correct right-to-left ordering — and no longer needs the PHP GD extension, so it runs on far more hosts. The QR is drawn on your own server, with no third-party QR service involved.

= Trace any leaked copy back to its buyer =

Every copy you deliver, PDF or ePub, is uniquely tied to the order it came from. A public verification page turns that into action: scan a copy's QR code and it shows the order the copy was licensed to, so a file that turns up on a sharing site points straight back to who shared it. This is ebook watermarking as deterrence, not lockdown — social DRM discourages casual sharing without the customer-hostile restrictions of hard DRM. It won't stop a determined pirate, and we don't pretend it does; it strongly deters the casual forwarding that costs indie sellers the most. Want to see precisely what a buyer receives before you sell it? A Test button on each book previews the real protected PDF or watermarked ePub — and asks which one when a book has both.

= More formats, more gateways, more reach (Pro) =

* Sell more file types: ePub, Mobi, TXT and ZIP, plus MP3 and MP4 so you can bundle audio and video with a book.
* Add card checkout with Stripe (cards, Apple Pay, Google Pay, Link, Klarna, SEPA and more) and Adyen.
* Already run a shop? WooCommerce integration links an ebook to a product and works with the cart, variable products and High-Performance Order Storage.
* Grow faster with a bulk book importer, automatic customer accounts for re-downloads, Kindle delivery, and per-ebook email and thank-you overrides.
* Connect the tools you already use: Mailchimp, Brevo, WP Affiliate Manager, Google Analytics 4, Elementor and WPBakery / Visual Composer.

= Free vs Pro at a glance =

Free: sell and deliver PDF ebooks, PayPal checkout, a thank-you page with download links, optional email delivery and in-browser reading, a 3D preview, free samples, and the store-readiness setup panel.

Pro adds: PDF DRM and PDF watermarking, ePub watermarking (ePub DRM / social DRM), leaked-copy traceability with a QR verification page, the ePub / Mobi / TXT / ZIP / MP3 / MP4 formats, the Stripe and Adyen gateways, WooCommerce integration, a bulk importer, automatic customer accounts, Kindle delivery and the marketing integrations. Nothing in the free version is time-limited or switched off.

= Who it's for =

Authors, publishers, course creators and coaches who want to sell ebooks and digital file downloads directly — ebooks, PDFs, ePub, audio, video and ZIP bundles — from a site they own, and keep casual sharing from quietly draining their revenue.

Ebook Store ships in English, German, Spanish, French, Portuguese, Hindi and Arabic (with right-to-left support), so both your store and your buyer watermarks read correctly for a global audience.

= Ready to protect what you sell? =

Get Ebook Store Pro: https://www.shopfiles.com/index.php/products/wordpress-ebook-store

Questions before you buy? Email support@shopfiles.com. Security issues can be reported through the Patchstack Vulnerability Disclosure Program.

== Installation ==

1. In your WordPress admin go to **Plugins > Add New**, search for "Ebook Store", click **Install Now** and then **Activate**. To install from a zip file instead, use **Plugins > Add New > Upload Plugin**.
2. Go to **Settings > Ebook Store**. The readiness panel at the top tells you exactly what is stopping you from taking orders — a missing payment method, a missing thank-you page, no books yet — and links to the screen that fixes each one.
3. Enter your PayPal email address on the **PayPal** tab, or your keys on the **Stripe** or **Adyen** tab, and save.
4. Click **Create it now** on the "Thank-you page is missing" item. The plugin creates and publishes the page buyers are sent to after paying.
5. Go to **Ebook Store > Add New**, fill in the title, description, price and cover image, upload your ebook file, and publish.
6. Copy the shortcode shown for that book in **Ebook Store > Ebooks** and paste it into the post or page where you want the order form to appear.

That is the whole setup. Everything after this — email delivery, watermarking, VAT, download limits — is optional and lives in the settings tabs.

**Selling through WooCommerce (Pro):**

1. Add your book under **Ebook Store > Add New** as above.
2. Open the WooCommerce product that should deliver it and switch to the **Ebook Store** tab in the product data box.
3. Pick the ebook and save. Buyers now see a Downloads section on their order confirmation page, and the delivery email works the same way.

== Shortcodes ==

= [ebook_store] =

The full order form for one book: cover, description, price, preview and buy button. This is the shortcode shown next to each book in **Ebook Store > Ebooks**.

* `ebook_id` — the ID of the ebook to display. Required. Example: `[ebook_store ebook_id="123"]`
* `template` — which order-form design to use for this one form, overriding the site-wide choice in Settings. Accepts `2026`, `modern`, `hello-elementor-2026`, `legacy`, or the key of a template you saved yourself in Settings > Pages & emails. An unknown value falls back to `2026`. Example: `[ebook_store ebook_id="123" template="modern"]`

= [ebook_store_buy] =

The same thing with the buy button only — no cover, description or details panel. Useful when your page already describes the book and you just want a button.

* `ebook_id` — the ID of the ebook to sell. Required.
* `template` — same values as above.

Example: `[ebook_store_buy ebook_id="123"]`

= [ebook_thank_you] =

Placed on the thank-you page, this renders the buyer's download links, passwords and order details after a payment. The **Create it now** button in Settings puts this on the page for you; you only need it by hand if you build the thank-you page yourself.

* `ebook_id` — optional, and normally left out. The order is identified from the link the buyer arrives on, not from this attribute.
* `template` — same values as above.

Example: `[ebook_thank_you]`

= [ebook_store_row] =

A wrapper that lays several order forms out side by side in one row. It is an enclosing shortcode: put the individual book shortcodes between the opening and closing tags.

* `col` — how many columns the row should use. A whole number.

Example:

`[ebook_store_row col="3"][ebook_store ebook_id="12"][ebook_store ebook_id="13"][ebook_store ebook_id="14"][/ebook_store_row]`

= [ebook_store_downloads] =

Lists the orders belonging to the currently logged-in customer, each linking to its download page. Put it on a "My downloads" or account page. It takes no attributes and shows nothing to logged-out visitors.

Example: `[ebook_store_downloads]`

== Frequently Asked Questions ==

= How do I sell an ebook on my WordPress site? =

Upload your book under Ebook Store > Add New, set a price and a cover, and save. The plugin hands you a shortcode; paste it into any post or page and that page becomes an order form with a checkout. Buyers land on a thank-you page with their download links and get an optional delivery email. The free version does all of this with PayPal built in — no code and no separate storefront.

= What do I get for free, and what needs Pro? =

The free version is a complete store: sell ebooks and digital downloads in PDF, take payment with PayPal, and deliver by download, email or in-browser reading — with a store-readiness panel that walks you through setup. Ebook Store Pro adds ebook watermarking and PDF DRM, ePub DRM (social DRM), leaked-copy traceability with a QR verification page, more formats (ePub, Mobi, TXT, ZIP, MP3, MP4), the Stripe and Adyen gateways, WooCommerce integration, a bulk importer, automatic customer accounts, Kindle delivery and more. Pro only adds capabilities — it never disables anything the free version does.

= Which payment methods can I use? =

PayPal is built into the free version (PayPal balance, card, eCheck and bank transfer), so you can start taking money right away. Ebook Store Pro adds Stripe (cards, Apple Pay, Google Pay, Link, Klarna, SEPA and more) and Adyen, and can hand checkout to WooCommerce so the gateways you run there work too.

= How do I watermark an ePub without breaking Kindle, Apple Books or Kobo? =

An ePub can't be password-locked without stopping e-readers from opening it, so Ebook Store Pro uses social DRM instead. It stamps each buyer's identity into the book's pages and its hidden metadata, with an optional QR verification code, and you choose where it goes — the opening page, the start of every chapter, or a licence page at the end. The delivered file stays a fully valid ePub that opens in Apple Books, Kindle, Kobo and calibre, with no apps and no logins, and it works in any language.

= How do I add DRM or a password to a PDF? =

With Ebook Store Pro you can encrypt each purchased PDF, set an open password (fixed, random per order, the buyer's own email, or open-but-restricted), and disable printing, copying, editing and annotations. That's full PDF DRM, plus a per-buyer watermark and QR code stamped on every page. It's all on the PDF protection tab in settings, and a Test button lets you preview the exact protected file first.

= If someone shares a file I sold, can I trace it back to the buyer? =

Yes, when you sell with Pro. Every PDF and ePub you deliver is uniquely tied to its order and carries the buyer's name, email and order number. Scan the copy's QR code and the public verification page shows the order it was licensed to, so a leaked file points straight back to who shared it. Social DRM deters casual sharing and traces leaks — it's honest deterrence, not an unbreakable lock, and it won't stop a determined pirate.

= Will protecting a file break it or annoy my customers? =

No. A watermarked ePub stays a valid file that opens everywhere, and a protected PDF still opens for the buyer. Protection never restricts the reader beyond the print and copy limits you choose; files that already carry DRM or font obfuscation are passed through untouched; and a paid download is never blocked — if watermarking can't run for any reason, the buyer still gets their file. You can preview the exact protected file a buyer receives with the Test button before you ever sell it.

= Do I need the PHP GD extension to watermark PDFs? =

No — not anymore. Older versions relied on PHP's GD extension, but the watermarking engine was rebuilt on TCPDF, which removed that requirement. Buyer watermarks and QR codes now print in any language, including Cyrillic, Hebrew and Arabic with correct right-to-left ordering, on far more hosts, with no GD needed. (If you read otherwise in older documentation, that note is out of date.)

= Can I sell ebooks with WooCommerce? =

Yes, with Ebook Store Pro. Link an ebook to a WooCommerce product and it works with the cart, variable products and High-Performance Order Storage (HPOS). Buyers see their downloads on the order confirmation page, and the same watermarking and delivery apply.

= Can buyers read in the browser instead of downloading? =

Yes, and it's in the free version. You can deliver a book as an in-browser read instead of, or as well as, a download — handy when you'd rather the file didn't leave your site at all.

= Can I sell a book for free, or take donations? =

Yes. Set the price to zero and the order form becomes a download form. You can still require buyers to leave their email address, and in Pro the file can still be watermarked.

= I upgraded from an older version and Square is gone. What happened? =

Square checkout was removed in 6.00: its SDK required PHP 8.1, which locked the whole plugin out of every site still on PHP 7.4. Set up PayPal, Stripe or Adyen instead, or sell through WooCommerce and use a Square gateway there. Your existing orders and downloads are untouched.

= What are the requirements? =

Ebook Store needs WordPress 5.8 or newer and PHP 7.4 or newer.

= How can I report security bugs? =

You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team helps validate, triage and handle any security vulnerabilities. [Report a security vulnerability.](https://patchstack.com/database/vdp/1205b489-cf87-4d64-ab01-827d86b87a7a)

== Screenshots ==

1. One shortcode turns any page into a full order form — cover, description, price and a buy button, ready for buyers.
2. The details view with the optional 3D book preview.
3. The ebook list, with a ready-to-paste shortcode for every book.
4. The store-readiness panel at the top of settings tells you exactly what's stopping you from selling — and links straight to the fix.
5. The Add New Ebook screen: title, price, cover and file uploads for every format.
6. Payment settings — PayPal in the free version, with Stripe, Adyen and the WooCommerce integration in Pro.
7. PDF protection: passwords, print and copy restrictions, and watermark position, colour and placement.
8. A protected PDF stamped with the buyer's name, email and order, plus a QR verification code — in any language, including right-to-left.
9. ePub protection: choose where each buyer's watermark and QR go — the opening page, every chapter, or a licence page at the end; a subtle line or a boxed notice.
10. The exact watermarked ePub a buyer receives — stamped with their name, email and order, and still a valid file for Apple Books, Kindle, Kobo and calibre.
11. The public verification page: scan a copy's QR code and it shows the order the copy was licensed to, so a leak points straight back to who shared it.
12. Delivery settings: email delivery, attachments, link expiry, download limits and VAT.
13. The thank-you page and delivery email template editors.
14. WooCommerce product integration — choose which ebook a product delivers, and the downloads a buyer sees on the order confirmation page.

== Changelog ==

= 6.25 =
* PayPal: new REST API checkout. PayPal has deprecated Website Payments Standard (the "Buy Now" form) and Instant Payment Notification - no new IPN integrations since the end of 2025, deprecated as of January 2026, switched off in January 2027. The plugin now talks to PayPal's current Orders API instead: paste the Client ID and Secret of a REST app from the PayPal developer dashboard on the PayPal tab and the store authenticates with OAuth 2.0, creates each order server-side when the buyer clicks, sends them to PayPal's hosted checkout, and captures the payment when they return. Nothing about your account (not even its email address) is posted through the buyer's browser any more.
* PayPal: signed webhooks replace IPN. Paste the Webhook ID from the developer dashboard and every notification is verified with PayPal before it is acted on; a buyer who closes the tab after paying still receives their book, and refunds or reversals made in your PayPal account are reflected on the order.
* PayPal: orders paid through the REST checkout can be refunded from the order screen, like Stripe and Adyen orders.
* PayPal: the "Buy Now" form and IPN keep working for stores that have not entered REST credentials yet, so nothing changes until you switch. The PayPal tab now explains the deprecation and walks through the switch.
* Stripe: no change was needed. The plugin already uses Stripe's current hosted Checkout Sessions (which present the Payment Element with cards, wallets and local methods), signed webhooks and restricted or secret API keys; it never used the retired Sources or Charges flows.

= 6.24 =
* Stripe: one order per payment even when the thank-you page and the webhook arrive together; the checkout session is created on click, not on page load.
* Adyen: recoverable webhook failures are redelivered instead of dropped; payment-link records live as long as the link.
* WooCommerce: download allowance counted per ebook, "Reset downloads" order action, "Read online" serves the buyer's protected copy.
* PayPal (legacy form): price, currency and tax are signed and verified. Free-download email form enforced server-side. Free and donation ebooks are no longer switched to paid by a licence-check hiccup.

= 6.23 =
* Security: closed three ways to download without paying (edited bonus links, anonymous "latest order" link, unpaid or refunded WooCommerce orders).
* Adyen webhooks and live mode work again; Stripe button fixed on VAT stores; correct amounts for zero- and three-decimal currencies.
* WooCommerce delivery restored on wizard-configured and HPOS shops; refunds and chargebacks reflected on orders; many delivery and watermark fixes.

= 6.22 =
* Fixed non-PDF download links refused as "not valid for that order", and missing order keys on HPOS WooCommerce shops.

= 6.21 =
* Security: PayPal notifications are verified, must be paid to your account, completed, and can only be used once. Restored PayPal order processing broken in 6.20. Chunked uploads for large books.

= 6.20 =
* ePub protection (social DRM) with QR verification, PDF watermarking rebuilt on TCPDF, public verification page.

Earlier versions: see the full changelog at https://plugins.trac.wordpress.org/browser/ebook-store/tags/6.24/readme.txt

== Upgrade Notice ==

= 6.25 =
Adds PayPal's REST API checkout. PayPal is retiring the old Buy Now form and IPN (deprecated January 2026, switched off January 2027, and new accounts can no longer enable IPN). Update, then paste a REST app's Client ID, Secret and Webhook ID on the PayPal tab; until you do, checkout continues on the old form exactly as before. Stripe needs no action.

= 6.24 =
Follow-up to 6.23. Stops duplicate Stripe orders and duplicate delivery emails, stops Adyen dropping a paid order when its API is briefly unreachable, and makes the Stripe button create its checkout on click so pages load faster and cached pages cannot serve an expired session. WooCommerce download allowances are now counted per ebook (and are enforced at all on High-Performance Order Storage shops), "Read online" shows the buyer's protected copy instead of a 403, and PayPal payments are now checked against the expected currency and tax. Free downloads enforce the email form on the server, and a free ebook is no longer silently switched to paid when the licence check fails.

= 6.23 =
Security and delivery fix release — update now. Closes three ways to download without paying (edited bonus links, an anonymous "latest order" link, and unpaid or refunded WooCommerce orders), makes Adyen payments and live mode work again, fixes the Stripe button on VAT stores and the 100x overcharge in cent-less currencies, restores WooCommerce delivery on wizard-configured and virtual-product shops (and on High-Performance Order Storage), and fixes buyers stuck on "your copy is being generated", the Kindle option suppressing emails, the empty checkout pop-up, and refunds not being reflected. Store owners who had unticked "Confirm every payment with PayPal" should save the PayPal tab once.

= 6.22 =
Fixes "This download link is not valid for that order." when buyers download ePub and other non-PDF formats from the thank-you page or delivery email, and restores download links on WooCommerce shops using High-Performance Order Storage. Update if you sell books in more than one format or run WooCommerce.

= 6.21 =
Security and critical fix release — update now if you sell with PayPal. Faked payment messages could previously unlock your ebooks for free, because the check that authenticates them shipped switched off; it is now on by default, and a payment is only accepted if the money really came to your account, only when it has completed, and only once. Separately, orders stopped arriving after 6.20 because PayPal notifications were no longer being processed, so payments produced no order, no email and no download link. This release restores them — update immediately if you sell with PayPal. It also fixes ePub uploads being rejected as a forbidden file type, and adds chunked uploading with a progress bar so large books are no longer blocked by the server's upload limit.

= 6.20 =
Version 6.20 introduces ePub protection: every ePub you sell is now watermarked to its buyer — visibly in the pages, again in the hidden metadata, with an optional QR verification code — while staying a fully valid file for Apple Books, Kindle, Kobo and calibre. Scan a copy's QR on the new public verification page and it shows the order it was licensed to, so a leak points straight back to who shared it. The PDF watermarking engine has been rebuilt on TCPDF, so buyer watermarks and QR codes print in any language, including right-to-left, and no longer need the PHP GD extension. Recommended for everyone.

= 6.00 =
Important security and compatibility release. Square checkout is removed — if you take payment with Square, switch to PayPal, Stripe, Adyen or WooCommerce before updating. The plugin works on PHP 7.4 again, is 156 MB smaller, and fixes several download and payment authorisation issues. Update as soon as you can.

= 5.94 =
Adds Brevo, WooCommerce variable products, the Import books tool and safer defaults for downloads and tax.
