BoxCart – Local Pickup & Click and Collect Ordering
BoxCart is a standalone click and collect ordering plugin for WordPress. Give your customers a polished pickup-ordering experience with configurable time slots, a modern card-view storefront, customer accounts, and a built-in admin dashboard – all without WooCommerce. Whether you call it local pickup, click and collect, store pickup, or order ahead, it is the same idea: customers order online and collect in person, at a time that suits them. BoxCart handles the whole flow, from storefront to time slots to order management, without the weight of a full e-commerce platform. Built for: farm shops, bakeries, butchers, delis, greengrocers, fishmongers, florists, coffee roasters, pizza shops, meal-prep kitchens, and any business where customers order ahead and collect. What you get in the free build Click & collect ordering with configurable time slots on your pickup schedule. One pickup location with its own address, collection instructions, opening hours, and per-slot capacity. Card-view storefront with category filters, search, and mini-basket. Sell by unit, weight, or pack – offer multiple quantity options per product, such as single units, 500g, 1kg, or a 6-pack. Customer accounts with order history, plus optional up-front registration. Admin order management with a status lifecycle (pending, processing, ready, completed, cancelled). Order export to CSV from the orders screen, filtered by date, status, and location. Transactional email templates (order confirmation and status updates) with branding controls and a live preview editor. Plus a new-order admin notification. Cash on collection and bank transfer payment methods. 5 Gutenberg blocks and 5 shortcodes for embedding BoxCart anywhere – products, basket, checkout, account, mini basket. Developer-friendly – 50+ action hooks and 35 filter hooks, CSS custom properties throughout, zero external PHP dependencies. Cache-resilient – pages render as empty shells that hydrate via AJAX, with a bypass cookie for customer sessions. Compatible with Cloudflare, WP Rocket, LiteSpeed, and similar. Translation-ready with a .pot file included. GDPR-aware – self-hosted fonts, optional full data cleanup on uninstall. Why BoxCart? Standalone – no WooCommerce required. A single, focused plugin with its own data model. Time-slot ordering baked in. Configure your schedule, slot length, and capacity. Customers see live availability. Developer extensible – documented hooks, filters, and CSS custom properties. Not a stripped-down demo – the free build is a complete, working click & collect store. Paid Pro upgrade (optional) A paid Pro build is available from boxcart.dev with additional features: Multiple pickup locations Stripe card payments (with Apple Pay, Google Pay, Link, Klarna, PayPal, Afterpay) Table-view storefront Members-only pricing (hide prices and the add-to-cart button from logged-out visitors) Customer favourites and one-click reorder Two-way order messaging Customer-side order modification Holiday closures and per-date capacity overrides Printable pick lists & packing slips Sales reports CSV product & category import/export 195+ customisation settings Pro is optional – the free build will continue to receive updates and is genuinely useful on its own. Live demo Three demo stores at demo.boxcart.dev – a greengrocer, a bakery, and a butcher – each configured differently to show the range of what BoxCart can do. Documentation Full documentation at docs.boxcart.dev covering every admin workflow and the developer API. External Services This plugin uses the Freemius plugin framework (https://freemius.com/) for optional anonymous usage tracking, licence handling for the paid Pro upgrade, and update delivery for Pro customers. Freemius is a well-known WordPress plugin distribution platform and the integration is entirely standard. What data is sent, and when: When you activate BoxCart, you are shown an opt-in prompt asking whether to share anonymous usage diagnostics. You can skip the prompt – the plugin works either way. If you opt in, Freemius receives: your site URL, admin email, WordPress version, PHP version, plugin version, activation/deactivation events, and non-personal environment data (e.g. active theme, locale). You can opt out at any time from BoxCart → Account. If you purchase the Pro upgrade, Freemius also handles your licence key, renewal state, and update delivery for the Pro build. BoxCart never sends your customers’ data, your orders, your products, or the contents of your store to Freemius or anywhere else. Endpoints contacted: api.freemius.com, wp.freemius.com. Freemius’s own privacy policy and terms: https://freemius.com/privacy/ https://freemius.com/terms/
Top keywords
- boxcart11×1.61%
- freemius11×1.61%
- order10×1.46%
- pro7×1.02%
- collect6×0.88%
- customers6×0.88%
- admin5×0.73%
- build5×0.73%
- com5×0.73%
- data5×0.73%
- freemius com5×0.73%
- optional5×0.73%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!