Abmahn-Shield prüft deinen WooCommerce-Shop auf die häufigsten Abmahnrisiken im deutschen E-Commerce:
Basierend auf aktueller Rechtsprechung (BGH, EuGH) und Gesetzeslage:
Dies ist eine technische Compliance-Einschätzung, keine Rechtsberatung im Sinne des RDG. Für rechtsverbindliche Prüfung bitte einen Fachanwalt hinzuziehen.
This plugin connects to the Abmahn-Shield API to perform Deep-Scans and process payments. The Quick-Scan runs entirely locally within your WordPress installation and does not send any data to external servers.
When you initiate a Deep-Scan, the plugin sends your shop’s URL to the Abmahn-Shield API for a comprehensive compliance analysis. No customer data, order data, or product data is ever transmitted.
https://abmahn-shield.de/api/wc/register — One-time site registration. Called only on the first Deep-Scan or first Deep-Scan checkout (never during the local Quick-Scan).https://abmahn-shield.de/api/wc/scan — Sends the shop URL for Deep-Scan analysis.https://abmahn-shield.de/api/wc/checkout — Initiates the payment process for the Deep-Scan report.When you purchase a Deep-Scan report, the payment is processed by Stripe. The plugin does not handle any payment credentials directly. You are redirected to Stripe’s secure payment page.
The Quick-Scan analyzes your shop’s HTML output locally within WordPress to identify whether common third-party tracking scripts or font CDNs are loaded by your theme or other plugins. The plugin performs string comparisons against well-known domain names but does not connect to, transmit data to, or otherwise interact with any of these services. The domain names below appear in the plugin source code (includes/class-scanner.php) only as literal string arguments to PHP’s strpos() function.
We document them here together with their terms and privacy policies so that you, as the shop operator, can make an informed compliance decision if the Quick-Scan reports that any of these scripts are present on your store.
fonts.googleapis.com, fonts.gstatic.com
google-analytics.com, googletagmanager.com (and gtag( function call)
connect.facebook.net, facebook.com/tr (and fbevents.js)
tiktok.com/i18n/pixel
hotjar.com
clarity.ms
To repeat: the plugin does not connect to, request from, or send any data to the services listed above. These domain strings exist only to recognize when those services are already embedded by the shop operator’s theme or other plugins, so the Quick-Scan can warn about consent-related compliance risks under TDDDG §25 and GDPR Art. 6.