AnonAge Age Verification

AnonAge Age Verification

Details
View on WordPress

AnonAge Age Verification puts an age gate in front of your content. It works out of the box with no
account, no API key and no cost.

Two free self-declaration modes

  • Confirm — the visitor clicks “I am over 18” (or 13, 16, 21).
  • Year of birth — the visitor enters their year of birth. They are only asked for the month, and
    then the day, when the year alone does not settle it. Most people answer one question.

Three levels of enforcement

  • Cover the page — the gate is drawn over the content in the browser. Cache-friendly and
    keeps the page fully indexable, but it is advisory: a visitor can remove it with developer
    tools, or by turning JavaScript off. Fine as a courtesy notice; it is not a lock.
  • Hide the restricted part (recommended) — the page still loads and is still found by search
    engines. Everything below a marker you place never leaves your server until the visitor has
    proved their age. Works under any page cache with nothing to configure, because the page sent
    to every visitor is identical.
  • Withhold the whole page — nothing but the gate is sent. The strongest option, and the right
    one for a page with nothing safe to show, but search engines see only the gate.

Built for real WordPress sites

  • Works with your cache plugin. The gate is applied in the browser, so the HTML served to every
    visitor is identical. Nothing to configure in WP Rocket, LiteSpeed, W3TC or Cloudflare.
  • No flash of gated content. The cover is painted from <head> before the page renders, not
    after everything has already appeared on screen.
  • Administrators are never gated by default, so you can still edit your site.
  • Gate the whole site, selected pages (ticking a parent covers its children), or everything under
    a URL path such as /gated/. Set how long a visitor stays through the gate, exclude URLs and
    roles, and restyle every part of the panel.
  • Membership sites: for a logged-in visitor the result is recorded against their account, so
    they verify once rather than once per device. Fires anonage_member_verified for your own
    records.
  • No third-party requests. No tracking. Nothing is loaded from anyone else’s server.

Verified mode — not in this release

Self-declaration is honest about what it is: anyone can click a button. Verified mode checks the
visitor’s age against a real identity check through the AnonAge app — they scan a QR code, or tap
through on a phone, and your site receives a yes or no. You never see their documents, their name
or their date of birth. That is the mode that meets “highly effective age assurance” style
requirements.

It is not enabled in this version. The code is here and the option is visible in the settings,
marked as arriving in a later release, so that nothing about your gate changes when it does. It is
switched off rather than left selectable because a mode that appears to check identity and does not
is worse than one that is plainly unavailable. Everything described above this line works today and
always will, with no account.

When it arrives it will need an AnonAge account and a paid plan. There is no free live tier: an
account costs a one-time £2 set-up fee for the identity check on your own account, and then from
£2 a month, which includes 10,000 verifications. Up to 50,000 a month is £5, and beyond that
£2.50 per additional 50,000 — so 200,000 a month is £12.50 and a million is £52.50. USD
and EUR are charged at the same numbers rather than converted. Test keys are free and are never
counted against any of it. Billing follows usage, with no manual plan changes, and you can set a
monthly cap and warning thresholds so a spike is not a surprise invoice.

  • Your secret key never leaves your server. The QR code carries only an opaque session reference.
  • Results arrive over an HMAC-signed callback that is verified against the raw request body, with
    a timestamp window so an old result cannot be replayed.
  • If your site cannot receive inbound requests — a firewall, a staging domain, localhost — the
    plugin asks AnonAge for the result instead, so verification still completes.
  • The QR code is generated on your own server. Nothing is sent to a third-party image service.

Is this “highly effective age assurance”?

It depends on two independent choices, and both have to be right.

How the age is checked. Self-declaration is a statement by the visitor, not a check — anyone
can click a button or type a year. It is what most sites run and it is a reasonable default, but
it is not highly effective age assurance. Verified mode, which checks against a real identity
check, is.

How the content is protected. “Cover the page” delivers the content and hides it in the
browser, so it can be recovered with developer tools. “Hide the restricted part” and “Withhold the
whole page” do not deliver it at all.

Getting one right and not the other achieves nothing: a real identity check behind a removable
overlay still lets a child read the page. The settings screen warns you if you configure that
combination.

External services

The free self-declaration modes make no external requests at all. Nothing leaves your server.

Verified mode communicates with the AnonAge API at https://api.anonage.io to open a verification
session and receive its result. Your secret API key stays on your server and is never sent to the
browser. The data exchanged is a session identifier, a one-time nonce and a yes/no answer — no
personal data about your visitor is sent to us or returned to you.

  • Terms: https://anonage.io/terms
  • Privacy policy: https://anonage.io/privacy

Details

Plugin code:
anonage-age-verification
Plugin version:
0.6.1
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-09
Rating:
Times rated:
0
age-gate
age-restriction
age-verification
compliance
online-safety-act