For a theme or a script sold to someone who is not a developer, killing the site on an unlicensed copy is the wrong move: the person who suffers is usually the buyer whose key was mistyped, and your support inbox pays for it. banniere() returns a small fixed notice instead — nothing else on the page changes.
require_once __DIR__ . '/Licence.php';
$reglages = @include __DIR__ . '/license.php';
$licence = new Licence(
is_array($reglages) ? $reglages['cle'] : '',
__DIR__ . '/cache'
);
register_shutdown_function(function () use ($licence) {
echo $licence->banniere('My theme');
});
The buyer clears it by putting their key in one file, next to the library. That file is the only thing they have to touch.
<?php
return array(
'cle' => '',
);
It returns an empty string when the licence is valid, and also when the network failed — a visitor never sees a notice because our server had a bad night. On a development key it says so, discreetly, which is what you want while you build.
An HTML theme, a Figma file, an icon set, a font: nothing of that runs on a server you can reach. Everything you ship is read, edited and redistributed by whoever holds the files. There is no check to add, and no version of this page where that changes.
Do not fake it. An obfuscated script that phones home from a static page, a hidden canvas fingerprint, a build that breaks after thirty days: all of it is removed in an afternoon by the one person who was going to pirate you, and all of it ends up as a support ticket from the fifty who paid. You would be spending your credibility to protect nothing.
What exists instead works at delivery, not at runtime. Every download is repackaged for the buyer who asked for it, and carries three things:
That is traceability, not prevention, and we will not sell it to you as anything else: a buyer who deletes the file and strips the comment leaves with a clean copy. What it does give you is a name when a copy surfaces somewhere it should not, a reason for that buyer to think twice, and the two things a pirated copy never gets — the updates and your support.
One distinction matters here. If your theme has any PHP at all — a contact form, a config file, an include — then it runs on a server, the check above is real, and the notice works. It is only the fully static case, HTML and CSS and nothing else, where there is no runtime check to be had.
Write to us from your author area. A question that needed asking usually means this page is missing a paragraph.