{"id":349733,"date":"2026-08-18T18:38:49","date_gmt":"2026-08-18T18:38:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/checkout-firewall-for-woocommerce\/"},"modified":"2026-08-18T18:38:15","modified_gmt":"2026-08-18T18:38:15","slug":"checkout-firewall","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/checkout-firewall\/","author":16754268,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.4","requires":"6.8","requires_php":"8.0","requires_plugins":null,"header_name":"Checkout Firewall for WooCommerce","header_author":"Codeprint","header_description":"Helps protect WooCommerce checkout from automated abuse before payment processing.","assets_banners_color":"","last_updated":"2026-08-18 18:38:15","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/checkoutfirewall.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":35,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"codeprint","date":"2026-08-18 18:38:15"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3653423,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3653423,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Overview showing Standard or Observe Mode and local system health.","2":"Activity showing synthetic masked checkout interventions and explanations.","3":"Blocks showing a synthetic masked local block, release action, and trusted exemptions.","4":"Settings showing challenge providers, security notifications, retention, and proxy controls with no secret visible.","5":"Privacy &amp; help showing data disclosures, uninstall behavior, and the support snapshot action."}},"plugin_section":[],"plugin_tags":[166108,262525,237432,595,286],"plugin_category":[38,45],"plugin_contributors":[276353],"plugin_business_model":[],"class_list":["post-349733","plugin","type-plugin","status-publish","hentry","plugin_tags-bot-protection","plugin_tags-card-testing","plugin_tags-checkout-security","plugin_tags-recaptcha","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-codeprint","plugin_committers-codeprint"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/checkout-firewall\/assets\/icon-128x128.png?rev=3653423","icon_2x":"https:\/\/ps.w.org\/checkout-firewall\/assets\/icon-256x256.png?rev=3653423","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Checkout Firewall protects Classic, Blocks, and supported Store API checkout with signed flow proof, local evidence, velocity controls, recoverable challenges, temporary blocks, and Emergency Mode. WooCommerce is required. New installations begin in Observe Mode; enforcement starts only after an administrator enables Standard Mode.<\/p>\n\n<p>Free includes narrow exact-IP, CIDR, and authenticated-user exemptions plus a local incident notice and optional rate-limited WordPress email. Exemptions never bypass manual blocks or invalid\/replayed proof; incident signals are not fraud determinations.<\/p>\n\n<p>Free works locally without a Codeprint or Freemius account, and anonymous use creates no licensing traffic. WordPress.org distributes and updates this complete Free plugin. An optional, explicit Freemius connection supports account and purchase surfaces for the separately distributed Premium replacement plugin. Checkout security, shopper, order, gateway, and payment data is not sent to Codeprint or Freemius.<\/p>\n\n<p>Checkout Firewall never reads or stores card data and never automatically disables a payment gateway. It cannot stop all fraud or guarantee against chargebacks.<\/p>\n\n<p>Cloudflare is optional. Direct and verified Cloudflare traffic is recognized automatically; another reverse proxy requires explicit trusted ranges.<\/p>\n\n<p>Checkout Firewall is an independent Codeprint product, not endorsed by WooCommerce, Automattic, Cloudflare, Google, or Freemius.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Checkout Firewall processes abuse signals locally using HMAC-derived identifiers and masked hints, not card data, gateway payloads, or request bodies. Activity and terminal blocks are retained for at most seven days; masked block hints for at most 90 days. A temporary keyed order snapshot is removed after a recorded payment outcome and otherwise follows Activity retention. WordPress email erasure removes directly attributable records. Full uninstall deletion requires explicit administrator opt-in.<\/p>\n\n<p>Observe Mode stores bounded aggregate would-intervene records while allowing checkout. Exact IPs are keyed; authenticated-user exemptions store local user ID; narrow CIDRs remain readable only for range matching.<\/p>\n\n<p>The randomized honeypot, signed timing evidence, and default account-free browser proof are evaluated locally. They are supporting automation friction, not proof of humanity.<\/p>\n\n<p>Selected Turnstile or reCAPTCHA loads only after a challenge and may process browser\/network signals. Server verification omits the optional shopper IP and sends no payment details.<\/p>\n\n<p>Optional Freemius connection may share administrator name\/email, site URL, versions, license\/installation identifiers, and activation state for account, purchase, Premium licensing, and Premium updates. Site-profile, diagnostic, extension-inventory, and newsletter permissions are disabled; anonymous activation and Skip send nothing. Free updates come from WordPress.org.<\/p>\n\n<p>The support snapshot is generated locally and is not uploaded. It excludes site\/customer identity, orders, gateways, credentials, requests, logs, and raw errors.<\/p>\n\n<h3>External services<\/h3>\n\n<p>These services are conditional; local protection needs no Codeprint account:<\/p>\n\n<p><strong>Freemius.<\/strong> Contacted only after explicit connection, or by the separately installed Premium plugin for connected licensing\/update functions; never per checkout. Anonymous activation and Skip send nothing. Free updates come from WordPress.org. <a href=\"https:\/\/freemius.com\/\">Service<\/a>, <a href=\"https:\/\/freemius.com\/terms\/\">Terms<\/a>, <a href=\"https:\/\/freemius.com\/privacy\/\">Privacy<\/a>.<\/p>\n\n<p><strong>Cloudflare Turnstile.<\/strong> Contacted only when selected\/configured and local signals require a challenge. Browser\/network signals, response token, and merchant secret may be processed; optional shopper IP and payment details are not sent by Checkout Firewall. <a href=\"https:\/\/developers.cloudflare.com\/turnstile\/\">Service<\/a>, <a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">Terms<\/a>, <a href=\"https:\/\/www.cloudflare.com\/turnstile-privacy-policy\/\">Privacy<\/a>.<\/p>\n\n<p><strong>Google reCAPTCHA.<\/strong> Contacted only when selected\/configured and local signals require a challenge. Browser\/network signals, response token, and merchant secret may be processed; optional shopper IP and payment details are not sent by Checkout Firewall. <a href=\"https:\/\/developers.google.com\/recaptcha\">Service<\/a>, <a href=\"https:\/\/developers.google.com\/terms\/\">API Terms<\/a>, <a href=\"https:\/\/policies.google.com\/terms\">Terms<\/a>, <a href=\"https:\/\/policies.google.com\/privacy\">Privacy<\/a>.<\/p>\n\n<p>The local challenge, decisions, records, and support snapshot contact no challenge service or Codeprint scoring API. <a href=\"https:\/\/github.com\/codeprintagency\/Checkout-Firewall\">Source and build instructions<\/a>.<\/p>\n\n<h3>Support<\/h3>\n\n<p>Include the plugin version, software-version section, closed health states, and schedule states from the support snapshot. Do not send payment payloads, request bodies, production database exports, raw shopper identifiers, passwords, secret keys, tokens, or license keys.<\/p>\n\n<h4>Is card data collected?<\/h4>\n\n<p>No. Checkout Firewall must never read, store, log, hash, or transmit card data.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate Checkout Firewall.<\/li>\n<li>Open WooCommerce \u2192 Checkout Firewall.<\/li>\n<li>Leave the new installation in Observe Mode while reviewing what Standard Mode would have done. The suggested review date is advisory; enforcement never starts automatically.<\/li>\n<li>Add only necessary trusted exemptions, then explicitly turn on Standard Mode when ready.<\/li>\n<li>Review the local health status. The private local browser check works immediately; optionally select Cloudflare Turnstile or Google reCAPTCHA.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20free%20protection%20require%20an%20account%3F\"><h3>Does Free protection require an account?<\/h3><\/dt>\n<dd><p>No. Free protection works locally and Free updates come from WordPress.org. Freemius connection is optional.<\/p><\/dd>\n<dt id=\"is%20premium%20code%20included%20or%20locked%20inside%20free%3F\"><h3>Is Premium code included or locked inside Free?<\/h3><\/dt>\n<dd><p>No. This WordPress.org plugin is complete and contains no Premium implementation or license-gated local feature. Premium is a separately downloaded GPL-compatible replacement plugin available outside WordPress.org.<\/p><\/dd>\n<dt id=\"does%20checkout%20firewall%20disable%20payment%20gateways%3F\"><h3>Does Checkout Firewall disable payment gateways?<\/h3><\/dt>\n<dd><p>No. Checkout Firewall does not disable, hide, reorder, or wrap payment gateways.<\/p><\/dd>\n<dt id=\"do%20i%20need%20cloudflare%3F\"><h3>Do I need Cloudflare?<\/h3><\/dt>\n<dd><p>No. Checkout Firewall works without Cloudflare. If the store uses Cloudflare, the plugin detects a verified Cloudflare connection automatically and safely uses its visitor-address header. Cloudflare can add DDoS and bot mitigation at the network edge before requests reach WordPress.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20with%20checkout%20blocks%20and%20hpos%3F\"><h3>Does the plugin work with Checkout Blocks and HPOS?<\/h3><\/dt>\n<dd><p>Yes. Checkout Firewall declares compatibility with WooCommerce Cart and Checkout Blocks and High-Performance Order Storage.<\/p><\/dd>\n<dt id=\"which%20checkout%20surfaces%20are%20protected%20in%20version%201.0.0%3F\"><h3>Which checkout surfaces are protected in version 1.0.0?<\/h3><\/dt>\n<dd><p>Checkout Firewall protects the normal Classic Checkout flow, Checkout Blocks, and the customer Store API checkout routes, including the Store API existing-order route. WooCommerce's legacy Classic <code>order-pay<\/code> payment-retry endpoint is not protected in version 1.0.0. Existing WooCommerce authorization still applies there, but Checkout Firewall does not add its proof, velocity, or challenge decision to that legacy endpoint.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20uninstall%20it%3F\"><h3>What happens when I uninstall it?<\/h3><\/dt>\n<dd><p>Data is preserved by default. Full deletion occurs only after a site administrator explicitly opts in before uninstalling. Multisite deletion is not supported.<\/p><\/dd>\n<dt id=\"can%20a%20legitimate%20checkout%20be%20challenged%20or%20blocked%3F\"><h3>Can a legitimate checkout be challenged or blocked?<\/h3><\/dt>\n<dd><p>Yes. Automated controls can produce false positives. Challenge recovery works out of the box with the private local check and can instead use verified Turnstile or reCAPTCHA. Review Activity and Blocks, release a local block if appropriate, and stop Emergency Mode when the incident ends.<\/p><\/dd>\n<dt id=\"can%20i%20see%20what%20the%20plugin%20would%20do%20before%20it%20affects%20checkout%3F\"><h3>Can I see what the plugin would do before it affects checkout?<\/h3><\/dt>\n<dd><p>Yes. A new installation starts in Observe Mode. The same decision engine measures activity and labels would-challenge and would-block results, but checkout continues and no automatic payment-failure block is created. The merchant must explicitly enable Standard Mode.<\/p><\/dd>\n<dt id=\"can%20i%20exempt%20a%20wholesale%20customer%20or%20office%20network%3F\"><h3>Can I exempt a wholesale customer or office network?<\/h3><\/dt>\n<dd><p>Yes. Add a trusted exemption for a specific authenticated WordPress user, exact IP, or narrow CIDR. Email addresses cannot grant an exemption because a guest can type any billing email. Exemptions never bypass manual blocks or invalid\/replayed checkout proof.<\/p><\/dd>\n<dt id=\"what%20does%20emergency%20mode%20do%3F\"><h3>What does Emergency Mode do?<\/h3><\/dt>\n<dd><p>For a selected, time-limited period it requires a fresh selected-provider challenge for guest checkout. It does not change payment gateways. If challenge recovery becomes unavailable, Emergency Mode ends automatically and Standard Mode remains active.<\/p><\/dd>\n<dt id=\"how%20do%20i%20roll%20back%3F\"><h3>How do I roll back?<\/h3><\/dt>\n<dd><p>Deactivate Checkout Firewall, verify the checksum of the previously tested package, replace the plugin files, and reactivate it. Version 1.0.0 uses schema v3 and preserves data by default.<\/p><\/dd>\n<dt id=\"where%20can%20i%20get%20diagnostic%20information%3F\"><h3>Where can I get diagnostic information?<\/h3><\/dt>\n<dd><p>Open WooCommerce \u2192 Checkout Firewall \u2192 Privacy &amp; help and download the privacy-bounded support snapshot.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release with Classic and Blocks checkout protection, non-enforcing Observe Mode for new installations, narrow trusted exemptions, sustained-activity notices, local automation signals and velocity controls, provider-neutral challenge recovery, Emergency Mode, privacy tools, and bounded support diagnostics.<\/li>\n<\/ul>","raw_excerpt":"Checkout Firewall provides local, explainable checkout-abuse protection before payment processing.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349733"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/codeprint"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349733"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349733"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349733"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349733"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349733"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}