Title: Checkout Firewall for WooCommerce
Author: codeprint
Published: <strong>August 18, 2026</strong>
Last modified: August 18, 2026

---

Search plugins

![](https://ps.w.org/checkout-firewall/assets/icon-256x256.png?rev=3653423)

# Checkout Firewall for WooCommerce

 By [codeprint](https://profiles.wordpress.org/codeprint/)

[Download](https://downloads.wordpress.org/plugin/checkout-firewall.1.0.0.zip)

 * [Details](https://pcd.wordpress.org/plugins/checkout-firewall/#description)
 * [Reviews](https://pcd.wordpress.org/plugins/checkout-firewall/#reviews)
 *  [Installation](https://pcd.wordpress.org/plugins/checkout-firewall/#installation)
 * [Development](https://pcd.wordpress.org/plugins/checkout-firewall/#developers)

 [Support](https://wordpress.org/support/plugin/checkout-firewall/)

## Description

Checkout Firewall protects Classic, Blocks, and supported Store API checkout with
signed flow proof, local evidence, velocity controls, recoverable challenges, temporary
blocks, and Emergency Mode. WooCommerce is required. New installations begin in 
Observe Mode; enforcement starts only after an administrator enables Standard Mode.

Free includes narrow exact-IP, CIDR, and authenticated-user exemptions plus a local
incident notice and optional rate-limited WordPress email. Exemptions never bypass
manual blocks or invalid/replayed proof; incident signals are not fraud determinations.

Free works locally without a Codeprint or Freemius account, and anonymous use creates
no licensing traffic. WordPress.org distributes and updates this complete Free plugin.
An optional, explicit Freemius connection supports account and purchase surfaces
for the separately distributed Premium replacement plugin. Checkout security, shopper,
order, gateway, and payment data is not sent to Codeprint or Freemius.

Checkout Firewall never reads or stores card data and never automatically disables
a payment gateway. It cannot stop all fraud or guarantee against chargebacks.

Cloudflare is optional. Direct and verified Cloudflare traffic is recognized automatically;
another reverse proxy requires explicit trusted ranges.

Checkout Firewall is an independent Codeprint product, not endorsed by WooCommerce,
Automattic, Cloudflare, Google, or Freemius.

### Privacy

Checkout Firewall processes abuse signals locally using HMAC-derived identifiers
and masked hints, not card data, gateway payloads, or request bodies. Activity and
terminal blocks are retained for at most seven days; masked block hints for at most
90 days. A temporary keyed order snapshot is removed after a recorded payment outcome
and otherwise follows Activity retention. WordPress email erasure removes directly
attributable records. Full uninstall deletion requires explicit administrator opt-
in.

Observe Mode stores bounded aggregate would-intervene records while allowing checkout.
Exact IPs are keyed; authenticated-user exemptions store local user ID; narrow CIDRs
remain readable only for range matching.

The randomized honeypot, signed timing evidence, and default account-free browser
proof are evaluated locally. They are supporting automation friction, not proof 
of humanity.

Selected Turnstile or reCAPTCHA loads only after a challenge and may process browser/
network signals. Server verification omits the optional shopper IP and sends no 
payment details.

Optional Freemius connection may share administrator name/email, site URL, versions,
license/installation identifiers, and activation state for account, purchase, Premium
licensing, and Premium updates. Site-profile, diagnostic, extension-inventory, and
newsletter permissions are disabled; anonymous activation and Skip send nothing.
Free updates come from WordPress.org.

The support snapshot is generated locally and is not uploaded. It excludes site/
customer identity, orders, gateways, credentials, requests, logs, and raw errors.

### External services

These services are conditional; local protection needs no Codeprint account:

**Freemius.** Contacted only after explicit connection, or by the separately installed
Premium plugin for connected licensing/update functions; never per checkout. Anonymous
activation and Skip send nothing. Free updates come from WordPress.org. [Service](https://freemius.com/),
[Terms](https://freemius.com/terms/), [Privacy](https://freemius.com/privacy/).

**Cloudflare Turnstile.** Contacted only when selected/configured and local signals
require a challenge. Browser/network signals, response token, and merchant secret
may be processed; optional shopper IP and payment details are not sent by Checkout
Firewall. [Service](https://developers.cloudflare.com/turnstile/), [Terms](https://www.cloudflare.com/website-terms/),
[Privacy](https://www.cloudflare.com/turnstile-privacy-policy/).

**Google reCAPTCHA.** Contacted only when selected/configured and local signals 
require a challenge. Browser/network signals, response token, and merchant secret
may be processed; optional shopper IP and payment details are not sent by Checkout
Firewall. [Service](https://developers.google.com/recaptcha), [API Terms](https://developers.google.com/terms/),
[Terms](https://policies.google.com/terms), [Privacy](https://policies.google.com/privacy).

The local challenge, decisions, records, and support snapshot contact no challenge
service or Codeprint scoring API. [Source and build instructions](https://github.com/codeprintagency/Checkout-Firewall).

### Support

Include the plugin version, software-version section, closed health states, and 
schedule states from the support snapshot. Do not send payment payloads, request
bodies, production database exports, raw shopper identifiers, passwords, secret 
keys, tokens, or license keys.

#### Is card data collected?

No. Checkout Firewall must never read, store, log, hash, or transmit card data.

## Installation

 1. Upload and activate Checkout Firewall.
 2. Open WooCommerce  Checkout Firewall.
 3. Leave the new installation in Observe Mode while reviewing what Standard Mode would
    have done. The suggested review date is advisory; enforcement never starts automatically.
 4. Add only necessary trusted exemptions, then explicitly turn on Standard Mode when
    ready.
 5. Review the local health status. The private local browser check works immediately;
    optionally select Cloudflare Turnstile or Google reCAPTCHA.

## FAQ

### Does Free protection require an account?

No. Free protection works locally and Free updates come from WordPress.org. Freemius
connection is optional.

### Is Premium code included or locked inside Free?

No. This WordPress.org plugin is complete and contains no Premium implementation
or license-gated local feature. Premium is a separately downloaded GPL-compatible
replacement plugin available outside WordPress.org.

### Does Checkout Firewall disable payment gateways?

No. Checkout Firewall does not disable, hide, reorder, or wrap payment gateways.

### Do I need Cloudflare?

No. Checkout Firewall works without Cloudflare. If the store uses Cloudflare, the
plugin detects a verified Cloudflare connection automatically and safely uses its
visitor-address header. Cloudflare can add DDoS and bot mitigation at the network
edge before requests reach WordPress.

### Does the plugin work with Checkout Blocks and HPOS?

Yes. Checkout Firewall declares compatibility with WooCommerce Cart and Checkout
Blocks and High-Performance Order Storage.

### Which checkout surfaces are protected in version 1.0.0?

Checkout Firewall protects the normal Classic Checkout flow, Checkout Blocks, and
the customer Store API checkout routes, including the Store API existing-order route.
WooCommerce’s legacy Classic `order-pay` payment-retry endpoint is not protected
in version 1.0.0. Existing WooCommerce authorization still applies there, but Checkout
Firewall does not add its proof, velocity, or challenge decision to that legacy 
endpoint.

### What happens when I uninstall it?

Data is preserved by default. Full deletion occurs only after a site administrator
explicitly opts in before uninstalling. Multisite deletion is not supported.

### Can a legitimate checkout be challenged or blocked?

Yes. Automated controls can produce false positives. Challenge recovery works out
of the box with the private local check and can instead use verified Turnstile or
reCAPTCHA. Review Activity and Blocks, release a local block if appropriate, and
stop Emergency Mode when the incident ends.

### Can I see what the plugin would do before it affects checkout?

Yes. A new installation starts in Observe Mode. The same decision engine measures
activity and labels would-challenge and would-block results, but checkout continues
and no automatic payment-failure block is created. The merchant must explicitly 
enable Standard Mode.

### Can I exempt a wholesale customer or office network?

Yes. Add a trusted exemption for a specific authenticated WordPress user, exact 
IP, or narrow CIDR. Email addresses cannot grant an exemption because a guest can
type any billing email. Exemptions never bypass manual blocks or invalid/replayed
checkout proof.

### What does Emergency Mode do?

For a selected, time-limited period it requires a fresh selected-provider challenge
for guest checkout. It does not change payment gateways. If challenge recovery becomes
unavailable, Emergency Mode ends automatically and Standard Mode remains active.

### How do I roll back?

Deactivate Checkout Firewall, verify the checksum of the previously tested package,
replace the plugin files, and reactivate it. Version 1.0.0 uses schema v3 and preserves
data by default.

### Where can I get diagnostic information?

Open WooCommerce  Checkout Firewall  Privacy & help and download the privacy-bounded
support snapshot.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Checkout Firewall for WooCommerce” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ codeprint ](https://profiles.wordpress.org/codeprint/)

[Translate “Checkout Firewall for WooCommerce” into your language.](https://translate.wordpress.org/projects/wp-plugins/checkout-firewall)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/checkout-firewall/),
check out the [SVN repository](https://plugins.svn.wordpress.org/checkout-firewall/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/checkout-firewall/)
by [RSS](https://plugins.trac.wordpress.org/log/checkout-firewall/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release with Classic and Blocks checkout protection, non-enforcing Observe
   Mode for new installations, narrow trusted exemptions, sustained-activity notices,
   local automation signals and velocity controls, provider-neutral challenge recovery,
   Emergency Mode, privacy tools, and bounded support diagnostics.

## Meta

 *  Version **1.0.0**
 *  Last updated **21 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.8 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/checkout-firewall/)
 * Tags
 * [bot protection](https://pcd.wordpress.org/plugins/tags/bot-protection/)[card-testing](https://pcd.wordpress.org/plugins/tags/card-testing/)
   [checkout security](https://pcd.wordpress.org/plugins/tags/checkout-security/)
   [recaptcha](https://pcd.wordpress.org/plugins/tags/recaptcha/)[woocommerce](https://pcd.wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://pcd.wordpress.org/plugins/checkout-firewall/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/checkout-firewall/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/checkout-firewall/reviews/)

## Contributors

 *   [ codeprint ](https://profiles.wordpress.org/codeprint/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/checkout-firewall/)