COMING SOON

WordPress.org review is in progress. Downloads are not available yet.

Documentation · Specification draft

Configure, verify, and understand every protection layer.

Documentation is structured for launch, while unverified admin labels and click paths remain intentionally generic.

DOC

Install

Installation guidance will be finalized when the WordPress.org package and verified admin labels are available.

Read guide →
DOC

Getting started

A safe first-run sequence: run the protection health check, confirm checkout surfaces, configure Turnstile if desired, and observe Standard Mode before tightening protection.

Read guide →
DOC

Turnstile setup

Use merchant-owned Cloudflare Turnstile site and secret keys. Server-side validation is required. Cloudflare does not need to be your CDN.

Read guide →
DOC

Standard Mode

Standard Mode uses conservative local velocity controls and requests a challenge when proof or risk signals warrant one.

Read guide →
DOC

Emergency Mode

Emergency Mode is a manual, time-limited response for an attack in progress. It can require fresh challenges and tighten local limits without disabling the gateway.

Read guide →
DOC

Event log and reason codes

Aggregated events explain allow, challenge, and block decisions with stable reason codes and masked identifiers.

Read guide →
DOC

Blocked customers and unblock

Review currently blocked identifiers and release a mistaken temporary block in one click.

Read guide →
DOC

Proxy and Cloudflare

Cloudflare-aware IP resolution and manually trusted proxy CIDRs prevent a reverse proxy from collapsing every customer into one apparent address.

Read guide →
DOC

Checkout Blocks

Checkout Firewall is designed to protect WooCommerce Checkout Blocks as well as Classic Checkout.

Read guide →
DOC

Store API protection

Store API checkout requests receive the same layered evaluation even when traffic does not load the visible checkout form.

Read guide →
DOC

Compatibility

Use the public matrix as the source of truth. Items remain not yet tested until evidence supports a stronger status.

Read guide →
DOC

Privacy and retention

No card data is inspected. Long-term identifiers are hashed or masked, repeated events are aggregated, and Free retains seven days of event history.

Read guide →
DOC

Troubleshooting

Start with the protection health check, then review reason codes, proxy configuration, Turnstile validation, and checkout implementation.

Read guide →
DOC

Freemius and licenses

Freemius manages paid checkout, tax, subscriptions, licenses, premium downloads, and premium updates. The protection engine does not depend on Freemius per checkout.

Read guide →

Pre-launch · Be ready before the next burst

Put a control between checkout abuse and your payment gateway.

Checkout Firewall is being prepared for release. No download or paid checkout is live yet.