Documentation · Specification draft
Configure, verify, and understand every protection layer.
Documentation is structured for launch, while unverified admin labels and click paths remain intentionally generic.
Install
Installation guidance will be finalized when the WordPress.org package and verified admin labels are available.
Read guide →DOCGetting started
A safe first-run sequence: run the protection health check, confirm checkout surfaces, configure Turnstile if desired, and observe Standard Mode before tightening protection.
Read guide →DOCTurnstile setup
Use merchant-owned Cloudflare Turnstile site and secret keys. Server-side validation is required. Cloudflare does not need to be your CDN.
Read guide →DOCStandard Mode
Standard Mode uses conservative local velocity controls and requests a challenge when proof or risk signals warrant one.
Read guide →DOCEmergency Mode
Emergency Mode is a manual, time-limited response for an attack in progress. It can require fresh challenges and tighten local limits without disabling the gateway.
Read guide →DOCEvent log and reason codes
Aggregated events explain allow, challenge, and block decisions with stable reason codes and masked identifiers.
Read guide →DOCBlocked customers and unblock
Review currently blocked identifiers and release a mistaken temporary block in one click.
Read guide →DOCProxy and Cloudflare
Cloudflare-aware IP resolution and manually trusted proxy CIDRs prevent a reverse proxy from collapsing every customer into one apparent address.
Read guide →DOCCheckout Blocks
Checkout Firewall is designed to protect WooCommerce Checkout Blocks as well as Classic Checkout.
Read guide →DOCStore API protection
Store API checkout requests receive the same layered evaluation even when traffic does not load the visible checkout form.
Read guide →DOCCompatibility
Use the public matrix as the source of truth. Items remain not yet tested until evidence supports a stronger status.
Read guide →DOCPrivacy and retention
No card data is inspected. Long-term identifiers are hashed or masked, repeated events are aggregated, and Free retains seven days of event history.
Read guide →DOCTroubleshooting
Start with the protection health check, then review reason codes, proxy configuration, Turnstile validation, and checkout implementation.
Read guide →DOCFreemius and licenses
Freemius manages paid checkout, tax, subscriptions, licenses, premium downloads, and premium updates. The protection engine does not depend on Freemius per checkout.
Read guide →Pre-launch · Be ready before the next burst
Put a control between checkout abuse and your payment gateway.
Checkout Firewall is being prepared for release. No download or paid checkout is live yet.