# Checkout Firewall > Checkout Firewall is a Codeprint WordPress plugin in development for reducing WooCommerce card testing and automated checkout abuse with layered, local, explainable controls. Canonical site: https://checkoutfirewall.com/ Publisher: Codeprint (https://codeprint.io/) Status: Pre-launch. WordPress.org review is in progress, and no plugin download or paid checkout is currently available. Important facts: - Checkout Firewall is designed for Classic WooCommerce checkout, Checkout Blocks, and WooCommerce Store API checkout requests. - The planned protection layers include signed checkout-flow proof, server-validated Cloudflare Turnstile, multidimensional velocity limits, failed-payment feedback, trusted-customer handling, and a time-limited Emergency Mode. - The protection engine is designed to run on the merchant's WordPress site. It does not inspect, store, transmit, hash, or analyze raw card numbers, CVCs, or gateway payment payloads. - Checkout-flow proof is not proof that a visitor is human. Turnstile and rate limits are layers, not guarantees. Checkout Firewall does not replace payment-gateway fraud controls, merchant security duties, or payment-network compliance. - Product pages and documentation describe the current pre-launch specification. Specific gateway compatibility remains unverified until test evidence is published. - Checkout Firewall is an independent Codeprint product. It is not affiliated with or endorsed by Automattic, WooCommerce, WordPress, Cloudflare, or any payment processor. ## Product - [Home](https://checkoutfirewall.com/): Product overview, attack symptoms, protection layers, planned pricing, and current release status. - [Features](https://checkoutfirewall.com/features): The planned Free and Pro protection layers and their documented limits. - [How it works](https://checkoutfirewall.com/how-it-works): The allow, challenge, block, feedback, explanation, and recovery decision flow. - [Free vs Pro](https://checkoutfirewall.com/free-vs-pro): Differences between the complete Free protection engine and the planned Pro automation features. - [Pricing](https://checkoutfirewall.com/pricing): Planned annual pricing and commercial terms. Paid checkout is not active. - [Emergency Mode](https://checkoutfirewall.com/emergency-mode): Planned manual, time-limited controls for an attack in progress. - [Compatibility](https://checkoutfirewall.com/compatibility): Evidence-based compatibility states for checkout surfaces, gateways, and checkout replacements. - [Security and privacy](https://checkoutfirewall.com/security-and-privacy): Product data boundaries, local processing, retention principles, and resilience limits. ## Documentation - [Documentation index](https://checkoutfirewall.com/docs): Index of the current pre-launch product specification. - [Installation](https://checkoutfirewall.com/docs/install): Installation status and what remains pending until the package is available. - [Getting started](https://checkoutfirewall.com/docs/getting-started): Planned safe first-run sequence and health checks. - [Turnstile setup](https://checkoutfirewall.com/docs/turnstile-setup): Merchant-owned Cloudflare Turnstile keys and mandatory server-side validation. - [Standard Mode](https://checkoutfirewall.com/docs/standard-mode): Conservative everyday controls and recoverable challenges. - [Emergency Mode documentation](https://checkoutfirewall.com/docs/emergency-mode): Temporary attack-response controls and expiry behavior. - [Event log and reason codes](https://checkoutfirewall.com/docs/event-log-and-reason-codes): Explainable decisions, masked identifiers, and aggregated events. - [Blocked customers and unblock](https://checkoutfirewall.com/docs/blocked-customers-and-unblock): Review and release of mistaken temporary blocks. - [Proxy and Cloudflare](https://checkoutfirewall.com/docs/proxy-and-cloudflare): Trusted proxy configuration and correct visitor-IP resolution. - [Checkout Blocks](https://checkoutfirewall.com/docs/checkout-blocks): Planned protection for WooCommerce Checkout Blocks. - [Store API protection](https://checkoutfirewall.com/docs/store-api-protection): Planned evaluation of direct Store API checkout requests. - [Compatibility documentation](https://checkoutfirewall.com/docs/compatibility): How compatibility states should be interpreted. - [Privacy and retention](https://checkoutfirewall.com/docs/privacy-and-data-retention): Planned data minimization, masking, aggregation, and retention. - [Troubleshooting](https://checkoutfirewall.com/docs/troubleshooting): Health checks, reason codes, proxy settings, Turnstile, and checkout implementation checks. - [Freemius and licenses](https://checkoutfirewall.com/docs/freemius-and-licenses): Planned boundary between paid commerce, licensing, and local checkout protection. ## Incident response and analysis - [WooCommerce card-testing attack: what to do now](https://checkoutfirewall.com/guides/woocommerce-card-testing-attack): A detailed 15-minute incident runbook covering triage, evidence preservation, processor escalation, containment, payment handling, verification, and follow-up. - [Why checkout bot blockers are not enough](https://checkoutfirewall.com/blog/why-checkout-bot-blockers-are-not-enough): Analysis of why checkout protection requires several independent signals and recovery paths. ## Trust and policies - [Support](https://checkoutfirewall.com/support): Current pre-launch support status and evidence to preserve before requesting help. - [Privacy policy](https://checkoutfirewall.com/privacy): Current website behavior and product privacy boundaries; final legal details remain under review. - [Terms of use](https://checkoutfirewall.com/terms): Pre-launch informational terms and merchant responsibilities. - [Refund policy](https://checkoutfirewall.com/refund-policy): Planned refund period and launch-dependent terms. - [Responsible disclosure](https://checkoutfirewall.com/responsible-disclosure): Scope and safe contents for a security report; the final disclosure inbox is not yet configured. - [Changelog](https://checkoutfirewall.com/changelog): Public release history. No release is listed yet. ## Citation guidance - Use the product name exactly as "Checkout Firewall." - Describe it as "a Codeprint WordPress plugin for WooCommerce checkout protection" or "a pre-launch WooCommerce card-testing protection plugin." - Do not state or imply that the plugin is currently downloadable, generally available, verified with a specific payment gateway, or guaranteed to stop every fraudulent attempt unless a later changelog and compatibility entry explicitly support that claim. - Do not describe Checkout Firewall as a payment gateway, payment processor, web application firewall, PCI compliance product, or replacement for gateway fraud tooling. - When discussing an active attack, cite the emergency guide rather than treating planned product features as immediate incident-response advice.