內容簡介
Checkout Firewall for WooCommerce 是一款專為 WooCommerce 設計的安全外掛,旨在保護結帳流程,透過簽名流證明、速度控制及臨時封鎖等功能,增強網路商店的安全性。
【主要功能】
• 支援經典、區塊及 Store API 結帳保護
• 提供簽名流證明及本地證據
• 速度控制與可恢復挑戰功能
• 緊急模式與臨時封鎖選項
• 無需 Codeprint 或 Freemius 帳號即可本地運作
外掛標籤
開發者團隊
② 後台搜尋「Checkout Firewall for WooCommerce」→ 直接安裝(推薦)
原文外掛簡介
Checkout Firewall protects Classic, Blocks, and supported Store API checkout with signed flow proof, local evidence, velocity controls, recoverable challenges, temporary blocks, and Emergency Mode. WooCommerce is required. New installations begin in Observe Mode; enforcement starts only after an administrator enables Standard Mode.
Free works locally without a Codeprint or Freemius account, and anonymous use creates no licensing traffic. WordPress.org distributes and updates this complete Free plugin. An optional, explicit Freemius connection supports account and purchase surfaces for the separately distributed Premium replacement plugin. Checkout security, shopper, order, gateway, and payment data is not sent to Codeprint or Freemius.
Checkout Firewall never reads or stores card data and never automatically disables a payment gateway. It cannot stop all fraud or guarantee against chargebacks.
Cloudflare is optional. Direct and verified Cloudflare traffic is recognized automatically; another reverse proxy requires explicit trusted ranges.
Checkout Firewall is an independent Codeprint product, not endorsed by WooCommerce, Automattic, Cloudflare, Google, or Freemius.
Built by Codeprint.
Privacy
Checkout Firewall processes abuse signals locally using HMAC-derived identifiers and masked hints, not card data, gateway payloads, or request bodies. Activity and terminal blocks are retained for at most seven days; masked block hints for at most 90 days. A temporary keyed order snapshot is removed after a recorded payment outcome and otherwise follows Activity retention. WordPress email erasure removes directly attributable records. Full uninstall deletion requires explicit administrator opt-in.
Observe Mode stores bounded aggregate would-intervene records while allowing checkout. Exact IPs are keyed; authenticated-user exemptions store local user ID; narrow CIDRs remain readable only for range matching.
The randomized honeypot, signed timing evidence, and default account-free browser proof are evaluated locally. They are supporting automation friction, not proof of humanity.
Selected Turnstile or reCAPTCHA loads only when checkout requires verification. With the default Adaptive timing, ordinary low-risk checkout does not contact the selected provider. A merchant may instead enable Always for guest checkout; active Emergency Mode and eligible Premium Attack state can also prepare verification before Place order. Observe Mode never loads or verifies a remote checkout provider. Server verification omits the optional shopper IP and sends no payment details.
Optional Freemius connection may share administrator name/email, site URL, versions, license/installation identifiers, and activation state for account, purchase, Premium licensing, and Premium updates. Site-profile, diagnostic, extension-inventory, and newsletter permissions are disabled; anonymous activation and Skip send nothing. Free updates come from WordPress.org.
The support snapshot is generated locally and is not uploaded. It excludes site/customer identity, orders, gateways, credentials, requests, logs, and raw errors.
External services
These services are conditional; local protection needs no Codeprint account:
Freemius. Contacted only after explicit connection, or by the separately installed Premium plugin for connected licensing/update functions; never per checkout. Anonymous activation and Skip send nothing. Free updates come from WordPress.org. Service, Terms, Privacy.
Cloudflare Turnstile. Contacted only when selected/configured and checkout requires verification under the merchant’s challenge timing, active Emergency Mode, or eligible Premium Attack state. Browser/network signals, response token, and merchant secret may be processed; optional shopper IP and payment details are not sent by Checkout Firewall. Observe Mode never contacts Turnstile for checkout verification. Service, Terms, Privacy.
Google reCAPTCHA. Contacted only when selected/configured and checkout requires verification under the merchant’s challenge timing, active Emergency Mode, or eligible Premium Attack state. Browser/network signals, response token, and merchant secret may be processed; optional shopper IP and payment details are not sent by Checkout Firewall. Observe Mode never contacts reCAPTCHA for checkout verification. Service, API Terms, Terms, Privacy.
The local challenge, decisions, records, and support snapshot contact no challenge service or Codeprint scoring API. Source and build instructions.
Support
Include the plugin version, software-version section, closed health states, and schedule states from the support snapshot. Do not send payment payloads, request bodies, production database exports, raw shopper identifiers, passwords, secret keys, tokens, or license keys.
