Compatibility · Evidence first

Transparent status—without guessing about gateways.

Core WooCommerce surfaces have exact-package evidence. Specific live gateways and checkout replacements remain unverified until their exact integrations are tested.

Checkout Firewall compatibility by WooCommerce surface
SurfaceStatusNotes
Classic WooCommerce checkoutQualifiedNormal Classic Checkout passed exact-package browser and integration evidence.
WooCommerce Checkout BlocksQualifiedBlocks checkout passed exact-package browser and integration evidence.
WooCommerce Store API checkoutQualifiedExact protected checkout routes passed integration and response-contract evidence.
High-Performance Order StorageCompatibleCompatibility is declared and lifecycle/order metadata paths are HPOS-aware.
Local browser challengeQualifiedBundled account-free challenge passed runtime, packaging, and latency evidence.
Cloudflare TurnstileQualifiedConditional rendering, server verification, fallback, and privacy boundaries were tested without a real payment.
Google reCAPTCHA v2QualifiedConditional rendering, server verification, fallback, and privacy boundaries were tested without a real payment.
Legacy Classic order-payNot protectedDocumented version 1 limitation; WooCommerce authorization remains, but Checkout Firewall does not evaluate this endpoint.
Specific live payment gatewaysNot yet testedNo real transaction was run; no gateway-specific compatibility claim is made.
Checkout replacement pluginsNot yet testedCompatibility varies by implementation.

Version 1.0.0 · Available on WordPress.org

Put a control between checkout abuse and your payment gateway.

Install the complete Free edition from the official WordPress.org Plugin Directory. New installations begin safely in Observe Mode.