Compatibility · Evidence first
Transparent status—without guessing about gateways.
Core WooCommerce surfaces have exact-package evidence. Specific live gateways and checkout replacements remain unverified until their exact integrations are tested.
| Surface | Status | Notes |
|---|---|---|
| Classic WooCommerce checkout | Qualified | Normal Classic Checkout passed exact-package browser and integration evidence. |
| WooCommerce Checkout Blocks | Qualified | Blocks checkout passed exact-package browser and integration evidence. |
| WooCommerce Store API checkout | Qualified | Exact protected checkout routes passed integration and response-contract evidence. |
| High-Performance Order Storage | Compatible | Compatibility is declared and lifecycle/order metadata paths are HPOS-aware. |
| Local browser challenge | Qualified | Bundled account-free challenge passed runtime, packaging, and latency evidence. |
| Cloudflare Turnstile | Qualified | Conditional rendering, server verification, fallback, and privacy boundaries were tested without a real payment. |
| Google reCAPTCHA v2 | Qualified | Conditional rendering, server verification, fallback, and privacy boundaries were tested without a real payment. |
| Legacy Classic order-pay | Not protected | Documented version 1 limitation; WooCommerce authorization remains, but Checkout Firewall does not evaluate this endpoint. |
| Specific live payment gateways | Not yet tested | No real transaction was run; no gateway-specific compatibility claim is made. |
| Checkout replacement plugins | Not yet tested | Compatibility varies by implementation. |
Version 1.0.0 · Available on WordPress.org
Put a control between checkout abuse and your payment gateway.
Install the complete Free edition from the official WordPress.org Plugin Directory. New installations begin safely in Observe Mode.