Changelog
On this page3 sections
This Checkout Bouncer changelog lists every released version, newest first. Versions follow semantic versioning. The first number changes when something breaks, the second when a feature lands, the third for fixes.
1.0.0August 2026Current
The first release. Everything in this Checkout Bouncer changelog entry ships in version 1.0.0. That release is finished, tested and live on WordPress.org.
Checkout coverage
- Scores the classic shortcode checkout, the block checkout through the WooCommerce Store API, pay-for-order, and optionally add-payment-method.
- Registers its own Store API endpoint data, so the reCAPTCHA token travels with the block checkout request. Your server verifies it before the order exists.
- Verification happens before the order exists, so failed attempts never reach your orders list.
The Checkout Scanner
- Finds the store's active checkout page and identifies what renders it. Block, classic shortcode, or Elementor, Divi, WPBakery, Beaver, Bricks or Oxygen.
- Hunts duplicate and rogue checkout pages elsewhere on the site.
- Checks whether the Store API checkout route answers requests, and flags settings that quietly verify nothing.
- Every finding carries a one-click Protect or Block. The scanner never offers to block the store's own active checkout.
Blocking
- For stores that only use the classic checkout, the plugin hard-blocks the Store API checkout route with a 404 or a 403.
- You can block rogue duplicate checkout pages outright.
- Blocking stands apart from the master switch and from your reCAPTCHA keys. Turning the plugin off does not reopen a route you chose to close.
Rate limiting
- Per IP address: maximum orders per hour, maximum failed payments per 15 minutes, maximum distinct billing emails per hour.
- Monitor mode logs what it would have blocked without blocking anything, so you can tune the limits against real traffic first.
Control and visibility
- Score threshold with a configurable fail-open or fail-closed choice for when Google does not answer.
- Per-gateway targeting, built from the store's real gateway list.
- Staff roles bypass the check so phone orders never get stuck. IP allowlist accepts IPv4, IPv6 and CIDR ranges.
- Event log with verdict, route, reason, score against the threshold, anonymised address and linked order, filterable and exportable to CSV.
- The log anonymises addresses by default. Neither the reCAPTCHA token nor your secret key is ever written to the log.
Compatibility
- WordPress 6.2+, PHP 7.4+, WooCommerce 7.0+.
- Works with HPOS custom order tables and with the block checkout.
- Behind Cloudflare or another reverse proxy, set the
checkout_bouncer_trusted_proxy_headerfilter so the plugin sees the shopper's address rather than your proxy's.
NextUnreleased
Pro remains a plan rather than a release. Nothing on this site sits behind it today, and the free plugin is fully functional. If you want to hear when it lands, the waitlist is on the pricing page.
How to read this Checkout Bouncer changelog
Entries group by release, newest at the top, and each one lists what changed rather than what anyone planned. A version number moves under semantic versioning. The first number marks a breaking change, the second a feature, the third a fix. Every release goes to the plugin page on WordPress.org, which carries its own changelog tab from the plugin readme. If a change alters what shoppers experience at the checkout, the entry says so in the first line. And the setup documentation changes in the same release.