Pricing
Free today. Pro when it is ready.
Checkout Bouncer pricing is quickly explained. The plugin stops fake orders and card-testing bots at the WooCommerce checkout. The version you can install is the whole plugin. No trial timer, no locked settings, no upsell screen inside the admin.
A Pro tier is in development. It is not on sale, so you will not find a price or a buy button for it on this Checkout Bouncer pricing page. You will find the roadmap and a waitlist.
Two tiers. One of them exists.
Here is the honest position. The free plugin is finished, tested and doing the job on live stores. Pro is a plan. We are not going to charge you for a plan.
Available now
Free
No cost
GPL licensed. Free on WordPress.org.
Every item below is in the plugin you install today. It is not a stripped-down edition of a paid product. It is the product.
- reCAPTCHA v3 scoring on the classic shortcode checkout
- reCAPTCHA v3 scoring on the block checkout, through the WooCommerce Store API
- Pay-for-order protected, and add-payment-method if you want it
- The Checkout Scanner, with one-click Protect or Block on every finding
- Hard-block the Store API checkout route with a 404 or a 403
- Block rogue duplicate checkout pages found elsewhere on the site
- Order-rate throttle per IP, with a monitor mode that logs without blocking
- Per-gateway targeting: all gateways, an include list, or an exclude list
- Staff-role bypass and an IP allowlist that takes IPv4, IPv6 and CIDR
- Events table and dashboard: pass, fail and block counts, top block reasons, CSV export
- Configurable score threshold, and fail-open so orders keep flowing if Google is unreachable
- HPOS and block-checkout compatible
Requires WordPress 6.2 or later, WooCommerce 7.0 or later, and PHP 7.4 or later. You supply free Google reCAPTCHA v3 keys. Setup takes about five minutes. Read the setup guide.
In development
Pro
No price yet
Not for sale. No release date.
Pro will sit on top of the free plugin rather than replace it. Until it is built and tested on real stores, there is nothing to buy and we will not pretend otherwise. This is the plan, labelled as a plan.
Planned, not shipped
- Shared threat-intelligence blocklist across stores
- Agency dashboard covering many sites at once
- Extra fraud rules beyond the current throttle
- Edge blocking via Cloudflare, before the request reaches WordPress
- Alerts and email digests when something spikes
- Longer log retention for the events table
- Priority support
The waitlist is an email address on the support page. No card details, because there is nothing to charge for.
What the free plugin actually does
Detect every route an order can enter the store. Protect the ones that can carry a token. Block the ones that cannot. All of it is in the free version.
The block checkout, properly
The block checkout submits through the Store API and never fires the classic checkout hooks. Several widely-installed captcha plugins still do not check that route, so the owner thinks the shop is covered when it is not. Checkout Bouncer registers Store API endpoint data, so the token travels with the request and the order gets scored.
Every way in, not just the front door
Classic shortcode checkout, block checkout, and pay-for-order links are all scored. Add-payment-method can be switched on as well, which is where card testers often go once the checkout stops paying out.
The Checkout Scanner
Finds the active checkout page, works out what renders it (block, classic shortcode, or Elementor, Divi, WPBakery, Beaver, Bricks or Oxygen), hunts for duplicate and rogue checkout pages elsewhere on the site, checks whether the Store API checkout route is exposed, and flags configuration that silently verifies nothing. See how the scanner works.
Block what cannot be protected
Some routes cannot carry a token. Those you close. Checkout Bouncer can hard-block the Store API checkout route with a 404 or a 403, and block rogue duplicate checkout pages. It never offers to block your store’s own active checkout.
Order-rate throttle
Per IP limits: maximum orders per hour, maximum failed payments per 15 minutes, maximum distinct billing emails per hour. Monitor mode logs what would have been stopped without stopping anything, so you can set the numbers against your own traffic first.
Control, and evidence
Target all gateways or an include or exclude list built from your real gateway list. Let staff roles through. Allowlist IPs by IPv4, IPv6 or CIDR. Then read the events table: pass, fail and block counts, top block reasons, and a CSV export for the day you have to explain a chargeback.
The full breakdown lives on the features page, and what changed in each release is on the changelog.
Checkout Bouncer pricing, free and Pro line by line
The Free column is what Checkout Bouncer pricing means today. The Pro column is a roadmap: nothing in it is available, nothing in it has a date, and nothing in it will ever be taken out of the free plugin to make room.
| Capability | Free (now) | Pro (planned) |
|---|---|---|
| reCAPTCHA v3 on classic shortcode checkout | Yes | Yes |
| reCAPTCHA v3 on block checkout via Store API | Yes | Yes |
| Pay-for-order protection | Yes | Yes |
| Add-payment-method protection (optional) | Yes | Yes |
| Checkout Scanner with one-click Protect or Block | Yes | Yes |
| Page builder detection (Elementor, Divi, WPBakery, Beaver, Bricks, Oxygen) | Yes | Yes |
| Rogue duplicate checkout page detection | Yes | Yes |
| Hard-block the Store API checkout route (404 or 403) | Yes | Yes |
| Order-rate throttle per IP, with monitor mode | Yes | Yes |
| Per-gateway targeting (all, include, exclude) | Yes | Yes |
| Staff-role bypass and IP allowlist (IPv4, IPv6, CIDR) | Yes | Yes |
| Events table, dashboard counts, CSV export | Yes | Yes |
| Configurable score threshold and fail-open | Yes | Yes |
| HPOS (custom order tables) compatible | Yes | Yes |
| Shared threat-intelligence blocklist | No | Planned |
| Agency dashboard across multiple sites | No | Planned |
| Extra fraud rules | No | Planned |
| Edge blocking via Cloudflare | No | Planned |
| Alerts and digests | No | Planned |
| Log retention | Events kept in your own database | Planned: longer retention |
| Support | Community support | Planned: priority support |
| Licence and price | GPL, free | Not on sale yet |
“Planned” means we intend to build it. It is not a commitment to a date, and you should not buy anything on the strength of it, which is convenient, because you cannot.
What Pro is meant to add
Free covers one store’s own checkout. The Pro ideas are all about the things a single store cannot do on its own: seeing what is hitting everybody else, watching many sites at once, and stopping traffic before it costs you a request.
Shared threat intelligence
A blocklist fed by what other protected stores are seeing, so the operation that burned through someone else’s checkout last night arrives at yours already known. Planned.
Agencies and multi-site
One dashboard across every store you look after, instead of logging into thirty admin areas to check thirty events tables. Planned.
Harder rules, and the edge
More fraud rules on top of the throttle, plus edge blocking through Cloudflare so a known attacker never reaches WordPress at all. Alerts, digests and longer retention sit alongside. Planned.
Want to know when Pro is real?
Put your email on the waitlist and we will write once, when there is something you can actually try. No countdown timers, no launch sequence, no card details taken today.
What it does not do, at any price
Worth reading before you install, not after.
- It uses Google reCAPTCHA v3 only. There is no v2 checkbox, no hCaptcha and no Turnstile.
- It protects the checkout. It does not protect login, registration, comments or contact forms.
- You need free Google reCAPTCHA v3 keys. They take a couple of minutes to create.
- It is not a firewall and it is not a malware scanner. It is a doorman on the checkout.
Questions people ask before installing
I already use Cloudflare. Do I need this?
Cloudflare and Checkout Bouncer solve different halves of the problem, and Cloudflare is genuinely better at its half than this plugin will ever be. It is the right tool for volume: floods, layer-7 denial of service, and traffic from known-bad networks, all stopped before it costs your server anything. Checkout Bouncer runs after WordPress has loaded, so every request it judges has already cost you PHP.
What Cloudflare cannot see is your orders. It inspects HTTP requests, so it does not know which gateway was charged, which billing address was used, or whether a request actually created an order. It cannot express the rule that matters most against card testing: this address has placed nine orders with nine different email addresses in the last hour, and seven of them failed authorisation. That information only exists inside WooCommerce.
Rate limiting does not map neatly onto checkouts either. The block checkout posts to the same Store API namespace that real shoppers use for cart updates and shipping recalculation, so a blunt limit there turns customers away before it stops a bot.
There is a pricing reality too. The Cloudflare product that genuinely scores this traffic is Bot Management, an Enterprise feature. Most WooCommerce stores run on the free or Pro plan, where the available bot protection is tuned for crude automation rather than a headless browser on a residential proxy placing a handful of orders an hour.
Run both. Cloudflare for volume, Checkout Bouncer for intent. And note that Cloudflare will never tell you your block checkout is unprotected. The Checkout Scanner will.
What the free version includes
Is the free version limited in any way?
No. There is no trial period, no order cap, no locked settings and no watermark. The reCAPTCHA v3 scoring, the block-checkout support through the Store API, the Checkout Scanner, the blocking, the throttle, the events table and the CSV export are all in the free plugin. It is GPL, so you can read every line of it.
Do I need a Google account?
Yes. Checkout Bouncer uses Google reCAPTCHA v3, so you create a free set of v3 keys for your domain and paste the site key and secret key into the plugin settings. The keys cost nothing. If you would rather not use Google at all, this is not the plugin for you, because v3 is the only engine it supports.
Will it slow my site down or annoy my customers?
Customers see nothing. There are no puzzles and no image grids. reCAPTCHA v3 scores a visitor quietly in the background, which is why the script loads sitewide by default: v3 judges whole-site behaviour, and that is what Google recommends. If you would rather it only ran on checkout screens, that is a setting, and you can narrow it whenever you like.
Does it work with my page builder?
The Checkout Scanner works out what actually renders your checkout: the block checkout, the classic shortcode, or one of six page builders, namely Elementor, Divi, WPBakery, Beaver Builder, Bricks and Oxygen. It then tells you whether that route can carry a token, and offers a one-click Protect or Block on each finding. If a builder page turns out to be a duplicate checkout you forgot about, it flags that too.
Scores, outages and what Pro changes
What happens if Google is unreachable?
You decide. Fail-open is configurable. Leave it on and orders keep flowing when the verification call cannot complete, which is the right choice for most shops, because a checkout that refuses everyone costs more than the odd unscored order. Turn it off if you would rather stop everything than let one bot through. Either way the event is logged.
What score threshold should I use, and will it block real customers?
The threshold is configurable and 0.5 is Google’s own recommendation, so that is the sensible starting point. Watch the events table for a few days: it shows pass, fail and block counts and the top block reasons, so you can see exactly what is being stopped before you tighten anything. The order-rate throttle has a monitor mode as well, which logs without blocking while you settle on your numbers. Staff roles can bypass, and you can allowlist your own IP.
Will features move out of Free and into Pro later?
No. What is in the free plugin stays in the free plugin. It is GPL, and the version you have keeps working whatever happens next. Pro, when it exists, will add things the free version has never done, such as shared threat intelligence and a multi-site dashboard.
When does Pro ship, and what will it cost?
We do not know yet, and we are not going to invent a date or a number to fill this space. Pro is in development. When it is ready to be used by someone other than us, the waitlist hears first. Until then there is nothing on this page to buy.
Install it, then scan your checkout.
Most stores find something in the first scan: a Store API route sitting wide open, or a duplicate checkout page a builder left behind two redesigns ago. It costs nothing to look.
Checkout Bouncer is made by NeoDigify. Questions about Checkout Bouncer pricing before you install? The support page is the place.