Store API Guard
Rate-limit cart and checkout abuse without breaking shoppers.
Store API Guard is a proposed WordPress plugin — Rate-limit cart and checkout abuse without breaking shoppers. It is not available for download yet — 0 of the 60 votes needed have been cast. Vote to move it forward, or join the waitlist to be emailed on release.
Updated
At a glance
- Status
- Collecting votes
- Votes
- 0 of 60 (60 to go)
- Requirements
- WordPress 6.4+, WooCommerce 8.5+, PHP 8.1+
- Integrations
- WooCommerce Blocks, Cloudflare signals, webhook endpoints
- Pricing
- Pro only · Pro from $39/year
- Build time
- ~7 weeks after threshold
The problem
Automated checkout and Store API traffic can exhaust resources or test stolen cards before generic tools identify the pattern.
Who this WordPress plugin is for
WooCommerce store owners, security teams, and hosts protecting high-volume checkout endpoints.
Store API Guard is a proposed WordPress plugin for WooCommerce store owners, security teams, and hosts protecting high-volume checkout endpoints..
It adds targeted Store API and checkout controls with observability while payment-fraud scoring stays with specialist providers. The WordPress plugin stays deliberately narrow so teams can validate one repeatable job before adding adjacent workflows.
Proposed plugin features
What this WordPress plugin would include in an initial release.
-
Endpoint budgets
Endpoint budgets gives the team a focused, reviewable way to act on this workflow.
-
Pattern detection
Pattern detection gives the team a focused, reviewable way to act on this workflow.
-
Safe exemptions
Safe exemptions gives the team a focused, reviewable way to act on this workflow.
Not in the first release
Kept out of scope on purpose, so the first version ships small and focused.
- Payment fraud scoring
- A general web application firewall
- Bot challenge pages
Concept screens
What happens after you vote
Every draft follows the same path from proposal to release.
-
1
Collecting votes You are here
The community decides whether this plugin gets built.
-
2
Threshold reached
Enough votes — the draft enters the build queue.
-
3
In development
Scope stays close to the published feature list.
-
4
Ready to download
Waitlisted voters are emailed first, with download details.
WooCommerce Blocks, Cloudflare signals, webhook endpoints
WordPress 6.4+, WooCommerce 8.5+, PHP 8.1+
Pro only · Pro from $39/year
WAF rules, gateway fraud tools, custom reverse-proxy limits
Frequently asked questions
Common questions about this WordPress plugin draft.
What does Store API Guard cover?
It adds targeted Store API and checkout controls with observability while payment-fraud scoring stays with specialist providers.
What is outside the first release?
The first release does not include payment fraud scoring.
Is Store API Guard available to download yet?
No. Store API Guard is a proposed WordPress plugin, not a finished download. It has 0 of the 60 votes needed before development starts.
What does Store API Guard do?
Rate-limit cart and checkout abuse without breaking shoppers. It is a WordPress plugin proposal published on DraftPlugins, where the community votes on which plugins get built.
When will Store API Guard be released?
Estimated build time is ~7 weeks after threshold. Everyone on the waitlist is emailed as soon as it ships.
How much will Store API Guard cost?
Expected pricing: Pro only · Pro from $39/year. Pricing for a draft is indicative and can change before release.
How do I get notified when Store API Guard is ready?
Vote on this page and join the waitlist with your email. We only email you about Store API Guard — release notes and access details.
What does Store API Guard require?
Planned requirements: WordPress 6.4+, WooCommerce 8.5+, PHP 8.1+.