Reycob Form Firewall

Reycob Form Firewall

Details
View on WordPress

Reycob Form Firewall adds a lightweight protection layer for public forms without using an external CAPTCHA service.

Main features:

  • Local math CAPTCHA loaded only when the visitor interacts with the checkbox.
  • Browser proof token, honeypot field, and origin validation for protected forms.
  • Rate limits per visitor and per endpoint.
  • Specific protection for WooCommerce product reviews against links, duplicated spam, and repeated abusive submissions.
  • Automatic exclusions for WooCommerce cart, checkout, payments, coupons, shipping, Store API, REST API, webhooks, cron, and server-to-server requests.
  • Admin settings for limits, CAPTCHA, browser proof mode, IP source, and excluded paths.
  • Developer opt-out with data-rffw-skip="1" and opt-in for custom admin-post or admin-ajax actions through the rffw_protected_actions filter.

The plugin is designed for visible public forms. It does not modify global fetch or XMLHttpRequest, does not call third-party APIs, and does not log IP addresses or submitted form contents.

The JavaScript and CSS files distributed with the plugin are the human-readable source files. No minification, bundling, compilation, npm, webpack, or other build step is required.

Privacy

The plugin does not collect analytics, does not send data to external services, and does not store submitted form contents.

Temporary tokens and hashed rate-limit keys may be stored in WordPress transients to validate CAPTCHA challenges, browser proof checks, and request frequency. These temporary values expire automatically.

Details

Plugin code:
reycob-form-firewall
Plugin version:
1.3.3
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-09-07
Rating:
Times rated:
0
captcha
forms
login-security
spam-protection
woocommerce