Title: Reycob Form Firewall
Author: Victor Rodriguez
Published: <strong>7 setembro, 2026</strong>
Last modified: 7 setembro, 2026

---

Pesquisar plugins

![](https://ps.w.org/reycob-form-firewall/assets/banner-772x250.png?rev=3684157)

![](https://ps.w.org/reycob-form-firewall/assets/icon-256x256.png?rev=3684157)

# Reycob Form Firewall

 Por [Victor Rodriguez](https://profiles.wordpress.org/reycob38/)

[Baixar](https://downloads.wordpress.org/plugin/reycob-form-firewall.1.3.3.zip)

 * [Detalhes](https://br.wordpress.org/plugins/reycob-form-firewall/#description)
 * [Avaliações](https://br.wordpress.org/plugins/reycob-form-firewall/#reviews)
 *  [Instalação](https://br.wordpress.org/plugins/reycob-form-firewall/#installation)
 * [Desenvolvimento](https://br.wordpress.org/plugins/reycob-form-firewall/#developers)

 [Suporte](https://wordpress.org/support/plugin/reycob-form-firewall/)

## Descrição

Reycob Form Firewall adds a lightweight protection layer for public forms without
using an external CAPTCHA service.

Main features:

 * Local math CAPTCHA loaded only when the visitor interacts with the checkbox.
 * Browser proof token, honeypot field, and origin validation for protected forms.
 * Rate limits per visitor and per endpoint.
 * Specific protection for WooCommerce product reviews against links, duplicated
   spam, and repeated abusive submissions.
 * Automatic exclusions for WooCommerce cart, checkout, payments, coupons, shipping,
   Store API, REST API, webhooks, cron, and server-to-server requests.
 * Admin settings for limits, CAPTCHA, browser proof mode, IP source, and excluded
   paths.
 * Developer opt-out with `data-rffw-skip="1"` and opt-in for custom admin-post 
   or admin-ajax actions through the `rffw_protected_actions` filter.

The plugin is designed for visible public forms. It does not modify global `fetch`
or `XMLHttpRequest`, does not call third-party APIs, and does not log IP addresses
or submitted form contents.

The JavaScript and CSS files distributed with the plugin are the human-readable 
source files. No minification, bundling, compilation, npm, webpack, or other build
step is required.

### Privacy

The plugin does not collect analytics, does not send data to external services, 
and does not store submitted form contents.

Temporary tokens and hashed rate-limit keys may be stored in WordPress transients
to validate CAPTCHA challenges, browser proof checks, and request frequency. These
temporary values expire automatically.

## Instalação

 1. Upload the plugin folder to `/wp-content/plugins/reycob-form-firewall/`, or install
    it through the WordPress Plugins screen.
 2. Activate **Reycob Form Firewall**.
 3. Go to **Settings > Form Firewall**.
 4. Review the default limits and clear any page cache/CDN cache after activation.
 5. Test your public contact forms, login, registration, comments, product reviews,
    cart, checkout, and payment flow.

## Perguntas frequentes

### Does it use Google reCAPTCHA or another external service?

No. The CAPTCHA is generated and verified locally by WordPress.

### Does it protect WooCommerce checkout?

No. Checkout, cart, coupons, payment callbacks, shipping calculations, Store API,
and product add-to-cart actions are intentionally excluded so normal store operations
keep working.

### Does it protect WooCommerce reviews?

Yes. Product reviews use the general form protections plus an additional review-
specific spam check.

### Can I exclude a form?

Yes. Add `data-rffw-skip="1"` to the form element. Administrators can also exclude
paths from the settings screen.

### Can developers protect custom AJAX or admin-post actions?

Yes. Use the `rffw_protected_actions` filter to return an array of action names 
that should require the firewall checks.

## Avaliações

Não há avaliações para este plugin.

## Colaboradores e desenvolvedores

“Reycob Form Firewall” é um programa de código aberto. As seguintes pessoas contribuíram
para este plugin.

Colaboradores

 *   [ Victor Rodriguez ](https://profiles.wordpress.org/reycob38/)

[Traduzir o “Reycob Form Firewall” para seu idioma.](https://translate.wordpress.org/projects/wp-plugins/reycob-form-firewall)

### Interessado no desenvolvimento?

[Navegue pelo código](https://plugins.trac.wordpress.org/browser/reycob-form-firewall/),
consulte o [repositório SVN](https://plugins.svn.wordpress.org/reycob-form-firewall/)
ou assine o [registro de desenvolvimento](https://plugins.trac.wordpress.org/log/reycob-form-firewall/)
por [RSS](https://plugins.trac.wordpress.org/log/reycob-form-firewall/?limit=100&mode=stop_on_copy&format=rss).

## Registro de alterações

#### 1.3.3

 * Use WordPress-generated endpoint paths for admin AJAX, admin post, comments, 
   login, REST, XML-RPC, and admin area detection.
 * Move CAPTCHA styles into a human-readable CSS source file and enqueue it normally.

#### 1.3.2

 * Prepared WordPress.org readme, centralized sanitized request reads, and adjusted
   automated review compatibility.

#### 1.3.1

 * Limited protection scope to public forms, login, registration, comments, and 
   WooCommerce product reviews.
 * Excluded WooCommerce cart, checkout, payments, Store API, webhooks, and license/
   API requests.
 * Removed global request interception and added on-demand CAPTCHA loading.

## Meta

 *  Versão **1.3.3**
 *  Última atualização **1 dia atrás**
 *  Instalações ativas **10+**
 *  Versão do WordPress ** 6.0 ou superior **
 *  Testado até **7.1**
 *  Versão do PHP ** 7.4 ou superior **
 *  Idioma
 * [English (US)](https://wordpress.org/plugins/reycob-form-firewall/)
 * Tags
 * [captcha](https://br.wordpress.org/plugins/tags/captcha/)[forms](https://br.wordpress.org/plugins/tags/forms/)
   [login security](https://br.wordpress.org/plugins/tags/login-security/)[spam protection](https://br.wordpress.org/plugins/tags/spam-protection/)
   [woocommerce](https://br.wordpress.org/plugins/tags/woocommerce/)
 *  [Visualização avançada](https://br.wordpress.org/plugins/reycob-form-firewall/advanced/)

## Classificações

Ainda não foi enviada nenhuma avaliação.

[Sua avaliação](https://wordpress.org/support/plugin/reycob-form-firewall/reviews/#new-post)

[Ver todas avaliações](https://wordpress.org/support/plugin/reycob-form-firewall/reviews/)

## Colaboradores

 *   [ Victor Rodriguez ](https://profiles.wordpress.org/reycob38/)

## Suporte

Tem algo a dizer? Precisa de ajuda?

 [Ver fórum de suporte](https://wordpress.org/support/plugin/reycob-form-firewall/)