Title: Reycob Form Firewall
Author: Victor Rodriguez
Published: <strong>7 de setembre de 2026</strong>
Last modified: 7 de setembre de 2026

---

Cerca extensions

![](https://ps.w.org/reycob-form-firewall/assets/banner-772x250.png?rev=3684157)

![](https://ps.w.org/reycob-form-firewall/assets/icon-256x256.png?rev=3684157)

# Reycob Form Firewall

 Per [Victor Rodriguez](https://profiles.wordpress.org/reycob38/)

[Baixa](https://downloads.wordpress.org/plugin/reycob-form-firewall.1.3.3.zip)

 * [Detalls](https://ca.wordpress.org/plugins/reycob-form-firewall/#description)
 * [Ressenyes](https://ca.wordpress.org/plugins/reycob-form-firewall/#reviews)
 *  [Instal·lació](https://ca.wordpress.org/plugins/reycob-form-firewall/#installation)
 * [Desenvolupament](https://ca.wordpress.org/plugins/reycob-form-firewall/#developers)

 [Suport](https://wordpress.org/support/plugin/reycob-form-firewall/)

## Descripció

Reycob Form Firewall adds a lightweight protection layer for public forms without
using an external CAPTCHA service.

Main features:

 * Local math CAPTCHA loaded only when the visitor interacts with the checkbox.
 * Browser proof token, honeypot field, and origin validation for protected forms.
 * Rate limits per visitor and per endpoint.
 * Specific protection for WooCommerce product reviews against links, duplicated
   spam, and repeated abusive submissions.
 * Automatic exclusions for WooCommerce cart, checkout, payments, coupons, shipping,
   Store API, REST API, webhooks, cron, and server-to-server requests.
 * Admin settings for limits, CAPTCHA, browser proof mode, IP source, and excluded
   paths.
 * Developer opt-out with `data-rffw-skip="1"` and opt-in for custom admin-post 
   or admin-ajax actions through the `rffw_protected_actions` filter.

The plugin is designed for visible public forms. It does not modify global `fetch`
or `XMLHttpRequest`, does not call third-party APIs, and does not log IP addresses
or submitted form contents.

The JavaScript and CSS files distributed with the plugin are the human-readable 
source files. No minification, bundling, compilation, npm, webpack, or other build
step is required.

### Privacy

The plugin does not collect analytics, does not send data to external services, 
and does not store submitted form contents.

Temporary tokens and hashed rate-limit keys may be stored in WordPress transients
to validate CAPTCHA challenges, browser proof checks, and request frequency. These
temporary values expire automatically.

## Instal·lació

 1. Upload the plugin folder to `/wp-content/plugins/reycob-form-firewall/`, or install
    it through the WordPress Plugins screen.
 2. Activate **Reycob Form Firewall**.
 3. Go to **Settings > Form Firewall**.
 4. Review the default limits and clear any page cache/CDN cache after activation.
 5. Test your public contact forms, login, registration, comments, product reviews,
    cart, checkout, and payment flow.

## PMF

### Does it use Google reCAPTCHA or another external service?

No. The CAPTCHA is generated and verified locally by WordPress.

### Does it protect WooCommerce checkout?

No. Checkout, cart, coupons, payment callbacks, shipping calculations, Store API,
and product add-to-cart actions are intentionally excluded so normal store operations
keep working.

### Does it protect WooCommerce reviews?

Yes. Product reviews use the general form protections plus an additional review-
specific spam check.

### Can I exclude a form?

Yes. Add `data-rffw-skip="1"` to the form element. Administrators can also exclude
paths from the settings screen.

### Can developers protect custom AJAX or admin-post actions?

Yes. Use the `rffw_protected_actions` filter to return an array of action names 
that should require the firewall checks.

## Ressenyes

No hi ha ressenyes per a aquesta extensió.

## Col·laboradors i desenvolupadors

«Reycob Form Firewall» és programari de codi obert. La següent gent ha col·laborat
en aquesta extensió.

Col·laboradors

 *   [ Victor Rodriguez ](https://profiles.wordpress.org/reycob38/)

[Traduïu «Reycob Form Firewall» a la vostra llengua.](https://translate.wordpress.org/projects/wp-plugins/reycob-form-firewall)

### Interessats en el desenvolupament?

[Navegueu pel codi](https://plugins.trac.wordpress.org/browser/reycob-form-firewall/),
baixeu-vos el [repositori SVN](https://plugins.svn.wordpress.org/reycob-form-firewall/),
o subscriviu-vos al [registre de desenvolupament](https://plugins.trac.wordpress.org/log/reycob-form-firewall/)
per [fisl de subscripció RSS](https://plugins.trac.wordpress.org/log/reycob-form-firewall/?limit=100&mode=stop_on_copy&format=rss).

## Registre de canvis

#### 1.3.3

 * Use WordPress-generated endpoint paths for admin AJAX, admin post, comments, 
   login, REST, XML-RPC, and admin area detection.
 * Move CAPTCHA styles into a human-readable CSS source file and enqueue it normally.

#### 1.3.2

 * Prepared WordPress.org readme, centralized sanitized request reads, and adjusted
   automated review compatibility.

#### 1.3.1

 * Limited protection scope to public forms, login, registration, comments, and 
   WooCommerce product reviews.
 * Excluded WooCommerce cart, checkout, payments, Store API, webhooks, and license/
   API requests.
 * Removed global request interception and added on-demand CAPTCHA loading.

## Meta

 *  Versió **1.3.3**
 *  Darrera actualització **fa 22 hores**
 *  Instal·lacions actives **Menys de 10**
 *  Versió del WordPress ** 6.0 o posterior **
 *  Provada fins a **7.1**
 *  Versió del PHP ** 7.4 o posterior **
 *  Idioma
 * [English (US)](https://wordpress.org/plugins/reycob-form-firewall/)
 * Etiquetes
 * [captcha](https://ca.wordpress.org/plugins/tags/captcha/)[forms](https://ca.wordpress.org/plugins/tags/forms/)
   [login security](https://ca.wordpress.org/plugins/tags/login-security/)[spam protection](https://ca.wordpress.org/plugins/tags/spam-protection/)
   [woocommerce](https://ca.wordpress.org/plugins/tags/woocommerce/)
 *  [Vista avançada](https://ca.wordpress.org/plugins/reycob-form-firewall/advanced/)

## Valoracions

Encara no s'ha enviat cap ressenya.

[La vostra ressenya](https://wordpress.org/support/plugin/reycob-form-firewall/reviews/#new-post)

[Visualitza totes les ressenyes](https://wordpress.org/support/plugin/reycob-form-firewall/reviews/)

## Col·laboradors

 *   [ Victor Rodriguez ](https://profiles.wordpress.org/reycob38/)

## Suport

Teniu quelcom a dir? Necessiteu ajuda?

 [Visualitza els fòrums de suport](https://wordpress.org/support/plugin/reycob-form-firewall/)