WooCommerce Protection (Pro) adds rate limits and coupon brute-force protection for WooCommerce stores. It sits under Security Ninja → Firewall → WooCommerce. Cloud Firewall should be enabled for full enforcement with the rest of the firewall stack.
What it covers
- Rate limiting: checkout attempts, add-to-cart actions, and order placement
- Coupon abuse: temporary ban after too many invalid coupon tries
- Country blocking: when country rules apply to login forms, WooCommerce login and registration are included
Blocked attempts are logged in Security Ninja → Events (search for woo_ related actions).
Rate limiting defaults
| Action | Default limit | Default window |
|---|---|---|
| Checkout | 3 attempts | 5 minutes (300 seconds) |
| Add to cart | 10 actions | 1 minute (60 seconds) |
| Order placement | 2 orders | 10 minutes (600 seconds) |
When a limit is hit, WooCommerce shows an error (checkout may send the customer back to the cart). Adjust the numbers to match a busy store versus a quiet one.
Coupon brute-force protection
Defaults: 3 failed coupon attempts within 3 minutes (180 seconds) → ban coupon use for that IP for 15 minutes (900 seconds).
- Works with classic forms, AJAX, and WooCommerce block cart/checkout.
- A valid coupon clears the failure counter.
- Ban messages include remaining time; normal use resumes when the ban ends.
Configuration
- Go to Security Ninja → Firewall → WooCommerce.
- Enable rate limiting and/or coupon protection.
- Set limits, windows, and ban duration.
- Save settings.
- Place a test order and apply a valid coupon to confirm normal shoppers are unaffected.
If real customers are blocked, raise the limits and review Events for false positives.

