LightningByrd

WooCommerce plugins · by store operators

Catch card-testers. Kill coupon abuse. Hear your store break.

Four single-purpose plugins that keep WooCommerce stores safe, fast, and watched, built by the team that runs production stores, not a plugin farm. No SaaS behind them, no telemetry, and every one ships safe by default.

  • Safe by default, observe first
  • No telemetry, data stays on your site
  • GPL-2.0 licensed
  • 60-day money-back guarantee

The catalog

Four plugins, one enemy: the failure you don't see.

Silent checkout breakage, card-testing bursts, leaked coupon codes, database bloat, the expensive problems are the quiet ones. Each plugin takes one of them off your plate.

Best value

The Storm Kit

All three paid plugins, the full defensive perimeter for one store. Pulse, IP Shield, and Coupon Fence on one license, plus every WooCommerce plugin we ship next while it’s active. Featherweight is free for everyone, always.

Pulse markIP Shield markCoupon Fence mark
$119/yr

Save $38 vs. buying separately

How buying works today: secure online checkout is coming soon. Until it lands, click Buy and tell us which plugin you want, we deliver the plugin zip and an invoice by email within one business day, covered by the same 60-day guarantee.

The house rule

Safe by default. Armed when you say so.

A protection tool that guesses wrong on day one costs you real orders. So every Lightningbyrd plugin activates in a mode that records what it would do, and enforces nothing until you've seen a week of receipts and armed it yourself.

Pulse mark

Pulse

Observe mode by default

Activation records events and sends nothing. No email or webhook leaves the site until alerts are explicitly armed, so you calibrate against real traffic before a single notification fires.

IP Shield mark

IP Shield

Dry-run by default

Fresh installs start in Easy Mode with dry-run ON, activating the plugin never enforces anything until you say so. The velocity rule also ships in dry-run, so you see what it would ban before arming it.

Coupon Fence mark

Coupon Fence

Log-only by default

Activation never blocks a shopper or sends an email until you explicitly switch to Enforce. The Activity tab shows would-block verdicts in Log-only, a week of receipts before you enforce anything.

Featherweight mark

Featherweight

Dry-run by default

Every cleanup only reports what it would delete until you untick dry-run. Plus hard-coded guarantees: nothing younger than its retention, pending jobs sacred, and orders, products, customers and users never touched at all.

Built by operators

Born on a production store, not a whiteboard.

IP Shield started life ending a real card-testing incident on a production WooCommerce store we run, and it’s armed on that store right now. The rest of the suite came from the same place: problems we hit operating stores, researched across operator forums and public issue trackers, then solved properly.

  • Every claim on these pages is honest, no fabricated reviews, no invented install counts, no named-competitor trash talk.
  • Every plugin ships with its manual inside wp-admin, a real changelog, and unit tests that run green before release.
  • Need it installed, tuned, or watched for you? The same team builds and maintains WooCommerce stores for a living.

60-day money-back guarantee

Full refund within 60 days of purchase. No questions, no forms, no hard feelings. If a plugin isn’t the right fit for your store, you shouldn’t pay for it.

What's next

Coming soon: the same care, for all of WordPress.

Three plugins in research and development right now, same brand rules: single-purpose, safe by default, no SaaS strings.

Crawl Fence markIn development

Crawl Fence

AI crawler control

AI crawlers now make up a meaningful share of most sites' traffic, and WordPress gives you no way to see it. Crawl Fence keeps a ledger of every bot that visits, then lets you decide, bot by bot, who gets in, who slows down, and who gets the gate. Observe mode first, always.

Tick markResearching

Tick

wp-cron watchdog

Half of WordPress runs on a clock that only ticks when someone visits your site, and when it stops, nothing tells you. Tick watches every scheduled job, learns its rhythm, and alerts you the moment one goes quiet. No SaaS account, no per-job setup.

Hush markResearching

Hush

admin-notice quarantine

Your dashboard shouldn't be a billboard. Hush moves plugin ads and review begs into a quiet inbox you check on your terms, and refuses, on principle, to hide real security warnings or to ever show you an ad of its own.

Questions

The suite, straight answers.

How does buying work before your checkout launches?

Click Buy on any plugin and send us the contact form, we deliver the plugin zip and an invoice by email within one business day. Every purchase is covered by the 60-day money-back guarantee, and Featherweight is a free direct download today.

What does a license include?

One year of updates and support for one site, at the listed price. The plugins are GPL-2.0 licensed and keep working if you don't renew, renewal covers continued updates, compatibility, and support.

Do you offer 5-site or agency licenses?

Yes, multi-site licensing is available at roughly 2× the single-site price. Tell us how many stores you run and we'll sort you out.

Will these plugins slow my store down?

No measurable effect, by design. Each plugin is single-purpose: cached lookups, indexed queries, no external calls, and zero JavaScript on your checkout. The exact performance notes are on every product page.

Do the plugins send my data anywhere?

No. There is no SaaS behind them, no telemetry, no accounts, and no API keys. Everything, events, bans, logs, scans, is stored in your own database and pruned on retention windows.

Why do they all start in observe / dry-run mode?

Because a protection tool that guesses wrong on day one costs you real orders. Every Lightningbyrd plugin records what it would do against your real traffic first, and enforces only when you explicitly arm it.

Do they work together?

They're built as a suite: Pulse detects a failed-order spike, IP Shield bans the source, Coupon Fence guards the coupons the attacker probes next, and Featherweight keeps the database they all write to lean. Each also stands completely alone.

What about the block-based (Store API) checkout and HPOS?

All four are classic + block checkout aware and HPOS compatible, orders are only ever read through WooCommerce's supported APIs.

Ready when you are

Put a bird on the wire.

Start free with Featherweight, or take the Storm Kit for the full perimeter. Either way, you're covered by the 60-day no-quibble guarantee.