WPCalibrate Access Gate
High-performance, tamper-proof, server-side agreement & verification gate for WordPress and WooCommerce.
by WPCalibrate · github.com/zeeshanraza-official/wpcalibrate-access-gate · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/zeeshanraza-official/wpcalibrate-access-gate/archive/refs/heads/main.zipA high-performance, tamper-proof, server-side agreement and verification gate designed for WordPress and WooCommerce. Protect your site, ensure age & regulatory compliance, and deliver an elegant user experience with zero DOM leaks.
Table of Contents
- About
- Key Features
- Method & Security Architecture
- How to Use & Configuration
- Installation
- Dashboard Updates via GitHub
- Developer Hooks & API
- Frequently Asked Questions (FAQ)
- Changelog
- License & Support
About
Most age verification and consent plugins on WordPress rely solely on client-side JavaScript popups or CSS overlays (display: none; or visibility: hidden;). Anyone with browser Developer Tools (F12) can simply delete the modal element or disable JavaScript in their browser to instantly view sensitive content and pricing.
WPCalibrate Access Gate solves this problem permanently. Built from the ground up by senior WordPress engineers, it intercepts requests on WordPress's early template_redirect hook (priority 9). If a visitor has not consented to your agreement, the protected page HTML is NEVER generated, queried, or sent across the network.
Once a visitor consents, a tamper-proof cryptographic cookie (signed with WordPress AUTH_KEY and HMAC-SHA256) is set, allowing them to browse seamlessly without recurring interruptions for the duration you configure.
Key Features
- 🛡️ Server-Side Gate Interception: Zero DOM leaks. If not accepted, protected content is never sent to the browser.
- 🔐 Cryptographic HMAC-SHA256 Cookie: First-party cookie signed with WordPress core secret salts. Client-side tampering or cookie forgery is detected and rejected immediately.
- 🔄 Instant Agreement Invalidation: Changing the agreement version (e.g. from
1.0to1.1) instantly invalidates all previous visitor cookies globally, requiring re-agreement. - 🎯 Granular Targeting Modes:
- Entire Website: Gate the entire frontend.
- Selected Content: Protect specific page IDs or post IDs.
- Selected Post Types: Protect specific post types (e.g.
product,post,custom_post_type). - Exclusions Override: Explicitly exclude specific IDs (e.g. Privacy Policy, Terms page) even when Entire Site mode is active.
- ⏳ Flexible Cookie Lifespans:
- Browser Session (expires when browser window closes)
- 1 Day
- 7 Days
- 30 Days (Default)
- 90 Days
- 1 Year (365 Days)
- Custom duration (configurable number of days)
- 🚫 Safe Exception Whitelist: Automatically avoids intercepting critical infrastructure:
- WordPress Admin (
/wp-admin/) - Login page (
wp-login.php) - REST API endpoints (
/wp-json/) - WP-Cron (
wp-cron.php) - XML-RPC (
xmlrpc.php) - RSS / Atom Feeds
- Search engine bots (
robots.txt) - WooCommerce Payment Gateway callbacks (
wc-api) & AJAX endpoints (wc-ajax)
- WordPress Admin (
- ♿ WCAG 2.2 AA Accessible & No-JS Fallback:
- High color contrast, visible keyboard focus indicators, screen reader ARIA landmarks.
- Full HTTP POST-Redirect-GET workflow functions 100% without JavaScript enabled.
- 🎨 Modern Design Customizer:
- Centered Modal or Full Screen overlay layouts.
- Brand logo uploader with WordPress Media Library integration.
- Primary accent color, background color, and backdrop blur customization.
- 🧪 Testing & Diagnostic Tools:
- Admin Preview Mode (inspect the gate with secure nonces without locking yourself out).
- One-click "Reset My Consent" button to test first-time visitor experiences.
- In-depth system diagnostics tab (PHP, WordPress, DB versions, HTTPS, cookie parameters).
- 📦 Clean Data Retention Options:
- Preserves settings on plugin deactivation and standard uninstallation by default.
- Optional toggle to completely purge all options upon uninstall if desired.
Method & Security Architecture
Incoming Request
│
▼
Request Eligibility Check (wp-admin, wp-login, REST, Cron, XML-RPC, wc-api)
│───► Eligible for Bypass? ───► ALLOW REQUEST (Normal WP Execution)
▼
Administrator Bypass Check (manage_options active & admin_bypass enabled?)
│───► Admin Bypassed? ───────► ALLOW REQUEST
▼
Targeting Evaluation (Entire Site vs Post Types vs Specific IDs)
│───► Not in Target Scope? ──► ALLOW REQUEST
▼
Consent Cookie Verification (HMAC-SHA256 signature & agreement_version check)
│───► Valid Token? ──────────► ALLOW REQUEST
▼
[INTERCEPT AT template_redirect]
Render Standalone Gate View (HTTP 200 / 403)
Send Anti-Cache Headers (no-store, no-cache, must-revalidate)
exit; (Protected template never executes)
Cookie Specification
- Cookie Name:
wpcalibrate_access_gate_consent - Security Flags:
HttpOnly = true,Secure = is_ssl(),SameSite = Lax - Signing Algorithm: HMAC-SHA256 using
wp_salt('auth') - Verification: Timing-safe
hash_equals() - Payload: URL-safe Base64 encoded JSON containing
{v: version, iat: timestamp, exp: timestamp}
How to Use & Configuration
Step 1: Configure Agreement Content
- Go to WPCalibrate > Access Gate in your WordPress admin menu.
- Select the Content & Actions tab.
- Set your Gate Title, Welcome / Agreement Message, Agreement Details, and Button Labels ("Agree & Continue" / "Decline").
- Configure optional decline redirect URLs or use the built-in standalone Access Denied screen.
Step 2: Define Targeting Scope
- Navigate to the Targeting tab.
- Choose between Entire Website or Selected Post Types (e.g. WooCommerce Products).
- Specify any content IDs to explicitly exclude (such as your Privacy Policy or Contact page).
Step 3: Customize Gate Appearance
- Open the Design tab.
- Upload your company logo using the WordPress Media Library.
- Select your preferred layout: Centered Modal or Full Screen.
- Choose your brand primary accent color and backdrop blur settings.
Step 4: Enable the Gate
- Go to the General tab.
- Toggle Enable Access Gate to ON.
- Select your desired cookie lifespan (e.g. 30 Days or Session).
- Click Save Changes.
Step 5: Test Your Setup
- Click the Preview Gate button in the top action bar to inspect your gate in a new tab.
- Click Reset My Consent to clear your browser's cookie and test the live experience as a first-time visitor.
Installation
Manual Installation
- Download
wpcalibrate-access-gate-1.0.0.zipfrom the Latest Release. - In your WordPress admin dashboard, go to Plugins > Add New > Upload Plugin.
- Choose the downloaded ZIP file and click Install Now.
- Click Activate Plugin.
Git Clone Installation
cd wp-content/plugins/
git clone https://github.com/zeeshanraza-official/wpcalibrate-access-gate.git
Dashboard Updates via GitHub
WPCalibrate Access Gate features native in-dashboard update detection powered by GitHub Releases.
- When a new release is published on GitHub, WordPress will automatically display an update notification under Dashboard > Updates and Plugins.
- Click Update Now to update the plugin with a single click directly from your WordPress admin dashboard.
- Compatible with the standard WordPress Upgrader and GitHub Updater.
Developer Hooks & API
Filters
// Customize whitelisted bypasses
add_filter('wpcalibrate_access_gate_eligible', function(bool $eligible): bool {
if (is_page('special-landing-page')) {
return false; // Bypasses the gate on this page
}
return $eligible;
});
// Filter gate view parameters before rendering
add_filter('wpcalibrate_access_gate_view_data', function(array $data): array {
$data['custom_notice'] = 'Special legal advisory applies.';
return $data;
});
Frequently Asked Questions (FAQ)
Does this slow down my website?
No. The interception runs early before queries or templates execute, reducing server resource consumption for unconsented requests. Assets are only enqueued when the gate is rendered.
Can visitors bypass the gate using Developer Tools (F12)?
No. Unlike JavaScript popups that hide content client-side, protected page HTML is never rendered or sent across the network until the server validates the cryptographic cookie.
Does this work with caching plugins and CDNs (Cloudflare, LiteSpeed, WP Rocket)?
Yes. When the gate is rendered, it sends strict no-store, no-cache, must-revalidate HTTP headers. For edge caching (Cloudflare, Varnish), configure the cache to vary on or bypass the wpcalibrate_access_gate_consent cookie.
Does this affect Google SEO indexing?
Standard bot requests to robots.txt are whitelisted. For public pages that should remain indexable, use the Selected Post Types or Exclusions targeting features.
Changelog
Version 1.0.0 (2026-10-07)
- Initial Release: Production-ready access gate and agreement verification engine.
- Server-Side Interception: Early
template_redirectrequest guard preventing protected content delivery to unconsented visitors. - HMAC-SHA256 Token Engine: First-party cookie signing with WordPress core auth salts and timing-safe signature verification.
- Agreement Versioning: Instant invalidation of prior consent across all visitors when agreement version is bumped.
- Overview & Onboarding Tab: Dedicated interactive guide with live status indicators, purpose breakdown, architecture docs, and 5-step quick setup workflow.
- Targeting Matrix: Entire site, selected content IDs, selected post types, and strict exclusion overrides.
- WooCommerce Compatibility: Native machine endpoint bypasses (
wc-api,wc-ajax, webhooks). - In-Dashboard GitHub Updates: Native update detection for automated updates directly from WordPress admin.
- Responsive Layout Fixes: Symmetrical 2-column Support grid with defensive overflow protection and standard 20×20px admin sidebar logo constraints.
License & Support
- License: GNU General Public License v2.0 or later (GPL-2.0-or-later)
- Author: WPCalibrate
- Email Support: support@wpcalibrate.com
- Marketplace: https://marketplace.wpcalibrate.com/
- Phone / WhatsApp: +447474795976