A Cron task retries every failed 5xx response.
The same failure keeps opening a new provider call while nobody is watching the dashboard.
Background scope + matching-retry cooldownRetry loops, repeated requests, oversized input or output, an expensive model, or a background job can turn one bug into a fast-growing bill. Pro limits the blast radius by time, request, caller, model, and execution context.
request_retry_circuitA monthly ceiling is a necessary last wall. Pro adds earlier, cause-specific decisions so one malfunction does not get the entire budget to itself.
The same failure keeps opening a new provider call while nobody is watching the dashboard.
Background scope + matching-retry cooldownA form loop or automated visitor repeats the same normalized work faster than a monthly counter explains it.
One-minute velocity + keyed repetition detectionTotal usage can look ordinary while estimated spend changes sharply for one caller and one model.
Per-source budget + provider/model capDeterministic safety rules run before business-aware signals. An absolute hard stop remains the final authority.
Control velocity, request size, repetition, retries, caller, model, and execution context with explicit thresholds.
Use Human, Bot, Unknown, and optional WooCommerce or custom revenue signals to avoid unnecessary interruption of valuable demand.
Receive threshold and incident alerts, keep blocked reasons, export records, and see a recommended response without storing raw conversations.
Every new guardrail is opt-in. Start in Monitoring, review normal behavior, disable or adjust any unsafe rule, and only then switch the global mode to Enforcement.
Rolling one-minute and one-hour limits include conservative reservations for in-flight calls.
Set monthly USD, request, or token budgets for a plugin, mu-plugin, theme, core, or unknown source.
Match canonicalized work using a keyed HMAC-SHA256 digest without persisting raw prompt content.
Block an estimated input that is too large and explicitly block or clamp supported output limits.
Cool down matching retryable failures and use a source-level fallback circuit when exact transport matching is unavailable.
Apply a monthly estimated-USD cap to the resolved provider and model using rates you configure.
Apply guardrails to public, signed-in, administration, or background/Cron/CLI requests.
Free is a dependable sitewide baseline. Pro is for production sites where the cause, speed, and business value of a spike matter.
A block without context creates another emergency. Pro records the operational reason, inferred source, resolved model, context, and conservative usage metadata locally.
Email thresholds for sitewide and per-source limits
Traffic confidence, velocity, action, and recommended response
Optional notifications with an allowlisted, content-minimized payload
Review and export operational evidence without request fingerprints
02:13:18inventory-syncbackgroundrequest_retry_circuit02:13:11support-chatpublicduplicate_request_loop02:12:46product-writeradminmodel_monthly_usdPro is designed to avoid turning a new safety setting into a new outage.
Run supported native AI Client calls and identify normal sources and models.
Add current input and output rates when you need estimated-USD policies.
Enable only the relevant guardrails and leave the global mode in Monitoring.
Review would-block decisions, disable or adjust unsafe rules, then switch the global mode to Enforcement.
Test email delivery; save optional Slack/webhook settings only after checking the destination and payload. Enable Smart Protection when business signals help.
Raw prompts and responses are never persisted. When repetition protection is enabled, selected request fields are canonicalized transiently in memory and only a keyed, non-reversible HMAC-SHA256 digest and operational counters are stored locally.
Privacy details →Token and USD values can be conservative or incomplete estimates. The provider invoice remains authoritative.
Lifecycle accounting plus exact matching-request/retry checks, resolved-model caps, estimated-input checks, and provider-aware supported-output block or clamp before send.
Lifecycle accounting and source-level fallback protection; exact second-stage transport controls may be bypassed.
Calls that bypass the native WordPress AI Client lifecycle are outside the current product scope.
Annual billing is the best value. The same complete Pro feature set is also available month to month.
$99 is charged now and every year until canceled online. One production hostname.
The same complete Pro protection with flexible monthly billing.
Subscribe — $10/month →$10 is charged now and every month until canceled online. No minimum term. One production hostname.
Start with Free →Managing more hostnames? See Agency & Unlimited →Estimated USD uses rates you configure and is not a provider billing cap. Keep provider-side limits as the final backstop.
By continuing to Stripe, you agree to automatic renewal and the Terms · Commercial Disclosure · online cancellation route.
No. Provider limits remain an important final backstop. Pro adds earlier WordPress-side decisions by caller, context, request pattern, and resolved model.
No. Classification is a signal, not certainty, and deterministic or absolute limits can still stop a request. Smart Protection aims to avoid unnecessary interruption of valuable demand.
No raw prompt or response is persisted. Selected fields are processed transiently and only a keyed HMAC-SHA256 digest is stored locally when the feature is enabled.
Saved monthly request, token, and USD limits plus the seven guardrails continue. Smart traffic and revenue decisions, settings changes, early 50/75/90 alerts, seller-hosted downloads and updates, support, and license services pause until access is restored. The 100% alert, emergency stop, CSV export, and data deletion remain available.
No. It uses configured model rates and recorded or reserved usage. The provider invoice is authoritative.