Settings reference

Settings reference

Every setting below can be set from Wynko → Settings, or, if marked “deployable”, via an environment variable or a wp-config.php constant of the same name instead — whichever fits how you deploy. An environment variable can come from your host, a container, or a .env file your hosting stack loads into the environment; Wynko reads it the same way either way, no extra setup required.

Setting Default Bounds Deployable
Cache duration 60 minutes 1–1440 Yes (WYNKO_CACHE_MINUTES)
Log level info error / warning / info Yes (WYNKO_LOG_LEVEL)
Signup rate-limit window 10 minutes 1–1440 Yes (WYNKO_THROTTLE_WINDOW)
Signups per address, per window 15 1–1000 Yes (WYNKO_THROTTLE_IP_MAX)
Signups per form, per window 400 1–100000 Yes (WYNKO_THROTTLE_FORM_MAX)
Critical email alerts off Yes (WYNKO_NOTIFY_ENABLED)
Alert recipients none up to 10 addresses Yes (WYNKO_NOTIFY_EMAILS)

On multisite, add that site’s own blog ID as a suffix to override a setting for one site only, e.g. WYNKO_CACHE_MINUTES_3 for the site whose blog ID is 3 — every site has its own ID (find it under Sites → All Sites), so use whichever ID belongs to the site you’re configuring, not literally _3.

Precedence, highest first: the environment variable or constant for this site, then the one for the network, then the stored option — the same order the API key already uses, applied to everything else. A value the setting can’t take — an unknown log level, a word where a number belongs, an exported-but-empty variable — is ignored rather than applied, so a typo can’t silently reconfigure a site.

Rate limiting

Two limits apply together: a per-address cap (generous, since an office or school can share one IP address) and a much higher per-form cap that acts as a catastrophe backstop rather than a first line of defense — a tight form-wide cap would let one attacker lock out every legitimate signup.

The settings page warns once per form per day when a form’s window crosses 80% of its cap, so you find out before signups start being turned away rather than after.

Critical email alerts

Off until you opt in — an update never starts sending mail on its own. When enabled, an alert email is capped at one per hour per site so a failing sync can’t flood your inbox.

Activity log

Records key checks, connection checks, syncs, and signups. Filterable by level, exportable as a .txt file, and capped at 200 entries — wide enough that a run of automatic syncs can’t push a day-old error off the end. It never records your API key or a submitted email address / field value.