The questions buyers and new owners ask most, answered plainly. If your question isn’t here, search the docs or reach out from the contact page.
Punchwell is a self-hosted WordPress time clock and HR suite. Its flagship feature is a hard-enforced office-IP clock-in lock that blocks off-site and “buddy” punching — it refuses the punch server-side rather than just logging a location. Per site, never per seat; unlimited employees; your data stays on your own server.
Pricing & licensing
Is Punchwell per-seat? What happens when I hire more people?
No per-seat fee, ever. Pricing is per site, not per employee:
- Free / Community — $0 on WordPress.org
- Pro — $99 / year, per site
Every tier includes unlimited employees. Hire your 26th, 50th, or 100th person and your bill doesn’t change. That’s the whole point of per-site pricing — compare it to per-head SaaS clocks, where a 25-person shop pays roughly $1,500–2,100/year (figures approximate, as of June 2026). Full details on the pricing page.
What counts as a “site”?
One WordPress installation on one domain. A Pro license covers that one install with unlimited employees at no extra cost. Multiple locations of one business on a single site are built in — one $99 license covers unlimited offices. Separate businesses you want kept fully independent each take their own Pro license at $99/year. Pricing is per site, never per seat.
Is my renewal price locked?
Yes — as long as you don’t let your license lapse, you renew at the price you signed up at ($99 per site). No introductory-rate-then-surprise-increase routine; no hike at employee #26 or in year three. If you lapse and come back later, you re-join at whatever the current price is, so keeping the license active is what protects your rate.
It’s GPL — do I really own it? Can I self-host freely?
Yes. GPL means the code is genuinely yours: install it on the licensed number of sites, keep your data in your own WordPress database, and never get held hostage by a vendor that disappears — which is exactly what happened to the plugin Punchwell replaces. Your license pays for the Pro features bundle, updates, and support — the same model as most professional WordPress plugins. Your data never phones home; all of the original’s outbound network code was removed and verified, and the only outbound call Pro makes is validating your license key against our own billing server — never your data.
Self-hosting & your data
Self-hosting sounds like a burden. Do I have to manage servers?
No. If you already run a WordPress site, you have everything you need — Punchwell installs like any other plugin. There’s no separate server to manage and no cloud account to set up. “Self-hosted” just means your employee and attendance data lives in your own WordPress database instead of a vendor’s cloud. You’re responsible for the things you already manage for any WordPress site: hosting, backups, and keeping WordPress and your plugins updated.
Where does my data live, and does anything leave my server?
Your data lives in your WordPress database — employees are WordPress users, and timesheets are rows in your tables. Nothing syncs to a vendor cloud: all of the original’s outbound network code was removed and verified, so there is no data call-home: the free version makes no outbound calls at all, and the only outbound call Pro makes is validating your license key against our own billing server, never your data. The only external content is optional, standard WordPress fare — YouTube tutorial embeds (only if you open them) and Gravatar avatars.
Because it’s self-hosted, your data never leaves your server, which helps with privacy obligations. Compliance itself (GDPR, HIPAA, etc.) depends on how you configure and operate your site — it’s your configuration, not a certification we issue.
What is my responsibility as a self-hoster?
The same as for any WordPress plugin you run: maintaining your hosting, taking regular backups, and applying WordPress, PHP, and plugin updates. Punchwell is PHP 8 / WordPress 7 / MySQL 8 clean, so it’s built for current environments. The upside of self-hosting is ownership — there’s no Punchwell cloud that can go down and take your time clock with it, and even if you cancel, the plugin and every record stay on your server.
Updates & support
How long do updates and support last?
For as long as your license is active. Pro includes updates and support while you’re licensed; renew each year and they continue. If you let the license lapse, you keep the version you have (it’s GPL — it’s genuinely yours), you just stop receiving new updates and ticket support until you renew.
Note on update delivery: an in-dashboard update channel is being set up. Until it’s confirmed live, plan on installing updates manually through your WordPress dashboard. [Maintainer: confirm and describe the automatic update channel here once it’s live.]
What does support cover, by plan?
| Free / Community | Pro | |
|---|---|---|
| Documentation at /docs/ | ✓ | ✓ |
| Community / WordPress.org forum | ✓ | ✓ |
| Authenticated ticket support | — | ✓ While your license is active |
| Pro feature updates | — | ✓ |
| Migration guidance | ✓ Self-serve guide | ✓ Self-serve guide + ticket support |
Pro ticket support comes from the people who actually maintain the code — not an outsourced tier-1 script — and covers installation, configuration, the IP-lock and attendance setup, payroll export, and migration questions while your license is active.
[Maintainer: set the specific support channel and response-time target — e.g. email-based ticket support, business-day response — and state it here so expectations are clear.]
How do I open a support ticket?
Ticket support is part of Punchwell Pro. Sign in with your Sturdyhaus account at app.sturdyhaus.com/submitticket and we’ll already have your license and version on hand. On the free version or just evaluating? Use the contact page for pre-sales help and lean on the docs for setup. See the full support page for the fastest path to an answer.
What happens to my data and support access if I let my license lapse?
You keep the plugin and every record — it’s GPL and self-hosted, so nothing is held hostage. You lose ticket support and Pro updates until you renew, and your renewal price stays locked as long as you never lapse.
The product & the IP lock
Is Punchwell affiliated with the original WP Human Resource Management plugin?
No. Punchwell is an independent, third-party maintained fork of the GPL-licensed “WP Human Resource Management” plugin. Sturdyhaus is not affiliated with, endorsed by, or sponsored by wpspear, weDevs, or the original author. We reference the original plugin’s name only descriptively, to help people still running the abandoned version find a maintained alternative. The original was removed from WordPress.org in 2025 and last shipped code around 2019; Punchwell is the hardened, PHP 8–ready continuation — and your data carries over.
Does the IP lock work for remote staff?
Yes — because the lock is per employee, not site-wide. Only the employees you flag as “requires office IP” are restricted; everyone else clocks in from anywhere. So you can lock on-site cashiers to the building while remote staff punch in from home or the road. One setting per employee decides who’s office-only and who isn’t.
When a flagged employee is off-network, Punchwell refuses the punch server-side — it doesn’t merely log a location. The allowlist supports exact IPs, CIDR blocks (like 203.0.113.0/24), and address ranges, in both IPv4 and IPv6, with company-wide, per-office, and per-employee scopes unioned together (adding an entry only ever widens access). You can also choose Block, Warn, or Flag enforcement. See how the IP lock works for setup.
Does Punchwell move money or run payroll?
No — and that’s deliberate. It does the calculation and the export: per-employee pay type and rate, a payout report with weekly and daily overtime, double-time and holiday pay, worker classification (1099/FT/PT), and CSV export, plus SurePayroll and Gusto connectors. It does not move money — no payment processing, no direct deposit, no tax filing, no tax custody. Keeping money movement out means there’s no payment-processor or tax-custody risk for you. You take the payroll-ready CSV to your payroll provider. Details on payroll export.
Does Punchwell work with WordPress Multisite?
No. Punchwell is not designed for WordPress Multisite. Run it on a standard, single-site WordPress installation. Several locations of one business live happily on a single install — multi-location is built into Pro. If you run separate businesses on separate installs, each takes its own Pro license — see pricing.
Billing & refunds
What is your refund policy?
Refund terms are set out at checkout in your Sturdyhaus billing account at app.sturdyhaus.com — review them before you purchase, and reach out from the contact page with any pre-sales question.
A few things worth knowing either way:
- Try before you buy. The free community version on WordPress.org lets you evaluate the base HR suite and the basic single-office IP lock at no cost and no card — a low-risk way to confirm Punchwell fits your shop before upgrading to Pro.
- You’re never locked in. Because Punchwell is GPL and self-hosted, even if you cancel you keep the plugin and every record on your own server. There’s no vendor cloud that can lock you out of your own data.
[Maintainer: state your specific refund window and conditions here (e.g. “30-day money-back guarantee”) and mirror them in your billing terms, so this answer matches checkout exactly.]
What payment methods and billing schedule do you use?
Pro is billed annually (per site) through your Sturdyhaus account at app.sturdyhaus.com. Specific payment methods and invoicing details are shown at checkout.
Trust & security
Is the original plugin’s security problem fixed in Punchwell?
Punchwell addresses the issues behind the public CVEs in the original abandoned plugin — it capability-gates the endpoints that were missing authorization checks, removed the call-home code, and modernized the dead libraries that broke on PHP 8. We don’t claim it’s “unhackable” or “100% secure”; we say it’s security-audited and capability-gated, and that it refuses an off-site punch server-side. For the background on the public CVEs and how this fork addresses each, see the security advisory and security overview.
I think I found a security issue. How do I report it?
Please report it privately rather than in a public forum. Pro holders can open a ticket at app.sturdyhaus.com/submitticket; everyone can reach us from the contact page.
Still have a question?
- Pricing and what fits your shop → Pricing
- Setup and how-to → Docs
- Switching from the old plugin → Migration guide
- Account, billing, and tickets → app.sturdyhaus.com
- Anything else → Contact
Punchwell, by Sturdyhaus. Self-hosted, GPL, no cloud and no data call-home — your data stays on your server.
Punchwell is an independent, third-party maintained fork of the GPL-licensed “WP Human Resource Management” plugin. Sturdyhaus is not affiliated with, endorsed by, or sponsored by wpspear, weDevs, or the original author. Product names are referenced descriptively only. Competitor prices are approximate and current as of June 2026.