WC Antifraud releases
Multi-layer anti-fraud protection for WooCommerce
Install
The author publishes release zips, so WP-CLI can install straight from GitHub:
wp plugin install https://github.com/prowoos-devs/wc-antifraud/releases/download/v1.12.2/wc-antifraud-1.12.2.zipMulti-layer anti-fraud protection for WooCommerce. Origin verification, repeated-payment-failure detection with optional pre-payment blocking and auto-ban, blacklists and allowlist (email, IP, phone), a bundled disposable-email list, REST API hardening, registration protection, and automated fraud management with a monitor mode and email alerts.
Current Version: 1.12.1 | Released: September 25, 2026
Features
Detection Rules
- Detection mode - Block (cancel suspicious orders) or Monitor (flag, note, and alert without touching the order status; nothing is reported to AbuseIPDB)
- Unknown origin detection - flag orders placed outside the standard checkout flow
- Linked to known fraud - tie a new order to a recent fraud order sharing the billing email, the ship-to address, or (within an hour) the IP; catches the retry with a second card or gateway and the reshipping pattern that gateway verdicts miss
- Repeated payment failures - failed payments are counted per visitor (checkout session and IP) over a rolling 24 hours; from 5 failures an admin notice appears, and an optional limit refuses further checkouts from that visitor before they reach the gateway, on the classic and the Block Checkout alike
- Auto-ban - when the failure limit refuses a checkout, the IP can be banned for a configurable time; bans expire on their own and never touch allowlisted IPs
- Suspicious amount detection - flag orders matching a known fraudulent amount
- Disposable email detection - bundled list of 8,714 throwaway domains (public-domain disposable-email-domains project) plus your own additions
- IP repeat order detection - track and flag multiple orders from the same IP
- Proxy/VPN detection - identify orders placed through anonymizing services
- Registration protection - refuse sign-ups from banned or blacklisted IPs and disposable or blacklisted emails, with a per-IP hourly limit
Lists
- IP allowlist - CIDR supported, IPv4 and IPv6; bypasses every check, never flagged, never banned
- Trusted proxies - the customer address is the connecting address unless it comes through Cloudflare (ranges refreshed daily), a proxy on the same host (detected automatically), or a proxy you declare; forwarding headers from anyone else are ignored, so a bot cannot forge its address. An undeclared public proxy is detected and offered for one-click trust
- Email blacklist - block specific email addresses
- IP blacklist - block IPs with CIDR notation support, IPv4 and IPv6
- Phone blacklist - block phone numbers with wildcard support
- Temporary bans - active auto-bans listed with Unban and Lift-all links
- "Block this customer" - order-screen action that adds the order's email and IP to the blacklists
Checkout Protection
- Blacklists, bans, and the failure limit are enforced pre-payment on both the classic checkout and the Block Checkout (Store API)
- Classic checkout lock - on a store whose checkout page renders the Block Checkout, the classic checkout's AJAX endpoints (
wc-ajax=checkout,wc-ajax=update_order_reviewand their admin-ajax forms) are answered with HTTP 403 before any order or gateway call. No customer of such a store ever sends those requests; card-testing toolkits that walk the legacy flow with one stolen card per fresh IP do. Engages only while the Block Checkout is detected, counts refusals on the Reports tab, and emails an alert at most once an hour. On by default for new installs; stores updating from an earlier version keep it off until they turn it on - Customizable block messages via the
wcaf_checkout_block_messageandwcaf_classic_lock_messagefilters
REST API Hardening
- Block unauthenticated order creation via WC REST API and Store API
- One-click self-test that fires a nonce-less Store API checkout POST at the store and reports who stopped it
Automated Fraud Management
- Custom order statuses: "Auto Cancelled" (plugin detections) and "Cancelled by Stripe" (gateway fraud verdicts)
- Single "Fraud" view on the Orders list gathering every fraud order from both statuses, plus any that a refund has since relabelled Refunded; monitor-mode detections show a gray "Flagged" badge
- Stripe decline intelligence - failed Stripe payments get the real decline reason (Radar block, risk level, decline code, card) as an order note, order meta, and a panel on the order screen with a direct Stripe Dashboard link; Radar-blocked / issuer-fraud-declined orders are auto-marked as fraud (no AbuseIPDB reporting for gateway verdicts)
- Email alerts with order details and fraud indicators
- AbuseIPDB reporting - opt-in reporting of fraud-order IPs to the AbuseIPDB community database (categories: Fraud Orders + Web App Attack), no customer PII ever included
wcaf_suspicious_order_detectedandwcaf_ip_auto_bannedaction hooks for extensibility. The suspicious-order hook receives theWC_Order, an array of reason labels, and a boolean that istrueonly for monitor-mode detections
Settings & Reporting
- Tabbed settings UI: Detection Rules, Lists, Notifications, Activity Log, Reports
- Activity log of cancelled and monitor-flagged orders
- Reports dashboard with fraud summary counts and top offenders
Privacy
WC Antifraud makes two automatic maintenance requests: it checks GitHub for plugin releases (cached for 12 hours) and refreshes Cloudflare's published IP ranges daily. Those requests contain no order or customer data. The plugin overrides WordPress's default HTTP User-Agent so the site URL is not sent; as with any network request, the destination can still observe the server's source IP.
Two optional features send data to outside services:
- AbuseIPDB reporting (Reports tab) sends the customer's IP, the detection reasons, and the order timestamp of orders marked as fraud to abuseipdb.com. It never sends names, contact details, or order contents.
- Usage reports (Notifications > Privacy, asked once after activation) send one pseudonymous report a day to prowoos.com containing only: a random install ID (never your site address); plugin, WordPress, WooCommerce, and PHP versions and the site locale; whether HPOS, the Block Checkout, and Order Attribution are in use; which rules are on and the detection mode; whether Cloudflare or a proxy was detected; and yesterday's event counts (orders marked by reason, monitor flags, checkouts refused by reason, REST blocks, repeated-failure alerts, auto-bans, bans lifted by hand, "Block this customer" uses, fraud orders un-marked by an admin). The report payload never contains emails, IP addresses, order details, URLs, or user data. You can stop at any time, and "Delete my data" asks the receiver to remove everything stored for your install ID.
Requirements
- WordPress 5.8+
- WooCommerce 5.0+
- PHP 7.4+
Installation
- Upload the
wc-antifraudfolder to/wp-content/plugins/ - Activate the plugin through the WordPress Plugins menu
- Go to the Antifraud menu in wp-admin to configure. A new store starts in Monitor mode; switch to Block once the Activity Log shows only real fraud. Stores that were already installed keep the mode they had.
Development
Version Bump
./dev-tools/version-bump.sh [major|minor|patch] "description"
Updates version in: plugin header, WCAF_VERSION constant, README.md badge, and CHANGELOG.md.
Changelog
See CHANGELOG.md for a detailed history of changes.
License
This plugin is licensed under the GPL v2 or later.
Releases
21 releases. Each count is every asset in that release; expand a row for the breakdown.
Active-site estimate ≈10 comes from the v1.12.0 cohort. Method.