Sohoj Secure Order
A secure customer order management plugin with fraud detection and order prevention features.
by WebDevArif · github.com/webdevarif/sohojsecureorder · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/webdevarif/sohojsecureorder/archive/refs/heads/main.zipSohoj Secure Order - WordPress Plugin
Version: 1.0.5
A comprehensive WordPress plugin for secure customer information validation with advanced fraud detection, VPN blocking, phone validation, and repeat validation prevention. Built with OOP architecture, license key validation, and automatic update checking from GitHub.
Features
Core Features
- OOP Architecture: Well-organized object-oriented PHP code structure
- License Management: Secure license key validation and activation
- Auto Updates: Automatic update checking from GitHub repository
- Security Features: Advanced fraud detection and prevention
- Database Integration: Custom database tables for leads and settings
- Security: Nonce verification, data sanitization, and proper validation
Security Features
- Phone Validation: Require 11-digit phone numbers for validation
- VPN Blocking: Block validation requests from VPN connections
- Fraud Detection: Auto-block suspicious browsers/IPs
- Incomplete Lead Tracking: Save leads from incomplete validations
- Repeat Validation Blocking: Block repeat validations by time/limit per phone
- Phone History: View previous validation history by phone number
- IP Blocking: Block specific IP addresses and phone numbers
Admin Features
- Dashboard: Overview of security features and quick actions
- Security Settings: Configure all security features
- Phone History: Search and view validation history by phone number
- Settings Panel: Configure notifications and general settings
- License Management: Activate and manage plugin license
- Update Notifications: Automatic update notifications
- AJAX Integration: Smooth admin interface with AJAX functionality
Public Features
- Security Validation Forms: Frontend customer information validation
- Phone Validator: Standalone phone number validation
- Responsive Design: Mobile-friendly forms and interfaces
- Email Notifications: Automatic email notifications for security events
- Security Validation: Real-time security checks on validation submission
Installation
- Upload the plugin files to
/wp-content/plugins/sohoj-secure-order/ - Activate the plugin through the 'Plugins' screen in WordPress
- Go to 'Sohoj Secure Order' > 'License' to enter your license key
- Configure security settings in 'Sohoj Secure Order' > 'Security Settings'
Usage
Shortcodes
Security Validation Form
[sohoj_security_form show_phone="yes" show_email="yes" show_name="yes"]
Phone Validator
[sohoj_phone_validator]
Admin Interface
- Dashboard: Overview of security features and quick actions
- Security Settings: Configure all security features
- Phone History: Search and view validation history by phone number
- Settings: Configure general settings and notifications
- License: Manage plugin license
Configuration
License Setup
- Navigate to 'Sohoj Secure Order' > 'License'
- Enter your license key
- Click 'Activate License'
Security Configuration
- Go to 'Sohoj Secure Order' > 'Security Settings'
- Configure:
- Phone validation (11-digit requirement)
- VPN blocking
- Fraud detection
- Incomplete lead tracking
- Repeat validation blocking (time/limit)
- IP and phone number blocking
Update Configuration
The plugin automatically checks for updates from the configured GitHub repository using the WordPress GitHub Plugin Updater. Update the repository URL in the GitHub_Updater configuration if needed.
File Structure
sohoj-secure-order/
├── sohoj-secure-order.php # Main plugin file
├── includes/
│ ├── Core/
│ │ ├── Plugin.php # Main plugin class
│ │ ├── License_Manager.php # License management
│ │ ├── GitHub_Updater.php # GitHub-based update checking
│ │ ├── Activator.php # Plugin activation
│ │ ├── Deactivator.php # Plugin deactivation
│ │ └── Uninstaller.php # Plugin uninstallation
│ ├── Admin/
│ │ ├── Admin.php # Admin functionality
│ │ └── Settings.php # Settings management
│ └── Public/
│ └── Public_Frontend.php # Public functionality
├── assets/
│ ├── css/
│ │ ├── admin.css # Admin styles
│ │ └── public.css # Public styles
│ └── js/
│ ├── admin.js # Admin JavaScript
│ └── public.js # Public JavaScript
└── README.md # This file
Database Tables
The plugin creates the following database tables:
wp_sohoj_incomplete_leads
id: Primary keycustomer_name: Customer namecustomer_email: Customer emailcustomer_phone: Customer phoneip_address: Client IP addressuser_agent: Browser user agentcreated_at: Creation timestamp
wp_sohoj_settings
id: Primary keysetting_key: Setting keysetting_value: Setting valuecreated_at: Creation timestampupdated_at: Last update timestamp
API Endpoints
AJAX Endpoints
Public Endpoints
sohoj_validate_customer: Validate customer informationsohoj_check_security_status: Check security status for phone number
Admin Endpoints
sohoj_save_settings: Save plugin settingssohoj_activate_license: Activate license keysohoj_deactivate_license: Deactivate license key
Security Features
Phone Validation
- Requires exactly 11 digits for phone numbers
- Validates format:
[0-9]{11} - Example:
01712345678
VPN Blocking
- Detects common VPN IP ranges
- Blocks suspicious user agents
- Prevents validation from VPN connections
Fraud Detection
- Rate limiting (max 10 requests per hour per IP)
- Bot/crawler detection
- Suspicious user agent blocking
- IP range checking
IP Blocking
- Block specific IP addresses
- Block IP ranges (CIDR notation)
- Block phone numbers
- Configurable blocking lists
Repeat Validation Blocking
- Configurable blocking time (1-720 hours)
- Blocks repeat validations from same phone
- Time-based blocking after last validation
Incomplete Lead Tracking
- Saves customer information even if validation incomplete
- Stores IP address and user agent
- Tracks validation attempts for analysis
Development
Adding New Security Features
- Add the feature to the
perform_security_checks()method inPublic_Frontend.php - Add corresponding settings in
Settings.php - Update the admin interface to configure the feature
- Add any necessary database fields
Customizing Security Rules
The plugin provides a flexible framework for adding custom security rules:
// Example: Add custom security check
private function custom_security_check($form_data) {
// Your custom logic here
return ['success' => true];
}
Support
For support and updates, please visit the GitHub repository or contact the plugin author.
License
This plugin is licensed under the GPL v2 or later.
Changelog
Version 1.0.0
- Initial release
- Security validation functionality
- Phone validation (11-digit requirement)
- VPN blocking
- Fraud detection
- IP and phone blocking
- Repeat validation blocking
- Incomplete lead tracking
- License management
- Automatic updates from GitHub