Detection Rules
- Detection mode – Block (cancel suspicious orders) or Monitor (flag, note and alert without touching the order status)
- Unknown origin detection – flag orders placed outside the standard checkout flow
- Linked to known fraud – tie a new order to a recent fraud order that shares the billing email, the ship-to address, or (within an hour) the IP
- Repeated payment failures – failed payments counted per visitor (checkout session and IP) over a rolling 24 hours; an admin notice from 5 failures, and an optional limit that refuses further checkouts before they reach the gateway
- Auto-ban – temporary, self-expiring IP bans when the failure limit refuses a checkout
- Suspicious amount detection – flag orders matching a known fraudulent amount
- Disposable email detection – bundled list of 8,714 throwaway domains plus your own additions
- IP repeat order detection – track and flag multiple orders from the same IP
- Proxy/VPN detection – identify orders placed through anonymizing services
- Registration protection – refuse sign-ups from banned or blacklisted IPs and from disposable or blacklisted emails, with a per-IP hourly limit
Lists
- IP allowlist – CIDR, IPv4 and IPv6; bypasses every check, never flagged, never banned
- Trusted proxies – the customer address is the connecting address unless it comes through Cloudflare, a proxy on the same host, or a proxy you declare; forged forwarding headers are ignored
- Email, IP and phone blacklists – CIDR and wildcard support, plus a “Block this customer” action on the order screen
Checkout Protection
- Blacklists, bans and the failure limit are enforced before payment on both the classic checkout and the Block Checkout (Store API)
- Classic checkout lock – on a Block Checkout store, the classic checkout’s AJAX endpoints are refused with HTTP 403 before any order or gateway call; card-testing toolkits walk exactly that legacy flow, real customers never do
- Customizable block messages via the
wcaf_checkout_block_messageandwcaf_classic_lock_messagefilters
REST API Hardening
- Block unauthenticated order creation via the WC REST API and the Store API, with a one-click self-test
Automated Fraud Management
- Custom order statuses “Auto Cancelled” and “Cancelled by Stripe”, and a single “Fraud” view on the Orders list
- Stripe decline intelligence – the real decline reason (Radar block, risk level, decline code, card) on the order, with a direct Stripe Dashboard link
- Email alerts with order details and fraud indicators
- Opt-in AbuseIPDB reporting of fraud-order IPs, never customer data
wcaf_suspicious_order_detectedandwcaf_ip_auto_bannedaction hooks for extensibility
Settings & Reporting
- Tabbed settings UI: Detection Rules, Lists, Notifications, Activity Log, Reports
- Activity log of cancelled and flagged orders, and a Reports dashboard with fraud counts, top offenders and requests refused before payment
- Compatible with HPOS and the Block Checkout; automatic updates from GitHub releases







Reviews
There are no reviews yet.