Linux 软件免费装
Banner图

Carticy Checkout Shield for WooCommerce

开发者 carticy
alikhallad
更新时间 2026年1月25日 20:16
捐献地址: 去捐款
PHP版本: 8.0 及以上
WordPress版本: 6.9
版权: GPLv2 or later
版权网址: 版权信息

标签

security woocommerce checkout fraud bot protection

下载

1.0.0

详情介绍:

Carticy Checkout Shield stops card testing attacks and fake orders that bypass your CAPTCHA. Card testing bots don't fill out your checkout form. They send requests directly to WooCommerce's Store API, completely skipping any reCAPTCHA or hCaptcha you've set up. That's why CAPTCHA alone doesn't stop them. This plugin intercepts those API requests and verifies they come from real browser sessions. Automated scripts that can't prove they're human get blocked before WooCommerce processes them. Why This Plugin? Features

安装:

  1. Upload the plugin files to /wp-content/plugins/carticy-checkout-shield-for-woocommerce/
  2. Activate the plugin through the 'Plugins' menu in WordPress
  3. That's it. Protection is active immediately.
Optional: Go to WooCommerce → Settings → Advanced → Checkout Shield to adjust settings or view blocked attempts. Requirements

屏幕截图:

  • Dashboard widget - Monitor blocked and passed requests
  • Orders column - View shield status for each order

常见问题:

Does this slow down checkout?

No. Validation happens locally in microseconds. No external API calls, no waiting on third-party services.

Will this block real customers?

Very unlikely. The default Balanced mode is tuned to avoid blocking legitimate orders. If you're cautious, start with Learning mode - it logs what would be blocked without actually blocking anyone.

Does it work with Block Checkout?

Yes. Works with both classic checkout and the newer block-based checkout.

What about PayPal, Stripe, and other payment gateways?

All major gateways work normally. Payment confirmations from gateways aren't affected by checkout validation.

I run a headless store. Will this break my setup?

Not if you configure it. Add your frontend's server IP to the whitelist, or use API key authentication. Both options let legitimate automated requests through.

Do I still need CAPTCHA?

Up to you. This plugin catches bots that CAPTCHA misses (the ones hitting your API directly). You can use both, or drop CAPTCHA entirely and reduce checkout friction.

How do I know it's working?

Check the Activity Log in the plugin settings. You'll see every blocked attempt with the reason, timestamp, and IP address.

更新日志:

1.0.0