Linux 软件免费装
Banner图

Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing

开发者 carticy
alikhallad
更新时间 2026年3月8日 20:38
捐献地址: 去捐款
PHP版本: 8.0 及以上
WordPress版本: 6.9
版权: GPLv2 or later
版权网址: 版权信息

标签

security woocommerce checkout fraud bot protection

下载

1.1.0 1.0.0

详情介绍:

Checkout Shield stops fake checkout orders and card testing attacks — the kind that bypass your CAPTCHA. Card testing bots don't fill out your checkout form. They hit your store's checkout API directly, completely skipping any reCAPTCHA or hCaptcha you've set up. That's why CAPTCHA alone doesn't stop them. This plugin verifies that every checkout request comes from a real browser session. Bots that can't prove they loaded your checkout page get blocked before WooCommerce processes the order. Why Store Owners Choose This Plugin Features (Free) Pro Features Take control with advanced tools: Learn more about Pro features

安装:

  1. Upload the plugin files to /wp-content/plugins/carticy-checkout-shield-for-woocommerce/
  2. Activate the plugin through the 'Plugins' menu in WordPress
  3. That's it. Protection is active immediately.
Optional: Go to WooCommerce → Settings → Advanced → Checkout Shield to adjust settings. Requirements

屏幕截图:

  • Dashboard widget - Monitor blocked and passed requests
  • Orders column - View shield status for each order

常见问题:

Does this slow down checkout?

No. Validation happens locally in microseconds. No external API calls, no waiting on third-party services.

Will this block real customers?

Very unlikely. The default Balanced mode is tuned to avoid blocking legitimate orders. If you want to be cautious, start with Learning mode — it logs what would be blocked without actually blocking anyone.

Does it work with Block Checkout?

Yes. Works with both classic checkout and the newer block-based checkout.

What about PayPal, Stripe, and other payment gateways?

All major gateways work normally. Payment confirmations from gateways aren't affected by checkout validation.

I run a headless store. Will this break my setup?

Not if you configure it. Add your frontend's server IP to the whitelist, or use API key authentication. Both options let legitimate automated requests through.

Do I still need CAPTCHA?

Up to you. This plugin catches bots that CAPTCHA misses (the ones hitting your API directly). You can use both together, or drop CAPTCHA entirely to reduce checkout friction.

How do I know it's working?

Check the dashboard widget for a quick overview, or go to WooCommerce → Status → Logs and filter by "carticy-checkout-shield" for detailed logs.

更新日志:

1.1.0 1.0.0