Noventum Fake Order Protection helps WooCommerce stores reduce fake checkout activity, repeated failed payment attempts, and automated order abuse.
The plugin monitors checkout traffic across both WooCommerce Store API requests and the classic WooCommerce AJAX checkout flow. This helps protect stores using Checkout Blocks, traditional checkout templates, and payment gateways that rely on different checkout request methods.
Protection is built from several lightweight layers:
- Rate limiting for repeated checkout and cart requests.
- A hidden honeypot field for simple bot detection.
- Checks for suspicious user agents.
- Origin and referer validation for checkout requests.
- Failed payment retry tracking.
- Repeated order amount pattern detection.
- Temporary IP blocking for abusive activity.
- Optional Google reCAPTCHA v3 verification for higher-risk attempts.
When suspicious activity is detected, the plugin can rate-limit the request, require reCAPTCHA verification when enabled, or temporarily block abusive IP activity. Normal checkout traffic can continue without adding friction for every customer.
Administrators can configure the protection mode, reCAPTCHA keys, block duration, trusted API bypass settings, and logging options from the plugin settings page. The plugin also includes basic logs and a blocked IP list so store owners can review protection activity and manually remove blocked IPs when needed.
This plugin does not create fake orders. It is designed to help reduce fake or abusive order attempts in WooCommerce stores.
If you find this plugin useful, you can support ongoing development with a
voluntary donation.
For stores that need help with setup, troubleshooting, or custom WooCommerce protection rules, Noventum can provide optional support and customization services.