Linux 软件免费装
Banner图

Predax Fraud Guard for WooCommerce

开发者 ipsentry
更新时间 2026年8月19日 05:21
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

woocommerce chargeback fraud prevention vpn detection card testing

下载

1.9.0 1.10.0 1.11.0 1.7.0 1.7.1 1.7.3 1.8.0 1.8.1 1.8.2 1.8.3 1.8.4

详情介绍:

Stop fraudulent WooCommerce orders before they're placed. Card testers, stolen-card fraudsters, and serial chargeback abusers almost always hide behind VPNs, proxies, Tor, or datacenter IPs. Predax Fraud Guard screens the customer's IP the moment they check out, scores its fraud risk from 0 to 100, and lets your store tag, hold, or block the order — before payment is taken and before a chargeback can happen. Think of it as an order guard standing in front of your checkout. You stay in control of every decision: start in tag-only mode to see which orders would have been flagged, then turn on blocking for the risk levels you choose. Screening works with both the classic and block (Store API) checkout. Fully opt-in: on a fresh install the plugin does nothing — no outbound requests are made until you connect a Predax API key (one-click via the setup wizard, or pasted in manually) and pick a protection mode. The default mode once configured is tag-only (no blocking), so you can review flagged orders in your dashboard before turning on anything that rejects a customer. What it stops Why it saves you money Screening runs during WooCommerce checkout validation — before the order is created and before any payment provider is contacted. A blocked attempt therefore never becomes a transaction, a gateway fee, or a chargeback. It works with any gateway, because it does not depend on which one you use, and it complements gateway-side tools such as Stripe Radar: your gateway only ever sees the orders that already passed the IP screen. How It Works
  1. You install and activate the plugin. Nothing happens — the plugin stays dormant until you finish setup.
  2. You connect your site. Click "Connect with Predax" in the 3-step setup wizard — this creates your free Predax account (or logs you into an existing one) and links your API key automatically, with no key to copy or paste. Prefer to do it manually? You can still paste in an existing API key instead.
  3. You pick a protection mode in Fraud Guard → Settings (or in the setup wizard). Choices: Tag + note, Block high risk, or Block critical only.
  4. On each WooCommerce checkout after that point, the plugin sends the customer's IP address to the Predax API, receives back a risk score and signal flags (is_vpn / is_proxy / is_tor / is_datacenter), and tags / holds / blocks the order according to your configuration. Results are cached for between 5 minutes and 1 hour per IP, following the lifetime the API recommends.
You can revoke the API key or switch the mode back to "Tag only" at any time. Risk Tagging Orders that reach the tag threshold (default: risk score 40) are tagged based on band: Features Screening that doesn't cost you real customers or search traffic The real risk of a fraud rule isn't the fraudster it misses — it's the genuine customer it turns away without you ever finding out. A blocked shopper rarely tries again, and a store quietly dropped from search results never learns why. Fraud Guard is built to make both failure modes visible and reversible: Combined with tag-only mode, this means you never have to guess what a rule would do: watch it tag first, turn on blocking when you're confident, and undo any bad block in one click. Defaults All protection toggles default to off on a fresh install. The only thing the plugin writes to options on activation is a database version marker for the events-log table. You will need to explicitly enable any rule you want to apply. Free Tier Click "Connect with Predax" in the setup wizard to create your free account and link your API key automatically — no separate sign-up step, no key to copy or paste. The free plan includes 5,000 IP checks per month with full VPN/proxy/Tor/datacenter detection and risk scoring — no credit card required. More Power With Paid Plans The free tier covers a small store comfortably (checkouts are only checked when they happen, and results are cached). Busier stores use up the included checks faster — paid plans raise the monthly limit from 5,000 up to 25 million IP checks, with higher request rates and bulk lookups. The Fraud Guard settings page shows your live usage each month, so you can see exactly when it's time to upgrade — same plugin, same settings, just a bigger allowance on your existing API key.

安装:

From your WordPress dashboard (recommended)
  1. Make sure WooCommerce is installed and activated.
  2. Go to Plugins → Add New Plugin in your WordPress admin.
  3. Search for "Predax Fraud Guard".
  4. Click Install Now, then Activate.
  5. The Setup Wizard launches on first activation. Either click Connect with Predax for OAuth one-click connection, or enter your API key manually.
  6. Pick a protection preset (Recommended / Strict / Monitor Only). This is the step where you opt in — IP lookups begin after this point.
  7. Fine-tune individual rules at Fraud Guard → Settings any time.
Manual installation
  1. Download the plugin ZIP from this page and upload it via Plugins → Add New Plugin → Upload Plugin (or extract the predax-fraud-guard-for-woocommerce folder to /wp-content/plugins/).
  2. Activate the plugin through the Plugins menu and follow the Setup Wizard.

屏幕截图:

  • The Fraud Rules settings tab: API key, risk thresholds, and per-signal VPN / proxy / Tor / datacenter rules.
  • Order detail: the Predax risk score, flags, and country appear as an order note and order tags.
  • Orders list: the Predax column shows each order's risk score and top threat flag.
  • Advanced rules: order velocity, billing-country mismatch, disposable-email, and timezone checks.
  • Geo blocking: allow, flag, or block checkout by country, region, or IP / CIDR list.
  • Setup Wizard — pick a fraud protection level (Monitor Only, Recommended, or Strict) in one step
  • Events Log filtered by reason — narrow blocked attempts down to a single category, like known-malicious IPs
  • Events Log with one-click allow-listing — approve a genuine customer's IP straight from the log, without editing a settings field

升级注意事项:

1.11.0 The Disposable Email rule now uses a continuously updated list instead of the small built-in one. Only the domain is checked - never the address itself. Also fixes flags being lost during a brief API outage, and a malformed domain briefly pausing IP screening. 1.10.0 The Community Threat Network opt-in now appears in the setup wizard as an explicit, unticked checkbox — still off by default, and nothing is shared unless you tick it. Also fixes a shared-cache issue that could stop Predax Security's crawler policy applying to a checkout visitor. 1.9.0 Fixes one shopper's screening result being reused for a different shopper on the same network, the Events Log reason filter returning nothing on the Flagged tab, and the Blocks checkout not contributing to the Community Threat Network. Also reduces how many checks each visitor costs. 1.8.4 Fixes a daily check limit being reported as the monthly one - the notice claimed screening was paused until the 1st when it actually resumes the same day. Also reduces how much of your allowance each checkout consumes. 1.8.3 Fixes the Monitor Only wizard preset leaving known-malicious IP blocking on, which could reject checkouts despite the preset promising to block nothing. 1.8.2 Adds a one-click option to join the Community Threat Network, so fraudsters blocked at other stores are already known to yours. Entirely optional. 1.8.1 Fixes VPN/proxy shoppers set to Monitor still being blocked when datacenter blocking is enabled, and corrects the signals sent to the Community Threat Network. 1.8.0 Fixes VPN/proxy checkout blocks that happened with both toggles off, and stops verified search engines being caught by category rules. 1.7.4 Fixes VPN/proxy checkout blocks that happened even with both toggles switched off, and which were logged under the wrong reason. Recommended if legitimate orders were being blocked unexpectedly. Safe to upgrade. 1.7.3 Fixes malicious-IP blocking so it actually works (a normalization bug in 1.7.2 silently prevented it from ever triggering), adds specific Events Log messaging, and masks the API key field. Safe to upgrade. 1.7.2 Adds known-malicious IP blocking as its own off-by-default category and a reason filter for the Events Log. No settings are changed automatically. Safe to upgrade. 1.7.1 Adds a live API usage meter, a quota-exhausted notice, and an API circuit-breaker so a slow API can never hang checkouts (timeout lowered 8s to 3.5s). Events Log emails are now stored masked. Screening decisions are unchanged. Safe to upgrade. 1.7.0 IPSentry is now Predax — first WordPress.org release. Your settings, API key, and order data are preserved. Checkout screening is unchanged and still fully opt-in (no outbound requests until you add a key and enable a mode). 1.6.2 WP.org compliance pass: removes self-updater, extracts inline script/style tags, tightens sanitisation, and makes the community-feedback telemetry opt-in (off by default). Core checkout screening is unchanged. Upgrade is safe. 1.6.1 OAuth connect popup now auto-closes reliably after authorization. Per-user OAuth transients prevent conflicts on multi-admin sites. Safe to upgrade — no behaviour changes. 1.6.0 Adds a 3-step setup wizard with One-Click Connect (OAuth) shown on first activation. Existing installs unaffected — the wizard only triggers on fresh activation with no API key. Re-run anytime from Developer → Run Setup Wizard. 1.5.0 Adds Events Log page and risk column on the orders list. Safe to upgrade — no behaviour changes, new DB table created automatically on first load. 1.4.3 Adds a dedicated admin menu page (Predax → Fraud Guard). Safe to upgrade — all existing settings are preserved. 1.4.2 Adds settings import/export and a configurable support email address for block messages. Safe to upgrade — no behaviour changes on upgrade. 1.4.0 Adds order hold, velocity rules, country mismatch detection, disposable email blocking, and chargeback feedback. All new features default to off.

常见问题:

How do I stop a card testing attack that's happening right now?

Enable a blocking mode (the wizard's Recommended preset blocks risk 50 and above), turn on the order velocity rule, and set VPN, proxy and datacenter to Block. Card-testing bots run from datacenter, proxy and VPN addresses, so these rules cut the attack off at the connection. Every blocked attempt is listed in the Events Log, and because screening runs during checkout validation — before the order reaches your payment gateway — a blocked attempt never becomes a transaction, a gateway fee, or a chargeback.

Does it work with Stripe, PayPal, or my payment gateway?

Yes, with any gateway. Screening runs during WooCommerce's own checkout validation, before the order is created and before any payment provider is contacted, so it does not depend on which gateway you use. It complements gateway-side screening such as Stripe Radar: your gateway only ever sees the orders that already passed the IP screen.

How is this different from other WooCommerce anti-fraud plugins?

Most anti-fraud plugins score orders using rules about the order itself — mismatched names, order size, email patterns. Predax Fraud Guard adds the signal those rules can't see: live IP intelligence. It knows whether the customer is connecting through a VPN, proxy, Tor, or a datacenter server right now, backed by a continuously-updated commercial threat database — the same signal used to catch card testing and stolen-card fraud before payment is taken. It works well alongside rule-based fraud plugins and payment-processor screening such as Stripe Radar, and alongside security plugins like Wordfence (which protect your site, not your checkout).

Does the plugin phone home before I finish setup?

No. Before you enter an API key and save a protection mode, the plugin makes zero outbound requests to predax.io. Nothing happens silently on activation.

Will it block legitimate customers?

Only if you enable a blocking mode. Until you complete setup, the mode is Tag only (no blocking — orders just get tags and notes). In the setup wizard, the pre-selected Recommended preset enables blocking of high-risk checkouts (risk score 50+); choose Monitor Only instead if you don't want any blocking yet — each preset card lists exactly what it switches on.

What is the risk score?

A score from 0 to 100 representing how likely an IP is to be associated with fraud, anonymisation, or abuse. 0 = clean residential IP, 100 = the strongest combination of threat signals (for example a known-malicious IP arriving over an anonymised connection). The score combines VPN/proxy/Tor detection, datacenter identification, historical abuse signals, and geographic heuristics.

Does it work with Cloudflare?

Yes — enable Fraud Guard → Settings → Advanced → "Behind a proxy / CDN" (or the same toggle on the WooCommerce → Predax tab). With it on, the plugin reads the real customer IP from the CF-Connecting-IP / X-Forwarded-For headers instead of the Cloudflare edge IP. It is off by default: when your store connects directly to visitors, trusting those headers would let a customer spoof their IP to bypass fraud checks, so you only turn it on when a proxy/CDN really is in front of your site.

How do I test it without affecting real customers?

Fraud Guard → Settings → Developer tab → enter a Test IP Override. Every checkout is then evaluated as if it came from that IP. A red admin banner reminds you test mode is active. Clear the override before going live. Use 185.220.101.1 (risk 85, Tor-adjacent) to exercise blocking paths, or 1.1.1.1 to verify pass-through.

What order metadata is stored?

On each tagged order the plugin stores:

  • _ipsentry_risk_score — numeric risk score (0–100)
  • _ipsentry_ip — detected customer IP
  • _ipsentry_country_code — detected IP country code
  • _ipsentry_flags — comma-separated threat flag list

Does it work alongside the Predax Security plugin?

Yes. The plugins are independent but complementary — Security protects logins and registrations, Fraud Guard protects WooCommerce checkout. Both can share the same API key.

Will this block real customers or hurt my store's SEO?

Search first: verified search engine crawlers — Googlebot, Bingbot and others confirmed by reverse DNS — are never caught by your category rules, on both the classic and the block-based checkout, so screening does not affect how your store is crawled or indexed. For customers, the plugin is built so you never have to guess. Start in tag-only mode and watch what your rules would have done in the Events Log before you enable any blocking. Every screening decision is recorded with its reason, and a good customer caught by an over-strict rule can be allow-listed in one click straight from the log. If your store serves audiences where VPN use is common, prefer Monitor mode for the VPN rule.

更新日志:

1.11.0 1.10.0 Setup wizard 1.9.0 Checkout accuracy 1.8.4 1.8.3 1.8.2 1.8.1 1.8.0 1.7.4 1.7.3 1.7.2 1.7.1 1.7.0 1.6.2 1.6.1 1.6.0 1.5.0 1.4.3 1.4.2 1.4.1 1.4.0 1.3.0 1.2.0 1.1.0 1.0.0