Linux 软件免费装
Banner图

Predax Fraud Guard for WooCommerce – Anti-Fraud, Fake Order & Card Testing Protection

开发者 ipsentry
更新时间 2026年9月23日 11:30
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

fraud prevention Prevent fake orders WooCommerce Anti-Fraud card testing chargeback prevention

下载

1.9.0 1.11.0 1.10.0 1.12.0 1.7.0 1.7.1 1.7.3 1.8.0 1.8.1 1.8.2 1.8.3 1.8.4 1.12.1 1.12.2

详情介绍:

Predax Fraud Guard is anti-fraud for WooCommerce: it stops fake orders, card testing and chargebacks before the order exists. Card testers and stolen-card fraudsters typically check out from behind a VPN, proxy, Tor or datacenter IP. Fraud Guard screens the customer's IP at checkout and scores its fraud risk from 0 to 100, and for each rule you choose what happens. Block refuses the checkout before payment is taken, so a blocked attempt never becomes a gateway fee or a chargeback. Hold lets the payment go through and keeps the order on hold for your review, so nothing ships until you decide. Or simply tag the order. Works with any payment gateway and with both the classic and block checkout. See what Predax knows about your own IP — free, no signup. Off by default. A fresh install sends nothing anywhere. Connect your Predax key and choose a protection mode; until then the plugin does nothing. What it stops Start in tag-only mode The default once configured is Tag + note: flagged orders get a "Predax: Medium / High / Critical Risk" tag and an order note, and nothing is blocked. Watch what the rules would have done, then turn on Block high risk or Block critical only when you're confident. Optionally send high-risk orders to On Hold for review instead of rejecting them: the payment is taken and the order waits for you before anything ships, so you can refund a fraudulent one instead of sending the goods. Safe for real customers and search traffic Also included Risk score, threat flags and country saved on every order for reporting · Refund/chargeback feedback that adds the IP to your deny list · IP and CIDR allow/deny lists · Optional Community Threat Network sharing Free plan Click Connect with Predax in the setup wizard and your free account and API key are created for you — nothing to copy or paste. The free plan includes 5,000 IP checks a month with full VPN, proxy, Tor and datacenter detection and risk scoring. No credit card. Checkouts are only checked when they happen and results are cached, so it covers a small store comfortably; busier stores can move to a paid plan — same plugin, same settings, same key.

安装:

From your WordPress dashboard (recommended)
  1. Make sure WooCommerce is installed and activated.
  2. Go to Plugins → Add New Plugin in your WordPress admin.
  3. Search for "Predax Fraud Guard".
  4. Click Install Now, then Activate.
  5. The Setup Wizard launches on first activation. Either click Connect with Predax for OAuth one-click connection, or enter your API key manually.
  6. Pick a protection preset (Recommended / Strict / Monitor Only). This is the step where you opt in — IP lookups begin after this point.
  7. Fine-tune individual rules at Fraud Guard → Settings any time.
Manual installation
  1. Download the plugin ZIP from this page and upload it via Plugins → Add New Plugin → Upload Plugin (or extract the predax-fraud-guard-for-woocommerce folder to /wp-content/plugins/).
  2. Activate the plugin through the Plugins menu and follow the Setup Wizard.

屏幕截图:

  • The Fraud Rules settings tab: API key, risk thresholds, and per-signal VPN / proxy / Tor / datacenter rules.
  • Order detail: the Predax risk score, flags, and country appear as an order note and order tags.
  • Orders list: the Predax column shows each order's risk score and top threat flag.
  • Advanced rules: order velocity, billing-country mismatch, disposable-email, and timezone checks.
  • Geo blocking: allow, flag, or block checkout by country, region, or IP / CIDR list.
  • Setup Wizard — pick a fraud protection level (Monitor Only, Recommended, or Strict) in one step
  • Events Log filtered by reason — narrow blocked attempts down to a single category, like known-malicious IPs
  • Events Log with one-click allow-listing — approve a genuine customer's IP straight from the log, without editing a settings field

升级注意事项:

1.12.4 Clock & Country can now Block (refuse the checkout before the card is charged) as well as Hold (take payment, hold for review). Your current setting is kept. Held orders are now listed as held in the Events Log. 1.12.3 Important if you use Auto Hold: orders paid by card were released from hold as soon as the payment went through. They now stay on hold until you release them. The clock-and-country hold also gets its own switch and now works on default settings. 1.12.2 Holds an order for review when the billing country, the order's country and the browser clock all disagree - the pattern of a card used from somewhere the cardholder is not. Also fixes the browser timezone never reaching the check that used it, and stops two false positives (a Paris browser on a German address, a Californian on a US address). 1.12.1 Maintenance release. Corrects the plugin's name on the Plugins screen, replaces an oversized bundled icon (about 220 KB smaller), and fixes the in-plugin "What's new" panel showing the previous release's notes. Nothing about screening or your settings changes. 1.11.0 The Disposable Email rule now uses a continuously updated list instead of the small built-in one. Only the domain is checked - never the address itself. Also fixes flags being lost during a brief API outage, and a malformed domain briefly pausing IP screening. 1.10.0 The Community Threat Network opt-in now appears in the setup wizard as an explicit, unticked checkbox — still off by default, and nothing is shared unless you tick it. Also fixes a shared-cache issue that could stop Predax Security's crawler policy applying to a checkout visitor. 1.9.0 Fixes one shopper's screening result being reused for a different shopper on the same network, the Events Log reason filter returning nothing on the Flagged tab, and the Blocks checkout not contributing to the Community Threat Network. Also reduces how many checks each visitor costs. 1.8.4 Fixes a daily check limit being reported as the monthly one - the notice claimed screening was paused until the 1st when it actually resumes the same day. Also reduces how much of your allowance each checkout consumes. 1.8.3 Fixes the Monitor Only wizard preset leaving known-malicious IP blocking on, which could reject checkouts despite the preset promising to block nothing. 1.8.2 Adds a one-click option to join the Community Threat Network, so fraudsters blocked at other stores are already known to yours. Entirely optional. 1.8.1 Fixes VPN/proxy shoppers set to Monitor still being blocked when datacenter blocking is enabled, and corrects the signals sent to the Community Threat Network. 1.8.0 Fixes VPN/proxy checkout blocks that happened with both toggles off, and stops verified search engines being caught by category rules. 1.7.4 Fixes VPN/proxy checkout blocks that happened even with both toggles switched off, and which were logged under the wrong reason. Recommended if legitimate orders were being blocked unexpectedly. Safe to upgrade. 1.7.3 Fixes malicious-IP blocking so it actually works (a normalization bug in 1.7.2 silently prevented it from ever triggering), adds specific Events Log messaging, and masks the API key field. Safe to upgrade. 1.7.2 Adds known-malicious IP blocking as its own off-by-default category and a reason filter for the Events Log. No settings are changed automatically. Safe to upgrade. 1.7.1 Adds a live API usage meter, a quota-exhausted notice, and an API circuit-breaker so a slow API can never hang checkouts (timeout lowered 8s to 3.5s). Events Log emails are now stored masked. Screening decisions are unchanged. Safe to upgrade. 1.7.0 IPSentry is now Predax — first WordPress.org release. Your settings, API key, and order data are preserved. Checkout screening is unchanged and still fully opt-in (no outbound requests until you add a key and enable a mode). 1.6.2 WP.org compliance pass: removes self-updater, extracts inline script/style tags, tightens sanitisation, and makes the community-feedback telemetry opt-in (off by default). Core checkout screening is unchanged. Upgrade is safe. 1.6.1 OAuth connect popup now auto-closes reliably after authorization. Per-user OAuth transients prevent conflicts on multi-admin sites. Safe to upgrade — no behaviour changes. 1.6.0 Adds a 3-step setup wizard with One-Click Connect (OAuth) shown on first activation. Existing installs unaffected — the wizard only triggers on fresh activation with no API key. Re-run anytime from Developer → Run Setup Wizard. 1.5.0 Adds Events Log page and risk column on the orders list. Safe to upgrade — no behaviour changes, new DB table created automatically on first load. 1.4.3 Adds a dedicated admin menu page (Predax → Fraud Guard). Safe to upgrade — all existing settings are preserved. 1.4.2 Adds settings import/export and a configurable support email address for block messages. Safe to upgrade — no behaviour changes on upgrade. 1.4.0 Adds order hold, velocity rules, country mismatch detection, disposable email blocking, and chargeback feedback. All new features default to off.

常见问题:

How do I stop a card testing attack that's happening right now?

Enable a blocking mode (the wizard's Recommended preset blocks risk 50 and above), turn on the order velocity rule, and set VPN, proxy and datacenter to Block. Card-testing bots run from datacenter, proxy and VPN addresses, so these rules cut the attack off at the connection. Every blocked attempt is listed in the Events Log, and because screening runs during checkout validation — before the order reaches your payment gateway — a blocked attempt never becomes a transaction, a gateway fee, or a chargeback.

Does it work with Stripe, PayPal, or my payment gateway?

Yes, with any gateway. Screening runs during WooCommerce's own checkout validation, before the order is created and before any payment provider is contacted, so it does not depend on which gateway you use. It complements gateway-side screening such as Stripe Radar: your gateway only ever sees the orders that already passed the IP screen.

How is this different from other WooCommerce anti-fraud plugins?

Most anti-fraud plugins score orders using rules about the order itself — mismatched names, order size, email patterns. Predax Fraud Guard adds the signal those rules can't see: live IP intelligence. It knows whether the customer is connecting through a VPN, proxy, Tor, or a datacenter server right now, backed by a continuously-updated commercial threat database — the same signal used to catch card testing and stolen-card fraud before payment is taken. It works well alongside rule-based fraud plugins and payment-processor screening such as Stripe Radar, and alongside security plugins like Wordfence (which protect your site, not your checkout).

Does the plugin phone home before I finish setup?

No. Before you enter an API key and save a protection mode, the plugin makes zero outbound requests to predax.io. Nothing happens silently on activation.

Will it block legitimate customers?

Only if you enable a blocking mode. Until you complete setup, the mode is Tag only (no blocking — orders just get tags and notes). In the setup wizard, the pre-selected Recommended preset enables blocking of high-risk checkouts (risk score 50+); choose Monitor Only instead if you don't want any blocking yet — each preset card lists exactly what it switches on.

What is the risk score?

A score from 0 to 100 representing how likely an IP is to be associated with fraud, anonymisation, or abuse. 0 = clean residential IP, 100 = the strongest combination of threat signals (for example a known-malicious IP arriving over an anonymised connection). The score combines VPN/proxy/Tor detection, datacenter identification, historical abuse signals, and geographic heuristics.

Does it work with Cloudflare?

Yes — enable Fraud Guard → Settings → Advanced → "Behind a proxy / CDN" (or the same toggle on the WooCommerce → Predax tab). With it on, the plugin reads the real customer IP from the CF-Connecting-IP / X-Forwarded-For headers instead of the Cloudflare edge IP. It is off by default: when your store connects directly to visitors, trusting those headers would let a customer spoof their IP to bypass fraud checks, so you only turn it on when a proxy/CDN really is in front of your site.

How do I test it without affecting real customers?

Fraud Guard → Settings → Developer tab → enter a Test IP Override. Every checkout is then evaluated as if it came from that IP. A red admin banner reminds you test mode is active. Clear the override before going live. Use 185.220.101.1 (risk 85, Tor-adjacent) to exercise blocking paths, or 1.1.1.1 to verify pass-through.

What order metadata is stored?

On each tagged order the plugin stores:

  • _ipsentry_risk_score — numeric risk score (0–100)
  • _ipsentry_ip — detected customer IP
  • _ipsentry_country_code — detected IP country code
  • _ipsentry_flags — comma-separated threat flag list

Does it work alongside the Predax Security plugin?

Yes. The plugins are independent but complementary — Security protects logins and registrations, Fraud Guard protects WooCommerce checkout. Both can share the same API key.

Will this block real customers or hurt my store's SEO?

Search first: verified search engine crawlers — Googlebot, Bingbot and others confirmed by reverse DNS — are never caught by your category rules, on both the classic and the block-based checkout, so screening does not affect how your store is crawled or indexed. For customers, the plugin is built so you never have to guess. Start in tag-only mode and watch what your rules would have done in the Events Log before you enable any blocking. Every screening decision is recorded with its reason, and a good customer caught by an over-strict rule can be allow-listed in one click straight from the log. If your store serves audiences where VPN use is common, prefer Monitor mode for the VPN rule.

更新日志:

1.12.4 1.12.3 1.12.2 1.12.1 1.12.0 1.11.0 1.10.0 Setup wizard 1.9.0 Checkout accuracy 1.8.4 1.8.3 1.8.2 1.8.1 1.8.0 1.7.4 1.7.3 1.7.2 1.7.1 1.7.0 1.6.2 1.6.1 1.6.0 1.5.0 1.4.3 1.4.2 1.4.1 1.4.0 1.3.0 1.2.0 1.1.0 1.0.0