Predax Fraud Guard for WooCommerce

Beschrijving

Stop fraudulent WooCommerce orders before they’re placed.

Card testers, stolen-card fraudsters, and serial chargeback abusers almost always hide behind VPNs, proxies, Tor, or datacenter IPs. Predax Fraud Guard screens the customer’s IP the moment they check out, scores its fraud risk from 0 to 100, and lets your store tag, hold, or block the order — before payment is taken and before a chargeback can happen.

Think of it as an order guard standing in front of your checkout. You stay in control of every decision: start in tag-only mode to see which orders would have been flagged, then turn on blocking for the risk levels you choose. Screening works with both the classic and block (Store API) checkout.

Fully opt-in: on a fresh install the plugin does nothing — no outbound requests are made until you connect a Predax API key (one-click via the setup wizard, or pasted in manually) and pick a protection mode. The default mode once configured is tag-only (no blocking), so you can review flagged orders in your dashboard before turning on anything that rejects a customer.

What it stops

  • Card testing — bots running stolen card numbers through your checkout in bulk.
  • Orders from hidden connections — VPN, proxy, Tor and datacenter addresses at checkout.
  • Too many orders, too fast — velocity rules catch rapid repeat attempts.
  • Details that do not match — flag orders where the billing country differs from where the customer actually is.
  • Throwaway emails — reject checkouts using disposable email providers.

Why it saves you money

Screening runs during WooCommerce checkout validation — before the order is created and
before any payment provider is contacted
. A blocked attempt therefore never becomes a
transaction, a gateway fee, or a chargeback. It works with any gateway, because it does not
depend on which one you use, and it complements gateway-side tools such as Stripe Radar:
your gateway only ever sees the orders that already passed the IP screen.

How It Works

  1. You install and activate the plugin. Nothing happens — the plugin stays dormant until you finish setup.
  2. You connect your site. Click “Connect with Predax” in the 3-step setup wizard — this creates your free Predax account (or logs you into an existing one) and links your API key automatically, with no key to copy or paste. Prefer to do it manually? You can still paste in an existing API key instead.
  3. You pick a protection mode in Fraud Guard Settings (or in the setup wizard). Choices: Tag + note, Block high risk, or Block critical only.
  4. On each WooCommerce checkout after that point, the plugin sends the customer’s IP address to the Predax API, receives back a risk score and signal flags (is_vpn / is_proxy / is_tor / is_datacenter), and tags / holds / blocks the order according to your configuration. Results are cached for between 5 minutes and 1 hour per IP, following the lifetime the API recommends.

You can revoke the API key or switch the mode back to “Tag only” at any time.

Risk Tagging

Orders that reach the tag threshold (default: risk score 40) are tagged based on band:

  • Risk 40–69 — tagged “Predax: Medium Risk” with an order note
  • Risk 70–89 — tagged “Predax: High Risk” with an order note
  • Risk 90–100 — tagged “Predax: Critical Risk” with an order note

Features

  • Checkout screening (after you enable a protection mode) — every order is checked against Predax IP threat intelligence
  • VPN / Proxy / Tor / Datacenter flags — detect anonymised connections at checkout
  • Risk score threshold blocking — optionally block checkouts above a configurable risk score
  • Automatic order hold (opt-in) — move high-risk orders to On Hold for manual review instead of processing them
  • Order velocity rules (opt-in) — flag or block customers placing too many orders in a short window
  • Billing country vs IP mismatch (opt-in) — flag or block orders where billing country differs from detected IP country
  • Disposable email detection (opt-in) — reject checkouts using throwaway email providers (30+ supported)
  • Refund / chargeback feedback (opt-in) — when a tagged order is refunded or cancelled, add its IP to your local deny list, and/or report the outcome to the Community Threat Network (when that opt-in is enabled)
  • Order meta logging — stores risk score, threat flags, and detected country on every order for WooCommerce reporting
  • Events Log — a dashboard page showing blocked attempts and flagged orders
  • One-click allow-listing — approve any IP directly from the Events Log, no settings field to edit
  • Search-engine safe — verified crawlers (Googlebot, Bingbot) are exempt from category rules, so screening doesn’t affect how your store is crawled and indexed

Screening that doesn’t cost you real customers or search traffic

The real risk of a fraud rule isn’t the fraudster it misses — it’s the genuine customer it turns away without you ever finding out. A blocked shopper rarely tries again, and a store quietly dropped from search results never learns why. Fraud Guard is built to make both failure modes visible and reversible:

  • Verified search engines are exempt from category rules. Googlebot, Bingbot, and other crawlers confirmed by reverse DNS are never caught by your VPN, proxy, datacenter, country, or risk-score rules — on both the classic and block-based checkout. Search engines crawl from datacenter IP ranges, so a datacenter rule would otherwise turn them away and erode your store’s search visibility. Threat rules and your own deny list still apply to everyone regardless.
  • Every screening decision is on the record. The Events Log shows exactly which orders your rules flagged, held, or blocked, and why — so if a rule is too strict, you see it in the log rather than in falling sales.
  • One-click allow-listing. Spot a good customer caught by an over-strict rule? Approve their IP straight from the Events Log — no copying it into the allow-list field — and they can check out again immediately.

Combined with tag-only mode, this means you never have to guess what a rule would do: watch it tag first, turn on blocking when you’re confident, and undo any bad block in one click.

Defaults

All protection toggles default to off on a fresh install. The only thing the plugin writes to options on activation is a database version marker for the events-log table. You will need to explicitly enable any rule you want to apply.

Free Tier

Click “Connect with Predax” in the setup wizard to create your free account and link your API key automatically — no separate sign-up step, no key to copy or paste. The free plan includes 5,000 IP checks per month with full VPN/proxy/Tor/datacenter detection and risk scoring — no credit card required.

More Power With Paid Plans

The free tier covers a small store comfortably (checkouts are only checked when they happen, and results are cached). Busier stores use up the included checks faster — paid plans raise the monthly limit from 5,000 up to 25 million IP checks, with higher request rates and bulk lookups. The Fraud Guard settings page shows your live usage each month, so you can see exactly when it’s time to upgrade — same plugin, same settings, just a bigger allowance on your existing API key.

Third Party Services

This plugin connects to external services operated by Predax (https://predax.io) only after you have saved an API key: checkout screening additionally requires a protection mode to be enabled, and the admin-side account-usage lookup (described below) sends no visitor data at all. By activating this plugin and entering an API key you agree to the Predax Terms of Service and Privacy Policy.

You are responsible for ensuring your use of customer IP data at checkout complies with applicable privacy laws (including but not limited to GDPR, CCPA) and your own store’s privacy policy. This plugin does not assert PCI-DSS, GDPR, or CCPA compliance on your behalf.

Predax IP Intelligence API

Used to look up a risk score and classification signals for each checkout IP.

  • Data sent: the customer’s IP address at checkout; the browser-reported IANA timezone string (when available on the classic checkout form — used for the timezone-mismatch signal); your custom scoring weights (only if Custom Scoring is enabled).
  • What is NOT sent: no billing/shipping names, street addresses, phone numbers, email addresses (only the email’s domain part, and only under the separate Email Domain Screening below), product details, prices, or payment data. The billing-country-mismatch rule compares your order’s billing country against the API’s IP-country result locally — billing details never leave your site.
  • When: during WooCommerce checkout validation, and only while a protection mode is saved in settings.
  • Caching: classification results are cached in the site’s transients for between 5 minutes and 1 hour per IP (the lifetime the API recommends), so repeat checkouts from the same IP do not generate duplicate API calls.
  • Endpoint: POST https://predax.io/api/v1/check/ip
  • Service URL: https://predax.io
  • Terms of Service: https://predax.io/terms
  • Privacy Policy: https://predax.io/privacy

Email Domain Screening (only when the Disposable Email rule is enabled)

Used to check whether the billing email’s provider is a disposable/throwaway service, against a server-side list of thousands of domains (the plugin’s built-in list covers only ~50).

  • Data sent: the domain part of the billing email address only — for example gmail.com. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.
  • When: during checkout validation, and only while the Disposable Email rule is set to Flag or Block. If the API is unreachable, the plugin falls back to its built-in local list and the checkout proceeds normally.
  • Caching: email-domain results are cached in the site’s transients for up to 6 hours per domain, so repeat checkouts with the same email provider do not generate duplicate API calls.
  • Endpoint: POST https://predax.io/api/v1/validate/email
  • Plan usage: email-domain lookups count against your Predax plan allowance, the same as checkout IP checks. Results are cached per domain for 6 hours and the built-in list is checked first, so in practice this is roughly one lookup per new email provider your customers use.
  • Service URL: https://predax.io
  • Terms of Service: https://predax.io/terms
  • Privacy Policy: https://predax.io/privacy

Account Usage Lookup (admin pages only)

Used to show the “API usage this month” meter on the Fraud Guard settings page, and only when an API key is saved.

  • Data sent: your Predax API key (as the authentication header). No customer or visitor data is sent.
  • When: when an administrator views the Fraud Guard settings page. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.
  • Endpoint: GET https://predax.io/api/v1/auth/usage
  • Service URL: https://predax.io
  • Privacy Policy: https://predax.io/privacy

Predax Community Threat Network (opt-in, off by default)

The plugin can optionally send an anonymised telemetry signal — the IP address, its risk score and detection flags, its network (ASN) number and name, its country code, and the checkout outcome (allowed / monitored / blocked, or refund/chargeback feedback) — to the Predax Community Threat Network so all participating stores benefit from a shared feed. The Refund / Chargeback Feedback “Log” action reports through this same channel, so it requires this opt-in; its “Blacklist” action updates your local deny list regardless.

This feature is off by default. It is controlled by the ipsentry_woo_community_enabled option, which defaults to 'no', with a checkbox on the Advanced settings tab. The plugin will not send community-feedback telemetry unless you enable it. Customers’ personal data (names, emails, billing/shipping addresses, order contents) is never included in the telemetry payload.

  • Endpoint: POST https://predax.io/api/v1/telemetry/event
  • Service URL: https://predax.io
  • Privacy Policy: https://predax.io/privacy

OAuth One-Click Connect (optional)

Only triggered when an administrator clicks the Connect with Predax button in the setup wizard. Your browser is redirected to predax.io to authorise the connection, which returns an API key to your site.

  • Data sent: your WordPress site URL, site name, and a PKCE state/code-challenge pair. No customer data is involved.
  • When: only during the click-to-connect OAuth flow.
  • Endpoint: POST https://predax.io/api/v1/oauth/token
  • Service URL: https://predax.io
  • Privacy Policy: https://predax.io/privacy

Deactivation Feedback (optional, admin-initiated)

Shown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the “why are you deactivating?” prompt.

  • Data sent: the plugin slug, the plugin version, and a single pre-defined reason code you select (e.g. “it blocked real customers”). No site URL, no email address, no visitor data, and no IP address are sent.
  • When: only when you select a reason and click “Send & deactivate”. Clicking “Skip & deactivate” sends nothing at all.
  • Endpoint: POST https://predax.io/api/v1/feedback/deactivation
  • Service URL: https://predax.io
  • Privacy Policy: https://predax.io/privacy

Cookies set by this plugin

  • ipsentry_tz — set on WooCommerce checkout pages (only while an API key is configured) via assets/js/ipsentry-woo-tz.js. Stores the customer’s browser-reported IANA timezone (string, max 64 chars). Used server-side for the optional timezone-mismatch fraud rule. Expires after 24 hours (max-age=86400), path=/, SameSite=Lax, and marked Secure on HTTPS stores. The plugin reads this cookie only at checkout-validation time.

The plugin does not set any advertising, analytics, or tracking cookies.

Schermafbeeldingen

Installatie

From your WordPress dashboard (recommended)

  1. Make sure WooCommerce is installed and activated.
  2. Go to Plugins → Add New Plugin in your WordPress admin.
  3. Search for “Predax Fraud Guard”.
  4. Click Install Now, then Activate.
  5. The Setup Wizard launches on first activation. Either click Connect with Predax for OAuth one-click connection, or enter your API key manually.
  6. Pick a protection preset (Recommended / Strict / Monitor Only). This is the step where you opt in — IP lookups begin after this point.
  7. Fine-tune individual rules at Fraud Guard Settings any time.

Manual installation

  1. Download the plugin ZIP from this page and upload it via Plugins → Add New Plugin → Upload Plugin (or extract the predax-fraud-guard-for-woocommerce folder to /wp-content/plugins/).
  2. Activate the plugin through the Plugins menu and follow the Setup Wizard.

FAQ

How do I stop a card testing attack that’s happening right now?

Enable a blocking mode (the wizard’s Recommended preset blocks risk 50 and above), turn on
the order velocity rule, and set VPN, proxy and datacenter to Block. Card-testing bots run
from datacenter, proxy and VPN addresses, so these rules cut the attack off at the
connection. Every blocked attempt is listed in the Events Log, and because screening runs
during checkout validation — before the order reaches your payment gateway — a blocked
attempt never becomes a transaction, a gateway fee, or a chargeback.

Does it work with Stripe, PayPal, or my payment gateway?

Yes, with any gateway. Screening runs during WooCommerce’s own checkout validation, before
the order is created and before any payment provider is contacted, so it does not depend on
which gateway you use. It complements gateway-side screening such as Stripe Radar: your
gateway only ever sees the orders that already passed the IP screen.

How is this different from other WooCommerce anti-fraud plugins?

Most anti-fraud plugins score orders using rules about the order itself — mismatched names, order size, email patterns. Predax Fraud Guard adds the signal those rules can’t see: live IP intelligence. It knows whether the customer is connecting through a VPN, proxy, Tor, or a datacenter server right now, backed by a continuously-updated commercial threat database — the same signal used to catch card testing and stolen-card fraud before payment is taken. It works well alongside rule-based fraud plugins and payment-processor screening such as Stripe Radar, and alongside security plugins like Wordfence (which protect your site, not your checkout).

Does the plugin phone home before I finish setup?

No. Before you enter an API key and save a protection mode, the plugin makes zero outbound requests to predax.io. Nothing happens silently on activation.

Will it block legitimate customers?

Only if you enable a blocking mode. Until you complete setup, the mode is Tag only (no blocking — orders just get tags and notes). In the setup wizard, the pre-selected Recommended preset enables blocking of high-risk checkouts (risk score 50+); choose Monitor Only instead if you don’t want any blocking yet — each preset card lists exactly what it switches on.

What is the risk score?

A score from 0 to 100 representing how likely an IP is to be associated with fraud, anonymisation, or abuse. 0 = clean residential IP, 100 = the strongest combination of threat signals (for example a known-malicious IP arriving over an anonymised connection). The score combines VPN/proxy/Tor detection, datacenter identification, historical abuse signals, and geographic heuristics.

Does it work with Cloudflare?

Yes — enable Fraud Guard Settings Advanced “Behind a proxy / CDN” (or the same toggle on the WooCommerce Predax tab). With it on, the plugin reads the real customer IP from the CF-Connecting-IP / X-Forwarded-For headers instead of the Cloudflare edge IP. It is off by default: when your store connects directly to visitors, trusting those headers would let a customer spoof their IP to bypass fraud checks, so you only turn it on when a proxy/CDN really is in front of your site.

How do I test it without affecting real customers?

Fraud Guard Settings Developer tab enter a Test IP Override. Every checkout is then evaluated as if it came from that IP. A red admin banner reminds you test mode is active. Clear the override before going live.

Use 185.220.101.1 (risk 85, Tor-adjacent) to exercise blocking paths, or 1.1.1.1 to verify pass-through.

What order metadata is stored?

On each tagged order the plugin stores:

  • _ipsentry_risk_score — numeric risk score (0–100)
  • _ipsentry_ip — detected customer IP
  • _ipsentry_country_code — detected IP country code
  • _ipsentry_flags — comma-separated threat flag list

Does it work alongside the Predax Security plugin?

Yes. The plugins are independent but complementary — Security protects logins and registrations, Fraud Guard protects WooCommerce checkout. Both can share the same API key.

Will this block real customers or hurt my store’s SEO?

Search first: verified search engine crawlers — Googlebot, Bingbot and others confirmed by
reverse DNS — are never caught by your category rules, on both the classic and the
block-based checkout, so screening does not affect how your store is crawled or indexed.

For customers, the plugin is built so you never have to guess. Start in tag-only mode and
watch what your rules would have done in the Events Log before you enable any blocking.
Every screening decision is recorded with its reason, and a good customer caught by an
over-strict rule can be allow-listed in one click straight from the log. If your store
serves audiences where VPN use is common, prefer Monitor mode for the VPN rule.

Beoordelingen

Er zijn geen beoordelingen voor deze plugin.

Bijdragers & ontwikkelaars

“Predax Fraud Guard for WooCommerce” is open source software. De volgende personen hebben bijgedragen aan deze plugin.

Bijdragers

Changelog

1.11.0

  • New: the Disposable Email rule now checks a continuously updated list of thousands of throwaway providers instead of the short built-in list. Only the DOMAIN part of the customer’s address is checked (for example “gmail.com”) – the address itself, and everything before the @, never leaves your store. The built-in list is still consulted first and still applies if the API is unreachable, so no store loses a block it had before.
  • New: orders from a domain that cannot receive mail, or with a machine-generated mailbox name, are noted on the order. Both are record-only signals – they never block a checkout, place an order on hold, or count towards the tag threshold.
  • Fixed: order flags were discarded when the Predax API was briefly unreachable, so a flagged order could go untagged and unlogged. Fixed on both the classic and the Blocks checkout.
  • Fixed: a malformed billing email domain could previously cause repeated API errors that temporarily paused IP screening at checkout. Malformed domains are now rejected on your own server and never sent.
  • Note: email-domain lookups count towards your Predax plan allowance. Results are cached for six hours per domain.

1.10.0

Setup wizard
* The Community Threat Network opt-in is now offered as an explicit, unticked checkbox in the setup wizard, with a plain-English description of exactly what is shared. It stays off by default and can be changed any time on the Advanced settings tab.

Housekeeping
* The plugin now identifies itself and its version in its API requests, which helps support diagnose issues faster.
* Fix: screening results written by this plugin now carry the same crawler-identity fields as Predax Security. A store running both plugins shares one cached verdict per visitor, and the missing fields could stop Security’s crawler policy from applying to a visitor whose verdict was cached at checkout.
* Corrected in this readme: cached screening results last between 5 minutes and 1 hour per IP (the lifetime the API recommends), not a fixed 5 minutes.
* Corrected in this readme: the “will this block real customers” answer described dashboard features belonging to the Predax Security plugin rather than this one.

1.9.0

Checkout accuracy
* Fixed one shopper’s screening result being reused for a different shopper behind the same network. The cached result was keyed on the IP alone, but the result also depends on the browser’s timezone – which the Blocks checkout and the classic checkout send differently – so a timezone mismatch could be inherited by the next genuine customer and get their order tagged or held.
* An allow-listed IP no longer has its order tagged from a screening result recorded before it was allow-listed.
* If the Predax API cannot be reached during checkout, any earlier screening result is now discarded rather than being applied to the new order. Previously a customer could be held on a verdict from a previous attempt, possibly from before they turned a VPN off.

Events Log
* “Filter by reason” now works on the Flagged tab. Flagged and held orders were saved without a reason, so the filter returned nothing whatever you chose.
* Flagged orders now record the rule that actually fired – order velocity, disposable email, billing mismatch or the risk threshold – instead of always claiming the risk threshold was crossed.
* The chosen reason filter is no longer lost when you move to the next page of results.

Community Threat Network
* The Blocks checkout now contributes to the Community Threat Network. Only the classic checkout did, so stores using the default Blocks checkout received other stores’ data without contributing any of their own.

Other fixes
* Risk labels on orders now match the bands the Predax API actually issues; an order scoring 75 previously showed a different level to the one the API reported.
* Importing a settings file can no longer redirect the plugin to a different address – the API key is sent to that address, so this is now restricted to http and https as the settings form already was.
* Uninstall now removes leftover lookup locks and the shared verdict cache.

Efficiency
* Predax Fraud Guard and Predax Security now share one cached verdict per visitor, so a store running both no longer spends two checks on the same person.
* Cached verdicts now follow the lifetime the API recommends (up to an hour) instead of a fixed five minutes.
* Tested up to WordPress 7.1.

1.8.4

  • Fix: hitting your plan’s DAILY check limit no longer reports it as the monthly limit. The notice used to say checkout screening was paused “until your quota resets on the 1st” when it actually resumes at midnight UTC the same day. It now names the right limit and tells you the exact time screening resumes.
  • Improved: fewer API checks are used for the same shopper. Checkout pages make several parallel requests, and each one used to trigger its own lookup; the plugin now performs a single lookup and shares the result.

1.8.3

  • Fix: re-running the Setup Wizard and choosing “Monitor Only” now also switches off known-malicious IP blocking. Previously that one rule stayed on if a stricter preset had enabled it, so a preset promising to block nothing could still reject checkouts.
  • Fix: Fraud Guard admin notices no longer appear on Predax Security plugin pages when both plugins are installed – they now show only on Fraud Guard’s own screens.

1.8.2

  • New: an invitation to join the Community Threat Network now appears on the Predax screens, with a one-click opt-in. Stores in the network warn each other, so a card tester blocked at another store is already known to yours. It remains entirely opt-in and was previously easy to miss.

1.8.1

  • Fix: shoppers on a VPN or proxy set to “Monitor” were still rejected when datacenter blocking was on, because VPN servers run in datacenters. Monitoring now means monitoring.
  • Fix: stores in the Community Threat Network were reporting every shopper as having no VPN/proxy/Tor/datacenter signal, so shared intelligence was based on incomplete data.

1.8.0

  • Fix: verified search engines are no longer caught by category rules, on both the classic and block-based checkout.
  • New: allow any IP directly from the Events Log.
  • New: tell us why you’re deactivating, so we can fix it.

1.7.4

  • Fix: turning OFF both “Block VPN” and “Monitor VPN” now genuinely ignores VPN shoppers. Previously the order fell through to the risk-score check and was blocked anyway, logged as “high risk” with no mention of VPN. Same fix for the proxy toggles, on both the classic checkout and the Store API (block-based checkout) paths.

1.7.3

  • Fix: known-malicious IP blocking (introduced in 1.7.2) now correctly reads the malicious signal from the Predax API — a normalization gap meant it never actually triggered a block.
  • New: the Events Log now shows the specific reason for a malicious-IP flag (botnet C2 vs. hijacked network range) instead of a generic “malicious” tag.
  • New: the API key field is now masked (with a Show/Hide toggle) instead of shown in plain text — both on the Fraud Rules tab and in the Setup Wizard’s manual-entry step — and is excluded from Settings Export/Import so it can never leave the site in a shared file.

1.7.2

  • New: known-malicious IP blocking — a dedicated category (separate from your general risk mode) for botnet C2 and hijacked-netblock IPs. Off by default; enable it via the Setup Wizard’s Recommended/Strict presets, the Fraud Rules tab, or the one-click “Enable malicious-IP blocking” notice.
  • New: filter the Events Log by reason — narrow the log to just one block category instead of scrolling the full list.

1.7.1

  • New: live API usage meter on the Fraud Guard settings page — shows your monthly IP-check usage against your plan’s quota (fetched hourly), with an upgrade link when you’re above 80%.
  • New: quota notice — if your plan’s monthly IP checks run out (checkout screening pauses and orders are allowed through until the quota resets), the plugin now tells you on its admin pages instead of failing silently. Dismissible per month.
  • New: API circuit-breaker — if the Predax API becomes slow or unreachable, checkouts now fail open instantly after a few consecutive failures instead of each waiting on the timeout, and the settings page shows an “API degraded” indicator. The API request timeout was lowered from 8s to 3.5s, so even a first failure delays a checkout far less.
  • Privacy: customer emails in the Events Log are now masked before storage (“bi***@example.com”). Enough to recognise a repeat customer; the linked order still holds the full email. Existing rows are untouched and age out via the log retention setting.
  • Performance: the IP allow/deny list options no longer autoload on every page request (the deny list can grow via the chargeback auto-append). A one-time migration updates existing installs.
  • Docs: installation instructions rewritten for installing from the WordPress.org plugin directory; added a section on free vs paid plan limits.

1.7.0

  • Rebrand: IPSentry is now Predax. This is the first WordPress.org release of the WooCommerce plugin. The plugin name, admin menu, and links now use Predax (predax.io). Your existing settings, API key, and order data are preserved — internal option names are unchanged, so nothing needs reconfiguring.
  • Admin menu moved to a lower position so it no longer sits among the core WordPress menu items.
  • Compliance: the OAuth-callback exit page now registers and prints its CSS/JS through the WordPress script API (wp_register_style/wp_register_script + wp_print_styles/wp_print_scripts) instead of hand-written tags. The WooCommerce settings save and checkout timezone read run inside WooCommerce’s own nonce-verified flows and carry inline justifications for the static analyser.
  • Compatibility: declared WooCommerce High-Performance Order Storage (HPOS) compatibility.
  • Fix: the order-velocity time window now uses a timestamp-based date query (the previous datetime-string form could be misread by WooCommerce and count orders outside the window).
  • Hardening: checkout error notices are HTML-escaped before being added; the settings-import upload is capped at 512 KB with bounded JSON depth; the API base URL accepts http/https only; the timezone cookie is marked Secure on HTTPS stores; the Store API block path gained an explicit return after blocking.
  • Clarity: Refund / Chargeback Feedback labels and docs now state that “Log” reports go through the Community Threat Network opt-in; the readme documents exact API endpoints and the full telemetry data list.
  • New: IP allow-list (never block trusted IPs) and a managed deny-list, both supporting single IPs and CIDR ranges (IPv4 + IPv6), editable from the settings page and the WooCommerce Predax tab.
  • New: the Community Threat Network opt-in is now a settings toggle (still off by default) instead of import/export only.
  • New: Events Log retention setting (default 90 days; 0 = keep forever) with automatic daily cleanup, plus a 7-day/all-time stats summary, CSV export, and a Clear Log button.
  • New: “Behind a proxy / CDN” setting (off by default). Enable it when your store is behind Cloudflare, a CDN, or a reverse proxy so the real customer IP is read from forwarded headers; when off, only the direct connection IP is used, so the customer IP cannot be spoofed to bypass fraud checks.
  • Security: the Events Log CSV export now neutralises spreadsheet formula-injection — a billing email such as “=…@example.com” can no longer execute as a formula when the export is opened in Excel/Sheets.
  • Fix: the “Flag for review” action on the velocity, disposable-email, and billing-country-mismatch rules now reliably tags the order, adds the order note, and writes the Events Log entry (previously these markers could be dropped on processed orders).
  • Fix: a critically-risky IP (risk score 90+) is now always blocked while a blocking mode is active, even when its VPN/proxy category is set to Monitor.
  • Fix: the WooCommerce Predax settings tab now saves correctly (removed an invalid nested import form; import is now on the Fraud Guard Developer page).
  • Hardening: /0 (match-all) entries are rejected in the IP allow/deny lists, and uninstall now cleans every site on a multisite network.
  • No change to the opt-in model — the plugin still makes zero outbound requests until you enter an API key and save a protection mode.

1.6.2

  • Compliance: community-feedback telemetry is now explicitly opt-in (off by default) behind a new ipsentry_woo_community_enabled option. Existing installs stop sending telemetry until they flip this on.
  • Compliance: all phoning-home defaults flipped to off — block_proxy, block_tor, and monitor_vpn default to 'no' on fresh installs.
  • Compliance: removed the self-hosted plugin updater class per WP.org Guideline 8.
  • Compliance: extracted every inline <script> / <style> block to enqueued asset files. OAuth-callback exit page now references an external CSS/JS pair.
  • Compliance: Privacy Policy content hook (wp_add_privacy_policy_content) so admins can pull suggested text from Tools Privacy.
  • Compliance: Setup-wizard privacy-disclosure boxes added above OAuth button, manual API-key field, and preset-picker cards.
  • Compliance: nonce-before-cap order fixed on every admin-post and AJAX handler.
  • Compliance: input sanitisation tightened on every $_GET / $_POST / $_FILES read; imported settings values now validated per option type.
  • Compliance: Test-mode admin notice now scoped to Predax pages only (not global).
  • Added: uninstall.php drops the events-log table and deletes every ipsentry_woo_* option on plugin deletion.
  • Added: Domain Path: /languages header + minimal .pot translation template.
  • Added: .distignore excluding dev artefacts from the WP.org zip.
  • No behaviour change for existing installs other than the community-feedback gate — core IP checking still works as before.

1.6.1

  • Improved: OAuth connect popup now auto-closes reliably after authorization.
  • Improved: Per-user OAuth transients prevent conflicts on multi-admin sites.

1.6.0

  • New: Setup Wizard — guided 3-step setup on first activation with fraud protection presets (Recommended, Strict, Monitor Only).
  • New: One-Click Connect — click “Connect with Predax” in the setup wizard to link your store via OAuth. No API key to copy or paste.
  • New: “Run Setup Wizard” link in Developer tab to re-run the wizard at any time.

1.5.0

  • New: Events Log admin page (Predax Events Log) — two tabs showing blocked checkout attempts and flagged/held orders with IP, risk score, flags, reason, and order links.
  • New: Predax risk column on WooCommerce Orders list — shows colour-coded score badge and top threat flag.
  • Improvement: Orders now store a combined _ipsentry_flags meta key for quick flag lookup.

1.4.3

  • New: Dedicated settings page under Predax Fraud Guard in the WordPress admin left nav — same tabbed UI as the Security plugin.

1.4.2

  • New: Settings import/export — back up your configuration or copy it between sites.
  • New: Support Email field — if set, checkout block error messages include a “Contact us at…” line.

1.4.1

  • Fix: VPN/proxy customers set to Monitor mode were incorrectly blocked by the risk threshold.

1.4.0

  • New: Automatic order hold, order velocity rules, billing country vs IP mismatch, disposable email detection, refund/chargeback feedback, test IP override.

1.3.0

  • New: Off/Monitor/Block radio groups for VPN, proxy, and Tor.
  • New: Custom risk scoring weights — adjust per-signal contribution to the final risk score.

1.2.0

  • New: Country-based blocking at checkout. Whitelist support. API timeout handling.

1.1.0

  • New: Configurable risk threshold. Order meta. Detailed order notes.

1.0.0

  • Initial release. Tag-only fraud screening at checkout. VPN / proxy / Tor / datacenter detection.