{"id":323963,"date":"2026-06-14T15:36:50","date_gmt":"2026-06-14T15:36:50","guid":{"rendered":"https:\/\/en-gb.wordpress.org\/plugins\/predax-fraud-guard-for-woocommerce\/"},"modified":"2026-08-18T21:21:48","modified_gmt":"2026-08-18T21:21:48","slug":"predax-fraud-guard-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/nl.wordpress.org\/plugins\/predax-fraud-guard-for-woocommerce\/","author":23475053,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.11.0","stable_tag":"1.11.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Predax Fraud Guard for WooCommerce","header_author":"Predax","header_description":"Tag and optionally block high-risk WooCommerce checkouts using Predax IP intelligence.","assets_banners_color":"091c1e","last_updated":"2026-08-18 21:21:48","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/predax.io\/integrations\/woocommerce","header_author_uri":"https:\/\/predax.io","rating":0,"author_block_rating":0,"active_installs":0,"downloads":449,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.10.0":{"tag":"1.10.0","author":"ipsentry","date":"2026-08-17 22:26:13"},"1.11.0":{"tag":"1.11.0","author":"ipsentry","date":"2026-08-18 21:21:48"},"1.7.0":{"tag":"1.7.0","author":"ipsentry","date":"2026-06-15 05:29:37"},"1.7.1":{"tag":"1.7.1","author":"ipsentry","date":"2026-07-13 18:53:58"},"1.7.3":{"tag":"1.7.3","author":"ipsentry","date":"2026-07-27 12:17:55"},"1.8.0":{"tag":"1.8.0","author":"ipsentry","date":"2026-08-08 09:30:33"},"1.8.1":{"tag":"1.8.1","author":"ipsentry","date":"2026-08-12 12:30:20"},"1.8.2":{"tag":"1.8.2","author":"ipsentry","date":"2026-08-12 15:28:38"},"1.8.3":{"tag":"1.8.3","author":"ipsentry","date":"2026-08-12 22:02:12"},"1.8.4":{"tag":"1.8.4","author":"ipsentry","date":"2026-08-13 22:11:47"},"1.9.0":{"tag":"1.9.0","author":"ipsentry","date":"2026-08-16 04:55:57"}},"upgrade_notice":{"1.11.0":"<p>The Disposable Email rule now uses a continuously updated list instead of the small built-in one. Only the domain is checked - never the address itself. Also fixes flags being lost during a brief API outage, and a malformed domain briefly pausing IP screening.<\/p>","1.10.0":"<p>The Community Threat Network opt-in now appears in the setup wizard as an explicit, unticked checkbox \u2014 still off by default, and nothing is shared unless you tick it. Also fixes a shared-cache issue that could stop Predax Security&#039;s crawler policy applying to a checkout visitor.<\/p>","1.9.0":"<p>Fixes one shopper&#039;s screening result being reused for a different shopper on the same network, the Events Log reason filter returning nothing on the Flagged tab, and the Blocks checkout not contributing to the Community Threat Network. Also reduces how many checks each visitor costs.<\/p>","1.8.4":"<p>Fixes a daily check limit being reported as the monthly one - the notice claimed screening was paused until the 1st when it actually resumes the same day. Also reduces how much of your allowance each checkout consumes.<\/p>","1.8.3":"<p>Fixes the Monitor Only wizard preset leaving known-malicious IP blocking on, which could reject checkouts despite the preset promising to block nothing.<\/p>","1.8.2":"<p>Adds a one-click option to join the Community Threat Network, so fraudsters blocked at other stores are already known to yours. Entirely optional.<\/p>","1.8.1":"<p>Fixes VPN\/proxy shoppers set to Monitor still being blocked when datacenter blocking is enabled, and corrects the signals sent to the Community Threat Network.<\/p>","1.8.0":"<p>Fixes VPN\/proxy checkout blocks that happened with both toggles off, and stops verified search engines being caught by category rules.<\/p>","1.7.4":"<p>Fixes VPN\/proxy checkout blocks that happened even with both toggles switched off, and which were logged under the wrong reason. Recommended if legitimate orders were being blocked unexpectedly. Safe to upgrade.<\/p>","1.7.3":"<p>Fixes malicious-IP blocking so it actually works (a normalization bug in 1.7.2 silently prevented it from ever triggering), adds specific Events Log messaging, and masks the API key field. Safe to upgrade.<\/p>","1.7.2":"<p>Adds known-malicious IP blocking as its own off-by-default category and a reason filter for the Events Log. No settings are changed automatically. Safe to upgrade.<\/p>","1.7.1":"<p>Adds a live API usage meter, a quota-exhausted notice, and an API circuit-breaker so a slow API can never hang checkouts (timeout lowered 8s to 3.5s). Events Log emails are now stored masked. Screening decisions are unchanged. Safe to upgrade.<\/p>","1.7.0":"<p>IPSentry is now Predax \u2014 first WordPress.org release. Your settings, API key, and order data are preserved. Checkout screening is unchanged and still fully opt-in (no outbound requests until you add a key and enable a mode).<\/p>","1.6.2":"<p>WP.org compliance pass: removes self-updater, extracts inline script\/style tags, tightens sanitisation, and makes the community-feedback telemetry opt-in (off by default). Core checkout screening is unchanged. Upgrade is safe.<\/p>","1.6.1":"<p>OAuth connect popup now auto-closes reliably after authorization. Per-user OAuth transients prevent conflicts on multi-admin sites. Safe to upgrade \u2014 no behaviour changes.<\/p>","1.6.0":"<p>Adds a 3-step setup wizard with One-Click Connect (OAuth) shown on first activation. Existing installs unaffected \u2014 the wizard only triggers on fresh activation with no API key. Re-run anytime from Developer \u2192 Run Setup Wizard.<\/p>","1.5.0":"<p>Adds Events Log page and risk column on the orders list. Safe to upgrade \u2014 no behaviour changes, new DB table created automatically on first load.<\/p>","1.4.3":"<p>Adds a dedicated admin menu page (Predax \u2192 Fraud Guard). Safe to upgrade \u2014 all existing settings are preserved.<\/p>","1.4.2":"<p>Adds settings import\/export and a configurable support email address for block messages. Safe to upgrade \u2014 no behaviour changes on upgrade.<\/p>","1.4.0":"<p>Adds order hold, velocity rules, country mismatch detection, disposable email blocking, and chargeback feedback. All new features default to off.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3572045,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3572045,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3572045,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3572045,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.10.0","1.11.0","1.7.0","1.7.1","1.7.3","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.9.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3606422,"resolution":"1","location":"assets","locale":"","width":1280,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3649320,"resolution":"2","location":"assets","locale":"","width":1440,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3649320,"resolution":"3","location":"assets","locale":"","width":1440,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3649320,"resolution":"4","location":"assets","locale":"","width":1440,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3652584,"resolution":"5","location":"assets","locale":"","width":1440,"height":900},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3652584,"resolution":"6","location":"assets","locale":"","width":1440,"height":900},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3649320,"resolution":"7","location":"assets","locale":"","width":1440,"height":900},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3649320,"resolution":"8","location":"assets","locale":"","width":1440,"height":900},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3638710,"resolution":"9","location":"assets","locale":"","width":1249,"height":709}},"screenshots":{"1":"A fraudulent order stopped at checkout: the customer sees a clear message and the order is never placed.","2":"The Fraud Rules settings tab: API key, risk thresholds, and per-signal VPN \/ proxy \/ Tor \/ datacenter rules.","3":"Order detail: the Predax risk score, flags, and country appear as an order note and order tags.","4":"Orders list: the Predax column shows each order's risk score and top threat flag.","5":"Advanced rules: order velocity, billing-country mismatch, disposable-email, and timezone checks.","6":"Geo blocking: allow, flag, or block checkout by country, region, or IP \/ CIDR list.","7":"Setup Wizard \u2014 pick a fraud protection level (Monitor Only, Recommended, or Strict) in one step","8":"Events Log filtered by reason \u2014 narrow blocked attempts down to a single category, like known-malicious IPs","9":"Events Log with one-click allow-listing \u2014 approve a genuine customer's IP straight from the log, without editing a settings field"}},"plugin_section":[],"plugin_tags":[262525,76320,132861,267121,286],"plugin_category":[45],"plugin_contributors":[264383],"plugin_business_model":[],"class_list":["post-323963","plugin","type-plugin","status-publish","hentry","plugin_tags-card-testing","plugin_tags-chargeback","plugin_tags-fraud-prevention","plugin_tags-vpn-detection","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-ipsentry","plugin_committers-ipsentry"],"banners":{"banner":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/banner-772x250.png?rev=3572045","banner_2x":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/banner-1544x500.png?rev=3572045","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/icon-128x128.png?rev=3572045","icon_2x":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/icon-256x256.png?rev=3572045","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-1.png?rev=3606422","caption":"A fraudulent order stopped at checkout: the customer sees a clear message and the order is never placed."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-2.png?rev=3649320","caption":"The Fraud Rules settings tab: API key, risk thresholds, and per-signal VPN \/ proxy \/ Tor \/ datacenter rules."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-3.png?rev=3649320","caption":"Order detail: the Predax risk score, flags, and country appear as an order note and order tags."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-4.png?rev=3649320","caption":"Orders list: the Predax column shows each order's risk score and top threat flag."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-5.png?rev=3652584","caption":"Advanced rules: order velocity, billing-country mismatch, disposable-email, and timezone checks."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-6.png?rev=3652584","caption":"Geo blocking: allow, flag, or block checkout by country, region, or IP \/ CIDR list."},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-7.png?rev=3649320","caption":"Setup Wizard \u2014 pick a fraud protection level (Monitor Only, Recommended, or Strict) in one step"},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-8.png?rev=3649320","caption":"Events Log filtered by reason \u2014 narrow blocked attempts down to a single category, like known-malicious IPs"},{"src":"https:\/\/ps.w.org\/predax-fraud-guard-for-woocommerce\/assets\/screenshot-9.png?rev=3638710","caption":"Events Log with one-click allow-listing \u2014 approve a genuine customer's IP straight from the log, without editing a settings field"}],"raw_content":"<!--section=description-->\n<p><strong>Stop fraudulent WooCommerce orders before they're placed.<\/strong><\/p>\n\n<p>Card testers, stolen-card fraudsters, and serial chargeback abusers almost always hide behind VPNs, proxies, Tor, or datacenter IPs. Predax Fraud Guard screens the customer's IP the moment they check out, scores its fraud risk from 0 to 100, and lets your store tag, hold, or block the order \u2014 before payment is taken and before a chargeback can happen.<\/p>\n\n<p>Think of it as an order guard standing in front of your checkout. You stay in control of every decision: start in <strong>tag-only<\/strong> mode to see which orders would have been flagged, then turn on blocking for the risk levels you choose. Screening works with both the classic and block (Store API) checkout.<\/p>\n\n<p><strong>Fully opt-in:<\/strong> on a fresh install the plugin does nothing \u2014 no outbound requests are made until <strong>you<\/strong> connect a Predax API key (one-click via the setup wizard, or pasted in manually) and pick a protection mode. The default mode once configured is tag-only (no blocking), so you can review flagged orders in your dashboard before turning on anything that rejects a customer.<\/p>\n\n<h4>What it stops<\/h4>\n\n<ul>\n<li><strong>Card testing<\/strong> \u2014 bots running stolen card numbers through your checkout in bulk.<\/li>\n<li><strong>Orders from hidden connections<\/strong> \u2014 VPN, proxy, Tor and datacenter addresses at checkout.<\/li>\n<li><strong>Too many orders, too fast<\/strong> \u2014 velocity rules catch rapid repeat attempts.<\/li>\n<li><strong>Details that do not match<\/strong> \u2014 flag orders where the billing country differs from where the customer actually is.<\/li>\n<li><strong>Throwaway emails<\/strong> \u2014 reject checkouts using disposable email providers.<\/li>\n<\/ul>\n\n<h4>Why it saves you money<\/h4>\n\n<p>Screening runs during WooCommerce checkout validation \u2014 <strong>before the order is created and\nbefore any payment provider is contacted<\/strong>. A blocked attempt therefore never becomes a\ntransaction, a gateway fee, or a chargeback. It works with any gateway, because it does not\ndepend on which one you use, and it complements gateway-side tools such as Stripe Radar:\nyour gateway only ever sees the orders that already passed the IP screen.<\/p>\n\n<h4>How It Works<\/h4>\n\n<ol>\n<li><strong>You install and activate the plugin.<\/strong> Nothing happens \u2014 the plugin stays dormant until you finish setup.<\/li>\n<li><strong>You connect your site.<\/strong> Click \"Connect with Predax\" in the 3-step setup wizard \u2014 this creates your free Predax account (or logs you into an existing one) and links your API key automatically, with no key to copy or paste. Prefer to do it manually? You can still paste in an existing API key instead.<\/li>\n<li><strong>You pick a protection mode<\/strong> in Fraud Guard \u2192 Settings (or in the setup wizard). Choices: Tag + note, Block high risk, or Block critical only.<\/li>\n<li><strong>On each WooCommerce checkout after that point<\/strong>, the plugin sends the customer's IP address to the Predax API, receives back a risk score and signal flags (is_vpn \/ is_proxy \/ is_tor \/ is_datacenter), and tags \/ holds \/ blocks the order according to your configuration. Results are cached for between 5 minutes and 1 hour per IP, following the lifetime the API recommends.<\/li>\n<\/ol>\n\n<p>You can revoke the API key or switch the mode back to \"Tag only\" at any time.<\/p>\n\n<h4>Risk Tagging<\/h4>\n\n<p>Orders that reach the tag threshold (default: risk score 40) are tagged based on band:<\/p>\n\n<ul>\n<li><strong>Risk 40\u201369<\/strong> \u2014 tagged \"Predax: Medium Risk\" with an order note<\/li>\n<li><strong>Risk 70\u201389<\/strong> \u2014 tagged \"Predax: High Risk\" with an order note<\/li>\n<li><strong>Risk 90\u2013100<\/strong> \u2014 tagged \"Predax: Critical Risk\" with an order note<\/li>\n<\/ul>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Checkout screening<\/strong> (after you enable a protection mode) \u2014 every order is checked against Predax IP threat intelligence<\/li>\n<li><strong>VPN \/ Proxy \/ Tor \/ Datacenter flags<\/strong> \u2014 detect anonymised connections at checkout<\/li>\n<li><strong>Risk score threshold blocking<\/strong> \u2014 optionally block checkouts above a configurable risk score<\/li>\n<li><strong>Automatic order hold<\/strong> (opt-in) \u2014 move high-risk orders to On Hold for manual review instead of processing them<\/li>\n<li><strong>Order velocity rules<\/strong> (opt-in) \u2014 flag or block customers placing too many orders in a short window<\/li>\n<li><strong>Billing country vs IP mismatch<\/strong> (opt-in) \u2014 flag or block orders where billing country differs from detected IP country<\/li>\n<li><strong>Disposable email detection<\/strong> (opt-in) \u2014 reject checkouts using throwaway email providers (30+ supported)<\/li>\n<li><strong>Refund \/ chargeback feedback<\/strong> (opt-in) \u2014 when a tagged order is refunded or cancelled, add its IP to your local deny list, and\/or report the outcome to the Community Threat Network (when that opt-in is enabled)<\/li>\n<li><strong>Order meta logging<\/strong> \u2014 stores risk score, threat flags, and detected country on every order for WooCommerce reporting<\/li>\n<li><strong>Events Log<\/strong> \u2014 a dashboard page showing blocked attempts and flagged orders<\/li>\n<li><strong>One-click allow-listing<\/strong> \u2014 approve any IP directly from the Events Log, no settings field to edit<\/li>\n<li><strong>Search-engine safe<\/strong> \u2014 verified crawlers (Googlebot, Bingbot) are exempt from category rules, so screening doesn't affect how your store is crawled and indexed<\/li>\n<\/ul>\n\n<h4>Screening that doesn't cost you real customers or search traffic<\/h4>\n\n<p>The real risk of a fraud rule isn't the fraudster it misses \u2014 it's the genuine customer it turns away without you ever finding out. A blocked shopper rarely tries again, and a store quietly dropped from search results never learns why. Fraud Guard is built to make both failure modes visible and reversible:<\/p>\n\n<ul>\n<li><strong>Verified search engines are exempt from category rules.<\/strong> Googlebot, Bingbot, and other crawlers confirmed by reverse DNS are never caught by your VPN, proxy, datacenter, country, or risk-score rules \u2014 on both the classic and block-based checkout. Search engines crawl from datacenter IP ranges, so a datacenter rule would otherwise turn them away and erode your store's search visibility. Threat rules and your own deny list still apply to everyone regardless.<\/li>\n<li><strong>Every screening decision is on the record.<\/strong> The Events Log shows exactly which orders your rules flagged, held, or blocked, and why \u2014 so if a rule is too strict, you see it in the log rather than in falling sales.<\/li>\n<li><strong>One-click allow-listing.<\/strong> Spot a good customer caught by an over-strict rule? Approve their IP straight from the Events Log \u2014 no copying it into the allow-list field \u2014 and they can check out again immediately.<\/li>\n<\/ul>\n\n<p>Combined with tag-only mode, this means you never have to guess what a rule would do: watch it tag first, turn on blocking when you're confident, and undo any bad block in one click.<\/p>\n\n<h4>Defaults<\/h4>\n\n<p>All protection toggles default to <strong>off<\/strong> on a fresh install. The only thing the plugin writes to options on activation is a database version marker for the events-log table. You will need to explicitly enable any rule you want to apply.<\/p>\n\n<h4>Free Tier<\/h4>\n\n<p>Click \"Connect with Predax\" in the setup wizard to create your free account and link your API key automatically \u2014 no separate sign-up step, no key to copy or paste. The free plan includes 5,000 IP checks per month with full VPN\/proxy\/Tor\/datacenter detection and risk scoring \u2014 no credit card required.<\/p>\n\n<h4>More Power With Paid Plans<\/h4>\n\n<p>The free tier covers a small store comfortably (checkouts are only checked when they happen, and results are cached). Busier stores use up the included checks faster \u2014 <a href=\"https:\/\/predax.io\/pricing\">paid plans<\/a> raise the monthly limit from 5,000 up to 25 million IP checks, with higher request rates and bulk lookups. The Fraud Guard settings page shows your live usage each month, so you can see exactly when it's time to upgrade \u2014 same plugin, same settings, just a bigger allowance on your existing API key.<\/p>\n\n<h3>Third Party Services<\/h3>\n\n<p>This plugin connects to external services operated by Predax (https:\/\/predax.io) only after you have saved an API key: checkout screening additionally requires a protection mode to be enabled, and the admin-side account-usage lookup (described below) sends no visitor data at all. By activating this plugin and entering an API key you agree to the <a href=\"https:\/\/predax.io\/terms\">Predax Terms of Service<\/a> and <a href=\"https:\/\/predax.io\/privacy\">Privacy Policy<\/a>.<\/p>\n\n<p>You are responsible for ensuring your use of customer IP data at checkout complies with applicable privacy laws (including but not limited to GDPR, CCPA) and your own store's privacy policy. This plugin does not assert PCI-DSS, GDPR, or CCPA compliance on your behalf.<\/p>\n\n<h4>Predax IP Intelligence API<\/h4>\n\n<p>Used to look up a risk score and classification signals for each checkout IP.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> the customer's IP address at checkout; the browser-reported IANA timezone string (when available on the classic checkout form \u2014 used for the timezone-mismatch signal); your custom scoring weights (only if Custom Scoring is enabled).<\/li>\n<li><strong>What is NOT sent:<\/strong> no billing\/shipping names, street addresses, phone numbers, email addresses (only the email's domain part, and only under the separate Email Domain Screening below), product details, prices, or payment data. The billing-country-mismatch rule compares your order's billing country against the API's IP-country result locally \u2014 billing details never leave your site.<\/li>\n<li><strong>When:<\/strong> during WooCommerce checkout validation, and only while a protection mode is saved in settings.<\/li>\n<li><strong>Caching:<\/strong> classification results are cached in the site's transients for between 5 minutes and 1 hour per IP (the lifetime the API recommends), so repeat checkouts from the same IP do not generate duplicate API calls.<\/li>\n<li><strong>Endpoint:<\/strong> <code>POST https:\/\/predax.io\/api\/v1\/check\/ip<\/code><\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/predax.io\/terms<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>Email Domain Screening (only when the Disposable Email rule is enabled)<\/h4>\n\n<p>Used to check whether the billing email's provider is a disposable\/throwaway service, against a server-side list of thousands of domains (the plugin's built-in list covers only ~50).<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> the domain part of the billing email address only \u2014 for example <code>gmail.com<\/code>. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.<\/li>\n<li><strong>When:<\/strong> during checkout validation, and only while the Disposable Email rule is set to Flag or Block. If the API is unreachable, the plugin falls back to its built-in local list and the checkout proceeds normally.<\/li>\n<li><strong>Caching:<\/strong> email-domain results are cached in the site's transients for up to 6 hours per domain, so repeat checkouts with the same email provider do not generate duplicate API calls.<\/li>\n<li><strong>Endpoint:<\/strong> <code>POST https:\/\/predax.io\/api\/v1\/validate\/email<\/code><\/li>\n<li><strong>Plan usage:<\/strong> email-domain lookups count against your Predax plan allowance, the same as checkout IP checks. Results are cached per domain for 6 hours and the built-in list is checked first, so in practice this is roughly one lookup per new email provider your customers use.<\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/predax.io\/terms<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>Account Usage Lookup (admin pages only)<\/h4>\n\n<p>Used to show the \"API usage this month\" meter on the Fraud Guard settings page, and only when an API key is saved.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> your Predax API key (as the authentication header). No customer or visitor data is sent.<\/li>\n<li><strong>When:<\/strong> when an administrator views the Fraud Guard settings page. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.<\/li>\n<li><strong>Endpoint:<\/strong> <code>GET https:\/\/predax.io\/api\/v1\/auth\/usage<\/code><\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>Predax Community Threat Network (opt-in, off by default)<\/h4>\n\n<p>The plugin can <strong>optionally<\/strong> send an anonymised telemetry signal \u2014 the IP address, its risk score and detection flags, its network (ASN) number and name, its country code, and the checkout outcome (allowed \/ monitored \/ blocked, or refund\/chargeback feedback) \u2014 to the Predax Community Threat Network so all participating stores benefit from a shared feed. The Refund \/ Chargeback Feedback \"Log\" action reports through this same channel, so it requires this opt-in; its \"Blacklist\" action updates your local deny list regardless.<\/p>\n\n<p>This feature is <strong>off by default<\/strong>. It is controlled by the <code>ipsentry_woo_community_enabled<\/code> option, which defaults to <code>'no'<\/code>, with a checkbox on the Advanced settings tab. The plugin will not send community-feedback telemetry unless you enable it. Customers' personal data (names, emails, billing\/shipping addresses, order contents) is never included in the telemetry payload.<\/p>\n\n<ul>\n<li><strong>Endpoint:<\/strong> <code>POST https:\/\/predax.io\/api\/v1\/telemetry\/event<\/code><\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>OAuth One-Click Connect (optional)<\/h4>\n\n<p>Only triggered when an administrator clicks the <strong>Connect with Predax<\/strong> button in the setup wizard. Your browser is redirected to predax.io to authorise the connection, which returns an API key to your site.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> your WordPress site URL, site name, and a PKCE state\/code-challenge pair. No customer data is involved.<\/li>\n<li><strong>When:<\/strong> only during the click-to-connect OAuth flow.<\/li>\n<li><strong>Endpoint:<\/strong> <code>POST https:\/\/predax.io\/api\/v1\/oauth\/token<\/code><\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>Deactivation Feedback (optional, admin-initiated)<\/h4>\n\n<p>Shown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the \"why are you deactivating?\" prompt.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> the plugin slug, the plugin version, and a single pre-defined reason code you select (e.g. \"it blocked real customers\"). No site URL, no email address, no visitor data, and no IP address are sent.<\/li>\n<li><strong>When:<\/strong> only when you select a reason and click \"Send &amp; deactivate\". Clicking \"Skip &amp; deactivate\" sends nothing at all.<\/li>\n<li><strong>Endpoint:<\/strong> <code>POST https:\/\/predax.io\/api\/v1\/feedback\/deactivation<\/code><\/li>\n<li><strong>Service URL:<\/strong> https:\/\/predax.io<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/predax.io\/privacy<\/li>\n<\/ul>\n\n<h4>Cookies set by this plugin<\/h4>\n\n<ul>\n<li><strong><code>ipsentry_tz<\/code><\/strong> \u2014 set on WooCommerce checkout pages (only while an API key is configured) via <code>assets\/js\/ipsentry-woo-tz.js<\/code>. Stores the customer's browser-reported IANA timezone (string, max 64 chars). Used server-side for the optional timezone-mismatch fraud rule. Expires after 24 hours (<code>max-age=86400<\/code>), <code>path=\/<\/code>, <code>SameSite=Lax<\/code>, and marked <code>Secure<\/code> on HTTPS stores. The plugin reads this cookie only at checkout-validation time.<\/li>\n<\/ul>\n\n<p>The plugin does not set any advertising, analytics, or tracking cookies.<\/p>\n\n<!--section=installation-->\n<h4>From your WordPress dashboard (recommended)<\/h4>\n\n<ol>\n<li>Make sure WooCommerce is installed and activated.<\/li>\n<li>Go to <strong>Plugins &rarr; Add New Plugin<\/strong> in your WordPress admin.<\/li>\n<li>Search for <strong>\"Predax Fraud Guard\"<\/strong>.<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<li>The Setup Wizard launches on first activation. Either click <strong>Connect with Predax<\/strong> for OAuth one-click connection, or enter your API key manually.<\/li>\n<li>Pick a protection preset (Recommended \/ Strict \/ Monitor Only). This is the step where you opt in \u2014 IP lookups begin after this point.<\/li>\n<li>Fine-tune individual rules at <strong>Fraud Guard \u2192 Settings<\/strong> any time.<\/li>\n<\/ol>\n\n<h4>Manual installation<\/h4>\n\n<ol>\n<li>Download the plugin ZIP from this page and upload it via <strong>Plugins &rarr; Add New Plugin &rarr; Upload Plugin<\/strong> (or extract the <code>predax-fraud-guard-for-woocommerce<\/code> folder to <code>\/wp-content\/plugins\/<\/code>).<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu and follow the Setup Wizard.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20stop%20a%20card%20testing%20attack%20that%27s%20happening%20right%20now%3F\"><h3>How do I stop a card testing attack that's happening right now?<\/h3><\/dt>\n<dd><p>Enable a blocking mode (the wizard's Recommended preset blocks risk 50 and above), turn on\nthe order velocity rule, and set VPN, proxy and datacenter to Block. Card-testing bots run\nfrom datacenter, proxy and VPN addresses, so these rules cut the attack off at the\nconnection. Every blocked attempt is listed in the Events Log, and because screening runs\nduring checkout validation \u2014 before the order reaches your payment gateway \u2014 a blocked\nattempt never becomes a transaction, a gateway fee, or a chargeback.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20stripe%2C%20paypal%2C%20or%20my%20payment%20gateway%3F\"><h3>Does it work with Stripe, PayPal, or my payment gateway?<\/h3><\/dt>\n<dd><p>Yes, with any gateway. Screening runs during WooCommerce's own checkout validation, before\nthe order is created and before any payment provider is contacted, so it does not depend on\nwhich gateway you use. It complements gateway-side screening such as Stripe Radar: your\ngateway only ever sees the orders that already passed the IP screen.<\/p><\/dd>\n<dt id=\"how%20is%20this%20different%20from%20other%20woocommerce%20anti-fraud%20plugins%3F\"><h3>How is this different from other WooCommerce anti-fraud plugins?<\/h3><\/dt>\n<dd><p>Most anti-fraud plugins score orders using rules about the order itself \u2014 mismatched names, order size, email patterns. Predax Fraud Guard adds the signal those rules can't see: <strong>live IP intelligence<\/strong>. It knows whether the customer is connecting through a VPN, proxy, Tor, or a datacenter server <em>right now<\/em>, backed by a continuously-updated commercial threat database \u2014 the same signal used to catch card testing and stolen-card fraud before payment is taken. It works well alongside rule-based fraud plugins and payment-processor screening such as Stripe Radar, and alongside security plugins like Wordfence (which protect your site, not your checkout).<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20phone%20home%20before%20i%20finish%20setup%3F\"><h3>Does the plugin phone home before I finish setup?<\/h3><\/dt>\n<dd><p>No. Before you enter an API key and save a protection mode, the plugin makes zero outbound requests to predax.io. Nothing happens silently on activation.<\/p><\/dd>\n<dt id=\"will%20it%20block%20legitimate%20customers%3F\"><h3>Will it block legitimate customers?<\/h3><\/dt>\n<dd><p>Only if you enable a blocking mode. Until you complete setup, the mode is <strong>Tag only<\/strong> (no blocking \u2014 orders just get tags and notes). In the setup wizard, the pre-selected <strong>Recommended<\/strong> preset enables blocking of high-risk checkouts (risk score 50+); choose <strong>Monitor Only<\/strong> instead if you don't want any blocking yet \u2014 each preset card lists exactly what it switches on.<\/p><\/dd>\n<dt id=\"what%20is%20the%20risk%20score%3F\"><h3>What is the risk score?<\/h3><\/dt>\n<dd><p>A score from 0 to 100 representing how likely an IP is to be associated with fraud, anonymisation, or abuse. 0 = clean residential IP, 100 = the strongest combination of threat signals (for example a known-malicious IP arriving over an anonymised connection). The score combines VPN\/proxy\/Tor detection, datacenter identification, historical abuse signals, and geographic heuristics.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20cloudflare%3F\"><h3>Does it work with Cloudflare?<\/h3><\/dt>\n<dd><p>Yes \u2014 enable <strong>Fraud Guard \u2192 Settings \u2192 Advanced \u2192 \"Behind a proxy \/ CDN\"<\/strong> (or the same toggle on the WooCommerce \u2192 Predax tab). With it on, the plugin reads the real customer IP from the <code>CF-Connecting-IP<\/code> \/ <code>X-Forwarded-For<\/code> headers instead of the Cloudflare edge IP. It is <strong>off by default<\/strong>: when your store connects directly to visitors, trusting those headers would let a customer spoof their IP to bypass fraud checks, so you only turn it on when a proxy\/CDN really is in front of your site.<\/p><\/dd>\n<dt id=\"how%20do%20i%20test%20it%20without%20affecting%20real%20customers%3F\"><h3>How do I test it without affecting real customers?<\/h3><\/dt>\n<dd><p>Fraud Guard \u2192 Settings \u2192 Developer tab \u2192 enter a Test IP Override. Every checkout is then evaluated as if it came from that IP. A red admin banner reminds you test mode is active. Clear the override before going live.<\/p>\n\n<p>Use <code>185.220.101.1<\/code> (risk 85, Tor-adjacent) to exercise blocking paths, or <code>1.1.1.1<\/code> to verify pass-through.<\/p><\/dd>\n<dt id=\"what%20order%20metadata%20is%20stored%3F\"><h3>What order metadata is stored?<\/h3><\/dt>\n<dd><p>On each tagged order the plugin stores:<\/p>\n\n<ul>\n<li><code>_ipsentry_risk_score<\/code> \u2014 numeric risk score (0\u2013100)<\/li>\n<li><code>_ipsentry_ip<\/code> \u2014 detected customer IP<\/li>\n<li><code>_ipsentry_country_code<\/code> \u2014 detected IP country code<\/li>\n<li><code>_ipsentry_flags<\/code> \u2014 comma-separated threat flag list<\/li>\n<\/ul><\/dd>\n<dt id=\"does%20it%20work%20alongside%20the%20predax%20security%20plugin%3F\"><h3>Does it work alongside the Predax Security plugin?<\/h3><\/dt>\n<dd><p>Yes. The plugins are independent but complementary \u2014 Security protects logins and registrations, Fraud Guard protects WooCommerce checkout. Both can share the same API key.<\/p><\/dd>\n<dt id=\"will%20this%20block%20real%20customers%20or%20hurt%20my%20store%27s%20seo%3F\"><h3>Will this block real customers or hurt my store's SEO?<\/h3><\/dt>\n<dd><p>Search first: verified search engine crawlers \u2014 Googlebot, Bingbot and others confirmed by\nreverse DNS \u2014 are never caught by your category rules, on both the classic and the\nblock-based checkout, so screening does not affect how your store is crawled or indexed.<\/p>\n\n<p>For customers, the plugin is built so you never have to guess. Start in tag-only mode and\nwatch what your rules <em>would<\/em> have done in the Events Log before you enable any blocking.\nEvery screening decision is recorded with its reason, and a good customer caught by an\nover-strict rule can be allow-listed in one click straight from the log. If your store\nserves audiences where VPN use is common, prefer Monitor mode for the VPN rule.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.11.0<\/h4>\n\n<ul>\n<li>New: the Disposable Email rule now checks a continuously updated list of thousands of throwaway providers instead of the short built-in list. Only the DOMAIN part of the customer's address is checked (for example \"gmail.com\") - the address itself, and everything before the @, never leaves your store. The built-in list is still consulted first and still applies if the API is unreachable, so no store loses a block it had before.<\/li>\n<li>New: orders from a domain that cannot receive mail, or with a machine-generated mailbox name, are noted on the order. Both are record-only signals - they never block a checkout, place an order on hold, or count towards the tag threshold.<\/li>\n<li>Fixed: order flags were discarded when the Predax API was briefly unreachable, so a flagged order could go untagged and unlogged. Fixed on both the classic and the Blocks checkout.<\/li>\n<li>Fixed: a malformed billing email domain could previously cause repeated API errors that temporarily paused IP screening at checkout. Malformed domains are now rejected on your own server and never sent.<\/li>\n<li>Note: email-domain lookups count towards your Predax plan allowance. Results are cached for six hours per domain.<\/li>\n<\/ul>\n\n<h4>1.10.0<\/h4>\n\n<p><strong>Setup wizard<\/strong>\n* The Community Threat Network opt-in is now offered as an explicit, unticked checkbox in the setup wizard, with a plain-English description of exactly what is shared. It stays off by default and can be changed any time on the Advanced settings tab.<\/p>\n\n<p><strong>Housekeeping<\/strong>\n* The plugin now identifies itself and its version in its API requests, which helps support diagnose issues faster.\n* Fix: screening results written by this plugin now carry the same crawler-identity fields as Predax Security. A store running both plugins shares one cached verdict per visitor, and the missing fields could stop Security's crawler policy from applying to a visitor whose verdict was cached at checkout.\n* Corrected in this readme: cached screening results last between 5 minutes and 1 hour per IP (the lifetime the API recommends), not a fixed 5 minutes.\n* Corrected in this readme: the \"will this block real customers\" answer described dashboard features belonging to the Predax Security plugin rather than this one.<\/p>\n\n<h4>1.9.0<\/h4>\n\n<p><strong>Checkout accuracy<\/strong>\n* Fixed one shopper's screening result being reused for a different shopper behind the same network. The cached result was keyed on the IP alone, but the result also depends on the browser's timezone - which the Blocks checkout and the classic checkout send differently - so a timezone mismatch could be inherited by the next genuine customer and get their order tagged or held.\n* An allow-listed IP no longer has its order tagged from a screening result recorded before it was allow-listed.\n* If the Predax API cannot be reached during checkout, any earlier screening result is now discarded rather than being applied to the new order. Previously a customer could be held on a verdict from a previous attempt, possibly from before they turned a VPN off.<\/p>\n\n<p><strong>Events Log<\/strong>\n* \"Filter by reason\" now works on the Flagged tab. Flagged and held orders were saved without a reason, so the filter returned nothing whatever you chose.\n* Flagged orders now record the rule that actually fired - order velocity, disposable email, billing mismatch or the risk threshold - instead of always claiming the risk threshold was crossed.\n* The chosen reason filter is no longer lost when you move to the next page of results.<\/p>\n\n<p><strong>Community Threat Network<\/strong>\n* The Blocks checkout now contributes to the Community Threat Network. Only the classic checkout did, so stores using the default Blocks checkout received other stores' data without contributing any of their own.<\/p>\n\n<p><strong>Other fixes<\/strong>\n* Risk labels on orders now match the bands the Predax API actually issues; an order scoring 75 previously showed a different level to the one the API reported.\n* Importing a settings file can no longer redirect the plugin to a different address - the API key is sent to that address, so this is now restricted to http and https as the settings form already was.\n* Uninstall now removes leftover lookup locks and the shared verdict cache.<\/p>\n\n<p><strong>Efficiency<\/strong>\n* Predax Fraud Guard and Predax Security now share one cached verdict per visitor, so a store running both no longer spends two checks on the same person.\n* Cached verdicts now follow the lifetime the API recommends (up to an hour) instead of a fixed five minutes.\n* Tested up to WordPress 7.1.<\/p>\n\n<h4>1.8.4<\/h4>\n\n<ul>\n<li>Fix: hitting your plan's DAILY check limit no longer reports it as the monthly limit. The notice used to say checkout screening was paused \"until your quota resets on the 1st\" when it actually resumes at midnight UTC the same day. It now names the right limit and tells you the exact time screening resumes.<\/li>\n<li>Improved: fewer API checks are used for the same shopper. Checkout pages make several parallel requests, and each one used to trigger its own lookup; the plugin now performs a single lookup and shares the result.<\/li>\n<\/ul>\n\n<h4>1.8.3<\/h4>\n\n<ul>\n<li>Fix: re-running the Setup Wizard and choosing \"Monitor Only\" now also switches off known-malicious IP blocking. Previously that one rule stayed on if a stricter preset had enabled it, so a preset promising to block nothing could still reject checkouts.<\/li>\n<li>Fix: Fraud Guard admin notices no longer appear on Predax Security plugin pages when both plugins are installed - they now show only on Fraud Guard's own screens.<\/li>\n<\/ul>\n\n<h4>1.8.2<\/h4>\n\n<ul>\n<li>New: an invitation to join the Community Threat Network now appears on the Predax screens, with a one-click opt-in. Stores in the network warn each other, so a card tester blocked at another store is already known to yours. It remains entirely opt-in and was previously easy to miss.<\/li>\n<\/ul>\n\n<h4>1.8.1<\/h4>\n\n<ul>\n<li>Fix: shoppers on a VPN or proxy set to \"Monitor\" were still rejected when datacenter blocking was on, because VPN servers run in datacenters. Monitoring now means monitoring.<\/li>\n<li>Fix: stores in the Community Threat Network were reporting every shopper as having no VPN\/proxy\/Tor\/datacenter signal, so shared intelligence was based on incomplete data.<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>Fix: verified search engines are no longer caught by category rules, on both the classic and block-based checkout.<\/li>\n<li>New: allow any IP directly from the Events Log.<\/li>\n<li>New: tell us why you're deactivating, so we can fix it.<\/li>\n<\/ul>\n\n<h4>1.7.4<\/h4>\n\n<ul>\n<li>Fix: turning OFF both \"Block VPN\" and \"Monitor VPN\" now genuinely ignores VPN shoppers. Previously the order fell through to the risk-score check and was blocked anyway, logged as \"high risk\" with no mention of VPN. Same fix for the proxy toggles, on both the classic checkout and the Store API (block-based checkout) paths.<\/li>\n<\/ul>\n\n<h4>1.7.3<\/h4>\n\n<ul>\n<li>Fix: known-malicious IP blocking (introduced in 1.7.2) now correctly reads the malicious signal from the Predax API \u2014 a normalization gap meant it never actually triggered a block.<\/li>\n<li>New: the Events Log now shows the specific reason for a malicious-IP flag (botnet C2 vs. hijacked network range) instead of a generic \"malicious\" tag.<\/li>\n<li>New: the API key field is now masked (with a Show\/Hide toggle) instead of shown in plain text \u2014 both on the Fraud Rules tab and in the Setup Wizard's manual-entry step \u2014 and is excluded from Settings Export\/Import so it can never leave the site in a shared file.<\/li>\n<\/ul>\n\n<h4>1.7.2<\/h4>\n\n<ul>\n<li>New: known-malicious IP blocking \u2014 a dedicated category (separate from your general risk mode) for botnet C2 and hijacked-netblock IPs. Off by default; enable it via the Setup Wizard's Recommended\/Strict presets, the Fraud Rules tab, or the one-click \"Enable malicious-IP blocking\" notice.<\/li>\n<li>New: filter the Events Log by reason \u2014 narrow the log to just one block category instead of scrolling the full list.<\/li>\n<\/ul>\n\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>New: live API usage meter on the Fraud Guard settings page \u2014 shows your monthly IP-check usage against your plan's quota (fetched hourly), with an upgrade link when you're above 80%.<\/li>\n<li>New: quota notice \u2014 if your plan's monthly IP checks run out (checkout screening pauses and orders are allowed through until the quota resets), the plugin now tells you on its admin pages instead of failing silently. Dismissible per month.<\/li>\n<li>New: API circuit-breaker \u2014 if the Predax API becomes slow or unreachable, checkouts now fail open instantly after a few consecutive failures instead of each waiting on the timeout, and the settings page shows an \"API degraded\" indicator. The API request timeout was lowered from 8s to 3.5s, so even a first failure delays a checkout far less.<\/li>\n<li>Privacy: customer emails in the Events Log are now masked before storage (\"bi***@example.com\"). Enough to recognise a repeat customer; the linked order still holds the full email. Existing rows are untouched and age out via the log retention setting.<\/li>\n<li>Performance: the IP allow\/deny list options no longer autoload on every page request (the deny list can grow via the chargeback auto-append). A one-time migration updates existing installs.<\/li>\n<li>Docs: installation instructions rewritten for installing from the WordPress.org plugin directory; added a section on free vs paid plan limits.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>Rebrand: IPSentry is now <strong>Predax<\/strong>. This is the first WordPress.org release of the WooCommerce plugin. The plugin name, admin menu, and links now use Predax (predax.io). Your existing settings, API key, and order data are preserved \u2014 internal option names are unchanged, so nothing needs reconfiguring.<\/li>\n<li>Admin menu moved to a lower position so it no longer sits among the core WordPress menu items.<\/li>\n<li>Compliance: the OAuth-callback exit page now registers and prints its CSS\/JS through the WordPress script API (wp_register_style\/wp_register_script + wp_print_styles\/wp_print_scripts) instead of hand-written tags. The WooCommerce settings save and checkout timezone read run inside WooCommerce's own nonce-verified flows and carry inline justifications for the static analyser.<\/li>\n<li>Compatibility: declared WooCommerce High-Performance Order Storage (HPOS) compatibility.<\/li>\n<li>Fix: the order-velocity time window now uses a timestamp-based date query (the previous datetime-string form could be misread by WooCommerce and count orders outside the window).<\/li>\n<li>Hardening: checkout error notices are HTML-escaped before being added; the settings-import upload is capped at 512 KB with bounded JSON depth; the API base URL accepts http\/https only; the timezone cookie is marked Secure on HTTPS stores; the Store API block path gained an explicit return after blocking.<\/li>\n<li>Clarity: Refund \/ Chargeback Feedback labels and docs now state that \"Log\" reports go through the Community Threat Network opt-in; the readme documents exact API endpoints and the full telemetry data list.<\/li>\n<li>New: IP allow-list (never block trusted IPs) and a managed deny-list, both supporting single IPs and CIDR ranges (IPv4 + IPv6), editable from the settings page and the WooCommerce \u2192 Predax tab.<\/li>\n<li>New: the Community Threat Network opt-in is now a settings toggle (still off by default) instead of import\/export only.<\/li>\n<li>New: Events Log retention setting (default 90 days; 0 = keep forever) with automatic daily cleanup, plus a 7-day\/all-time stats summary, CSV export, and a Clear Log button.<\/li>\n<li>New: \"Behind a proxy \/ CDN\" setting (off by default). Enable it when your store is behind Cloudflare, a CDN, or a reverse proxy so the real customer IP is read from forwarded headers; when off, only the direct connection IP is used, so the customer IP cannot be spoofed to bypass fraud checks.<\/li>\n<li>Security: the Events Log CSV export now neutralises spreadsheet formula-injection \u2014 a billing email such as \"=...@example.com\" can no longer execute as a formula when the export is opened in Excel\/Sheets.<\/li>\n<li>Fix: the \"Flag for review\" action on the velocity, disposable-email, and billing-country-mismatch rules now reliably tags the order, adds the order note, and writes the Events Log entry (previously these markers could be dropped on processed orders).<\/li>\n<li>Fix: a critically-risky IP (risk score 90+) is now always blocked while a blocking mode is active, even when its VPN\/proxy category is set to Monitor.<\/li>\n<li>Fix: the WooCommerce \u2192 Predax settings tab now saves correctly (removed an invalid nested import form; import is now on the Fraud Guard \u2192 Developer page).<\/li>\n<li>Hardening: \/0 (match-all) entries are rejected in the IP allow\/deny lists, and uninstall now cleans every site on a multisite network.<\/li>\n<li>No change to the opt-in model \u2014 the plugin still makes zero outbound requests until you enter an API key and save a protection mode.<\/li>\n<\/ul>\n\n<h4>1.6.2<\/h4>\n\n<ul>\n<li>Compliance: community-feedback telemetry is now explicitly opt-in (off by default) behind a new <code>ipsentry_woo_community_enabled<\/code> option. Existing installs stop sending telemetry until they flip this on.<\/li>\n<li>Compliance: all phoning-home defaults flipped to off \u2014 <code>block_proxy<\/code>, <code>block_tor<\/code>, and <code>monitor_vpn<\/code> default to <code>'no'<\/code> on fresh installs.<\/li>\n<li>Compliance: removed the self-hosted plugin updater class per WP.org Guideline 8.<\/li>\n<li>Compliance: extracted every inline <code>&lt;script&gt;<\/code> \/ <code>&lt;style&gt;<\/code> block to enqueued asset files. OAuth-callback exit page now references an external CSS\/JS pair.<\/li>\n<li>Compliance: Privacy Policy content hook (<code>wp_add_privacy_policy_content<\/code>) so admins can pull suggested text from Tools \u2192 Privacy.<\/li>\n<li>Compliance: Setup-wizard privacy-disclosure boxes added above OAuth button, manual API-key field, and preset-picker cards.<\/li>\n<li>Compliance: nonce-before-cap order fixed on every admin-post and AJAX handler.<\/li>\n<li>Compliance: input sanitisation tightened on every <code>$_GET<\/code> \/ <code>$_POST<\/code> \/ <code>$_FILES<\/code> read; imported settings values now validated per option type.<\/li>\n<li>Compliance: Test-mode admin notice now scoped to Predax pages only (not global).<\/li>\n<li>Added: <code>uninstall.php<\/code> drops the events-log table and deletes every <code>ipsentry_woo_*<\/code> option on plugin deletion.<\/li>\n<li>Added: <code>Domain Path: \/languages<\/code> header + minimal .pot translation template.<\/li>\n<li>Added: <code>.distignore<\/code> excluding dev artefacts from the WP.org zip.<\/li>\n<li>No behaviour change for existing installs other than the community-feedback gate \u2014 core IP checking still works as before.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Improved: OAuth connect popup now auto-closes reliably after authorization.<\/li>\n<li>Improved: Per-user OAuth transients prevent conflicts on multi-admin sites.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>New: Setup Wizard \u2014 guided 3-step setup on first activation with fraud protection presets (Recommended, Strict, Monitor Only).<\/li>\n<li>New: One-Click Connect \u2014 click \"Connect with Predax\" in the setup wizard to link your store via OAuth. No API key to copy or paste.<\/li>\n<li>New: \"Run Setup Wizard\" link in Developer tab to re-run the wizard at any time.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>New: Events Log admin page (Predax \u2192 Events Log) \u2014 two tabs showing blocked checkout attempts and flagged\/held orders with IP, risk score, flags, reason, and order links.<\/li>\n<li>New: Predax risk column on WooCommerce \u2192 Orders list \u2014 shows colour-coded score badge and top threat flag.<\/li>\n<li>Improvement: Orders now store a combined <code>_ipsentry_flags<\/code> meta key for quick flag lookup.<\/li>\n<\/ul>\n\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>New: Dedicated settings page under Predax \u2192 Fraud Guard in the WordPress admin left nav \u2014 same tabbed UI as the Security plugin.<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>New: Settings import\/export \u2014 back up your configuration or copy it between sites.<\/li>\n<li>New: Support Email field \u2014 if set, checkout block error messages include a \"Contact us at\u2026\" line.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Fix: VPN\/proxy customers set to Monitor mode were incorrectly blocked by the risk threshold.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: Automatic order hold, order velocity rules, billing country vs IP mismatch, disposable email detection, refund\/chargeback feedback, test IP override.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: Off\/Monitor\/Block radio groups for VPN, proxy, and Tor.<\/li>\n<li>New: Custom risk scoring weights \u2014 adjust per-signal contribution to the final risk score.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: Country-based blocking at checkout. Whitelist support. API timeout handling.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: Configurable risk threshold. Order meta. Detailed order notes.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release. Tag-only fraud screening at checkout. VPN \/ proxy \/ Tor \/ datacenter detection.<\/li>\n<\/ul>","raw_excerpt":"Stop card testing, stolen-card fraud and chargebacks before the order is placed. Screens every checkout IP for VPN, proxy, Tor and fraud risk.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/323963","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=323963"}],"author":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ipsentry"}],"wp:attachment":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=323963"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=323963"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=323963"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=323963"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=323963"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=323963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}