[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMZny6an3YpOu1VpEL5vfNRQMp7m3JcBBVQFPWuh_J64":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"ipsentry","Predax","https:\u002F\u002Fprofiles.wordpress.org\u002Fipsentry\u002F",1,0,100,30,94,"2026-08-29T01:40:48.800Z",[14],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"predax-fraud-guard-for-woocommerce","Predax Fraud Guard for WooCommerce","1.7.1","\u003Cp>\u003Cstrong>Stop fraudulent WooCommerce orders before they’re placed.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Card testers, stolen-card fraudsters, and serial chargeback abusers almost always hide behind VPNs, proxies, Tor, or datacenter IPs. Predax Fraud Guard screens the customer’s IP the moment they check out, scores its fraud risk from 0 to 100, and lets your store tag, hold, or block the order — before payment is taken and before a chargeback can happen.\u003C\u002Fp>\n\u003Cp>Think of it as an order guard standing in front of your checkout. You stay in control of every decision: start in \u003Cstrong>tag-only\u003C\u002Fstrong> mode to see which orders would have been flagged, then turn on blocking for the risk levels you choose. Screening works with both the classic and block (Store API) checkout.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Fully opt-in:\u003C\u002Fstrong> on a fresh install the plugin does nothing — no outbound requests are made until \u003Cstrong>you\u003C\u002Fstrong> enter a Predax API key and pick a protection mode. The default mode once configured is tag-only (no blocking), so you can review flagged orders in your dashboard before turning on anything that rejects a customer.\u003C\u002Fp>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>You install and activate the plugin.\u003C\u002Fstrong> Nothing happens — the plugin stays dormant until you finish setup.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You enter a Predax API key\u003C\u002Fstrong> (free account available at \u003Ca href=\"https:\u002F\u002Fpredax.io\" rel=\"nofollow ugc\">predax.io\u003C\u002Fa>).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You pick a protection mode\u003C\u002Fstrong> in Fraud Guard \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings (or in the 3-step setup wizard). Choices: Tag + note, Block high risk, or Block critical only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On each WooCommerce checkout after that point\u003C\u002Fstrong>, the plugin sends the customer’s IP address to the Predax API, receives back a risk score and signal flags (is_vpn \u002F is_proxy \u002F is_tor \u002F is_datacenter), and tags \u002F holds \u002F blocks the order according to your configuration. Results are cached for up to 5 minutes per IP.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>You can revoke the API key or switch the mode back to “Tag only” at any time.\u003C\u002Fp>\n\u003Ch4>Risk Tagging\u003C\u002Fh4>\n\u003Cp>Orders that reach the tag threshold (default: risk score 40) are tagged based on band:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Risk 40–69\u003C\u002Fstrong> — tagged “Predax: Medium Risk” with an order note\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Risk 70–89\u003C\u002Fstrong> — tagged “Predax: High Risk” with an order note\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Risk 90–100\u003C\u002Fstrong> — tagged “Predax: Critical Risk” with an order note\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Checkout screening\u003C\u002Fstrong> (after you enable a protection mode) — every order is checked against Predax IP threat intelligence\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VPN \u002F Proxy \u002F Tor \u002F Datacenter flags\u003C\u002Fstrong> — detect anonymised connections at checkout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Risk score threshold blocking\u003C\u002Fstrong> — optionally block checkouts above a configurable risk score\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic order hold\u003C\u002Fstrong> (opt-in) — move high-risk orders to On Hold for manual review instead of processing them\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order velocity rules\u003C\u002Fstrong> (opt-in) — flag or block customers placing too many orders in a short window\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Billing country vs IP mismatch\u003C\u002Fstrong> (opt-in) — flag or block orders where billing country differs from detected IP country\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disposable email detection\u003C\u002Fstrong> (opt-in) — reject checkouts using throwaway email providers (30+ supported)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Refund \u002F chargeback feedback\u003C\u002Fstrong> (opt-in) — when a tagged order is refunded or cancelled, add its IP to your local deny list, and\u002For report the outcome to the Community Threat Network (when that opt-in is enabled)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order meta logging\u003C\u002Fstrong> — stores risk score, threat flags, and detected country on every order for WooCommerce reporting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Events Log\u003C\u002Fstrong> — a dashboard page showing blocked attempts and flagged orders\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Defaults\u003C\u002Fh4>\n\u003Cp>All protection toggles default to \u003Cstrong>off\u003C\u002Fstrong> on a fresh install. The only thing the plugin writes to options on activation is a database version marker for the events-log table. You will need to explicitly enable any rule you want to apply.\u003C\u002Fp>\n\u003Ch4>Free Tier\u003C\u002Fh4>\n\u003Cp>Sign up at \u003Ca href=\"https:\u002F\u002Fpredax.io\" rel=\"nofollow ugc\">predax.io\u003C\u002Fa> for a free API key. The free plan includes 5,000 IP checks per month with full VPN\u002Fproxy\u002FTor\u002Fdatacenter detection and risk scoring — no credit card required.\u003C\u002Fp>\n\u003Ch4>More Power With Paid Plans\u003C\u002Fh4>\n\u003Cp>The free tier covers a small store comfortably (checkouts are only checked when they happen, and results are cached). Busier stores use up the included checks faster — \u003Ca href=\"https:\u002F\u002Fpredax.io\u002Fpricing\" rel=\"nofollow ugc\">paid plans\u003C\u002Fa> raise the monthly limit from 5,000 up to 25,000&ndash;25,000,000 IP checks, with higher request rates and bulk lookups. The Fraud Guard settings page shows your live usage each month, so you can see exactly when it’s time to upgrade — same plugin, same settings, just a bigger allowance on your existing API key.\u003C\u002Fp>\n\u003Ch3>Third Party Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to external services operated by Predax (https:\u002F\u002Fpredax.io) only after you have saved an API key: checkout screening additionally requires a protection mode to be enabled, and the admin-side account-usage lookup (described below) sends no visitor data at all. By activating this plugin and entering an API key you agree to the \u003Ca href=\"https:\u002F\u002Fpredax.io\u002Fterms\" rel=\"nofollow ugc\">Predax Terms of Service\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fpredax.io\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>You are responsible for ensuring your use of customer IP data at checkout complies with applicable privacy laws (including but not limited to GDPR, CCPA) and your own store’s privacy policy. This plugin does not assert PCI-DSS, GDPR, or CCPA compliance on your behalf.\u003C\u002Fp>\n\u003Ch4>Predax IP Intelligence API\u003C\u002Fh4>\n\u003Cp>Used to look up a risk score and classification signals for each checkout IP.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> the customer’s IP address at checkout; the browser-reported IANA timezone string (when available on the classic checkout form — used for the timezone-mismatch signal); your custom scoring weights (only if Custom Scoring is enabled).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What is NOT sent:\u003C\u002Fstrong> no billing\u002Fshipping names, street addresses, phone numbers, emails, product details, prices, or payment data. The billing-country-mismatch rule compares your order’s billing country against the API’s IP-country result locally — billing details never leave your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> during WooCommerce checkout validation, and only while a protection mode is saved in settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Caching:\u003C\u002Fstrong> classification results are cached in the site’s transients for 5 minutes per IP, so repeat checkouts from the same IP do not generate duplicate API calls.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> \u003Ccode>POST https:\u002F\u002Fpredax.io\u002Fapi\u002Fv1\u002Fcheck\u002Fip\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Account Usage Lookup (admin pages only)\u003C\u002Fh4>\n\u003Cp>Used to show the “API usage this month” meter on the Fraud Guard settings page, and only when an API key is saved.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> your Predax API key (as the authentication header). No customer or visitor data is sent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> when an administrator views the Fraud Guard settings page. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> \u003Ccode>GET https:\u002F\u002Fpredax.io\u002Fapi\u002Fv1\u002Fauth\u002Fusage\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Predax Community Threat Network (opt-in, off by default)\u003C\u002Fh4>\n\u003Cp>The plugin can \u003Cstrong>optionally\u003C\u002Fstrong> send an anonymised telemetry signal — the IP address, its risk score and detection flags, its network (ASN) number and name, its country code, and the checkout outcome (allowed \u002F monitored \u002F blocked, or refund\u002Fchargeback feedback) — to the Predax Community Threat Network so all participating stores benefit from a shared feed. The Refund \u002F Chargeback Feedback “Log” action reports through this same channel, so it requires this opt-in; its “Blacklist” action updates your local deny list regardless.\u003C\u002Fp>\n\u003Cp>This feature is \u003Cstrong>off by default\u003C\u002Fstrong>. It is controlled by the \u003Ccode>ipsentry_woo_community_enabled\u003C\u002Fcode> option, which defaults to \u003Ccode>'no'\u003C\u002Fcode>, with a checkbox on the Advanced settings tab. The plugin will not send community-feedback telemetry unless you enable it. Customers’ personal data (names, emails, billing\u002Fshipping addresses, order contents) is never included in the telemetry payload.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> \u003Ccode>POST https:\u002F\u002Fpredax.io\u002Fapi\u002Fv1\u002Ftelemetry\u002Fevent\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>OAuth One-Click Connect (optional)\u003C\u002Fh4>\n\u003Cp>Only triggered when an administrator clicks the \u003Cstrong>Connect with Predax\u003C\u002Fstrong> button in the setup wizard. Your browser is redirected to predax.io to authorise the connection, which returns an API key to your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> your WordPress site URL, site name, and a PKCE state\u002Fcode-challenge pair. No customer data is involved.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> only during the click-to-connect OAuth flow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint:\u003C\u002Fstrong> \u003Ccode>POST https:\u002F\u002Fpredax.io\u002Fapi\u002Fv1\u002Foauth\u002Ftoken\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpredax.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Cookies set by this plugin\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ccode>ipsentry_tz\u003C\u002Fcode>\u003C\u002Fstrong> — set on WooCommerce checkout pages (only while an API key is configured) via \u003Ccode>assets\u002Fjs\u002Fipsentry-woo-tz.js\u003C\u002Fcode>. Stores the customer’s browser-reported IANA timezone (string, max 64 chars). Used server-side for the optional timezone-mismatch fraud rule. Expires after 24 hours (\u003Ccode>max-age=86400\u003C\u002Fcode>), \u003Ccode>path=\u002F\u003C\u002Fcode>, \u003Ccode>SameSite=Lax\u003C\u002Fcode>, and marked \u003Ccode>Secure\u003C\u002Fcode> on HTTPS stores. The plugin reads this cookie only at checkout-validation time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin does not set any advertising, analytics, or tracking cookies.\u003C\u002Fp>\n","Stop fraudulent WooCommerce orders before they are placed. Screens each checkout IP for VPN, proxy, Tor, and fraud risk — tag, hold, or block.",140,"2026-07-13T18:53:00.000Z","7.0.2","5.8","7.4",[26,27,28,29,30],"checkout-security","fraud-prevention","ip-detection","vpn-detection","woocommerce","https:\u002F\u002Fpredax.io\u002Fintegrations\u002Fwoocommerce","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpredax-fraud-guard-for-woocommerce.1.7.1.zip",null,"2026-07-22T17:31:50.256Z"]