[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f87zRhyqbiWpEIwgulcveZKH-QPC6TQhyfnFWsg2dIBg":3,"$fUzlrFb0nFJ-rTeAYbBQiioGgJW8fuL7-gsp_Xd0OD00":129,"$f5wWauchAq9T4NiYZOmIKYLB-bAEouGhoF8-1fqg7cTA":134},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"toply-skimshield","Toply SkimShield","1.0.4","TonioWeb","https:\u002F\u002Fprofiles.wordpress.org\u002Ftoply\u002F","\u003Ch4>The Problem\u003C\u002Fh4>\n\u003Cp>Imagine a hacker silently adds a piece of JavaScript code to your WooCommerce checkout page. Every time a customer types in their credit card number, that hidden code copies it and sends it to the hacker — without you or your customer ever knowing. This type of attack is called \u003Cstrong>checkout skimming\u003C\u002Fstrong>, and it is one of the most common ways online stores get compromised.\u003C\u002Fp>\n\u003Cp>Toply SkimShield protects you by watching your checkout page and alerting you the moment anything changes.\u003C\u002Fp>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Step 1 — Takes a snapshot\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen you run the first scan, the plugin looks at every JavaScript file loaded on your checkout page and saves a unique fingerprint (a hash) for each one. This becomes your approved baseline — the “normal” state of your checkout.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 2 — Watches for changes\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery time someone visits your checkout page, the plugin silently compares the live scripts against that saved baseline. If everything matches, nothing happens. If a new script appears or an existing one has been modified, the plugin raises an alert immediately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 3 — Notifies you by email\u003C\u002Fstrong>\u003Cbr \u002F>\nThe moment a suspicious change is detected, you receive an email with details: which script changed, what it looked like before, what it looks like now, and a direct link to review it in your dashboard.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 4 — You decide what is legitimate\u003C\u002Fstrong>\u003Cbr \u002F>\nIn the admin dashboard you see a list of all scripts found on your checkout page. You approve the ones you recognise (WooCommerce, Stripe, PayPal, Google Analytics, etc.) and block anything that looks suspicious. The plugin remembers your decisions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 5 — Optionally block unauthorised scripts entirely (CSP)\u003C\u002Fstrong>\u003Cbr \u002F>\nOnce you have approved all your legitimate scripts, you can turn on the Content Security Policy feature. This tells the browser: “do not run any script on the checkout page that is not on the approved list.” Even if a hacker manages to inject a script, the browser will refuse to execute it.\u003C\u002Fp>\n\u003Ch4>Think of It Like a Security Camera for Your Checkout\u003C\u002Fh4>\n\u003Cp>The first scan registers who is allowed in. Every visit after that checks: is there anyone new? If yes — alarm. No technical knowledge required to use it.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Script monitoring\u003C\u002Fstrong> — detects new or modified scripts on every checkout page load\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant email alerts\u003C\u002Fstrong> — notified the moment something changes, via the standard WordPress email system\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Script whitelist\u003C\u002Fstrong> — approve or block scripts with one click from the admin dashboard\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Security Policy\u003C\u002Fstrong> — automatically generates a CSP header based on your approved scripts; start in Report-Only mode to avoid breaking checkout, then switch to Enforce when ready\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PCI-DSS compliance report\u003C\u002Fstrong> — generates a printable report covering requirements 6.4.3 and 12.10, ready to show to your payment processor or auditor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external dependencies\u003C\u002Fstrong> — everything runs on your own server, no API keys, no third-party services, no data sent anywhere\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Needs This\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Any WooCommerce store that accepts card payments\u003C\u002Fli>\n\u003Cli>Store owners who want to know immediately if their checkout page is tampered with\u003C\u002Fli>\n\u003Cli>Agencies managing WooCommerce stores on behalf of clients\u003C\u002Fli>\n\u003Cli>Stores that need to demonstrate PCI-DSS compliance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How to Test This Plugin\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong> WooCommerce must be active with at least one published product and a functioning checkout page (your shop must have a \u003Ccode>\u002Fcheckout\u002F\u003C\u002Fcode> page set up by WooCommerce).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step-by-step test procedure:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Install and activate\u003C\u002Fstrong> the plugin. Navigate to \u003Cstrong>SkimShield\u003C\u002Fstrong> in the admin sidebar.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Run a manual scan\u003C\u002Fstrong> — on the Dashboard tab, click the \u003Cstrong>Scan Now\u003C\u002Fstrong> button. The plugin fetches the WooCommerce checkout page and extracts every script tag (both external \u003Ccode>\u003Cscript src=\"…\">\u003C\u002Fcode> and inline \u003Ccode>\u003Cscript>…\u003C\u002Fscript>\u003C\u002Fcode>).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>View detected scripts\u003C\u002Fstrong> — click the \u003Cstrong>Script Whitelist\u003C\u002Fstrong> tab. You will see a table listing all scripts found on the checkout page, each with its handle, source URL (or inline snippet), type (enqueued\u002Finline), SHA-256 hash, and status (Pending).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Approve scripts\u003C\u002Fstrong> — click the \u003Cstrong>Approve\u003C\u002Fstrong> button next to each legitimate script. The status changes to “Approved”.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Verify real-time monitoring\u003C\u002Fstrong> — visit your store’s checkout page as a normal visitor (front-end). The plugin hooks into \u003Ccode>wp_enqueue_scripts\u003C\u002Fcode> at priority \u003Ccode>PHP_INT_MAX\u003C\u002Fcode> and records every script loaded. New scripts trigger an entry in the Incidents log.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Check the Incidents tab\u003C\u002Fstrong> — any scripts detected for the first time generate an incident with severity “High”. A hash change (simulating a tampering event) generates a “Critical” incident.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Test email alerts\u003C\u002Fstrong> — make sure the Alert Email address in \u003Cstrong>Settings\u003C\u002Fstrong> is a deliverable inbox. Visit the checkout page with a browser. If any new script is detected, an HTML email is sent immediately via \u003Ccode>wp_mail()\u003C\u002Fcode>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Enable CSP (optional)\u003C\u002Fstrong> — go to \u003Cstrong>Settings\u003C\u002Fstrong>, enable “CSP Header”, leave “Report-Only Mode” checked, and save. Visit the checkout page. The \u003Ccode>Content-Security-Policy-Report-Only\u003C\u002Fcode> HTTP header will now be present (verify with browser DevTools \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Network \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> checkout request headers).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Generate a compliance report\u003C\u002Fstrong> — click the \u003Cstrong>PCI-DSS Report\u003C\u002Fstrong> tab and review the auto-generated report covering requirements 6.4.3 and 12.10.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Expected results after running Scan Now:\u003C\u002Fstrong>\u003Cbr \u002F>\n– The Script Whitelist tab shows all scripts that are on the checkout page\u003Cbr \u002F>\n– Each row shows the script handle, source, type (enqueued or inline), a truncated SHA-256 hash, and status\u003Cbr \u002F>\n– Approve\u002FBlock\u002FRemove action buttons are functional\u003Cbr \u002F>\n– The Dashboard shows the count of Approved, Pending, and Blocked scripts\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin does \u003Cstrong>not\u003C\u002Fstrong> connect to any external service for its core functionality. All script monitoring and hashing is performed locally on your server.\u003C\u002Fp>\n\u003Cp>The auto-generated Content Security Policy (CSP) template includes default \u003Ccode>frame-src\u003C\u002Fcode> origins for common payment gateways (\u003Ccode>https:\u002F\u002Fwww.paypal.com\u003C\u002Fcode>, \u003Ccode>https:\u002F\u002Fjs.stripe.com\u003C\u002Fcode>, \u003Ccode>https:\u002F\u002Ffonts.gstatic.com\u003C\u002Fcode>). These are included only as a default starting point to prevent checkout from breaking when you first enable the CSP feature. No data is transmitted by this plugin to those domains — the browser uses the CSP header to decide which external resources to load, independently of this plugin.\u003C\u002Fp>\n\u003Cp>If your store does not use PayPal or Stripe, you can remove those origins via the Custom CSP Directives field in Settings.\u003C\u002Fp>\n","Real-time script integrity monitoring and CSP automation for WooCommerce checkout. No API dependencies. Detects unauthorized scripts on checkout.",0,141,"2026-05-31T13:25:00.000Z","7.0.2","5.8","7.4",[18,19,20,21,22],"checkout","pci-dss","script-monitoring","security","woocommerce","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftoply-skimshield\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.4.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"toply",3,30,94,"2026-08-28T23:46:28.657Z",[37,56,75,93,110],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":25,"num_ratings":47,"last_updated":48,"tested_up_to":14,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":54,"download_link":55,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"carticy-checkout-shield-for-woocommerce","Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing","1.1.1","carticy","https:\u002F\u002Fprofiles.wordpress.org\u002Fcarticy\u002F","\u003Cp>\u003Cstrong>Checkout Shield\u003C\u002Fstrong> stops fake checkout orders and card testing attacks — the kind that bypass your CAPTCHA.\u003C\u002Fp>\n\u003Cp>Card testing bots don’t fill out your checkout form. They hit your store’s checkout API directly, completely skipping any reCAPTCHA or hCaptcha you’ve set up. That’s why CAPTCHA alone doesn’t stop them.\u003C\u002Fp>\n\u003Cp>This plugin verifies that every checkout request comes from a real browser session. Bots that can’t prove they loaded your checkout page get blocked before WooCommerce processes the order.\u003C\u002Fp>\n\u003Ch4>Why Store Owners Choose This Plugin\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Catches what CAPTCHA misses\u003C\u002Fstrong> — blocks bots hitting your checkout API directly\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with any caching\u003C\u002Fstrong> — LiteSpeed, Cloudflare, WP Rocket, W3TC — no conflicts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero configuration\u003C\u002Fstrong> — activate and you’re protected\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external services\u003C\u002Fstrong> — everything runs on your server, no subscriptions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No performance impact\u003C\u002Fstrong> — validation adds microseconds, not seconds\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatic bot blocking\u003C\u002Fstrong> — works the moment you activate, no setup needed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>4 protection levels\u003C\u002Fstrong> — Learning, Permissive, Balanced, and Strict — choose how aggressive you want to be\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dashboard overview\u003C\u002Fstrong> — see blocked vs verified orders at a glance with a 7-day chart\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order status tracking\u003C\u002Fstrong> — know which orders were flagged, passed, or blocked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP whitelist\u003C\u002Fstrong> — let trusted addresses through, supports CIDR notation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API key authentication\u003C\u002Fstrong> — for headless and custom checkout setups\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with all checkout types\u003C\u002Fstrong> — classic, block-based, and all payment gateways\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HPOS compatible\u003C\u002Fstrong> — works with High-Performance Order Storage\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce logging\u003C\u002Fstrong> — full integration with WooCommerce Status logs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Features\u003C\u002Fh4>\n\u003Cp>Take control with advanced tools:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>3-level logging control\u003C\u002Fstrong> — turn logging off, log blocked attempts only, or log everything\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recent blocks feed\u003C\u002Fstrong> — last 50 blocked attempts on your dashboard with email, payment method, and reason\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic CDN\u002Fproxy detection\u003C\u002Fstrong> — identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stronger permissive mode\u003C\u002Fstrong> — tighter bot detection with referrer verification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checkout details in logs\u003C\u002Fstrong> — see which email and payment method bots tried to use\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customer blocklist\u003C\u002Fstrong> — block repeat offenders by email, name, address, phone, IP, or postal code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click order blocking\u003C\u002Fstrong> — block a customer directly from any order screen\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fcarticy.com\u002Fplugins\u002Fcheckout-shield-for-woocommerce\u002F\" rel=\"nofollow ugc\">Learn more about Pro features\u003C\u002Fa>\u003C\u002Fp>\n","Stops fake checkout orders, card testing attacks, and spam bots that bypass CAPTCHA. Works instantly with all checkout types.",200,1056,4,"2026-05-24T09:58:00.000Z","6.0","8.0",[52,18,53,21,22],"bot-protection","fraud","https:\u002F\u002Fcarticy.com\u002Fcheckout-shield","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcarticy-checkout-shield-for-woocommerce.1.1.1.zip",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":11,"num_ratings":11,"last_updated":66,"tested_up_to":67,"requires_at_least":49,"requires_php":16,"tags":68,"homepage":73,"download_link":74,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"checkout-origin-guard","Checkout Origin Guard","1.7.2","POTAR","https:\u002F\u002Fprofiles.wordpress.org\u002Fpotar\u002F","\u003Cp>\u003Cstrong>Checkout Origin Guard\u003C\u002Fstrong> protects your WooCommerce store from fake, fraudulent, or automated checkout attempts by identifying and blocking abusive origins before they clutter your order table or your logs.\u003C\u002Fp>\n\u003Cp>The plugin runs \u003Cstrong>client-origin heuristics\u003C\u002Fstrong>, \u003Cstrong>IP controls\u003C\u002Fstrong>, and \u003Cstrong>sequence analysis\u003C\u002Fstrong> to detect non-human traffic and suspicious behavior at checkout. It adds \u003Cstrong>Company Shield\u003C\u002Fstrong> for business and email sanity checks and an optional \u003Cstrong>AVS “U” signal handler\u003C\u002Fstrong> for gateways that report “Address not checked \u002F unavailable”.\u003C\u002Fp>\n\u003Cp>All controls live on a \u003Cstrong>single admin screen\u003C\u002Fstrong>; you can adjust sensitivity, manage allowlists and blocklists, and review traffic logs in one place.\u003C\u002Fp>\n\u003Ch3>Three layers of protection\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Bot Block (traffic level)\u003C\u002Fstrong>\u003Cbr \u002F>\nDetects and throttles abusive requests before they become orders:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Analyzes user agents, referrers, and known bot signatures  \u003C\u002Fli>\n\u003Cli>Watches rapid-fire hits to checkout and wc-ajax endpoints  \u003C\u002Fli>\n\u003Cli>Supports monitor, soft, and hard blocking modes  \u003C\u002Fli>\n\u003Cli>Built-in allowlist for search engines, uptime monitors, and core WordPress services\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Company Shield (checkout level)\u003C\u002Fstrong>\u003Cbr \u002F>\nValidates business identity and email quality at checkout:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Flags suspicious or synthetic business names  \u003C\u002Fli>\n\u003Cli>Detects repeated syllables, odd vowel ratios, and gibberish patterns  \u003C\u002Fli>\n\u003Cli>Identifies disposable email domains and role-based accounts (admin, info, sales, etc.)  \u003C\u002Fli>\n\u003Cli>Can run in:\n\u003Cul>\n\u003Cli>\u003Cstrong>Monitor\u003C\u002Fstrong>; log and annotate orders  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Soft\u003C\u002Fstrong>; create the order and automatically place it on hold or pending  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hard\u003C\u002Fstrong>; block checkout with a user-facing error message\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Payment AVS signals (post-payment; optional)\u003C\u002Fstrong>\u003Cbr \u002F>\nFor gateways that expose AVS results in order meta, Checkout Origin Guard can treat “AVS: U; unavailable \u002F not checked” as a \u003Cstrong>risk signal\u003C\u002Fstrong>:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Does not change how your gateway authorizes or captures payments  \u003C\u002Fli>\n\u003Cli>Can be configured to:\n\u003Cul>\n\u003Cli>Ignore the signal  \u003C\u002Fli>\n\u003Cli>Add an order note only  \u003C\u002Fli>\n\u003Cli>Add an order note and bump a risk-score meta field  \u003C\u002Fli>\n\u003Cli>Put the order on hold for manual review  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Uses flexible pattern matching; can scan specific gateway meta keys or fall back to scanning all order meta for common “AVS: U” messages such as the PayPal string  \u003C\u002Fli>\n\u003Cli>Off by default; you opt in and choose the behavior\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>🛡️ \u003Cstrong>Bot Block\u003C\u002Fstrong>; Detects and blocks automated bots by analyzing user agents, referrers, and checkout behavior patterns.\u003C\u002Fli>\n\u003Cli>⚡ \u003Cstrong>Rapid Sequence Detection\u003C\u002Fstrong>; Monitors frequency and timing between checkout attempts to identify scripted attacks and card testing activity.\u003C\u002Fli>\n\u003Cli>🧠 \u003Cstrong>Company Shield\u003C\u002Fstrong>; Flags suspicious or AI-generated business names, email domains, and mixed-character spam entries at checkout.\u003C\u002Fli>\n\u003Cli>🌎 \u003Cstrong>Allowlist Controls\u003C\u002Fstrong>; Preserve access for search engines, uptime monitors, and essential WordPress and WooCommerce services.\u003C\u002Fli>\n\u003Cli>🔒 \u003Cstrong>Hard \u002F Soft \u002F Monitor Modes\u003C\u002Fstrong>; Choose between logging only, soft blocking, or full hard blocking.\u003C\u002Fli>\n\u003Cli>🧾 \u003Cstrong>AVS “U” Risk Signals (optional)\u003C\u002Fstrong>; Treat “Address not checked \u002F unavailable” as a post-payment risk signal; add notes, increase risk score, or hold the order.\u003C\u002Fli>\n\u003Cli>🗂️ \u003Cstrong>Log Viewer\u003C\u002Fstrong>; See activity including timestamps, IPs, user agents, paths, and detection outcomes.\u003C\u002Fli>\n\u003Cli>🧩 \u003Cstrong>One-Page Dashboard\u003C\u002Fstrong>; Configure settings, review logs, and manage allow\u002Fdeny lists from a single screen.\u003C\u002Fli>\n\u003Cli>🚫 \u003Cstrong>Manual Block \u002F Unblock\u003C\u002Fstrong>; Instantly remove or restore access for specific IPs with one click.\u003C\u002Fli>\n\u003Cli>💾 \u003Cstrong>CSV Export\u003C\u002Fstrong>; Download checkout-origin activity logs for security review or record keeping.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Online Shops Need it\u003C\u002Fh3>\n\u003Cp>WooCommerce checkouts are frequent targets for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Card testing and BIN probing  \u003C\u002Fli>\n\u003Cli>Fake business registrations and spam accounts  \u003C\u002Fli>\n\u003Cli>Automated scripts hammering your checkout endpoints  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Checkout Origin Guard focuses on \u003Cstrong>checkout behavior and identity quality\u003C\u002Fstrong>, not just generic firewall rules. It helps you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Reduce chargeback and fraud risk  \u003C\u002Fli>\n\u003Cli>Keep your order list clean and reviewable  \u003C\u002Fli>\n\u003Cli>Shorten the time spent cleaning up junk orders and bogus signups  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin works alongside any existing firewall, CDN, or WAF; it does not rely on external APIs or subscriptions. All data stays on your server.\u003C\u002Fp>\n\u003Ch3>Use Cases\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Prevent card testing or order spam  \u003C\u002Fli>\n\u003Cli>Stop bots using nonsense or AI-generated company names  \u003C\u002Fli>\n\u003Cli>Detect rapid repeat checkout attempts from the same IP  \u003C\u002Fli>\n\u003Cli>Block suspicious POST requests that hit checkout endpoints  \u003C\u002Fli>\n\u003Cli>Add an extra layer of review for orders where the gateway reports “AVS unavailable \u002F not checked”  \u003C\u002Fli>\n\u003Cli>Maintain cleaner order history and logs for real customers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Developed by \u003Cstrong>Michael Winchester\u003C\u002Fstrong>\u003Cbr \u002F>\nFor documentation and updates, visit https:\u002F\u002Fmichaelwinchester.com\u003C\u002Fp>\n","One-page WooCommerce checkout hardening; bot blocking, rate\u002Fsequence checks, business\u002Femail heuristics, and optional AVS-based risk signals.",10,705,"2026-04-16T19:43:00.000Z","6.9.5",[52,69,70,71,72],"fraud-prevention","ip-blocker","spam","woocommerce-checkout-security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcheckout-origin-guard.1.7.2.zip",{"slug":76,"name":77,"version":78,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":64,"downloaded":83,"rating":11,"num_ratings":11,"last_updated":84,"tested_up_to":85,"requires_at_least":86,"requires_php":87,"tags":88,"homepage":90,"download_link":91,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":92},"safercheckout-lite","SaferCheckout Lite – Fraud prevention for WooCommerce","1.10","nintechnet","https:\u002F\u002Fprofiles.wordpress.org\u002Fnintechnet\u002F","\u003Ch4>Safeguard Your WooCommerce Store.\u003C\u002Fh4>\n\u003Cp>SaferCheckout (Lite) is a powerful security plugin to protect your WooCommerce store from fraudulent activities. It offers several unique and advanced features as well as customizable rules to filter every order on your online store: email address, IP address, IP location, order, customer, payment method and many more.\u003C\u002Fp>\n\u003Cp>As usual with all our WordPress plugins, you can be sure of its robustness, reliability, secure code and its compliance with privacy laws such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA).\u003C\u002Fp>\n\u003Cp>Protecting your WooCommerce store has never been so easy!\u003C\u002Fp>\n\u003Ch4>Documentation\u003C\u002Fh4>\n\u003Cp>Online documentation: \u003Ca href=\"https:\u002F\u002Fblog.nintechnet.com\u002Fhow-to-secure-woocommerce-checkout-process-and-protect-it-against-attacks\u002F\" rel=\"nofollow ugc\">How to secure WooCommerce checkout process and protect it against attacks\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>High-Performance Order Storage (HPOS) compatibility.\u003C\u002Fli>\n\u003Cli>Block-based checkout compatibility.\u003C\u002Fli>\n\u003Cli>Lightweight plugin: No additional database tables created.\u003C\u002Fli>\n\u003Cli>Customizable fraud risk levels.\u003C\u002Fli>\n\u003Cli>Multiple whitelists: IP address (IPv4, IPv6, AS number), email address, payment method, repeat or recurring customers.\u003C\u002Fli>\n\u003Cli>Multiple blacklists: IP address (IPv4, IPv6, AS number), Reverse DNS (Pro version), email address, shipping & billing address, user & company name.\u003C\u002Fli>\n\u003Cli>Advanced detection (Pro version):  Email MX\u002FA\u002FAAAA records check, email domain registration check, IP address rDNS check, IP address DNSBL check.\u003C\u002Fli>\n\u003Cli>Geolocation.\u003C\u002Fli>\n\u003Cli>Rate limiting to protect against carding and velocity attacks (Pro version).\u003C\u002Fli>\n\u003Cli>Suspicious bot detection (Pro version).\u003C\u002Fli>\n\u003Cli>Configuration import & export (Pro version).\u003C\u002Fli>\n\u003Cli>Simulation mode.\u003C\u002Fli>\n\u003Cli>Caching (Pro version).\u003C\u002Fli>\n\u003Cli>GDPR compliant.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Need more security? Take the time to explore the Pro version: \u003Ca href=\"https:\u002F\u002Fnintechnet.com\u002Fsafercheckout\u002F\" rel=\"nofollow ugc\">SaferCheckout Pro\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Requirements for running SaferCheckout (Lite)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 6.0.3 or above.\u003C\u002Fli>\n\u003Cli>PHP 8.1 or above.\u003C\u002Fli>\n\u003Cli>WooCommerce 7.0.0 or above\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>SaferCheckout (Lite) doesn’t collect any private data from you or your visitors, and doesn’t use cookies either. You can install and use it on your website in compliance with privacy laws such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA).\u003C\u002Fp>\n","Fraud prevention for WooCommerce Stores.",1703,"2026-04-14T10:21:00.000Z","6.9.4","6.0.3","8.1",[18,53,89,21,22],"prevention","https:\u002F\u002Fnintechnet.com\u002Fsafercheckout\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsafercheckout-lite.1.10.zip","2026-04-16T10:56:18.058Z",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":64,"downloaded":101,"rating":11,"num_ratings":11,"last_updated":102,"tested_up_to":67,"requires_at_least":15,"requires_php":16,"tags":103,"homepage":108,"download_link":109,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"verifypro-email-otp-for-woocommerce","VerifyPro Email OTP for WooCommerce","1.0.6","haroondev","https:\u002F\u002Fprofiles.wordpress.org\u002Fharoondev\u002F","\u003Cp>\u003Cstrong>VerifyPro Email OTP for WooCommerce\u003C\u002Fstrong> adds professional-grade email verification to your WooCommerce checkout, protecting your store from bot orders and ensuring genuine customer email addresses.\u003C\u002Fp>\n\u003Ch4>🚀 Why VerifyPro?\u003C\u002Fh4>\n\u003Cp>Stop losing revenue to fake orders and bot attacks. VerifyPro adds a simple yet powerful verification layer that ensures every customer has a valid, accessible email address before completing their purchase.\u003C\u002Fp>\n\u003Ch4>✨ Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>6-Digit OTP Codes\u003C\u002Fstrong> – Secure one-time passwords sent instantly via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bot Prevention\u003C\u002Fstrong> – Automatically blocks automated and spam orders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero Configuration\u003C\u002Fstrong> – Works immediately after activation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional UI\u003C\u002Fstrong> – Beautiful, branded interface with purple gradient theme\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightning Fast\u003C\u002Fstrong> – AJAX-powered, no page reloads\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Optimized\u003C\u002Fstrong> – Perfect experience on all devices\u003C\u002Fli>\n\u003Cli>\u003Cstrong>10-Minute Expiry\u003C\u002Fstrong> – OTP codes expire automatically for security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session-Based\u003C\u002Fstrong> – Secure verification using WooCommerce sessions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translation Ready\u003C\u002Fstrong> – Full internationalization support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HPOS Compatible\u003C\u002Fstrong> – Supports WooCommerce High-Performance Order Storage\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🎯 Perfect For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Online stores experiencing bot\u002Fspam orders\u003C\u002Fli>\n\u003Cli>High-value product sellers\u003C\u002Fli>\n\u003Cli>Subscription-based businesses\u003C\u002Fli>\n\u003Cli>Digital product stores\u003C\u002Fli>\n\u003Cli>Any WooCommerce store wanting verified customer emails\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>💼 How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Customer fills in billing details and enters email\u003C\u002Fli>\n\u003Cli>VerifyPro verification section appears automatically\u003C\u002Fli>\n\u003Cli>Customer clicks “Send Verification Code”\u003C\u002Fli>\n\u003Cli>6-digit code arrives in their email inbox\u003C\u002Fli>\n\u003Cli>Customer enters code and clicks “Verify”\u003C\u002Fli>\n\u003Cli>Email verified ✓ – Order can be placed\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>🔒 Security Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress nonce verification on all AJAX calls\u003C\u002Fli>\n\u003Cli>Sanitized and escaped data throughout\u003C\u002Fli>\n\u003Cli>Secure transient storage (auto-deleted after 10 minutes)\u003C\u002Fli>\n\u003Cli>Session-based verification status\u003C\u002Fli>\n\u003Cli>No permanent data storage\u003C\u002Fli>\n\u003Cli>CSRF protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🎨 Professional Design\u003C\u002Fh4>\n\u003Cp>VerifyPro features a modern, professional interface with:\u003Cbr \u002F>\n* Purple gradient theme\u003Cbr \u002F>\n* Smooth animations\u003Cbr \u002F>\n* Responsive design\u003Cbr \u002F>\n* Clear status messages\u003Cbr \u002F>\n* Countdown timer\u003Cbr \u002F>\n* Success indicators\u003C\u002Fp>\n\u003Ch4>🌐 Developer Friendly\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Clean, well-documented code\u003C\u002Fli>\n\u003Cli>WordPress Coding Standards compliant\u003C\u002Fli>\n\u003Cli>Properly prefixed functions (verifypro_eotp_)\u003C\u002Fli>\n\u003Cli>Translation ready with .pot file\u003C\u002Fli>\n\u003Cli>Hooks and filters available\u003C\u002Fli>\n\u003Cli>Easy to customize\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy & Data\u003C\u002Fh3>\n\u003Cp>VerifyPro respects user privacy:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>No Personal Data Collection\u003C\u002Fstrong>: The plugin does not collect or store any personal data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary Storage Only\u003C\u002Fstrong>: OTP codes are stored in WordPress transients for 10 minutes only\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Deletion\u003C\u002Fstrong>: All verification data is automatically deleted after verification or expiry\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session-Based\u003C\u002Fstrong>: Verification status uses WooCommerce sessions (temporary)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Third-Party Services\u003C\u002Fstrong>: All processing happens on your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR Friendly\u003C\u002Fstrong>: No cookies set, no tracking, no external requests\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, please use the WordPress.org support forums. We monitor and respond to all questions.\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Developed by haroondev\u003C\u002Fli>\n\u003Cli>Built with WordPress and WooCommerce best practices\u003C\u002Fli>\n\u003Cli>Uses jQuery for AJAX functionality\u003C\u002Fli>\n\u003Cli>Professional UI design with CSS3 gradients and animations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fverifypro-email-otp-for-woocommerce\u002F\" rel=\"ugc\">Plugin Homepage\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fverifypro-email-otp-for-woocommerce\u002F\" rel=\"ugc\">Documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fverifypro-email-otp-for-woocommerce\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fharoondev\u002F\" rel=\"nofollow ugc\">Developer\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Professional email verification for WooCommerce. Secure your checkout with OTP codes and prevent bot orders.",847,"2026-03-13T03:52:00.000Z",[104,105,106,107,22],"checkout-security","email-verification","otp","spam-prevention","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fverifypro-email-otp-for-woocommerce\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fverifypro-email-otp-for-woocommerce.1.0.0.zip",{"slug":111,"name":112,"version":113,"author":114,"author_profile":115,"description":116,"short_description":117,"active_installs":11,"downloaded":118,"rating":11,"num_ratings":11,"last_updated":119,"tested_up_to":14,"requires_at_least":120,"requires_php":16,"tags":121,"homepage":127,"download_link":128,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"checkout-bot-shield","Checkout Bot Shield","1.0.1","Pluximo","https:\u002F\u002Fprofiles.wordpress.org\u002Fpluximo\u002F","\u003Cp>Are carding bots and fake orders overwhelming your WooCommerce store?\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Checkout Bot Shield\u003C\u002Fstrong> is a lightweight security plugin designed to block rapid-fire, suspicious checkout attempts. It stops automated bots from using your store as a credit card testing ground (carding attacks) and spamming your database with fake orders—without hurting your real customers’ shopping experience.\u003C\u002Fp>\n\u003Cp>This \u003Cstrong>Lite version\u003C\u002Fstrong> serves as a fully functional checkout rate-limiter, allowing you to experience reliable bot protection before upgrading to Pro.\u003C\u002Fp>\n\u003Ch3>Why Your Store Needs This:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Prevent Carding Attacks:\u003C\u002Fstrong> Stops bots from testing stolen credit cards, saving you from high gateway transaction fees and chargebacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce Server Load:\u003C\u002Fstrong> Blocks rapid-fire checkout API requests, keeping your site fast and stable during an attack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero Complex Setup:\u003C\u002Fstrong> Runs quietly in the background. No complicated configurations or complex dashboards required.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Smart Rate Limiting:\u003C\u002Fstrong> Limits rapid checkout retries from the same visitor session.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Friendly Block Message:\u003C\u002Fstrong> Shows a clean, polite warning when checkout limits are exceeded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Store API Integration:\u003C\u002Fstrong> Fully compatible with modern block-based and classic checkouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native WooCommerce Logging:\u003C\u002Fstrong> Check blocked attempts anytime via your native WooCommerce logs.\u003C\u002Fli>\n\u003C\u002Ful>\n","Blocks suspicious, rapid-fire checkout attempts so fake orders and carding bots cannot overwhelm your WooCommerce store.",323,"2026-07-10T08:12:00.000Z","6.8",[122,123,124,125,126],"carding-protection","checkout-bot","fake-orders","rate-limit","woocommerce-security","https:\u002F\u002Fpluximo.com\u002Fcheckout-bot-shield-for-woocommerce\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcheckout-bot-shield.1.0.1.zip",{"error":130,"url":131,"statusCode":132,"statusMessage":133,"message":133},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ftoply-skimshield\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":135,"versions":136},5,[137,143,150,157,163],{"version":6,"download_url":24,"svn_tag_url":138,"released_at":26,"has_diff":139,"diff_files_changed":140,"diff_lines":26,"trac_diff_url":141,"vulnerabilities":142,"is_current":130},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftoply-skimshield\u002Ftags\u002F1.0.4\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftoply-skimshield%2Ftags%2F1.0.3&new_path=%2Ftoply-skimshield%2Ftags%2F1.0.4",[],{"version":144,"download_url":145,"svn_tag_url":146,"released_at":26,"has_diff":139,"diff_files_changed":147,"diff_lines":26,"trac_diff_url":148,"vulnerabilities":149,"is_current":139},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftoply-skimshield\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftoply-skimshield%2Ftags%2F1.0.2&new_path=%2Ftoply-skimshield%2Ftags%2F1.0.3",[],{"version":151,"download_url":152,"svn_tag_url":153,"released_at":26,"has_diff":139,"diff_files_changed":154,"diff_lines":26,"trac_diff_url":155,"vulnerabilities":156,"is_current":139},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftoply-skimshield\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftoply-skimshield%2Ftags%2F1.0.1&new_path=%2Ftoply-skimshield%2Ftags%2F1.0.2",[],{"version":113,"download_url":158,"svn_tag_url":159,"released_at":26,"has_diff":139,"diff_files_changed":160,"diff_lines":26,"trac_diff_url":161,"vulnerabilities":162,"is_current":139},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftoply-skimshield\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftoply-skimshield%2Ftags%2F1.0.0&new_path=%2Ftoply-skimshield%2Ftags%2F1.0.1",[],{"version":164,"download_url":165,"svn_tag_url":166,"released_at":26,"has_diff":139,"diff_files_changed":167,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":168,"is_current":139},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftoply-skimshield\u002Ftags\u002F1.0.0\u002F",[],[]]