Fraud and Scam Detection For WooCommerce
Fraud and Scam Detection For WooCommerce

Fraud and Scam Detection For WooCommerce

5/5 (1 ratings) 100 active installs Updated Sep 24, 2026
Screenshot 1

The Fraud and Scam Detection For WooCommerce plugin helps protect your online store by adding a verification layer to the WooCommerce checkout.
Using Google reCAPTCHA or Cloudflare Turnstile, the plugin automatically analyzes user interactions and blocks suspicious checkout attempts, reducing fraudulent transactions and ensuring safer payments.

Main Features:
– Integration with Google reCAPTCHA v3 (site key, secret key, configurable minimum score);
– Integration with Cloudflare Turnstile (site key, secret key, selectable widget theme: auto, light or dark);
– Protects WooCommerce checkout against automated bots and fraudulent activity;
– Configurable antifraud behavior — choose whether to block the order, mark it as fraud, add an internal note, or any combination of these actions;
– Marks suspicious orders with a dedicated custom fraud order status for manual review;
– Adds internal order notes with the validation result (reCAPTCHA score interpretation or Turnstile PASS);
– Advanced IP banning — ban IPs for a defined duration (hours, days, weeks, months, years) or permanently, with automatic expiration for temporary bans;
– Banned IPs management panel and IP lookup / order filtering by IP directly from the order detail page;
– Data-based blocking — block orders by email address, email domain, phone number, country, or device fingerprint;
– Compatible with both the classic and the block-based (Store API) checkout;
– Optional debug logging to the WooCommerce log for auditing and troubleshooting;
– Lightweight and optimized for performance.

Dependencies

This plugin requires WooCommerce to be installed and active.
For Google reCAPTCHA, you also need valid Google reCAPTCHA API keys.
For Cloudflare Turnstile, you need valid Cloudflare Turnstile site and secret keys.

User instructions

  1. Go to WordPress admin panel > WooCommerce > Settings > Anti-Fraud;

  2. Enable the antifraud option and choose between Google reCAPTCHA or Cloudflare Turnstile;

  3. Enter the corresponding Site Key and Secret Key for the chosen service;

  4. For reCAPTCHA: set the minimum score threshold (higher values = stricter validation);

  5. Optionally enable IP check to ban specific IP addresses from checkout;

  6. Optionally enable data-based blocking (email, email domain, phone, country, device) and manage the lists in the Block by Data tab;

  7. Optionally enable debug mode to log requests and responses;

  8. Save the settings. From now on, the WooCommerce checkout will require security validation.

External services

This plugin integrates with Google reCAPTCHA v3 and Cloudflare Turnstile to provide fraud and bot protection for WooCommerce checkout processes.

Google reCAPTCHA v3

What the service is and what it is used for:
Google reCAPTCHA v3 is a security service that analyzes user behavior to determine if a user is likely human or bot. It’s used to protect the WooCommerce checkout process from automated fraud attempts and malicious activities.

What data is sent and when:
When a customer attempts to complete a checkout, the plugin sends the following data to Google reCAPTCHA servers:
– User’s IP address
– Browser and device information
– User interaction patterns during checkout
– reCAPTCHA response token

  • Google reCAPTCHA Terms of Service: https://developers.google.com/recaptcha/docs/terms
  • Google Privacy Policy: https://policies.google.com/privacy

Cloudflare Turnstile

What the service is and what it is used for:
Cloudflare Turnstile is a privacy-friendly CAPTCHA alternative that verifies users without tracking or invasive data collection. It’s used to protect the WooCommerce checkout from bots and fraudulent activity.

What data is sent and when:
When a customer attempts to complete a checkout, the plugin sends the Turnstile response token to Cloudflare servers for validation:
– Turnstile response token
– User’s IP address (handled by Cloudflare)

  • Cloudflare Turnstile Terms of Service: https://www.cloudflare.com/terms/
  • Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/