

A fraudulent order stopped at checkout: the customer sees a clear message and the order is never placed.
Predax Fraud Guard is anti-fraud for WooCommerce: it stops fake orders, card testing and chargebacks before the order exists. Card testers and stolen-card fraudsters typically check out from behind a VPN, proxy, Tor or datacenter IP. Fraud Guard screens the customer’s IP at checkout and scores its fraud risk from 0 to 100, and for each rule you choose what happens. Block refuses the checkout before payment is taken, so a blocked attempt never becomes a gateway fee or a chargeback. Hold lets the payment go through and keeps the order on hold for your review, so nothing ships until you decide. Or simply tag the order. Works with any payment gateway and with both the classic and block checkout.
See what Predax knows about your own IP — free, no signup.
Off by default. A fresh install sends nothing anywhere. Connect your Predax key and choose a protection mode; until then the plugin does nothing.
The default once configured is Tag + note: flagged orders get a “Predax: Medium / High / Critical Risk” tag and an order note, and nothing is blocked. Watch what the rules would have done, then turn on Block high risk or Block critical only when you’re confident. Optionally send high-risk orders to On Hold for review instead of rejecting them: the payment is taken and the order waits for you before anything ships, so you can refund a fraudulent one instead of sending the goods.
Risk score, threat flags and country saved on every order for reporting · Refund/chargeback feedback that adds the IP to your deny list · IP and CIDR allow/deny lists · Optional Community Threat Network sharing
Click Connect with Predax in the setup wizard and your free account and API key are created for you — nothing to copy or paste. The free plan includes 5,000 IP checks a month with full VPN, proxy, Tor and datacenter detection and risk scoring. No credit card. Checkouts are only checked when they happen and results are cached, so it covers a small store comfortably; busier stores can move to a paid plan — same plugin, same settings, same key.
This plugin connects to external services operated by Predax (https://predax.io) only after you have saved an API key: checkout screening additionally requires a protection mode to be enabled, and the admin-side account-usage lookup (described below) sends no visitor data at all. By activating this plugin and entering an API key you agree to the Predax Terms of Service and Privacy Policy.
You are responsible for ensuring your use of customer IP data at checkout complies with applicable privacy laws (including but not limited to GDPR, CCPA) and your own store’s privacy policy. This plugin does not assert PCI-DSS, GDPR, or CCPA compliance on your behalf.
Used to look up a risk score and classification signals for each checkout IP.
POST https://predax.io/api/v1/check/ipUsed to check whether the billing email’s provider is a disposable/throwaway service, against a server-side list of thousands of domains (the plugin’s built-in list covers only ~50).
gmail.com. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.POST https://predax.io/api/v1/validate/emailUsed to show the “API usage this month” meter on the Fraud Guard settings page, and only when an API key is saved.
GET https://predax.io/api/v1/auth/usageThe plugin can optionally send an anonymised telemetry signal — the IP address, its risk score and detection flags, its network (ASN) number and name, its country code, and the checkout outcome (allowed / monitored / blocked, or refund/chargeback feedback) — to the Predax Community Threat Network so all participating stores benefit from a shared feed. The Refund / Chargeback Feedback “Log” action reports through this same channel, so it requires this opt-in; its “Blacklist” action updates your local deny list regardless.
This feature is off by default. It is controlled by the ipsentry_woo_community_enabled option, which defaults to 'no', with a checkbox on the Advanced settings tab. The plugin will not send community-feedback telemetry unless you enable it. Customers’ personal data (names, emails, billing/shipping addresses, order contents) is never included in the telemetry payload.
POST https://predax.io/api/v1/telemetry/eventOnly triggered when an administrator clicks the Connect with Predax button in the setup wizard. Your browser is redirected to predax.io to authorise the connection, which returns an API key to your site.
POST https://predax.io/api/v1/oauth/tokenShown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the “why are you deactivating?” prompt.
POST https://predax.io/api/v1/feedback/deactivationipsentry_tz — set on WooCommerce checkout pages (only while an API key is configured) via assets/js/ipsentry-woo-tz.js. Stores the customer’s browser-reported IANA timezone (string, max 64 chars). Used server-side for the optional timezone-mismatch fraud rule. Expires after 24 hours (max-age=86400), path=/, SameSite=Lax, and marked Secure on HTTPS stores. The plugin reads this cookie only at checkout-validation time.The plugin does not set any advertising, analytics, or tracking cookies.