Subscription includes
Support
Build your own defense with powerful, flexible rules. Target orders by email address, domain, phone number, IP address, country, city, postcode, billing or shipping address, customer name, payment method, or shipping method. Choose from exact match, contains, wildcard, or regex matching. Set rules to block, hold, or flag — and add expiration dates for temporary rules.
Every order is automatically assessed against six configurable risk signals: disposable email detection, IP reputation tracking, billing/shipping country mismatch, suspicious address keywords, new account age, and high-value order thresholds. Each signal has an adjustable weight, and you set the thresholds that determine whether an order is blocked, held, or flagged.
Shop Defender intercepts fraudulent orders at the earliest possible moment — before payment is processed. Full support for both the classic WooCommerce checkout and the newer WooCommerce Blocks checkout. When an order is blocked, draft orders are automatically cleaned up and the customer sees your customizable error message.
Every order gets a detailed risk assessment stored as metadata. A dedicated metabox on the order page shows a color-coded badge (blocked, on hold, flagged, or low risk), a visual risk score bar, and a breakdown of every risk factor that contributed to the score. Optionally display a fraud risk column directly on the orders list.
Target fraud from every angle:
Fine-tune fraud detection with six adjustable signals:
Choose the right response for every situation:
Every fraud check is logged for accountability and analysis:
Everything you need, right inside WooCommerce:
Transparent data handling built into the core:
Works with your existing WooCommerce setup:
The checkout is prevented and no payment is processed. The customer sees a customizable error message, the attempt is fully logged, and if using Blocks checkout, any draft order is automatically cleaned up. You can review every block from the logs.
Hold places the order on hold so it exists but won't proceed to fulfillment until you manually approve it. Flag allows the order to complete normally but attaches a warning note and risk score so you can review it when fulfilling. Both add detailed admin notes.
No. All fraud checks run 100% locally on your server — disposable email detection, IP tracking, risk scoring, and rule matching. No data is sent to any third-party API, and there are no per-transaction fees.
Yes. Every risk signal (disposable emails, failed IPs, country mismatch, address keywords, new accounts, high-value orders) has an adjustable weight from 0 to 100. You also set the block and hold thresholds. Set any weight to 0 to disable that signal entirely.
Yes. Shop Defender fully supports both the classic WooCommerce checkout and the newer WooCommerce Blocks checkout. For the Blocks checkout, it uses an early interception point to block orders before they are even created as drafts.
Quality Checks
Countries