Anti-Fraud for WooCommerce helps store owners identify suspicious orders, reduce card testing activity, and create fraud prevention workflows that fit their business.
Use configurable rules, risk checks, and automated actions to help protect your store from:
Card testing attacks
Stolen credit card attempts
Checkout bots
Fake customer accounts
High-risk orders
Chargeback risk
Built for WooCommerce, Anti-Fraud for WooCommerce gives merchants more control over how suspicious activity is detected, reviewed, and handled.
Whether you are dealing with fake orders, card testing attempts or suspicious customer behavior, Anti-Fraud for WooCommerce helps you decide when to approve, review, cancel or block an order.
Fraudsters use automated bots to test stolen credit card numbers against online stores.
A card testing attack may lead to:
Payment gateway restrictions
Higher processing risk
Chargebacks
Store downtime
Loss of customer trust
How OPMC Anti-Fraud Helps
Detects rapid order attempts
Flags suspicious activity patterns
Restricts high-risk customers
Applies automated rules
Integrates with reCAPTCHA and MaxMind
Anti-Fraud for WooCommerce helps reduce this risk with velocity checks, order risk rules, IP controls, and automated actions.
Why use Anti-Fraud for WooCommerce?
Fraud Protection Built Specifically for WooCommerce
Unlike generic fraud tools, Anti-Fraud was built specifically for WooCommerce and has been protecting stores since 2014.
Fraud prevention works best when it combines multiple signals. Anti-Fraud for WooCommerce uses a layered approach to help you evaluate order risk and take action before suspicious orders become costly problems.
The extension includes tools for:
AI-assisted fraud analysis
Velocity attack protection
Custom fraud rules
IP and country restrictions
Proxy and VPN detection
MaxMind minFraud integration
Automated actions and review workflows
Built-in controls for suspicious orders
Different stores have different risk tolerances. Anti-Fraud for WooCommerce lets you configure how strict your fraud prevention rules should be, so you can balance protection with a smooth customer experience.
Available controls include:
Customer whitelisting
Bulk whitelisting
Rule tuning
Manual review workflows
Risk thresholds
Custom order actions
You can configure the extension to help decide when orders should be:
Approved
Held for review
Cancelled
Blocked
This gives you more control over false positives while still helping protect your store from suspicious activity.
Recent improvements
Anti-Fraud for WooCommerce is actively maintained to support current WooCommerce stores and evolving fraud prevention needs.
Recent enhancements include:
Improved IP geolocation accuracy
Enhanced MaxMind integration
New whitelisting management tools
Improved performance for larger stores
Ongoing WooCommerce compatibility updates
Expanded fraud rule controls
User interface improvements
Best practices and limitations
No fraud prevention extension can guarantee that every fraudulent order will be detected. Fraud tactics change over time, and some suspicious activity may bypass automated checks.
For best results, we recommend:
Using multiple fraud indicators
Enabling MaxMind minFraud, where available
Reviewing high-risk orders before fulfillment
Keeping fraud rules up to date
Combining store-level fraud controls with payment gateway protections
No fraud prevention solution can guarantee complete protection against every fraudulent order. Use Anti-Fraud for WooCommerce alongside payment gateway protections and regular order review processes.
Is Anti-Fraud for WooCommerce right for your store?
Anti-Fraud for WooCommerce helps with
Detecting suspicious orders
Reducing card testing activity
Lowering chargeback risk
Automating fraud review workflows
Creating custom rules for your store
Anti-Fraud for WooCommerce does not
Guarantee that every fraudulent order will be detected
Replace your payment gateway security tools
Manage chargeback disputes on your behalf
Remove the need for secure store management practice
Looking for broader website protection? Anti-Fraud is designed to detect and prevent fraudulent orders and card testing attacks. To protect your WordPress and WooCommerce site from unauthorized access, VPNs and proxies, malware, and other website security threats, consider pairing it with Security for WooCommercefor a more comprehensive security solution.
Why Merchants Trust OPMC
OPMC has been developing WooCommerce extensions since 2014 and supports merchants around the world.
Our plugins are used by businesses ranging from small online stores to larger WooCommerce deployments. We actively maintain our products, release updates, and provide support from the team that builds the software.
Analytics dashboard
The analytics dashboard gives you a central view of recent fraud activity and order risk information.
High-risk order activity over the selected period
Approved versus flagged orders from the past seven days
Leading fraud detection sources and rule triggers
Current priority issues requiring action
Total number of recent high-risk orders
Changes in high-risk activity compared with the previous period
Recent high-risk orders, including score, reason and status
Orders currently waiting for manual review
Handle suspicious orders automatically
When a potentially fraudulent transaction is detected, Anti-Fraud for WooCommerce can automatically take action based on your configuration.
You can configure the extension to:
Cancel suspicious orders automatically
Place suspicious orders on hold
Email the admin about a suspected order without changing the order status
Blocklist suspicious emails and order details
Prevent payment gateway access before payment is processed
Preconfigured Protection Levels
Start protecting your store without building fraud rules from scratch.
Choose from three ready-made protection levels:
Low – Light screening for stores with minimal fraud risk. Medium – Balanced protection for most WooCommerce stores. High – Stricter controls for stores facing card testing, chargebacks or repeated suspicious orders.
Each level automatically applies recommended fraud checks, scoring rules and order thresholds. You can use the preset as-is or fine-tune individual settings as your store’s risk changes.
Customize the importance of each risk factor
Anti-Fraud for WooCommerce lets you assign a risk weight to each risk factor. This helps you decide how much each risk should influence the overall order risk score.
The higher the risk weight, the more impact that factor has when calculating the order’s risk score.
First-time purchase rules
Review new customers while streamlining checkout for trusted repeat buyers
MaxMind minFraud integration
Anti-Fraud for WooCommerce includes an optional integration with MaxMind minFraud Score.
This integration combines existing fraud rules with real-time risk scoring for each order. When enabled, you can receive order risk information when the score exceeds the threshold set in your minFraud settings.
Order quantity and amount checks
Order quantity and amount checks can help you identify suspicious purchases based on the number of products ordered, the order total or the types of products being purchased.
Check the risk of each order
Anti-Fraud for WooCommerce assigns a risk score to each order on a scale from 1 to 100. A higher score indicates a higher level of risk.
You can use the risk score to evaluate the transaction and decide which action to take. The risk score and related advice are available directly in the WooCommerce admin panel.
Users can also review warnings linked to the order. For example, a warning may appear if the customer’s IP address does not match the billing country.
Whitelist user roles, payment methods and emails
Whitelist trusted payment methods to prevent automatic holds or cancellations.
Select which payment gateways should be treated as trusted.
Add approved customer email addresses to the allow list.
Import larger email allow lists using a CSV file.
Enable role-based whitelisting for trusted customer groups.
Choose which WordPress user roles receive softer fraud handling.
Reduce false positives for known, trusted customers.
Keep full control over which orders bypass specific automated fraud actions.
Assess risk before a purchase is made
Enable pre-payment fraud checks — assesses the order before the payment is processed.
Block high-risk checkouts — prevents a suspicious order from proceeding when its fraud score reaches the configured threshold.
Customize the blocked-checkout message — choose the message customers see when an order cannot be completed for security reasons.
Enable or disable the assessment at any time — turn pre-purchase protection on or off without disabling the plugin.
The fraud-score thresholds and automatic hold or cancellation settings are configured separately under Risk Thresholds and Automatic Order Status.
IP, billing, and shipping address rules
Identify potential risks using IP address, geolocation, phone number, proxy, billing address, and shipping address data.
Physical address and IP address comparison rules
Billing and shipping address mismatch rules
Geolocation and billing or shipping address comparison rules
Proxy detection
Expand fraud prevention with integrations
Anti-Fraud for WooCommerce includes optional integrations with third-party services that can enhance order screening and security. Some services require separate accounts or API keys. Additonal charges may apply.
ChatGPT: Adds optional AI-assisted insights to order reviews and helps identify suspicious customer behavior.
MaxMind minFraud: Adds machine-learning risk scoring to support fraud detection with additional intelligence signals.
TrustSwiftly Identity Verification: Enables customer verification using methods such as ID checks, SMS, and device validation.
Google reCAPTCHA v2 and Cloudflare Turnstile: Add bot protection to checkout to help reduce automated card testing and velocity-based attacks.
PayPal Fraud Controls: Adds risk-screening and card attack protection for merchants processing payments through PayPal.
QuickEmailVerification: Validates customer email addresses in real time and helps identify disposable, fraudulent, or high-risk addresses.
BigDataCloud: Improves IP-to-location and address-related checks when configured with your own API key.
Testimonials
What Our Customers Say
“As a small business I manage all of my WordPress installation without benefit of a developer.
Keeping my site secure and functional amidst all of today’s threats is a tricky business for an
amateur. Hence, excellent and persistent assistance from support such as I have received from OPMC
is an absolute boon. They were happy to drill down on my problems beyond the point at which things
were just functional and well into the territory of getting them just right.”
Martin P.
“If I could give a 10-star review, I would. My experience has been so positive. My website is being
targeted for card testing. Unfortunately, PayPal was of very little help, and their recommendations
started blocking legitimate orders. I installed Anti-Fraud, reached out for support, and Tim has
been incredibly helpful. With his recommendations—back-and-forth messages over days and step-by-step
help—it has stopped the carding. I know I can reach out for help if those bastards find a way around
my website’s defenses. Thank you, Tim!”
Carol L.
FAQs
Why did a fraudulent order receive a Safe rating?
Fraud scoring is based on available risk indicators and no automated system can identify every fraudulent transaction. We recommend combining scoring with custom rules, MaxMind and manual review for high-value orders.
Can Anti-Fraud conflict with other security plugins?
While Anti-Fraud is compatible with most WooCommerce extensions, some security, checkout or CAPTCHA plugins may require additional configuration. Our support team can help identify and resolve conflicts.
Will Anti-Fraud block legitimate customers?
No. The plugin includes configurable thresholds, whitelisting tools and review workflows to help minimize false positives.
Can I customize how Anti-Fraud handles suspicious orders?
Yes. OPMC Anti-Fraud gives you complete control over how your store responds to potential fraud. Create custom rules based on customer details, IP address, country, order value, products, payment method, and more. Depending on the risk, you can automatically approve, hold for review, cancel, or block orders to match your business’s risk tolerance.
Does Anti-Fraud work alongside my payment gateway’s fraud protection?
Absolutely. OPMC Anti-Fraud is designed to complement—not replace—the fraud detection provided by payment gateways such as PayPal Payments and Stripe. By combining gateway protections with customizable WooCommerce fraud rules, AI-assisted analysis, and MaxMind integration, you create multiple layers of defense against evolving fraud tactics.
How long does it take to configure Anti-Fraud?
Most merchants can have Anti-Fraud protecting their store in just a few minutes. The plugin includes sensible default settings, allowing you to start with basic protection immediately. As your business grows, you can fine-tune advanced rules, integrations, and automation to match your specific fraud prevention strategy.
Will Anti-Fraud slow down my WooCommerce store?
No. Anti-Fraud is designed to analyze orders efficiently without impacting your customers’ shopping experience. Fraud checks occur during the checkout and order process, and we’ve continually optimized performance to ensure compatibility with both small stores and high-volume WooCommerce sites.
What support is available if I need help?
Our support team works directly with the developers who build the plugin, ensuring complex technical questions and bug reports are resolved as quickly as possible.
Does OPMC Anti-Fraud protect my website from hackers, malware or unauthorized access?
No. OPMC Anti-Fraud is designed to protect your checkout and payment process by identifying suspicious orders, preventing card testing attacks, detecting high-risk transactions, and helping reduce fraudulent purchases.
If you’re looking to protect your WordPress website and WooCommerce store from unauthorized access, malware, VPN and proxy users, country-based threats, or to secure downloadable products and sensitive areas of your site, we recommend Security for WooCommerce.
Many merchants use both plugins together—Anti-Fraud to protect against payment fraud and Security for WooCommerce to strengthen the overall security of their website. Together, they provide comprehensive protection for both your store and your customers.
Don’t Become Another Statistic.
Fraud is rising — but your store doesn’t have to be a victim. Protect your revenue and reputation by equipping your WooCommerce store with advanced, automated fraud prevention. Our WooCommerce Anti-Fraud plugin gives you the tools to stay ahead of threats and maximize legitimate sales. Take control. Fortify your store. Download the plugin today
If after you attempted to resolve issues with Support staff and feel the product(s) you purchased does/do not the best fit your requirements, we want to make things right.
Our policy offers a full refund within 30 days of your date of purchase. We’d love to know what went wrong and how we can improve, so please include details about the reason for your refund request if you reach out to us directly.
Woocommerce.opmc.com.au and our payment process submit the refund immediately and make every attempt to process the refund as quickly as possible. Your financial institution can take up to 20 days for the refund to reflect in your bank account/card.
WooCommerce Anti-Fraud checks for possible fraud whenever an order is placed through your store. The outcome of this check is the output of Risk Advise and Risk Scores. Furthermore, Artificial Intelligence based MaxMind’s minFraud services Integration with our plugin will give you an extra layer of security.
In Anti-Fraud Settings, you can set these automated actions based on Risk Score:
Cancel order
Put an order on hold
Send the administrator an email notification (but don’t change with the order status)
Verify Paypal before sending the order for fraud prevention.
Assess fraudulent activity with integrating minFraud® AI-based service by MaxMind.
The automated action section also allows for a list of email addresses that are whitelisted from these automated actions. Enter one email address per line. Save changes.
minFraud® Setup and Configuration
minFraud® Integration is an AI-based scoring system to check risk affiliated with orders you receive.
Signup for minFraud® fraud prevention service by clicking here
After signing up, click My Account and select My License Key from tabs on and then click Generate new license key
Note: Copy User ID, License key and save it in a safe place for future use, as License Key will be displayed in full only for the first time.
Check Enable MinFraud Settings and Device Tracking Settings
Paste User ID and License key and Click Save changes at the bottom.
Authentication message will appear on the successful integration and you are all set up.
Usage
WooCommerce Anti-Fraud checks for possible fraud whenever an order is placed. The outcome of this check is the output of Risk Advise and Risk Score.
For Risk Advise:
Low Risk – A Risk score lower than 25.
Medium Risk – A Risk score between 25 and 75.
High Risk – A Risk score higher than 75.
Risk Advise, Risk Score and a list of failed rules are added to the order edit display.
The Fraud Risk meta box
Risk Advise is also shown in the order overview screen as a colored shield, and the shield color is based on the level of Risk Advise.
Order overview
Risk Advise color key:
Green – Low Risk
Orange – Medium Risk
Red – High Risk
Grey – No fraud check is done
How are Fraud Advise and Fraud Score calculated?
We created a set of rules that vary from simple checking if the shipping address matches the billing address to advanced rules such as proxy detection. We calculate a score based on the number of rules the order fails, then display Fraud Advise based on this score.
Configuring the plugin’s settings
By navigating to WooCommerce > Settings and clicking the Anti-Fraud tab, you can configure how the plugin reacts to different risk scores.
Admin Email Settings – Leave this on if you want WordPress to send you emails regarding the outcome of anti-fraud checks.
Cancel score – This field allows you to determine when orders are automatically cancelled according to the score of their anti-fraud check. Orders with a risk score equal to or higher than the value entered will automatically be cancelled. By writing “0” in the field, this feature will be disabled and no orders will automatically be cancelled.
On-hold score – This field is used to determine when an order is automatically put on hold. When an order’s risk score equals or exceeds this value, it will be placed on hold to be reviewed. By writing “0” in the field, this feature will be disabled and no orders will automatically be put on hold.
Email notification score – Risk scores that meet or exceed this value will cause an email to be sent to your address.
Medium and high-risk thresholds – This field allows you to change what the plugin classifies as a medium-level risk or a high-level risk.
Enable first-order check – When enabled, the plugin will include a warning if the order placed is a user’s first order. The risk score will also be affected according to the rule’s risk weight.
Enable first-order check for processing order – When the first-order is placed by a new client and the order enters into processing mode because of the low risk involved, enabling this field will reinitiate our anti-fraud algorithm for giving you an extra layer of protection.
Enable international order check – This setting checks if an order has been placed internationally. If it is, a warning is displayed and the risk score will be affected according to the rule’s weight.
Enable IP geolocation check – When enabled, the plugin will look up the IP address of customers to determine their location. This information can help you detect illegitimate orders (eg. the IP location is in a different country to the shipping address).
Enable Billing and Shipping address check – Enabling Billing and shipping address check will trigger this feature when there is a conflict between billing and shipping address.
Enable Proxy check– If a buyer is using a proxy to buy from your store, the antifraud plugin will add score set for this feature to other indicators when enabled.
Enable suspicious domains check – By entering email domains (eg gmail.com, yahoo.com) into the “Suspicious Domains” field, the plugin can warn you when an order is placed using one of these addresses.
Enable unsafe countries check – Countries marked on this list are considered suspicious by the plugin. You can select multiple countries by holding CTRL (Windows) or ⌘ (Mac) when you are clicking them.
Enable order amount check – Unusually large orders are a common sign of fake transactions. By enabling this setting, you will be warned when an order is placed that exceeds the cost in the “Amount limit” box.
Check for attempt count – Enable this setting to check for multiple orders placed over short time spans (eg. 3 orders over 24 hours.
IP multiple details check – When enabled, this setting will check if multiple orders have been placed over the same IP address. This is helpful for detecting users who are attempting to purchase with several different emails.
Blacklist Settings
By adding an email to your blacklist, their purchases will automatically be detected as a high-risk.
By enabling automatic blacklisting, email addresses with a high risk of fraud will be added to this list automatically. You can also block individual email addresses by adding them to the list manually. Use this feature for fraudulent customers who you’ve had trouble with in the past.
Paypal Settings
Enable PayPal verification – When this setting is active, all PayPal payments will require verification. A verified PayPal email address is linked with more legitimate, low-risk orders. If verification fails, the order is put on hold.
Prevent downloads if verification fails – For WooCommerce stores which have digital downloads, this setting can be used to restrict access to the downloadable file(s) until the PayPal email is verified.
Time spend before further attempts – This setting adjusts how many days are allowed to pass before another email is sent.
Email body – This field allows you to customize the message that is sent to customers who need to verify their PayPal accounts.
Rule settings of minFraud®
By default Minimum MinFraud Risk Score for minFraud® integration is set to 30. It is the threshold value after which the minFraud alert is triggered in the WooCommerce antifraud plugin. Similarly, the default value of MinFraud Rule Weight is also set to 30, which is the weighting in proportion to the total per cent of fraud set for the minFraud.
You can also customise your setting how it suits you. For example, you want minFraud to trigger when you get a score of 50, you have to set Minimum minFraud Risk Score to 50. Similarly, if you want to give minFraud more weighting, for example, 40 on Fraud risk graph that is displayed in your order then set MinFraud Rule Weight to 40.
minFraud integration is inactive by default. You have to set it after activating the plugin following the procedure mentioned above.
Checking minFraud® Transactions on MaxMind website
Sign in to your MaxMind account.
Goto MY ACCOUNT > minFraud Transactions
By clicking on the Transaction ID you can see for details of each order.
Checking minFraud® integration Response on the order page
If the transaction score exceeds the threshold set in minFraud’s Rule Settings tab you‘ll see a notification on your order page. These scores are integrated with our already set scoring system that can check other aspects of fraud as well and gives you extra protection over the fraudulent activities.
Manually checking Fraud Risk on old orders
Orders that were placed prior to installing the Anti-Fraud extension can be manually checked by opening the order and clicking the Calculate Fraud Risk button in the Fraud Risk meta box.
The ‘Calculate Fraud Risk’ button.
Troubleshooting
I’m not receiving the administrator notifications email. ↑ Back to top
Not receiving the administrator email can have multiple causes.
Verify in WordPress default settings that the admin email address is entered correctly
Check your SPAM folder to ensure the message was not filtered
If neither, contact your host to check if your website is allowed to send the email.
By purchasing this product, you will be able to gain access to a downloadable .zip file. When you purchase this plugin, you are assigned an account and license key. This gives you access to one year of premium support and updates.
Basic Setup:
Purchase the WooCommerce Anti-fraud plugin to get started.
Download the .zip file to your device.
On your website, Go to: WordPress Admin > Plugins > Add New to upload the file you downloaded with Choose File.
Activate the plugin in Plugins > Installed Plugins.
Reviews
There are no reviews yet.