Lightweight anti-fraud protection for WooCommerce. Detect and block payment testing attacks with IP geolocation checks, minimum order thresholds, and velocity rate limiting.
Stop card testing attacks before they cost you money
Every WooCommerce store is a target. Automated bots cycle through thousands of stolen card numbers against your checkout, racking up failed transaction fees, triggering payment processor flags, and creating chargebacks that put your Stripe account at risk. Essential protection for stores using Refinery Payouts or any Stripe-based checkout. Refinery Fraud Guard works in two layers: a blocklist that stops known bad actors at checkout before their card is ever charged, and a detection engine that catches new fraud patterns and can automatically feed offenders back into the blocklist.
Checkout Blocking
The blocklist runs during checkout validation — before payment processing. If a customer's IP address, email, or email domain is on the blocklist, the order is rejected immediately and no charge is attempted. This is the difference between catching fraud after the money moves and preventing it from moving at all. Block entries can be permanent or set to expire after 1, 7, 30, or 90 days. Manage everything from a dedicated admin tab with search, filters, and bulk actions.
Auto-Blocking
When the detection engine flags an order, it can automatically add the offender's IP and email to the blocklist. Configure the severity threshold — only auto-block on cancellations, or cast a wider net and auto-block on holds too. First-time fraudsters get caught by the detection rules. If they come back, the blocklist stops them at the door.
IP Geolocation Check
Compares the customer's IP address location with their billing address. If someone in Vietnam is checking out with a billing address in Texas, that order gets flagged. Supports country-level and country + state matching. Uses a cascading lookup — Cloudflare headers first, then WooCommerce's built-in geolocation — so there's no extra API call slowing down your store. Results are cached for 24 hours.
Minimum Order Amount
Card testers don't buy your products — they place small orders to verify stolen card numbers. Set a minimum threshold and any order below it gets caught. Configurable to any amount.
Velocity Rate Limiting
Catches rapid-fire card testing from a single source. If the same IP address places more orders than your limit within a configurable time window, subsequent orders are flagged. Default: 3 orders per 60 minutes.
Disposable Email Blocking
Fraudsters use throwaway email addresses from services like Mailinator, Guerrillamail, and Yopmail. Fraud Guard ships with a curated blocklist of 100+ disposable email providers, plus you can add your own custom blocked domains.
VPN/Proxy Detection
Flag orders placed through VPN, proxy, or datacenter IP addresses using proxycheck.io. The free tier gives you 1,000 lookups per day with no API key required. Results are cached so repeat visitors don't cost extra queries.
Per-Rule Actions
Every detection rule has its own configurable response. Choose Hold for Review to put the order on hold for manual inspection, Auto-Cancel to reject it immediately, or Flag Only to add a note without changing the order status. You can also restrict each rule to specific payment methods — run geolocation checks on Stripe orders only, for example.
Whitelisting
Whitelist trusted IP addresses and email addresses (or entire domains) so they bypass all fraud checks. Whitelists always take priority over the blocklist — your team, your warehouse, and your biggest wholesale customer will never get blocked.
Dashboard and Fraud Log
A dedicated dashboard shows fraud stats at a glance — flagged orders, triggered rules, and recent activity. For broader store metrics and revenue analytics, see Refinery Analytics. The searchable fraud log records every flagged order with full details: which rules triggered, the IP country vs. billing country, order totals, and what action was taken. Every flagged order also gets an order note and meta box so your team can see exactly what happened without leaving the order screen.
Built for WooCommerce
HPOS compatible. Works with both the classic and block checkout. The blocklist check runs during checkout validation with a single indexed database query — typically under 1ms. The detection engine runs after order creation so it never slows down the checkout flow. Extensible with hooks and filters for developers who want to add custom rules or override behavior. Fraud Guard is included in the All Access Pass.
Documentation
Get up and running with Refinery Fraud Guard using the documentation: Getting started with Fraud Guard, configuring fraud rules and thresholds, managing the blocklist, reading the fraud log, and developer hooks.
Common Questions
Will Fraud Guard slow down my checkout?
No. The blocklist check is a single indexed database query, typically under 1ms. The detection engine runs after order creation, so it never blocks checkout.
Does it work with both classic and block checkout?
Yes. Fraud Guard hooks into WooCommerce checkout validation, so it works with the legacy classic checkout and the new Blocks-based checkout.
What happens to legitimate customers who get caught by a rule?
Every detection rule has a configurable response: Hold for Review (manual inspection), Auto-Cancel (reject immediately), or Flag Only (note the order without changing status). You can also whitelist trusted IPs and email domains to always bypass checks.
Do I need a paid VPN or proxy detection service?
No. Fraud Guard ships with proxycheck.io free-tier integration, 1,000 lookups per day with no API key required. Add your own key for higher volume.
Does it support High-Performance Order Storage (HPOS)?
Yes, fully HPOS-compatible.
What does each license tier cover?
Personal covers 1 site, Business covers 5 sites, and Agency covers unlimited sites. Site count is the number of WordPress installations the license can be active on at the same time.
How long do I get updates and support?
Every license includes 1 year of automatic updates and priority support. Renew annually to keep both. The plugin keeps working past renewal, you just stop receiving updates.
What is your refund policy?
All Refinery plugins come with a 14-day money-back guarantee. If it does not work for you, email [email protected] within 14 days of purchase for a full refund.
Can I cancel anytime?
Yes. Cancel anytime from your account dashboard. Your license stays active through the end of your current billing period.
Is the code open and customizable?
Yes. Refinery plugins are GPL-licensed and ship as standard WordPress plugins with documented hooks, filters, REST endpoints, and template overrides. Extend or theme as needed.
Where can I get help?
Support tickets are answered by the engineers who built the plugin. Email [email protected] or visit the support page for documentation and contact options.
Customer Reviews
Only logged in customers who have purchased this product may leave a review.
All Access Pass
Get every Refinery plugin — current and future — with a single subscription.
From $319.20/year
Get All AccessSubscription includes
- Product updates and improvements
- Customer support
- 30-day money-back guarantee
Reviews
There are no reviews yet.