Skip to content

v1.9.0 — Linked to known fraud

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 04 Sep 09:25
· 23 commits to main since this release

Added

  • Linked to known fraud. A new order is tied to an order already marked fraud in the last 30 days (Detection Rules > Linked to Known Fraud, look-back configurable, on by default) when the two share the billing email, the ship-to street and postcode, or the customer IP within an hour of each other. Catches the retry with a second card or gateway after a Radar block, and the reshipping pattern where a new name and card ship to the same address, neither of which a gateway verdict ties together.
  • On a failed order any fraud order can be the link, a Stripe verdict included. On a paid order only the plugin's own detections and manual marks count, never a Stripe verdict, so a real customer Radar blocked who then pays another way keeps the sale.
  • Customer-facing paths only (classic checkout and Store API). Orders marked by this rule alone are not reported to AbuseIPDB. The order note names the earlier order and what was shared.
  • WCAF_Order_Status::recent_fraud_anchors(): one query for recent fraud orders and their compared fields, on the posts store or the HPOS tables.