Skip to content

v1.2.0 — unknown-origin rule for classic checkout + fraud UX

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 01 Jul 13:47
· 34 commits to main since this release

Added

  • Optional Flag all unknown-origin orders as fraud rule (enable_unknown_origin): extends empty-attribution detection to classic-checkout orders, not just the Store API. Scoped to customer-facing paths only — admin/manual, subscription, and API-integration orders are never flagged.
  • Change status to Fraud bulk action on the Orders list (classic + HPOS).
  • Persistent fraud flag (_wcaf_is_fraud) and a Fraud badge column, so an order stays marked fraud after a refund relabels it Refunded.

Changed

  • Re-wired the previously inert enable_unknown_origin setting to control the classic-checkout unknown-origin rule.
  • Server-side post-payment detection: also hooks woocommerce_payment_complete and the processing/completed/on-hold transitions, so working-stolen-card orders that never render the thank-you page are still screened. analyze_order_after_payment() is now idempotent.
  • Failed/cancelled analysis is created_via-aware: Store API orders get the full check set; classic-checkout orders are judged only on the unknown-origin signal (never amount/IP-repeat), so a genuine decline+retry can't be false-flagged.