Skip to content

v1.3.0 - AbuseIPDB fraud-IP reporting

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 02 Jul 08:39
· 31 commits to main since this release

Added

  • AbuseIPDB reporting: the IP behind every order marked as fraud (automatic detection or manual bulk action) is reported to the AbuseIPDB community database with categories Fraud Orders + Web App Attack, so other stores and firewalls consuming AbuseIPDB blocklists can block the same attackers.
  • Opt-in via the settings form at the bottom of the Reports tab: enable toggle + API key field (free tier allows 1,000 reports/day). Reports contain only the IP, the detection reasons, and the order timestamp, never customer PII.
  • Safety rails per AbuseIPDB API rules: one report per IP per 15 minutes, orders older than two months are skipped (the API rejects older timestamps), private/reserved IPs are never reported, and each order is reported at most once (_wcaf_abuseipdb_reported meta). A note with the returned abuse confidence score is added to the order.