Repository navigation
v1.6.0 — Decline clustering, auto-ban, allowlist, bundled disposable list, monitor mode
Added
- Repeated payment failures (decline clustering). Failed payments are counted per visitor over a rolling 24 hours, under the checkout session and the customer IP stored on the order. From 5 failures a non-dismissible admin notice appears. Optionally, further checkouts from that visitor are refused before they reach the gateway, on the classic checkout and the Block Checkout alike. Failures are counted, never orders.
- Temporary auto-ban. When the failure limit refuses a checkout, the IP can be banned for a configurable time. Bans expire on their own, never touch allowlisted IPs, and are listed on the Lists tab with Unban links.
- IP allowlist (CIDR supported). Bypasses every check, never flagged, never banned.
- Bundled disposable-domain list. 8,714 known throwaway domains from the public-domain disposable-email-domains project, plus your own additions.
- Monitor mode. Suspicious orders are flagged, noted, and reported by email, but their status is never changed and nothing is reported to AbuseIPDB. Recommended for new installs.
- Registration protection (off by default): banned or blacklisted IPs, blacklisted or disposable emails, per-IP hourly limit.
- "Block this customer (Antifraud)" in the order-screen Actions dropdown.
- REST protection self-test button on the Detection Rules tab.
- Pre-payment checks (blacklists, bans, failure limit) now also run on the Block Checkout through the Store API.
Changed
- Post-payment rules judge an order by the customer IP stored on the order, not by the IP of the request running the analysis (which is often a gateway webhook).
- REST hardening's error code is now
wcaf_rest_forbidden. - The "Blacklists" tab is now "Lists".
Full details in CHANGELOG.md.