BACK TO DIRECTORY

Noventum Fake Order Protection

by noventum

0.0
(0 ratings)

Noventum Fake Order Protection helps WooCommerce stores reduce fake checkout activity, repeated failed payment attempts, and automated order abuse.

The plugin monitors checkout traffic across both WooCommerce Store API requests and the classic WooCommerce AJAX checkout flow. This helps protect stores using Checkout Blocks, traditional checkout templates, and payment gateways that rely on different checkout request methods.

Protection is built from several lightweight layers:

  • Rate limiting for repeated checkout and cart requests.
  • A hidden honeypot field for simple bot detection.
  • Checks for suspicious user agents.
  • Origin and referer validation for checkout requests.
  • Failed payment retry tracking.
  • Repeated order amount pattern detection.
  • Temporary IP blocking for abusive activity.
  • Optional Google reCAPTCHA v3 verification for higher-risk attempts.

When suspicious activity is detected, the plugin can rate-limit the request, require reCAPTCHA verification when enabled, or temporarily block abusive IP activity. Normal checkout traffic can continue without adding friction for every customer.

Administrators can configure the protection mode, reCAPTCHA keys, block duration, trusted API bypass settings, and logging options from the plugin settings page. The plugin also includes basic logs and a blocked IP list so store owners can review protection activity and manually remove blocked IPs when needed.

This plugin does not create fake orders. It is designed to help reduce fake or abusive order attempts in WooCommerce stores.

If you find this plugin useful, you can support ongoing development with a voluntary donation.

For stores that need help with setup, troubleshooting, or custom WooCommerce protection rules, Noventum can provide optional support and customization services.

Third-Party Services

This plugin can use Google reCAPTCHA v3 when reCAPTCHA is enabled and site keys are configured in the plugin settings.

When enabled, the plugin loads Google’s reCAPTCHA JavaScript from https://www.google.com/recaptcha/ on WooCommerce cart, checkout, and product pages. During protected checkout attempts, the plugin sends the reCAPTCHA token, the configured secret key, and the visitor IP address to Google’s verification endpoint at https://www.google.com/recaptcha/api/siteverify.

Google reCAPTCHA is provided by Google. Review Google’s terms and privacy information before enabling this option:

Privacy

The plugin processes technical request data such as IP address, user agent, checkout source headers, WooCommerce session state, checkout email fingerprint, order status, payment method, and order total to detect abusive checkout behavior.

By default, plugin log entries anonymize personal data before writing to disk. The plugin stores temporary risk counters in WordPress transients and stores temporary blocked IP rows in a custom database table.

Administrators can view blocked IP rows and plugin logs from the plugin settings page. Log files are stored under the WordPress uploads directory in noventum-oap/ and rotated automatically.

If Google reCAPTCHA is enabled, checkout verification data is sent to Google as described in the Third-Party Services section.

Plugin Details

Active Installs
0
Total Downloads
122
Version
1.0.0
Requires WP
6.3
Requires PHP
8.0
Tested Up To
7.0.4
Added
2026-08-18
Last Updated
2026-08-26 2:20pm GMT

Ratings

5
0
4
0
3
0
2
0
1
0