
內容簡介
Checkout Shield 是一款專為 WooCommerce 設計的外掛,能有效阻擋假訂單、垃圾機器人及卡片測試行為。它透過驗證提交的有效性,防止未經授權的 API 訪問,確保您的商店安全。
【主要功能】
• 自動阻擋機器人:無需配置規則,自動啟動保護
• 四種保護等級:學習、寬鬆、平衡與嚴格
• 實時攻擊時間線:即時監控被阻擋的攻擊
• 訂單狀態追蹤:了解哪些訂單被標記或阻擋
• IP 白名單:允許信任的地址通過
• WooCommerce 完整整合:與 WooCommerce 狀態日誌無縫連接
外掛標籤
開發者團隊
② 後台搜尋「Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing」→ 直接安裝(推薦)
原文外掛簡介
Checkout Shield blocks the scripted checkout submissions that CAPTCHA never sees.
Card testing bots don’t fill out your checkout form. They hit your store’s checkout API directly, completely skipping any reCAPTCHA or hCaptcha you’ve set up. That’s why CAPTCHA alone doesn’t stop them.
Your site signs a proof into the checkout page it serves. A submission that carries that proof loaded the page; one that doesn’t, didn’t. Submissions with no valid proof are stopped before WooCommerce processes the order.
What this stops, and what it does not
Being straight about this is more useful than a bigger promise.
It stops anything that posts to your checkout without loading the checkout page first: curl scripts, direct Store API calls, replayed form posts, and the card testing runs that work this way. This is the large majority of automated checkout abuse, and it is the part CAPTCHA misses.
It does not stop a bot that drives a real browser. Something that genuinely loads your checkout page receives a genuine proof, because that is exactly what the proof records. Once loaded, that proof stays valid for the life of the shopping session, so a script can reuse it. No proof of this kind can tell the second submission from the first, since the thing being proven is identical.
For that tier you want a bot mitigation service in front of the site (Cloudflare Bot Fight Mode, Sucuri) alongside this plugin. What this plugin can do is show you when it is happening: the dashboard reports payments that failed repeatedly from a single checkout visit, which is what working through stolen card numbers looks like. In Pro it can also act on it. Once a visit crosses a failure limit you set, the source IP is banned for a while so it can’t just start a fresh visit and keep going, and the ban lifts itself, so a bad guess never becomes a permanent lock-out. A determined attacker can still rotate IPs, which is why the service in front of the site stays the front line, but for the common case this turns the pattern off at the source.
Why Store Owners Choose This Plugin
Catches what CAPTCHA misses: blocks bots hitting your checkout API directly, without asking shoppers to prove anything
Works with any caching: LiteSpeed, Cloudflare, WP Rocket and W3TC, with no conflicts
Nothing to configure: no rules to write and no thresholds to tune
Never blocks your customers by mistake: it only starts once it has seen a real checkout on your store work, and if your theme ever stops carrying the proof it detects that, keeps letting real shoppers through, and tells you what to fix
No external services: everything runs on your server, no subscriptions
Adds milliseconds: the check is local, with no third-party call to wait on
Features (Free)
Automatic bot blocking: no rules to configure; it arms itself once it has seen one checkout on your store work
4 protection levels: Learning, Permissive, Balanced and Strict, so you choose how aggressive you want to be
One place for everything: a dedicated Checkout Shield screen with a live “what’s protected right now” overview, plus your settings and logs
Dashboard overview: see blocked vs verified orders at a glance with a 7-day chart
Order status tracking: know which orders were flagged, passed, or blocked
IP whitelist: let trusted addresses through, supports CIDR notation
API key authentication: for headless and custom checkout setups
Works with all checkout types: classic, block-based, and all payment gateways
HPOS compatible: works with High-Performance Order Storage
WooCommerce logging: full integration with WooCommerce Status logs
Pro Features
Pro is about two things: stopping more, and letting you see it happen.
Live attack timeline: watch scripted attempts get stopped as they arrive, with the surface, reason, masked email, and IP for each one
Test your protection: one button fires the real card-testing request at your own store and shows you it hit a wall, so you never have to wonder whether it’s working
Auto-ban repeat offenders: when one visit keeps failing payment past a limit you set, its IP is blocked for a while and then released on its own, so it can’t just start over
Registration protection: the same no-CAPTCHA proof on your sign-up forms, plus throwaway-email blocking and per-IP rate limiting, to stop the fake accounts that come before fraud
Throwaway email blocking: reject checkouts using a known disposable inbox, with a domain list the plugin keeps up to date for you
3-level logging control: turn logging off, log blocked attempts only, or log everything
Recent blocks feed: the last 50 blocked attempts with email, payment method, and reason
Automatic CDN/proxy detection: identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai
Stronger permissive mode: tighter bot detection with referrer and user-agent checks
Checkout details in logs: see which email and payment method bots tried to use
Customer blocklist: block repeat offenders by email, name, address, phone, IP, or postal code, all managed from the Checkout Shield screen
One-click order blocking: block a customer directly from any order screen
Learn more about Pro features
