[WordPress] 外掛分享: Noventum Fake Order Protection

首頁外掛目錄 › Noventum Fake Order Protection
WordPress 外掛 Noventum Fake Order Protection 的封面圖片
全新外掛
安裝啟用
尚無評分
5 天前
最後更新
問題解決
WordPress 6.3+ PHP 8.0+ v1.0.0 上架:2026-08-17

內容簡介

Noventum Fake Order Protection 外掛旨在幫助 WooCommerce 商店減少虛假結帳活動、重複的支付失敗嘗試及自動化訂單濫用。透過多層輕量級保護機制,確保正常的結帳流暢性,同時防範可疑行為。

【主要功能】
• 限制重複結帳和購物車請求的速率
• 隱藏的蜜罐欄位以檢測機器人
• 檢查可疑的使用者代理
• 驗證結帳請求的來源和參考
• 追蹤失敗支付重試
• 暫時封鎖濫用活動的 IP

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Noventum Fake Order Protection」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Noventum Fake Order Protection helps WooCommerce stores reduce fake checkout activity, repeated failed payment attempts, and automated order abuse.
The plugin monitors checkout traffic across both WooCommerce Store API requests and the classic WooCommerce AJAX checkout flow. This helps protect stores using Checkout Blocks, traditional checkout templates, and payment gateways that rely on different checkout request methods.
Protection is built from several lightweight layers:

Rate limiting for repeated checkout and cart requests.
A hidden honeypot field for simple bot detection.
Checks for suspicious user agents.
Origin and referer validation for checkout requests.
Failed payment retry tracking.
Repeated order amount pattern detection.
Temporary IP blocking for abusive activity.
Optional Google reCAPTCHA v3 verification for higher-risk attempts.

When suspicious activity is detected, the plugin can rate-limit the request, require reCAPTCHA verification when enabled, or temporarily block abusive IP activity. Normal checkout traffic can continue without adding friction for every customer.
Administrators can configure the protection mode, reCAPTCHA keys, block duration, trusted API bypass settings, and logging options from the plugin settings page. The plugin also includes basic logs and a blocked IP list so store owners can review protection activity and manually remove blocked IPs when needed.
This plugin does not create fake orders. It is designed to help reduce fake or abusive order attempts in WooCommerce stores.
If you find this plugin useful, you can support ongoing development with a voluntary donation.
For stores that need help with setup, troubleshooting, or custom WooCommerce protection rules, Noventum can provide optional support and customization services.
Third-Party Services
This plugin can use Google reCAPTCHA v3 when reCAPTCHA is enabled and site keys are configured in the plugin settings.
When enabled, the plugin loads Google’s reCAPTCHA JavaScript from https://www.google.com/recaptcha/ on WooCommerce cart, checkout, and product pages. During protected checkout attempts, the plugin sends the reCAPTCHA token, the configured secret key, and the visitor IP address to Google’s verification endpoint at https://www.google.com/recaptcha/api/siteverify.
Google reCAPTCHA is provided by Google. Review Google’s terms and privacy information before enabling this option:

Google Privacy Policy
Google Terms
reCAPTCHA information

Privacy
The plugin processes technical request data such as IP address, user agent, checkout source headers, WooCommerce session state, checkout email fingerprint, order status, payment method, and order total to detect abusive checkout behavior.
By default, plugin log entries anonymize personal data before writing to disk. The plugin stores temporary risk counters in WordPress transients and stores temporary blocked IP rows in a custom database table.
Administrators can view blocked IP rows and plugin logs from the plugin settings page. Log files are stored under the WordPress uploads directory in noventum-oap/ and rotated automatically.
If Google reCAPTCHA is enabled, checkout verification data is sent to Google as described in the Third-Party Services section.

延伸相關外掛

文章
Filter
Mastodon