Checkout Origin Guard

Changelog

1.7.1

  • Added two high-signal checker heuristics: all-lowercase billing first+last name; and unknown checkout origin (no referrer and no UTM).
  • When triggered, these flags can bump the order risk score meta for faster review and safer automation.

1.7.2

  • Hardened admin input handling for allowlists, blocklists, disposable-domain patterns, and emergency bypass activation.
  • Reduced repeated runtime work by caching normalized settings and precompiled path allow rules during each request.
  • Expanded settings-page guidance so advanced Company Shield thresholds are easier for non-technical store owners to tune safely.

1.7

  • Added optional AVS “U” handling as a post-payment risk signal; can add notes, bump a risk-score meta field, or hold orders for review.
  • Refined Company Shield heuristics and help text for business and email validation.
  • Minor performance and logging improvements in the checkout validation flow.

1.6

  • Confirmed compatibility with WordPress 6.9.
  • Updated code to align with upcoming WordPress coding and security guidelines.

1.5.3

  • Improved IP hard block stability and unblock handling.
  • Added real-time log refresh option.
  • Enhanced Company Shield heuristics for email and business name detection.
  • Unified all settings on one page with persistent values.
  • Performance improvements and code cleanup.

1.5.2

  • Added CSV export for logs.
  • Added referrer and nonce validation checks.
  • Expanded allowlist for common search engine bots.

1.5.1

  • Fixed settings persistence and default value population.
  • Added Populate Defaults button.
  • UI refinements and improved table layout.

1.5.0

  • Merged “Bad User Patterns” module into core.
  • Added company/email heuristics and rate-limit detection.
  • New single-page admin interface.

Plugin Website
Visit website

Author
POTAR
Version:
1.7.2
Last Updated
April 16, 2026
Requires
WordPress 6.0
Tested Up To
WordPress 6.9.4
Requires PHP
7.4

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.