This is an info Alert.
x402 Logo
  • Product
    • Become Agent-Ready
      • Merchants
        Agentic Commerce — list your store across ChatGPT, Gemini, Claude & Perplexity
      • Publishers
        Monetize your content when AI agents read, cite, or train on it
      • SaaS Companies
        Treat AI agents as first-class customers with agent-priced checkout
    • Monetize
      • Monetize MCP Server
        Charge per call on any MCP server in 2 minutes
      • Monetize AI Agents
        Turn n8n, Zapier, Activepieces workflows into revenue
      • Agent Feed
        Pay-per-query access to licensed publisher content for your agents
  • Resources
    • xpay Ecosystem
      • xpay✦ Tools
        1,000+ pay-per-use tools for your AI agents
      • Agent-Ready SaaS Index
        25,481 SaaS scored on agent-buyability
      • SaaS Pricing Database
        Pricing pages indexed across 1,000+ categories
      • Shopify Apps Directory
        Every Shopify app, with its full review history
      • WooCommerce Plugins Directory
        Every WooCommerce plugin, scored on how well it is maintained
      • GitHub
        Open source repositories
    • Agent Building
      • Agent Frameworks
        AI frameworks for building multi-agent systems
      • x402 Integration
        AI frameworks with x402 payment integration
      • Networks
        Blockchain networks supporting x402
    • Company
      • About xpay✦
        Our mission, products, and protocols
      • Blog
        Latest insights and updates
      • Docs
        Complete xpay documentation
  • Pricing
  • Blog
  • Docs
Get Started
  1. xpay✦ Commerce

  2. Directory

  3. WooCommerce plugins

  4. Checkout Origin Guard

Checkout Origin Guard

One-page WooCommerce checkout hardening; bot blocking, rate/sequence checks, business/email heuristics, and optional AVS-based risk signals.

10+ active installsFree on WordPress.org
View on WordPress.orgSupport forum
Will this break my store?

What the WordPress.org registry says about keeping Checkout Origin Guard running.

WordPress compatibility
Tested to 6.9.5 — 1 branch behind 7.0
Tested against the WordPress branch in use today.
Last updated
4 months ago
At least 7.4 releases a year since launch. WordPress.org only lists versions still available for download, so the real number may be higher.
Requires PHP
7.4
Your host must be running at least this version.
Requires WordPress
6.0
Contributors
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.

10+ active installsWordPress.org reports installs in bands, not exact counts.
Maintenance & trust

Scored on how Checkout Origin Guard is looked after — not on how many stores run it.

Solid
Not enough public feedback to put a confident number on this one. Little public feedback — score rests mostly on release activity. What we can see is below.

Maintenance
35 / 35
Updated 107 days ago.
WordPress compatibility
14 / 20
Tested to WP 6.9.5, 1 branch(es) behind.
Support responsiveness
Not enough data
Only 0 support thread(s) — not enough to judge.
Merchant satisfaction
Not enough data
No ratings yet.
Listing transparency
7 / 10
Provides: screenshots, description
2 of 5 measures had too little evidence to score. They are left out of the total rather than counted as zero — otherwise a plugin would be marked down for being small rather than for being poorly kept.Measured 2026-08-01 from the WordPress.org plugin registry.
Ratings

No one has rated this plugin on WordPress.org yet. That is a statement about the ratings page, not about the plugin — plenty of well-kept plugins never collect them.

Checkout Origin Guard protects your WooCommerce store from fake, fraudulent, or automated checkout attempts by identifying and blocking abusive origins before they clutter your order table or your logs.

The plugin runs client-origin heuristics, IP controls, and sequence analysis to detect non-human traffic and suspicious behavior at checkout. It adds Company Shield for business and email sanity checks and an optional AVS “U” signal handler for gateways that report “Address not checked / unavailable”.

All controls live on a single admin screen; you can adjust sensitivity, manage allowlists and blocklists, and review traffic logs in one place.

Three layers of protection

  1. Bot Block (traffic level)
    Detects and throttles abusive requests before they become orders:

    • Analyzes user agents, referrers, and known bot signatures
    • Watches rapid-fire hits to checkout and wc-ajax endpoints
    • Supports monitor, soft, and hard blocking modes
    • Built-in allowlist for search engines, uptime monitors, and core WordPress services
  2. Company Shield (checkout level)
    Validates business identity and email quality at checkout:

    • Flags suspicious or synthetic business names
    • Detects repeated syllables, odd vowel ratios, and gibberish patterns
    • Identifies disposable email domains and role-based accounts (admin, info, sales, etc.)
    • Can run in:
      • Monitor; log and annotate orders
      • Soft; create the order and automatically place it on hold or pending
      • Hard; block checkout with a user-facing error message
  3. Payment AVS signals (post-payment; optional)
    For gateways that expose AVS results in order meta, Checkout Origin Guard can treat “AVS: U; unavailable / not checked” as a risk signal:

    • Does not change how your gateway authorizes or captures payments
    • Can be configured to:
      • Ignore the signal
      • Add an order note only
      • Add an order note and bump a risk-score meta field
      • Put the order on hold for manual review
    • Uses flexible pattern matching; can scan specific gateway meta keys or fall back to scanning all order meta for common “AVS: U” messages such as the PayPal string
    • Off by default; you opt in and choose the behavior

Key Features

  • 🛡️ Bot Block; Detects and blocks automated bots by analyzing user agents, referrers, and checkout behavior patterns.
  • ⚡ Rapid Sequence Detection; Monitors frequency and timing between checkout attempts to identify scripted attacks and card testing activity.
  • 🧠 Company Shield; Flags suspicious or AI-generated business names, email domains, and mixed-character spam entries at checkout.
  • 🌎 Allowlist Controls; Preserve access for search engines, uptime monitors, and essential WordPress and WooCommerce services.
  • 🔒 Hard / Soft / Monitor Modes; Choose between logging only, soft blocking, or full hard blocking.
  • 🧾 AVS “U” Risk Signals (optional); Treat “Address not checked / unavailable” as a post-payment risk signal; add notes, increase risk score, or hold the order.
  • 🗂️ Log Viewer; See activity including timestamps, IPs, user agents, paths, and detection outcomes.
  • 🧩 One-Page Dashboard; Configure settings, review logs, and manage allow/deny lists from a single screen.
  • 🚫 Manual Block / Unblock; Instantly remove or restore access for specific IPs with one click.
  • 💾 CSV Export; Download checkout-origin activity logs for security review or record keeping.

Why Online Shops Need it

WooCommerce checkouts are frequent targets for:

  • Card testing and BIN probing
  • Fake business registrations and spam accounts
  • Automated scripts hammering your checkout endpoints

Checkout Origin Guard focuses on checkout behavior and identity quality, not just generic firewall rules. It helps you:

  • Reduce chargeback and fraud risk
  • Keep your order list clean and reviewable
  • Shorten the time spent cleaning up junk orders and bogus signups

The plugin works alongside any existing firewall, CDN, or WAF; it does not rely on external APIs or subscriptions. All data stays on your server.

Use Cases

  • Prevent card testing or order spam
  • Stop bots using nonsense or AI-generated company names
  • Detect rapid repeat checkout attempts from the same IP
  • Block suspicious POST requests that hit checkout endpoints
  • Add an extra layer of review for orders where the gateway reports “AVS unavailable / not checked”
  • Maintain cleaner order history and logs for real customers

Credits

Developed by Michael Winchester
For documentation and updates, visit https://michaelwinchester.com

Does this plugin affect SEO bots or uptime monitors?

Only if you disable the built-in allowlist. Common search engines and known uptime agents (such as Googlebot, Bing, and UptimeRobot) are allowed by default. You can customize the allowlist if needed.

Will it block my own IP?

Your logged-in administrator sessions are never blocked by Bot Block. If you manually block your own address, you can unblock it from the plugin dashboard with one click.

Does it replace a firewall or security plugin?

No. Checkout Origin Guard complements existing firewall or security plugins. It focuses specifically on WooCommerce checkout behavior and identity quality, rather than broad HTTP filtering.

Does this change how my gateway processes payments?

No. Checkout Origin Guard does not interfere with your payment gateway’s authorization or capture logic. The optional AVS “U” feature runs after the gateway has responded and only:

  • Adds order notes
  • Adjusts a risk-score meta field
  • Optionally changes the WooCommerce order status to “on-hold” for manual review

Your gateway interaction and funds flow remain unchanged.

What is AVS “U” and why should I care?

AVS (Address Verification Service) compares billing address details against card-issuer records. The code “U” usually means:

  • Address not checked, or
  • Service unavailable, or
  • Acquirer had no response

On its own, AVS U does not prove fraud, but combined with other signals (suspicious company name, disposable email, rapid sequence from one IP) it can be a useful reason to slow down and review the order.

I do not know my gateway meta keys. Can I still use AVS detection?

Yes. The AVS settings include an optional Gateway Meta Keys list. If you know the exact meta keys your gateway uses to store AVS results, you can enter them for more precise scanning. If you leave the field blank, Checkout Origin Guard will scan all order meta values for common AVS U patterns, including PayPal-style messages such as:

AVS: U: Unavailable / Address not checked, or acquirer had no response. Service not available.

Can I export my logs?

Yes. All log data can be exported to CSV from the plugin dashboard for review, forensics, or integration with external tools.

Where is log data stored?

Logs are stored in a dedicated database table inside your existing WordPress database. They contain timestamps, IP addresses, user agents, paths, HTTP methods, and a decision flag. No external services are used; all data remains on your server. You can clear or truncate this table using your preferred database tools if you want to reset history.

Categories
Security & spam
Plugin details
Version1.7.2
Last updated2026-04-16 7:43pm GMT
Added2025-10-09
Requires WordPress6.0
Tested up to6.9.5
Requires PHP7.4

Tags on WordPress.org
bot protection
fraud prevention
ip blocker
spam
woocommerce checkout security
Alternatives
Other plugins in the same categories.
SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
10K+ installs
4.7(20)
Block Emails & Addresses for WooCommerce Checkout
700+ installs
5.0(6)
Kitgenix CAPTCHA for Cloudflare Turnstile
600+ installs
5.0(6)
Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing
200+ installs
5.0(5)
FraudLabs Pro for WooCommerce
1K+ installs
4.2(18)
Identity Verification for WooCommerce
100+ installs
5.0(12)
x402 Logo

The agent-readiness stack for the AI shopping era — helping merchants, publishers and SaaS companies get discovered, cited and transacted with by ChatGPT, Perplexity, Claude, Gemini and the custom shopping agents underneath them.

CompanyAgentically Inc. (d/b/a xpay✦)1875 Mission St, Ste 103San Francisco, CA 94103, United Stateslegal@xpay.sh · privacy@xpay.sh
or ask your AI app
Company
About xpayAgency PartnersGitHubDiscordllms.txt
DevelopersDocumentationAPI ReferenceSDKs & LibrariesQuickstart GuideOpenAPI Spec
Stay Updated
Occasional product updates and agent-readiness playbooks from xpay (Agentically Inc.) — typically a couple of emails a month. Double opt-in: we email you a link to confirm before sending anything, and every email has one-click unsubscribe.
Social
  • For Publishers
    • News
    • Finance
    • Dev / Tech
    • Travel
    • View all verticals
  • Agent Feed
    • AI Search Engines
    • RAG Builders
    • Browser Agents
    • Vertical Research
    • Browse full catalog
  • Agent-Ready Index
    • SaaS Pricing Database
    • Agent-Ready SaaS Index
    • Verified band
    • AI & ML
    • Sales & CRM
  • Products
    • Pricing Widget
    • Monetize MCP Server
    • Paywall
    • Smart Proxy
    • Monetize AI Agents
    • xpay x402 Facilitator
  • Agentic Economy
    • Timeline
    • Resources
    • Manifesto
    • Stack
  • Agentic Commerce
    • Get listed
    • ChatGPT Ads
    • How ChatGPT Ads work
    • ChatGPT Ads · Apparel
    • ChatGPT Ads · Health & Beauty
    • xpay Listings · Amazon + Google
    • Pricing
    • Free audit
    • Shopify
    • WooCommerce
    • Apparel & Accessories
    • Health & Beauty
    • Overview
  • Commerce Index
    • Shopify apps directory
    • Agentic Commerce Ready Index
    • Methodology
    • Pet brands · WooCommerce
    • Pet brands · Shopify
  • Marketplace
    • 🛍️ xpay.deals — agentic storefront for deals
  • Protocols
    • Overview
    • x402
    • MPP
    • UCP
    • ACP
    • AP2
    • TAP
    • A2A
  • Agent Frameworks
    • Overview
    • LangChain
    • CrewAI
    • Claude MCP
    • AutoGPT
    • LangChain vs Mastra
    • LangGraph vs Pydantic AI
  • Company
    • About xpay
    • Blog
    • Docs
    • GitHub
  • Free prompts
    • Ecommerce prompts
    • Email marketing prompts
    • Product description prompts
    • Facebook ad prompts
    • Skincare prompts
    • Supplement prompts
    • Wine prompts
    • Electronics prompts

© 2025 Agentically Inc. All rights reserved.
Privacy PolicyTerms of UseAcceptable Use Policy