SentinelGuard — Fraud & Checkout Protection for WooCommerce

SentinelGuard — Fraud & Checkout Protection for WooCommerce

Details
View on WordPress

SentinelGuard provides targeted fraud and checkout protection for WooCommerce. It stops automated carding bots, defends against Magecart checkout skimmers, detects unauthorized payment gateway tampering, and blocks fake orders before they trigger payment processor fines or account bans.

While general firewalls handle basic network probes, SentinelGuard inspects checkout velocity, payment failure spikes, and Store API endpoints to protect your revenue and checkout pipeline.

Note: SentinelGuard is an application-level ecommerce defense layer. It is built to complement network-level edge WAFs (such as Cloudflare) and payment gateway fraud tools (such as Stripe Radar), not replace them.

Are you experiencing these attacks?

  • Card Testing Bots: Hundreds of rapid, small, or failed checkout attempts hitting Stripe, PayPal, or Authorize.Net.
  • Fake & Spam Orders: Automated bot checkouts using fake names, sequential numbers, or disposable email addresses.
  • High Decline Penalties: Warnings from payment gateways about elevated failure rates threatening your merchant account standing.
  • Checkout Script Tampering: Malicious JavaScript or Magecart sniffers attempting to harvest cardholder details on payment forms.
  • Stealth Database Backdoors: Rogue administrator accounts created directly in MySQL that stay invisible in the standard WordPress user list.

Stop WooCommerce Card Testing & Fake Orders

  • Pre-Gateway Rate Limiting: Evaluates payment velocity and failed attempt clusters before calls reach your payment gateway, eliminating unnecessary authorization fees.
  • Store API & REST Endpoint Security: Hardens both classic WooCommerce checkout and modern headless/Block checkout endpoints (/wc/store/v1/checkout) against bot floods.
  • Disposable Email & Velocity Filters: Flags temporary disposable inbox domains and enforces IP/email velocity limits during flash carding spikes.
  • Dynamic Store Baselines: Evaluates checkout surges against your store’s 60-day historical transaction volume instead of brittle rigid limits.

Checkout Protection & Skimmer Detection

  • Magecart & Skimmer Scanning: Continuously scans frontend scripts, database options, and active themes for card harvesting regexes, keylogger beacons, and suspicious eval() rotations.
  • Gateway Credential Integrity: Real-time alarms alert store owners immediately if Stripe API keys, PayPal merchant emails, or payout settings are modified.
  • Stealth Admin Account Detection: Queries the database directly to uncover shadow admin accounts that hide from the standard WordPress dashboard users screen.
  • Safe In-Database Quarantine: Isolates suspicious code into encoded database records with one-click restore and zero executable file storage in wp-content/uploads.
  • Safe Observe Mode: Ships in default Observe mode to record comprehensive threat telemetry without risking false positives on legitimate buyers.
  • HPOS & WooCommerce Blocks Ready: Native compatibility with High-Performance Order Storage (HPOS) and the Cart/Checkout Blocks architecture.

External Services Disclosure

This plugin uses third-party services to check for vulnerabilities and provide AI-assisted security summaries.

  1. WordPress.org APIs (api.wordpress.org):

    • Data sent: WP version, plugin/theme slugs & versions.
    • When: During security scans to verify core checksums.
    • Terms & Privacy: https://wordpress.org/about/privacy/
  2. Patchstack Vulnerability Database (api.patchstack.com — Optional):

    • Data sent: WP version, plugin/theme slugs.
    • When: Only if you enter your Patchstack API key in Settings.
    • Terms: https://patchstack.com/terms-and-conditions/
    • Privacy: https://patchstack.com/privacy-policy/
  3. WPScan Database (wpscan.com — Optional):

    • Data sent: WP version, plugin/theme slugs.
    • When: Only if you enter your WPScan API key in Settings.
    • Terms: https://wpscan.com/terms/
    • Privacy: https://automattic.com/privacy/
  4. OpenAI API (api.openai.com — Optional):

    • Data sent: Short, flagged code snippets (no user/store data).
    • When: Only if you enter your OpenAI API key to get plain-English explanations of findings.
    • Terms: https://openai.com/policies/terms-of-use/
    • Privacy: https://openai.com/policies/privacy-policy/
  5. Anthropic API (api.anthropic.com — Optional):

    • Data sent: Short, flagged code snippets.
    • When: Only if you enter your Anthropic API key.
    • Terms: https://www.anthropic.com/legal/commercial-terms
    • Privacy: https://www.anthropic.com/legal/privacy
  6. Google Gemini API (generativelanguage.googleapis.com — Optional):

    • Data sent: Short, flagged code snippets.
    • When: Only if you enter your Google Gemini API key.
    • Terms: https://ai.google.dev/gemini-api/terms
    • Privacy: https://policies.google.com/privacy
  7. Webhook Notifications (Optional):

    • Data sent: Alerts (e.g., “Suspicious login detected”).
    • When: Only if you configure a custom webhook URL (like Slack/Discord).

Details

Plugin code:
sentinelguard-ecommerce-protection
Plugin version:
0.4.6
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-08-31
Rating:
Times rated:
0
card-testing
checkout-security
fraud-protection
skimmer
woocommerce