KossLabs Anti-Carding & Bot Shield

Description

KossLabs Anti-Carding & Bot Shield protects online merchants from card testing fraud (carding attacks) by intercepting automated bot submissions before they reach payment gateways such as Stripe, PayPal, Square, or local payment providers.

When carding fraudsters target a WooCommerce store, they automate thousands of micro-authorization attempts using stolen credit card dumps. Even when transactions fail, merchants incur expensive authorization fees ($0.15 – $0.50 per attempt) and risk payment account suspension.

This plugin delivers a 4-layer zero-bloat defense that halts card testing attacks at the gateway threshold without adding custom database tables:

  • Layer 1: Invisible Honeypot Trap: Traps naive automated bots that blindly fill all form inputs.
  • Layer 2: Cryptographic Timestamp Token: Blocks headless scripts that submit forms faster than humanly possible (< 1.5 seconds) using HMAC-signed tokens.
  • Layer 3: Cloudflare Turnstile (Bring Your Own Key – BYOK): Frictionless, privacy-friendly bot challenge. Store owners use their own free Cloudflare credentials—no third-party proxy or developer API quota shared.
  • Layer 4: Transient IP Rate Limiter: Enforces strict attempt thresholds per IP (e.g., 3 failed attempts in 10 minutes) stored entirely in RAM (Transients API / Redis / Memcached).
  • Dual-Shield Architecture: Full compatibility with Classic Checkout and modern WooCommerce Blocks Store API (/wp-json/wc/store/v1/checkout).

Privacy Policy & External Services

This plugin integrates with Cloudflare Turnstile to protect your checkout against card testing and automated bot abuse.

  • Service: Cloudflare Turnstile
  • Provider: Cloudflare, Inc.
  • Service Description: Frictionless, privacy-preserving bot detection challenge.
  • Terms of Service: https://www.cloudflare.com/website-terms/
  • Privacy Policy: https://www.cloudflare.com/privacypolicy/
  • Data Transmitted: During checkout, the customer’s IP address and Turnstile response token are transmitted to Cloudflare’s validation endpoint (https://challenges.cloudflare.com/turnstile/v0/siteverify) to verify whether the submission is from a legitimate human. Store owners use their own Cloudflare account credentials (BYOK).

Installation

  1. Upload the kosslabs-anti-carding-shield folder to your /wp-content/plugins/ directory, or install directly via the WordPress Plugins menu.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. Ensure WooCommerce is installed and activated.
  4. Navigate to WooCommerce > Anti-Carding Shield in your WordPress admin menu.
  5. Enter your Cloudflare Turnstile Site Key and Secret Key (obtained free from your Cloudflare dashboard).
  6. Adjust rate limiting thresholds if desired, then click Save Configuration.

FAQ

Does this plugin add tables to my database?

No. It strictly adheres to a “Zero-Bloat” philosophy. All rate limiting and temporary blocks utilize the native WordPress Transients API, which operates in RAM when object caching (Redis or Memcached) is enabled.

Do I need a paid Cloudflare account?

No. Cloudflare Turnstile is completely free for up to 10 visible/managed sites per account with unlimited challenge responses.

Does this work with WooCommerce Blocks / Modern Checkout?

Yes. The plugin intercepts both traditional classic checkout (woocommerce_checkout_process) and modern Store API REST checkout endpoints (/wc/store/v1/checkout).

Will legitimate customers be interrupted by difficult CAPTCHAs?

No. Cloudflare Turnstile is designed to run non-interactively in the background without frustrating puzzles or image selections for genuine shoppers.

Reviews

ഈ പ്ലഗിന് റിവ്യൂകൾ ഒന്നുമില്ല.

Contributors & Developers

“KossLabs Anti-Carding & Bot Shield” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.0

  • Initial public release.
  • 4-layer defense: Honeypot, 1.5s cryptographic timestamp, Cloudflare Turnstile, and Transient IP rate limiting.
  • Full support for WooCommerce Classic Checkout and Gutenberg Store API.
  • Real-time attack mitigation counter.