Checkout Guard – Block Fake Orders, Spam & Fraud for WooCommerce
by Giannis Kipouros 5 (2 reviews)

Checkout Guard – Block Fake Orders, Spam & Fraud for WooCommerce

Block fake and spam WooCommerce orders at checkout. Stop disposable email, junk names, bad IPs, and countries you don't sell to.

Checkout Guard ranks #18,284 among WordPress.org plugins with 70+ active installations, is #2,945 of 12,560 in the E-commerce category, a 5/5 rating from 2 reviews, and was last updated Sep 20, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.2
v1.2.0 Current Version v1.2.0
Updated 2 days ago Last Update on 20 Sep, 2026
Refreshed 7 hours ago Last Refreshed on
#2,945 of 12,560 in E-commerce Top 25% by installs Downloads +23.2% this week Actively maintained
View on WordPress.org
Rank
#18,284
+295 this week
Active Installs
70+
+11.1%
KW Avg Position
25.8
0.3 worse
Downloads
1.9K
+4 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (2 reviews)

Next Milestone 80

Total Progress 50%
70+ 80+
827
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 80+

Rank Changes

18,221 18,357 18,493 18,629 18,765 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
18,163 18,425 18,687 18,948 19,210 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #18,284
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 30 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
2 reviews
Overall 100%
5
2 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Checkout Guard – Block Fake Orders, Spam & Fraud for WooCommerce

Set Protection Mode to Learning first. Every rule runs and records what it would have caught, but nothing is blocked and no customer is turned away. When the results look right, switch to Enforce.
Around 22,000, bundled with the plugin and based on the public disposable email domains list. The settings screen links to the source so you can check any domain. It is a copy taken when the plugin was released, so it will not match the source exactly.
No. Firefox Relay, Apple Hide My Email and Addy deliver to a real permanent inbox, so blocking them would reject a paying customer. They are excluded from the bundled list.
No. Matching is exact and whole-field, never a substring, so test blocks a customer who types "Test" as their whole name but never affects Testa, Contestabile or Testani. The full list is shown on the settings screen so you can check it before switching the rule on.
Enter *@bad-domain.com on its own line in the email blocklist. That blocks every billing email at that domain, and nothing else. You can also enter the bare domain, bad-domain.com. The difference is precision: a bare domain matches anywhere in the address, so it will also catch someone@notbad-domain.com. The *@ form matches the domain exactly. Prefer the wildcard unless you specifically want the looser match.
The * wildcard stands for any run of characters, and the pattern must match the whole address: *@bad-domain.com blocks every address at that domain. spam*@bad-domain.com blocks spammer@bad-domain.com but leaves nice@bad-domain.com alone. *.edu blocks every address ending in that TLD. Catch-all entries such as * or *@* would block every order on your store, so they are rejected and removed when you save.
Yes. Checkout Guard supports IPv4 wildcards, so 203.0.113.* covers that whole range. Wildcards are IPv4 only.
Yes. Checkout Guard reads forwarded proxy headers by default, so IP rules match the real visitor rather than the CDN edge. If your store is not behind a proxy you can switch that off in Store Setup.
Not currently. The country rule is a blocklist: you list the countries to turn away.
Yes. The classic checkout, the WooCommerce Checkout block and express checkouts are all enforced, with one known exception noted below, and the plugin declares HPOS compatibility.

More plugins by Giannis Kipouros

Sign In / Register

You need to sign in or register to use this feature.