WooCommerce fraud protection that lives inside your orders.
Real-time risk scoring, one-click review, and full session forensics — right inside your WooCommerce orders. Automatic risk-to-status routing on Pro.
Decide on the full order context
WPSentinel feeds real WooCommerce order details into every rule — not just the session.
Product categories
Score on what is in the cart and flag high-risk categories.
Cart amount
Weight the order value — large first orders raise risk.
Billing location
Use the billing address and country directly in your rules.
Delivery location
Compare the shipping destination against billing and IP.
Risky product
Tag specific products as high-risk and act on them.
Payment method
Factor the gateway and payment type into the decision.
Automatic order decision PRO
On Pro, WPSentinel maps each order’s risk result to a WooCommerce order status automatically, so risky orders route themselves and clean orders flow through. On Free, you decide each flagged order with one-click accept or reject.
Review and investigate from the order
Automatic risk → status mapping PRO
On Pro, define how each risk band maps to an order status. Set it once; it runs on every order.
Direct investigation link
Open the full session forensics for any order with one click — fingerprint, IP, graph and all.
One-click accept / reject
Accept keeps the order processing; reject cancels and notifies the customer. Every decision is logged.

Map every action to an order status
In the plugin settings, map each WPSentinel action — accept, review, challenge, reject — to the WooCommerce order status it should apply during checkout review, and set the support email shown on the fraud-block page.

Jump straight into the evidence
From an order, follow the investigation link into the graph: pivot across the email, IP, device, and address, run a breach check, and map the shipping address — then accept or reject with confidence.
A shared, GDPR-compliant device network PRO
On Pro, opt into a real-time, GDPR-compliant consortium where multiple entities share device-ID signals — so fraud caught on one store helps protect yours, without sharing personal data.