Beskrywing
Bot Protector for PayPal for WooCommerce helps store owners automatically block bot attacks, checkout spam, card-testing, and PayPal checkout abuse that generates repeated failed orders.
This plugin monitors suspicious traffic hitting:
- PayPal checkout requests
wc-ajax=checkout- WooCommerce Store API endpoints
- Automated card-testing sequences
It then blocks them based on:
- Adaptive rate limiting
- Automatic IP banning
- User-agent and referer validation
- Optional Cloudflare Turnstile CAPTCHA
- Logging and monitoring
No setup required — activate it and your store is instantly protected.
External services
This plugin connects to Cloudflare Turnstile API to verify CAPTCHA responses when the Turnstile feature is enabled. This service is used to validate that checkout attempts are made by humans rather than bots.
When Turnstile is enabled, the plugin sends the CAPTCHA response token to Cloudflare’s servers for verification. This occurs during checkout validation when a customer submits the checkout form with a Turnstile widget.
This service is provided by Cloudflare: Terms of Service, Privacy Policy
Features
- Lightweight bot firewall for PayPal checkout
- Rate limiting per IP
- Temporary automatic IP bans
- Blocks REST-based checkout attacks
- Blocks PayPal card-testing bots
- Turnstile CAPTCHA support
- Whitelist trusted IP addresses
- Admin log viewer
- No performance impact
- Works with all PayPal gateways for WooCommerce
Donations
Support continued development ❤️
https://www.paypal.com/ncp/payment/EP3HAP53U4MFU
Installation
- Upload the plugin folder to:
/wp-content/plugins/bot-protector-for-paypal-woocommerce/ - Activate the plugin in Plugins Installed Plugins
- Open WooCommerce Bot Protector to configure settings
Kwel-vrae
-
Will it block real customers?
-
No. It blocks only IPs showing strong bot behavior (no user agent, no referer, too many attempts, rapid API calls).
-
Does it work with any PayPal plugin for WooCommerce?
-
Yes — it is fully compatible with all PayPal payment gateway plugins.
-
Can it prevent API-based card testing?
-
Yes, it specifically targets automated card-testing and checkout spamming.
-
Does it store personal customer data?
-
No. It logs only basic IP events required for security.
-
What data is sent to Cloudflare Turnstile?
-
When Turnstile CAPTCHA is enabled, the plugin sends the CAPTCHA response token to Cloudflare for verification. No personal customer data is transmitted.
Aanbevelings
There are no reviews for this plugin.
Contributors & Developers
“Bot Protector for PayPal for WooCommerce” is oopbron sagteware. Die volgende mense het bygedra tot die ontwikkeling van hierdie uitbreiding:
ContributorsTranslate “Bot Protector for PayPal for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0
- Initial release.


