Title: Noventum Fake Order Protection
Author: noventum
Published: <strong>August 18, 2026</strong>
Last modified: August 18, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/noventum-fake-order-protection.svg)

# Noventum Fake Order Protection

 By [noventum](https://profiles.wordpress.org/noventum/)

[Download](https://downloads.wordpress.org/plugin/noventum-fake-order-protection.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/noventum-fake-order-protection/#description)
 * [Reviews](https://wordpress.org/plugins/noventum-fake-order-protection/#reviews)
 *  [Installation](https://wordpress.org/plugins/noventum-fake-order-protection/#installation)
 * [Development](https://wordpress.org/plugins/noventum-fake-order-protection/#developers)

 [Support](https://wordpress.org/support/plugin/noventum-fake-order-protection/)

## Description

Noventum Fake Order Protection adds defensive checks for WooCommerce checkout requests
made through the Store API and classic WooCommerce AJAX checkout.

The plugin can detect suspicious checkout behavior, rate-limit repeated attempts,
add a hidden honeypot field, temporarily block abusive IP fingerprints, and optionally
verify Google reCAPTCHA v3 tokens before allowing high-risk checkout attempts.

This plugin does not create fake orders. It is intended to reduce fake or abusive
order attempts in WooCommerce stores.

### Third-Party Services

This plugin can use Google reCAPTCHA v3 when reCAPTCHA is enabled and site keys 
are configured in the plugin settings.

When enabled, the plugin loads Google’s reCAPTCHA JavaScript from `https://www.google.
com/recaptcha/` on WooCommerce cart, checkout, and product pages. During protected
checkout attempts, the plugin sends the reCAPTCHA token, the configured secret key,
and the visitor IP address to Google’s verification endpoint at `https://www.google.
com/recaptcha/api/siteverify`.

Google reCAPTCHA is provided by Google. Review Google’s terms and privacy information
before enabling it:

 * Google Privacy Policy: https://policies.google.com/privacy
 * Google Terms: https://policies.google.com/terms
 * reCAPTCHA information: https://www.google.com/recaptcha/about/

### Privacy

The plugin processes technical request data such as IP address, user agent, checkout
source headers, WooCommerce session state, checkout email fingerprint, order status,
payment method, and order total to detect abusive checkout behavior.

By default, plugin log entries anonymize personal data before writing to disk. The
plugin stores temporary risk counters in WordPress transients and stores temporary
blocked IP rows in a custom database table.

Administrators can view blocked IP rows and plugin logs from the plugin settings
page. Log files are stored under the WordPress uploads directory in `noventum-oap/`
and rotated automatically.

If Google reCAPTCHA is enabled, checkout verification data is sent to Google as 
described in the Third-Party Services section.

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/`.
 2. Activate the plugin from the Plugins screen in WordPress.
 3. Make sure WooCommerce is installed and active.
 4. Configure the plugin under Settings > Fake Order Protection.
 5. Add Google reCAPTCHA v3 keys if you want reCAPTCHA verification.

## FAQ

### Does this plugin require WooCommerce?

Yes. The plugin only runs its protection features when WooCommerce is active.

### Does this plugin require Google reCAPTCHA?

No. reCAPTCHA is optional, but recommended for stronger protection.

### Does the plugin block real customers?

The plugin uses rate limits, session checks, and risk scoring. Start with Balanced
mode and review logs after enabling protection.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Noventum Fake Order Protection” is open source software. The following people have
contributed to this plugin.

Contributors

 *   [ noventum ](https://profiles.wordpress.org/noventum/)

[Translate “Noventum Fake Order Protection” into your language.](https://translate.wordpress.org/projects/wp-plugins/noventum-fake-order-protection)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/noventum-fake-order-protection/),
check out the [SVN repository](https://plugins.svn.wordpress.org/noventum-fake-order-protection/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/noventum-fake-order-protection/)
by [RSS](https://plugins.trac.wordpress.org/log/noventum-fake-order-protection/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial WordPress.org-ready release metadata and privacy documentation.

## Meta

 *  Version **1.0.0**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.3 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 8.0 or higher **
 * Tags
 * [checkout](https://wordpress.org/plugins/tags/checkout/)[fraud prevention](https://wordpress.org/plugins/tags/fraud-prevention/)
   [recaptcha](https://wordpress.org/plugins/tags/recaptcha/)[security](https://wordpress.org/plugins/tags/security/)
   [woocommerce](https://wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://wordpress.org/plugins/noventum-fake-order-protection/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/noventum-fake-order-protection/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/noventum-fake-order-protection/reviews/)

## Contributors

 *   [ noventum ](https://profiles.wordpress.org/noventum/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/noventum-fake-order-protection/)