{"id":352313,"date":"2026-08-28T01:27:19","date_gmt":"2026-08-28T01:27:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/fraud-screening-with-signifyd\/"},"modified":"2026-08-29T05:56:57","modified_gmt":"2026-08-29T05:56:57","slug":"riskloom-fraud-screening-for-signifyd","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/riskloom-fraud-screening-for-signifyd\/","author":14730775,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.3","stable_tag":"1.2.3","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Riskloom Fraud Screening for Signifyd","header_author":"Choice OMG","header_description":"Fraud screening for WooCommerce via Signifyd. Creates cases server-side, receives decisions by signed webhook, and lets staff close cases or purchase a guarantee from the order screen.","assets_banners_color":"111c31","last_updated":"2026-08-29 05:56:57","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/choice.marketing\/tools\/riskloom-signifyd\/","header_author_uri":"https:\/\/choice.marketing","rating":0,"author_block_rating":0,"active_installs":0,"downloads":60,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.2":{"tag":"1.2.2","author":"jaffray","date":"2026-08-28 01:26:54","revision":3669682},"1.2.3":{"tag":"1.2.3","author":"jaffray","date":"2026-08-29 05:56:57","revision":3671134}},"upgrade_notice":{"1.2.3":"<p>Points the Plugin URI at choice.marketing and adds listing screenshots. No functional change; no reconfiguration needed.<\/p>","1.2.2":"<p>Renames the plugin. Hooks, options, settings, and the webhook URL are unchanged; no reconfiguration needed.<\/p>","1.2.1":"<p>Corrects the plugin name shown in two admin notices. No functional change; no reconfiguration needed.<\/p>","1.2.0":"<p>Fixes a duplicate-case bug affecting sites with a persistent object cache, and stops error-response bodies reaching the log. Hooks and webhook URL are unchanged; no reconfiguration needed.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669681,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon-512x512.png":{"filename":"icon-512x512.png","revision":3669681,"resolution":"512x512","location":"assets","locale":"","width":512,"height":512}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669681,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3669681,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.2","1.2.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3671133,"resolution":"1","location":"assets","locale":"","width":1280,"height":873},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3671133,"resolution":"2","location":"assets","locale":"","width":1280,"height":1687},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3671133,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3671133,"resolution":"4","location":"assets","locale":"","width":1280,"height":873}},"screenshots":{"1":"Signifyd settings tab under WooCommerce &gt; Settings, with API key and screening options.","2":"Signifyd Score metabox on the WooCommerce order screen, showing case score and disposition.","3":"The plugin listed on the WordPress Plugins screen.","4":"Signifyd log entries on the WooCommerce Status &gt; Logs screen."}},"plugin_section":[],"plugin_tags":[129025,12891,132861,277981,286],"plugin_category":[45],"plugin_contributors":[277982],"plugin_business_model":[],"class_list":["post-352313","plugin","type-plugin","status-publish","hentry","plugin_tags-chargebacks","plugin_tags-fraud","plugin_tags-fraud-prevention","plugin_tags-signifyd","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-jaffray","plugin_committers-jaffray"],"banners":{"banner":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/banner-772x250.png?rev=3669681","banner_2x":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/banner-1544x500.png?rev=3669681","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/icon-256x256.png?rev=3669681","icon_2x":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/icon-256x256.png?rev=3669681","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/screenshot-1.png?rev=3671133","caption":"Signifyd settings tab under WooCommerce &gt; Settings, with API key and screening options."},{"src":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/screenshot-2.png?rev=3671133","caption":"Signifyd Score metabox on the WooCommerce order screen, showing case score and disposition."},{"src":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/screenshot-3.png?rev=3671133","caption":"The plugin listed on the WordPress Plugins screen."},{"src":"https:\/\/ps.w.org\/riskloom-fraud-screening-for-signifyd\/assets\/screenshot-4.png?rev=3671133","caption":"Signifyd log entries on the WooCommerce Status &gt; Logs screen."}],"raw_content":"<!--section=description-->\n<p>Signifyd has no official WooCommerce integration. It ships supported plugins for\nMagento 2, Salesforce Commerce Cloud, and BigCommerce, leaving WooCommerce stores\nto build their own. This plugin is that integration, written directly against\nSignifyd's REST API using WordPress's own HTTP client.<\/p>\n\n<p>When an eligible order is paid, the plugin builds a case from the order and\nsubmits it to Signifyd for screening. Signifyd returns its risk score and\nguarantee decision over a signed webhook, which the plugin verifies and stores on\nthe order. Staff get a compact panel on the order screen showing the score and\ndisposition, with buttons to refresh the case, dismiss it, or purchase Signifyd's\nfinancial guarantee.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Creates a Signifyd case automatically when an eligible order is paid<\/li>\n<li>Verifies signed webhooks (HMAC-SHA256) and stores the resulting score and\nguarantee disposition on the order<\/li>\n<li>Order-screen panel for staff: view case, refresh, close case, purchase guarantee<\/li>\n<li>Filterable payment-gateway meta mapping, so the plugin is not tied to one gateway<\/li>\n<li>Compatible with High-Performance Order Storage (HPOS)<\/li>\n<li>No bundled SDK and no vendor dependencies; the API client is a few hundred lines\non top of the WordPress HTTP API<\/li>\n<li>API key can live in <code>wp-config.php<\/code> instead of the database<\/li>\n<\/ul>\n\n<h4>Choosing which orders get screened<\/h4>\n\n<p>Screening is limited to the payment gateways you select on the settings screen,\nso only credit-card orders are sent. You choose whether the case is created on\npayment completion or when the order reaches processing status. A filter\n(<code>wc_signifyd_order_is_eligible<\/code>) lets you refine that per order.<\/p>\n\n<h4>What it deliberately does not do<\/h4>\n\n<ul>\n<li>It never handles card numbers or CVV values. Only risk-signal fields your\ngateway has already stored are read: AVS and CVV match results, card BIN, last\nfour digits, and expiry.<\/li>\n<li>It never writes request or response bodies to logs. Logging goes through the\nWooCommerce logger and records order IDs, case IDs, and status codes only.<\/li>\n<li>It never changes order status on its own. A <code>DECLINED<\/code> guarantee stores the\ndisposition and fires the <code>wc_signifyd_case_updated<\/code> action so each store can\napply its own policy, rather than cancelling orders behind your back.<\/li>\n<\/ul>\n\n<h4>Which Signifyd API this uses<\/h4>\n\n<p>This plugin calls the Signifyd <strong>V2 Cases API<\/strong>. Signifyd's current documentation\npromotes the V3 Decisions API for new integrations, and V2 remains available to\nexisting teams. Confirm with your Signifyd account team which API version your\ncredentials are provisioned for before installing.<\/p>\n\n<h4>Extending it<\/h4>\n\n<p>Ten filters and actions are available, covering gateway meta mapping, AVS code\ntranslation, order eligibility, the full case payload, request timeout, and a\npost-update action for custom workflow. The full reference lives in\n    docs\/ARCHITECTURE.md in the source repository.<\/p>\n\n<h4>Who maintains this<\/h4>\n\n<p>Choice OMG maintains this plugin. We are a digital marketing and web agency in\nEdmonton, Alberta, and we wrote it because a client's WooCommerce store needed\nSignifyd screening that Signifyd does not ship for WooCommerce. It runs in\nproduction on that store against the Moneris gateway.<\/p>\n\n<p>Setup notes and gateway mapping guidance live at\n<a href=\"https:\/\/choice.marketing\/\">Choice OMG<\/a>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to Signifyd, a third-party fraud-screening service. It is\nnot usable without a Signifyd account, because screening happens on Signifyd's\nservers rather than in WordPress.<\/p>\n\n<p><strong>When the plugin contacts Signifyd<\/strong><\/p>\n\n<ul>\n<li>When an eligible order is paid, to create a fraud case.<\/li>\n<li>When a staff member clicks Refresh, Close Case, or Purchase Guarantee on the\norder screen.<\/li>\n<\/ul>\n\n<p>Signifyd also sends data <em>to<\/em> your site, over a signed webhook, when a case is\ncreated, rescored, reviewed, or a guarantee completes.<\/p>\n\n<p><strong>What is sent<\/strong><\/p>\n\n<p>Creating a case transmits the information Signifyd needs to assess risk:<\/p>\n\n<ul>\n<li>Order details: order ID, order key, total, currency, creation time, payment\ngateway, and transaction ID<\/li>\n<li>Line items: product IDs, names, URLs, images, quantities, and prices<\/li>\n<li>Customer details: name, email address, phone number, billing address, shipping\naddress, and the IP address recorded on the order<\/li>\n<li>Account details, for registered customers: username, email, account ID, and\nregistration date<\/li>\n<li>Payment risk signals: the gateway's AVS and CVV match results, plus the card\nBIN, last four digits, and expiry month and year<\/li>\n<\/ul>\n\n<p>Full card numbers and CVV values are never transmitted; the plugin does not have\naccess to them.<\/p>\n\n<p>Other calls (refresh, close, guarantee) transmit only the Signifyd case ID.<\/p>\n\n<p><strong>Service, terms, and privacy policy<\/strong><\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.signifyd.com\/\">Signifyd<\/a><\/li>\n<li>Terms of service: <a href=\"https:\/\/www.signifyd.com\/terms\/\">https:\/\/www.signifyd.com\/terms\/<\/a><\/li>\n<li>Privacy policy: <a href=\"https:\/\/www.signifyd.com\/privacy\/\">https:\/\/www.signifyd.com\/privacy\/<\/a><\/li>\n<\/ul>\n\n<p>Because customer personal data is transmitted to a third party, review your own\nprivacy policy and any applicable data-protection obligations (GDPR, CCPA, PIPEDA\nand similar) before enabling this plugin on a live store.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>wp-content\/plugins\/riskloom-fraud-screening-for-signifyd\/<\/code>, or install it from the Plugins screen.<\/li>\n<li>Activate it through the Plugins screen. WooCommerce must be active.<\/li>\n<li>Go to <strong>WooCommerce &gt; Settings &gt; Signifyd<\/strong> and enter your Signifyd team API key.<\/li>\n<li>On the same screen, choose which payment gateways are screened and which order event creates the case.<\/li>\n<li>Copy the webhook URL shown on that screen into the Signifyd console under Settings &gt; Webhooks, subscribed to at least Case Creation, Case Rescore, Case Review, and Guarantee Completion.<\/li>\n<\/ol>\n\n<h4>Keeping the API key out of the database<\/h4>\n\n<p>Define it in <code>wp-config.php<\/code> instead of using the settings field:<\/p>\n\n<pre><code>define( 'WC_SIGNIFYD_API_KEY', 'your-team-api-key' );\n<\/code><\/pre>\n\n<p>The constant overrides the stored option, and the settings field is shown\ndisabled with a note explaining why.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20signifyd%20account%3F\"><h3>Do I need a Signifyd account?<\/h3><\/dt>\n<dd><p>Yes. Signifyd performs the screening, so the plugin cannot function without an\naccount and an API key. See the External services section for what is sent.<\/p><\/dd>\n<dt id=\"does%20this%20support%20the%20signifyd%20v3%20decisions%20api%3F\"><h3>Does this support the Signifyd V3 Decisions API?<\/h3><\/dt>\n<dd><p>Not currently. It targets the V2 Cases API, which remains available to existing\nSignifyd teams. Porting to V3 would mainly affect the API client.<\/p><\/dd>\n<dt id=\"does%20this%20store%20or%20transmit%20credit%20card%20numbers%3F\"><h3>Does this store or transmit credit card numbers?<\/h3><\/dt>\n<dd><p>No. It reads only the risk-signal fields your payment gateway has already stored\non the order: AVS and CVV match results, card BIN, last four digits, and expiry.\nThe full card number and the CVV value never pass through the plugin.<\/p><\/dd>\n<dt id=\"will%20it%20cancel%20orders%20that%20signifyd%20declines%3F\"><h3>Will it cancel orders that Signifyd declines?<\/h3><\/dt>\n<dd><p>No. The plugin stores the score and disposition and fires the\n    wc_signifyd_case_updated action. Acting on a declined guarantee is left to your\nown code or workflow, so the plugin never cancels or holds an order on its own.<\/p><\/dd>\n<dt id=\"my%20payment%20gateway%20is%20not%20moneris.%20will%20this%20work%3F\"><h3>My payment gateway is not Moneris. Will this work?<\/h3><\/dt>\n<dd><p>Yes, with a small amount of configuration. The order meta keys the plugin reads\ncard risk signals from are filterable through <code>wc_signifyd_gateway_meta_map<\/code>, and\nAVS code translation through <code>wc_signifyd_avs_map<\/code>. The defaults target the\nWooCommerce Moneris gateway because that is the gateway the plugin has run\nagainst in production.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20high-performance%20order%20storage%3F\"><h3>Is it compatible with High-Performance Order Storage?<\/h3><\/dt>\n<dd><p>Yes. All order access goes through the WooCommerce CRUD API, and the plugin\ndeclares HPOS compatibility. It works with both legacy post storage and HPOS.<\/p><\/dd>\n<dt id=\"does%20purchasing%20a%20guarantee%20cost%20money%3F\"><h3>Does purchasing a guarantee cost money?<\/h3><\/dt>\n<dd><p>Purchasing a guarantee is billable on your Signifyd account, so the button asks\nfor confirmation before submitting.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Pointed the Plugin URI at the plugin's page on choice.marketing instead of the GitHub repository.<\/li>\n<li>Added listing screenshots.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Renamed the plugin to \"Riskloom Fraud Screening for Signifyd\" so the name leads with a distinctive term rather than a generic description.<\/li>\n<li>Removed the <code>load_plugin_textdomain()<\/code> call, which WordPress has not needed since 4.6 and this plugin's minimum of 6.0 can never reach.<\/li>\n<li>Added the plugin owner to the contributor list.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Renamed the plugin in both admin notices, which still used the pre-1.2.0 name.<\/li>\n<li>Corrected the Plugin URI capitalisation to match the canonical repository path.<\/li>\n<li>Regenerated the translation template against the corrected strings.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Fixed the AVS mapping comment never being saved, which left that line blank in the order panel on every order.<\/li>\n<li>Fixed the duplicate-case guard being ineffective on sites with a persistent object cache, where it could allow two Signifyd cases to be created for one order.<\/li>\n<li>Stopped writing Signifyd error-response bodies into the WooCommerce log; only the HTTP status code is recorded now.<\/li>\n<li>Renamed the plugin for WordPress.org directory compliance. Internal hooks, options, and the webhook URL are unchanged.<\/li>\n<li>Added a translation template, documented every function and class, and added architecture and contributor documentation.<\/li>\n<li>Refreshed compatibility: tested against WordPress 7.0 and WooCommerce 11.0.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Removed the bundled SDK in favor of the WordPress HTTP API<\/li>\n<li>HPOS compatibility<\/li>\n<li>Filterable gateway meta map and AVS map<\/li>\n<li>Added WooCommerce settings tab and Purchase Guarantee button<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial internal version<\/li>\n<\/ul>","raw_excerpt":"Fraud screening for WooCommerce with Signifyd. Creates cases automatically, receives signed webhook decisions, and adds order-screen controls.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/352313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=352313"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jaffray"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=352313"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=352313"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=352313"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=352313"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=352313"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=352313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}