Woocommerce Anti-Fraud icon

14 versions

Woocommerce Anti-Fraud history.

Every release of Woocommerce Anti-Fraud is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.

14 of 14 releases scanned clean
v8.0.4Latest
September 2, 20261.8 MBScanned
Fixed
  • PLUGINS-3345: Fixed an incorrect Anti-Fraud admin warning appearing when manually creating WooCommerce orders.
  • PLUGINS-3347: Improved “Block Unknown Origin” protection across Classic Checkout, Store API, and CardPointe checkout flows for more consistent fraud protection.
  • PLUGINS-3373: Improved “Too Many Order Attempts” protection to reduce false blocks of legitimate customers caused by store-wide and aggregated matching.
  • PLUGINS-3374: Fixed Apple Pay and WooPayments tokenized cart checkout issues caused by WooCommerce Anti-Fraud interference.
  • ANTIFRAUD-278: Improved CAPTCHA provider compatibility and corrected reCAPTCHA support.
  • ANTIFRAUD-280: Added WooCommerce 10.9+ compatibility and fixed a fatal error related to email notification handling.
Added
  • ANTIFRAUD-275: Added Anti-Fraud Settings search to make configuration options easier to find.
Improved
  • ANTIFRAUD-288: Improved WooCommerce Anti-Fraud to meet Woo Marketplace Excellence Verified requirements.
August 11, 20261.8 MBScanned
Fixed
  • ANTIFRAUD-240 - reCAPTCHA checkout placement still unresolved on block checkout after ANTI-FRAUD-184
  • ANTIFRAUD-254 - Anti-Fraud PayPal Verification email can trigger with blank recipient when PayPal-specific payer email is unavailable
  • ANTIFRAUD-260 - PHP 8 Fatal Error Risk When wc-af-check Uses Associative WP-Cron Arguments
  • ANTIFRAUD-268 - Anti-Fraud repeatedly enables “Adjust status from fraud score” after plugin upgrades
  • ANTIFRAUD-269 - Anti-Fraud 8.0.1 upgrade can disable Checkout reCAPTCHA
  • ANTIFRAUD-279 - Investigate orphaned Anti-Fraud checks in 8.0.2
Improved
  • ANTIFRAUD-253 - AI Fraud Prevention does not run during manual Fraud Check and silently skips when setup is incomplete
  • ANTIFRAUD-258 - Wording on the setting page/License Management is confusing and should be updated
August 3, 20261.8 MBScanned
Fixed
  • ANTIFRAUD-259 - Correct Inaccurate Anti-Fraud Rule Settings in WooCommerce System Status Report
  • ANTIFRAUD-262 - Critical: Recursive Failed ↔ On hold order-status loop generates hundreds of order notes and WooCommerce emails
  • ANTIFRAUD-263 - Anti-Fraud 8.0.1 queue warning reports stale or misleading pending-check totals and “Last processed: Never” when orders are being checked.
  • ANTIFRAUD-264 - Anti-Fraud 8.0.x may allow repeated fraudulent Square transactions to progress through WooCommerce
  • ANTIFRAUD-265 - Fix PHP 8 fatal errors in wc-af-check cron arguments and clean up legacy events - Not resolved in previous fixes
  • ANTIFRAUD-266 - Prevent false-positive Anti-Fraud cron-health warnings on sites using external cron
  • ANTIFRAUD-267 - Anti-Fraud System Status uses obsolete option keys and misreports the effective rule configuration
Improved
  • ANTIFRAUD-271 - Incomplete plugin uninstall leaves database tables and most settings options behind
v8.0.1Unavailable
July 20, 20261.8 MBScanned
Fixed
  • ANTIFRAUD-224 - Detect and Surface WP-Cron Execution Failures
  • ANTIFRAUD-225 - Expose Fraud Queue State and Processing Metrics
  • ANTIFRAUD-226 - Validate Rule Weights Against Thresholds
  • ANTIFRAUD-256 - Anti-Fraud may retain a stale fraud score after a failed payment attempt instead of recalculating the score when the customer updates checkout details and successfully retries payment.
Improved
  • ANTIFRAUD-227 - Clarify Scope of “Auto Fraud Check” Setting
Added
  • ANTIFRAUD-228 - Provide Better Default Fraud Configuration Presets
  • ANTIFRAUD-229 - Prompt for Pre-Payment Protection Configuration
v8.0.0Unavailable
July 7, 20261.7 MBScanned
Improved
  • ANTIFRAUD-246 - Anti-Fraud UI/UX Updates Review
June 18, 20261.7 MBScanned
Fixed
  • ANTIFRAUD-221 - Prevent PHP 8.4 undefined variable warnings in whitelist settings rendering
  • ANTIFRAUD-222 - [SECURITY] Anti-Fraud trust bypass via spoofable signals (email domain + Referer-based Store API detection)
  • ANTIFRAUD-235 - Fatal error in HPOS helper when processing PayPal callbacks with invalid order object
  • ANTIFRAUD-238 - Turnstile checkout protection not rendering correctly and “Checkout Protection is not active” warning shown incorrectly
  • ANTIFRAUD-249 - [SECURITY] Unauthenticated AJAX Endpoint Allows Fraud Blacklist Manipulation. (PATCHSTACK)
Improved
  • ANTIFRAUD-237 - The “Card Attacks” tab is showing a red status with “Enable Checkout Protection: Not Active”, even though CAPTCHA is enabled on the site.
May 6, 20261.8 MBScanned
Fixed
  • ANTI-FRAUD-214 - Improved location matching by supporting both abbreviated and full state names.
  • ANTI-FRAUD-215 - Improved browser location handling so country details are retained more reliably during fraud checks.
  • ANTI-FRAUD-218 - Improved how browser location data is stored so order checks use the correct location details.
  • ANTI-FRAUD-206 - Improved GeoIP country and state handling in location-based fraud rules.
  • ANTI-FRAUD-207 - Improved GeoIP rule scoring to reduce false positives caused by city-level location matching.
  • ANTI-FRAUD-208 - Improved GeoIP data handling so each order check uses the correct location data.
Improved
  • ANTI-FRAUD-217 - Added postcode support to browser location validation for more accurate fraud checks.
  • ANTI-FRAUD-219 - Improved consistency between IP-based and browser-based location checks.
  • ANTI-FRAUD-220 - Improved location comparison logic to better balance IP and browser location signals.
  • ANTI-FRAUD-209 - Expanded MaxMind MinFraud support to use additional fraud signals, including proxy, VPN, TOR, and risk score checks.
Added
  • ANTI-FRAUD-216 - Added support for saving browser location postcodes for improved location validation.
v7.2.5Unavailable
April 28, 20261.8 MBScanned
Fixed
  • ANTI-FRAUD-169 - Improved how manual overrides and whitelisting are applied, ensuring approved customers and actions are recognized more consistently, including in cases where rules are updated after earlier fraud checks.
  • ANTI-FRAUD-171 - Improved plugin package handling and validation, strengthening file permission checks to help ensure more reliable and secure installation behavior.
  • ANTI-FRAUD-172 - Improved performance during high-load and bot attack scenarios, reducing unnecessary database delays and helping stores remain more stable under heavy traffic or abusive activity.
  • ANTI-FRAUD-192 - Improved compatibility with PayPal reCAPTCHA checks when Anti-Fraud is enabled, reducing misleading compliance warnings and ensuring smoother integration behavior.
  • ANTI-FRAUD-233 - Strengthened request validation and marketplace detection logic, improving protection against spoofing attempts and bypass techniques.
v7.2.4Unavailable
March 29, 20261.7 MBScanned
Improved
  • ANTI-FRAUD-194 - Improved handling of “New Order” email notifications. Adds the ability to delay or suppress new order emails until fraud checks are completed, helping prevent premature notifications for potentially fraudulent orders.
  • ANTI-FRAUD-195 - Improved control over Anti-Fraud email notifications, Introduces new configuration options to reduce excessive email alerts, giving store owners better control over when and how notifications are sent.
  • ANTI-FRAUD-210 - Improved protection against high-volume payment attempts, Enhances detection of rapid or repeated payment attempts across different sessions, helping protect stores against advanced card testing and velocity attacks.*
v7.2.3Unavailable
March 17, 20261.8 MBScanned
Fixed
  • ANTI-FRAUD-196 - AF - Improved handling of reCAPTCHA conflict warnings when Turnstile is used:
Other
  • This resolves an issue where the plugin could incorrectly display a reCAPTCHA conflict warning in the admin area when Cloudflare Turnstile was being used. The warning has been corrected and can now also be dismissed, helping keep the admin interface cleaner and reducing unnecessary alerts.
  • This update introduces a new option that allows store owners to configure where the reCAPTCHA appears on the WooCommerce checkout page. By selecting the appropriate hook or location, merchants can better control the checkout layout and ensure compatibility with different themes and custom checkout setups.
  • This update improves the IP Multiple Order Details rule to better account for services such as iCloud Private Relay and Cloudflare proxy networks. This helps reduce false fraud flags and improves the accuracy of IP-based checks when customers are using privacy or proxy services.
  • This update improves how the plugin identifies and handles orders originating from major marketplaces. By better recognising marketplace-generated orders, the plugin can apply fraud checks more appropriately and avoid unnecessary flags on legitimate marketplace transactions.
Improved
  • ANTI-FRAUD-184 - AF - Configurable Checkout reCAPTCHA placement:
  • ANTI-FRAUD-188 - AF - Improved IP Multiple Order detection with proxy and relay services:
  • ANTI-FRAUD-190 - AF - Marketplace-aware order source handling:

Why archive

Sometimes the latest release isn't the one you need. The archive lets you pin Woocommerce Anti-Fraud to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.