{"id":379466,"date":"2026-10-05T14:14:48","date_gmt":"2026-10-05T14:14:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/anti-carding-bot-defense-shield\/"},"modified":"2026-10-05T14:14:40","modified_gmt":"2026-10-05T14:14:40","slug":"kosslabs-anti-carding-shield","status":"publish","type":"plugin","link":"https:\/\/lmo.wordpress.org\/plugins\/kosslabs-anti-carding-shield\/","author":14651540,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"KossLabs Anti-Carding & Bot Shield","header_author":"KossLabs","header_description":"High-performance, zero-bloat anti-carding, rate-limiting, and Cloudflare Turnstile bot protection for WooCommerce Classic and Store API Checkout.","assets_banners_color":"0c4e6d","last_updated":"2026-10-05 14:14:40","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/profiles.wordpress.org\/theaikoss","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/kosslabs-anti-carding-shield\/","header_author_uri":"https:\/\/profiles.wordpress.org\/theaikoss","rating":0,"author_block_rating":0,"active_installs":0,"downloads":198,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"theaikoss","date":"2026-10-05 14:14:40","revision":3729071}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3729071,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3729071,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3729071,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3729071,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Admin Dashboard with real-time threat mitigation counter and Bring Your Own Key (BYOK) setup.","2":"Turnstile verification seamlessly embedded in WooCommerce Checkout."}},"plugin_section":[],"plugin_tags":[23683,166108,262525,284504,214603],"plugin_category":[],"plugin_contributors":[284505],"plugin_business_model":[],"class_list":["post-379466","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-fraud","plugin_tags-bot-protection","plugin_tags-card-testing","plugin_tags-stripe-fraud","plugin_tags-turnstile","plugin_contributors-theaikoss","plugin_committers-theaikoss"],"banners":{"banner":"https:\/\/ps.w.org\/kosslabs-anti-carding-shield\/assets\/banner-772x250.png?rev=3729071","banner_2x":"https:\/\/ps.w.org\/kosslabs-anti-carding-shield\/assets\/banner-1544x500.png?rev=3729071","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/kosslabs-anti-carding-shield\/assets\/icon-128x128.png?rev=3729071","icon_2x":"https:\/\/ps.w.org\/kosslabs-anti-carding-shield\/assets\/icon-256x256.png?rev=3729071","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>KossLabs Anti-Carding &amp; Bot Shield<\/strong> protects online merchants from card testing fraud (carding attacks) by intercepting automated bot submissions before they reach payment gateways such as Stripe, PayPal, Square, or local payment providers.<\/p>\n\n<p>When carding fraudsters target a WooCommerce store, they automate thousands of micro-authorization attempts using stolen credit card dumps. Even when transactions fail, merchants incur expensive authorization fees ($0.15 - $0.50 per attempt) and risk payment account suspension.<\/p>\n\n<p>This plugin delivers a <strong>4-layer zero-bloat defense<\/strong> that halts card testing attacks at the gateway threshold without adding custom database tables:<\/p>\n\n<ul>\n<li><strong>Layer 1: Invisible Honeypot Trap:<\/strong> Traps naive automated bots that blindly fill all form inputs.<\/li>\n<li><strong>Layer 2: Cryptographic Timestamp Token:<\/strong> Blocks headless scripts that submit forms faster than humanly possible (&lt; 1.5 seconds) using HMAC-signed tokens.<\/li>\n<li><strong>Layer 3: Cloudflare Turnstile (Bring Your Own Key - BYOK):<\/strong> Frictionless, privacy-friendly bot challenge. Store owners use their own free Cloudflare credentials\u2014no third-party proxy or developer API quota shared.<\/li>\n<li><strong>Layer 4: Transient IP Rate Limiter:<\/strong> Enforces strict attempt thresholds per IP (e.g., 3 failed attempts in 10 minutes) stored entirely in RAM (Transients API \/ Redis \/ Memcached).<\/li>\n<li><strong>Dual-Shield Architecture:<\/strong> Full compatibility with Classic Checkout and modern WooCommerce Blocks Store API (<code>\/wp-json\/wc\/store\/v1\/checkout<\/code>).<\/li>\n<\/ul>\n\n<h3>Privacy Policy &amp; External Services<\/h3>\n\n<p>This plugin integrates with Cloudflare Turnstile to protect your checkout against card testing and automated bot abuse.<\/p>\n\n<ul>\n<li><strong>Service:<\/strong> Cloudflare Turnstile<\/li>\n<li><strong>Provider:<\/strong> Cloudflare, Inc.<\/li>\n<li><strong>Service Description:<\/strong> Frictionless, privacy-preserving bot detection challenge.<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<li><strong>Data Transmitted:<\/strong> During checkout, the customer's IP address and Turnstile response token are transmitted to Cloudflare's validation endpoint (<code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code>) to verify whether the submission is from a legitimate human. Store owners use their own Cloudflare account credentials (BYOK).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>kosslabs-anti-carding-shield<\/code> folder to your <code>\/wp-content\/plugins\/<\/code> directory, or install directly via the WordPress Plugins menu.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Ensure WooCommerce is installed and activated.<\/li>\n<li>Navigate to <strong>WooCommerce &gt; Anti-Carding Shield<\/strong> in your WordPress admin menu.<\/li>\n<li>Enter your Cloudflare Turnstile <strong>Site Key<\/strong> and <strong>Secret Key<\/strong> (obtained free from your Cloudflare dashboard).<\/li>\n<li>Adjust rate limiting thresholds if desired, then click <strong>Save Configuration<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20add%20tables%20to%20my%20database%3F\"><h3>Does this plugin add tables to my database?<\/h3><\/dt>\n<dd><p>No. It strictly adheres to a \"Zero-Bloat\" philosophy. All rate limiting and temporary blocks utilize the native WordPress Transients API, which operates in RAM when object caching (Redis or Memcached) is enabled.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20paid%20cloudflare%20account%3F\"><h3>Do I need a paid Cloudflare account?<\/h3><\/dt>\n<dd><p>No. Cloudflare Turnstile is completely free for up to 10 visible\/managed sites per account with unlimited challenge responses.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20woocommerce%20blocks%20%2F%20modern%20checkout%3F\"><h3>Does this work with WooCommerce Blocks \/ Modern Checkout?<\/h3><\/dt>\n<dd><p>Yes. The plugin intercepts both traditional classic checkout (<code>woocommerce_checkout_process<\/code>) and modern Store API REST checkout endpoints (<code>\/wc\/store\/v1\/checkout<\/code>).<\/p><\/dd>\n<dt id=\"will%20legitimate%20customers%20be%20interrupted%20by%20difficult%20captchas%3F\"><h3>Will legitimate customers be interrupted by difficult CAPTCHAs?<\/h3><\/dt>\n<dd><p>No. Cloudflare Turnstile is designed to run non-interactively in the background without frustrating puzzles or image selections for genuine shoppers.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release.<\/li>\n<li>4-layer defense: Honeypot, 1.5s cryptographic timestamp, Cloudflare Turnstile, and Transient IP rate limiting.<\/li>\n<li>Full support for WooCommerce Classic Checkout and Gutenberg Store API.<\/li>\n<li>Real-time attack mitigation counter.<\/li>\n<\/ul>","raw_excerpt":"Protect your WooCommerce store against card testing bot attacks with zero-bloat rate limiting and Cloudflare Turnstile (BYOK).","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/379466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=379466"}],"author":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/theaikoss"}],"wp:attachment":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=379466"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=379466"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=379466"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=379466"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=379466"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=379466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}