A fraudulent order looks almost identical to a real one. Same checkout flow, same form fields filled in, same payment method. The card number works — it was stolen from someone else. The order ships. Two weeks later, the real cardholder files a dispute, the chargeback hits your account, and you’ve lost the product, the shipping cost, the chargeback fee, and an hour of someone’s time dealing with it.
Multiply that by a few orders a month and ecommerce fraud stops being an occasional nuisance and becomes a structural drain. According to LexisNexis’ 2026 True Cost of Fraud study, US merchants now lose $4.61 for every single dollar of fraud — up 37% from 2020 — once chargebacks, fees, inventory loss, and operational costs are factored in. Global ecommerce fraud losses hit $48 billion in 2025, and chargebacks are projected to surge 41% by 2026.
The answer most store owners reach for — reviewing suspicious orders manually — doesn’t scale. And the overcorrection — aggressive blanket rules that block anything unusual — costs US merchants more than $443 billion annually in false declines, turning away real customers to stop fraudsters. The solution is a risk-scoring system that distinguishes one from the other automatically.
StoreEngine’s approach to ecommerce fraud prevention on WordPress is two-layered: Fraud Shield scores every order against 12 behavioral and identity rules the moment it’s placed, then acts automatically on the result. Verification/OTP confirms that the contact placing an order is a real person — and when both layers run together, unverified contact becomes a fraud signal that feeds the score. By the end of this guide, you’ll understand exactly how both layers work and when they’re worth activating.
Quick Answer: What Is Ecommerce Fraud Prevention?
- Ecommerce fraud prevention is the practice of detecting and stopping fraudulent orders before they complete — protecting revenue, preventing chargebacks, and keeping legitimate customers flowing through checkout without unnecessary friction.
- The two main tools in StoreEngine: Fraud Shield (automatic risk scoring on every order, 0–100, with configurable auto-hold and auto-cancel thresholds) and Verification/OTP (a one-time code sent by email or SMS that confirms a real person is placing the order).
- Why it matters in 2026: US merchants lose $4.61 per $1 of fraud in total costs, and chargebacks are rising 41% by 2026. The cost of doing nothing compounds with every fraud cycle.
- The false-decline problem: overly strict fraud rules block real customers — false declines cost more than actual fraud losses. The right system targets risk signals, not legitimate buyers.
- How to start: activate Fraud Shield in StoreEngine Pro, let it score your next 30–50 orders without auto-actions enabled (dry-run), review what fires, then enable auto-hold and auto-cancel at your comfort thresholds.
Why Ecommerce Fraud Is Getting More Expensive in 2026
Fraud isn’t just more frequent — it’s more costly per incident. For every $100 in fraudulent orders, merchants lose roughly $207 in total once chargebacks, processing fees, operational time, and blocked legitimate orders are included. That’s over 2× the face value of the fraud itself.
The chargeback multiplier
A chargeback isn’t a refund — it’s a penalty. The customer gets their money back through the bank, the merchant loses the goods and the payment, and then pays a dispute fee (typically $15–$100 per chargeback, depending on the processor). Do it too often and you’re placed on a monitoring program with higher fees, and eventually risk losing your payment processing account.
Chargebacks are projected to grow from 238 million annually to 337 million by 2026 — a 41% surge. Friendly fraud alone — customers disputing legitimate purchases — is projected to represent 61% of all disputes by 2026, making “the customer just lied” the most common fraud vector in ecommerce.
The false-decline trap
The overcorrection is expensive too. Blanket fraud rules that trigger on anything unusual — an international IP, a new customer with a high-value order, a mismatched billing and shipping country — turn away real buyers as collateral damage. US merchants lose more to false declines than to actual fraud. Good fraud prevention is precise, not broad.
Why WordPress stores are targeted
SMBs spend 12% of annual ecommerce revenue on managing payment fraud, yet most WordPress stores have minimal automated fraud defenses. A plugin-based store processing orders without any risk scoring is a predictable target: easy to probe with card testing, no velocity detection, no IP geolocation, no blocklist. Fraudsters test stores exactly like this with small charges before the real attack.
How StoreEngine’s Fraud Shield Works
Fraud Shield is a rule-based risk scoring engine built into StoreEngine Pro. Every time a new order is placed, Fraud Shield runs it through up to 12 enabled rules, each contributing a weighted point value. The total score lands between 0 and 100, and that score drives an automatic decision — without you reviewing every order manually.

The scoring system
Scores are clamped to 0–100. Each rule has a configurable weight, and a rule that fires contributes up to its full weight to the total. Rules that don’t fire contribute zero — the score only goes up, never down from a baseline. One critical shortcut: if the order’s email, IP, or phone matches your allowlist, the entire scoring pass is skipped and the order is marked low-risk immediately. This protects your known-good customers from ever being touched by the scoring engine.
The three-tier decision
Once scored, Fraud Shield applies one of three decisions based on thresholds you set:
- Low (score below 40 by default): no action taken. The order proceeds normally.
- Medium (score 40–69 by default): the order is automatically held (on-hold status) and you receive an admin email alert. The order sits in review until you act on it.
- High (score 70+ by default): the order is automatically cancelled and you receive an admin alert. The system adds a note to the order recording the exact score and which rules fired.
Both thresholds are adjustable. If you want to be more aggressive, lower the high threshold to 60. If you’re seeing too many false holds, raise the medium threshold to 50. The defaults are starting points, not fixed rules.
The 12 Rules That Drive the Score
This is what makes Fraud Shield genuinely useful rather than a generic “high order value = suspicious” flag. Each of the 12 rules targets a specific, observable fraud signal, and each has its own configurable weight and threshold.
Velocity rules — detecting volume attacks
High velocity from same IP: if the same IP address places more than 5 orders within a 24-hour window (both configurable), it triggers. Card testers probe stores with rapid-fire small transactions from a single IP before making the real attack. This catches exactly that pattern.
High velocity from same email: flags when more than 3 different email addresses are associated with orders from the same session or contact cluster. Fraudsters rotate email addresses to bypass simple per-email limits.
Shared shipping address: when more than 4 accounts ship to the same address, it scores. A single shipping destination accumulating orders across many accounts is a common indicator of a reshipping scam or organized fraud ring.
Identity and mismatch rules — catching inconsistencies
IP/billing country mismatch: the IP address resolves to a different country than the billing address. Legitimate customers traveling abroad trigger this too, which is why it contributes to the score rather than blocking outright — it’s a signal, not a verdict.
Billing/shipping country mismatch: billing and shipping countries don’t match. Significant on higher-value orders; normal for gifts and business deliveries at lower values.
Disposable email: the billing email domain is on a known disposable-email domain list. Fraudsters use throwaway addresses to avoid traceable identifiers. You can add your own extra disposable domains beyond the built-in list.
Name quality: the billing name fails basic plausibility checks — random character strings, placeholder names, keyboard-mash patterns. Real customers don’t submit “asdfgh” as their name.
Address quality: for orders above a configurable threshold ($200 by default), a P.O. Box billing address flags as low-quality. High-value orders shipped to P.O. Boxes are disproportionately associated with fraud.
Behavioral rules — pattern anomalies
New customer, high-value order: a first-time customer placing an order more than 3× your store’s average order value. Calibrated to your actual store data. A $400 first order at a store averaging $50 is a different risk profile than a $400 order at a store averaging $300.
Odd hours, first order: a customer’s very first order placed between 2am and 5am local store time. Automated card testing scripts run at off-hours to minimize the chance of real-time human intervention. The hours window is configurable.
Failed payment attempts: when more than 2 payment failures occur before a successful transaction on the same order. Card testing — trying stolen card numbers until one works — produces exactly this pattern. The rule scales: each additional failed attempt past the threshold adds proportional risk points.
Blocklist rules — known bad actors
Blocklist match: checks the order’s email, IP, phone number, shipping address, and billing country against your blocklist. Any match fires the full rule weight. This is your permanent record of confirmed fraudsters — once an identity is on the blocklist, every future order from it is flagged automatically.
Allowlist, Blocklist, and Admin Review
The scoring engine is one half of Fraud Shield. The other half is what you do with the results and how you manage the lists that inform them.
Blocklist: known bad, always flagged
The blocklist stores identifiers of confirmed fraudsters: email addresses, IP addresses, phone numbers, shipping addresses, Bank Identification Numbers (BINs), and billing countries. When any of these match an incoming order, the blocklist rule fires at full weight.
Allowlist: known good, always safe
The allowlist is the inverse. Add an email, IP, or phone number to the allowlist and any order from that identifier skips the entire scoring pass — score is set to 0 and the decision is immediately low-risk. This exists specifically to protect your repeat loyal customers from ever being incorrectly held or cancelled.
Admin review: mark safe or mark fraud
In the order admin screen, Fraud Shield shows the complete risk picture for every order: the score, the decision tier (colour-coded), and each rule that fired with its point contribution and the specific detail that triggered it. You can see exactly why an order was held.
From that same screen, you have three actions:
- Re-score: re-run all rules against the current order data. Useful if you’ve updated a rule’s weight or threshold and want to see what the current score would be.
- Mark as Safe: clears the hold, adds the customer’s email, IP, and phone to the allowlist, and records the review. Future orders from this customer skip scoring entirely.
- Mark as Fraud: cancels the order if not already cancelled, adds the customer’s email, IP, and phone to the blocklist, and logs the action. Every future order from any of those identifiers will trigger the blocklist rule at full weight.
These two actions are what turn manual review into institutional memory. Every safe review builds your allowlist. Every confirmed fraud builds your blocklist. Over time, both lists get more accurate and the rate of orders needing manual review decreases.
Verification / OTP: Confirming a Real Person Is There
Fraud Shield detects behavioral and identity signals. OTP Verification addresses a different problem: it confirms that whoever is at the checkout actually has access to the contact method they provided. An OTP code sent to the billing email or phone number can’t be intercepted by someone who only stole a card number.
StoreEngine’s Verification addon is a full one-time password system with three modes and three SMS gateway integrations.
How OTP works at checkout
When OTP verification is enabled for checkout, a code generation field appears in the checkout flow. The customer enters their email or phone number, requests a code, and enters it before the order can be placed. Codes are:
- Hashed at storage: stored using wp_hash_password(), never in plaintext. Even database access doesn’t reveal actual codes.
- Rate-limited: 60-second resend cooldown and a maximum of 5 codes per hour per identifier.
- Short-lived: expire after 5 minutes by default (configurable from 60 seconds up).
- Attempt-locked: after 5 incorrect attempts, the code is consumed and a new one must be requested — preventing brute-force guessing.
- Verified in a window: once confirmed, the verification stays valid for 15 minutes (configurable), so a customer who verifies and then goes back to edit their cart doesn’t need to re-verify.
Three identifier modes
The addon supports three modes:
- Email only: verification code sent to the billing email address. No SMS gateway setup required.
- Phone only: code sent via SMS. Requires configuring one of the three supported SMS gateways.
- Phone or email: the customer chooses — enter their phone for an SMS code, or their email for an email code.
Three SMS gateway integrations
For SMS delivery, StoreEngine supports Twilio, Vonage (Nexmo), and a Generic HTTP gateway that lets you connect any SMS API with a configurable endpoint, HTTP method, and parameter mapping — no gateway-specific plugin needed for services outside of Twilio and Vonage.
OTP on login and registration
OTP verification isn’t limited to checkout. You can enable it for account login and new user registration, turning every customer account interaction into a verified touchpoint. The system even supports a force-OTP-auth mode that disables password sign-in for customer accounts entirely — useful for stores where account takeover is a genuine concern.
How Fraud Shield and Verification Work Together
When both addons are active, they reinforce each other through a native bridge. Here’s what happens:
At checkout, if OTP verification is enabled, the customer’s identity is confirmed before the order is placed. When the order is created, a verification flag (_storeengine_contact_verified) is stamped on the order — recording that the contact was OTP-confirmed at checkout time.
Fraud Shield runs at order creation (priority 20, after the flag is stamped at priority 5). If the Verification bridge is enabled, an optional 13th rule — “Contact not OTP-verified” — can add risk points to any order where that flag is absent. This turns unverified contact into a fraud signal, compounding the behavioral and identity signals already in the score.
The practical implication: a new customer placing a high-value order at 3am from an IP that mismatches their billing country is already suspicious. If their contact wasn’t OTP-verified, that order now scores measurably higher than the same order with a verified contact. The two systems are designed to work together.

Setting Up Fraud Prevention on Your WordPress Store
Both addons activate from the StoreEngine Pro addon panel — one toggle each. The recommended setup for most stores:
Phase 1: Dry run (first 2 weeks)
Activate Fraud Shield with score_on_order_created enabled but auto-hold and auto-cancel disabled. Let it score every order without taking any action. After two weeks, review the score distribution: what percentage of your real orders score above 40? Above 70? This tells you whether the default thresholds fit your store’s order profile before you let the system take any autonomous action.
Phase 2: Enable auto-actions
Once you’ve reviewed the score distribution and are confident the thresholds fit your traffic, enable auto_hold_medium and auto_cancel_high. The system will now hold suspicious orders and cancel high-risk ones automatically, with admin email alerts for each.
Phase 3: Add OTP for checkout
Enable Verification with email-only mode first (no SMS gateway configuration needed). Turn it on for checkout only. Watch your order flow for a week — does it cause any real friction for legitimate buyers? If your store’s order volume is high-trust, a 15-minute verification window means most customers verify once and won’t notice it on subsequent quick sessions.
For stores where phone verification matters (higher-value orders, age-restricted products, B2B), configure Twilio or Vonage and switch to phone-or-email mode.
Phase 4: Build your lists
As orders come in and you review them, use Mark as Safe and Mark as Fraud consistently. The blocklist and allowlist are the most durable parts of your fraud system — every confirmed data point makes future automated decisions more accurate.
Is Fraud Shield Right for Your Store?
- If you’re processing more than 50 orders a month, manual fraud review doesn’t scale. Every order that needs human review is time that could be spent on the business — Fraud Shield handles the routine screening automatically.
- If you’ve experienced chargebacks, the blocklist is the most direct tool: every confirmed fraud identity is permanently flagged for every future order. The blocklist doesn’t forget.
- If you sell high-average-order-value products, the new-customer high-value rule and the OTP verification layer together address exactly the scenario where fraud is most costly — a large first order from an unproven identity.
- If you want to reduce fraud without over-blocking real customers, the three-tier scoring system with configurable thresholds is designed specifically for this. Low-risk orders never see any friction. Only genuinely suspicious orders get held or cancelled.
- For the full picture of how fraud prevention fits alongside checkout optimization and conversion tools, see StoreEngine’s ecommerce conversion rate optimization guide — fraud protection and conversion rate aren’t in conflict when the system targets risk signals rather than friction-adding blanket rules.
Frequently Asked Questions
What is ecommerce fraud prevention?
Ecommerce fraud prevention is the practice of detecting and stopping fraudulent orders before they complete, protecting merchants from chargebacks, stolen-card purchases, and account takeover attacks. In 2026, this typically means automated risk scoring — analyzing behavioral signals, identity consistency, and known-bad identifiers on every order — combined with identity verification to confirm real people are placing the orders.
How much does ecommerce fraud actually cost merchants?
According to LexisNexis’ 2026 True Cost of Fraud study, US merchants lose $4.61 for every dollar of direct fraud loss once chargebacks, fees, inventory replacement, and operational costs are included. For every $100 in fraudulent orders, total merchant losses average $207. SMBs spend around 12% of annual ecommerce revenue managing payment fraud.
What does StoreEngine’s Fraud Shield actually do?
Fraud Shield scores every new order against 12 behavioral and identity rules — velocity from the same IP or email, country mismatches, disposable emails, new-customer high-value orders, odd-hours first orders, failed payment attempts, shared shipping addresses, and blocklist matches. The total score (0–100) drives an automatic decision: orders scoring below your medium threshold proceed normally; medium scores are held for review; high scores are auto-cancelled. Every action is logged, and admin email alerts fire for medium and high decisions.
How is OTP verification different from fraud scoring?
Fraud scoring analyzes behavioral signals around an order. OTP verification confirms identity: a code is sent to the billing email or phone, and the customer must enter it before the order can be placed. Fraud scoring says “this order looks suspicious.” OTP verification says “the person placing this order has access to the contact they claimed.” When both run together, unverified contact becomes an additional fraud signal in the score.
Will OTP verification hurt checkout conversion rates?
It adds one step, so there’s a tradeoff to calibrate. StoreEngine’s implementation minimizes friction: the verification window (15 minutes by default) means customers who verify once don’t need to re-verify if they edit their cart. For most stores, enabling OTP for checkout sees minimal conversion impact on legitimate buyers while eliminating a significant share of automated and stolen-card fraud — fraudsters typically don’t have access to the email or phone they’re providing.
What is the difference between a blocklist and an allowlist?
A blocklist contains identifiers of confirmed fraudsters — emails, IPs, phone numbers, addresses, BINs, and countries. Any order matching a blocklist entry fires the blocklist rule at full weight. An allowlist contains identifiers of confirmed legitimate customers. Any order matching an allowlist entry skips the entire scoring pass entirely, returning a score of 0 regardless of any other signals. The “Mark as Fraud” and “Mark as Safe” admin actions add identifiers to the respective lists automatically.
Do I need WooCommerce to use StoreEngine’s Fraud Shield?
No. Fraud Shield is built into StoreEngine Pro, which is a standalone WordPress ecommerce plugin. It doesn’t require WooCommerce. The fraud scoring and blocklist management are native to the StoreEngine order engine, so there’s no plugin bridge or compatibility dependency to maintain.
What happens to a high-risk order that gets auto-cancelled?
The order is moved to cancelled status, an admin email alert is sent with the score and the specific rules that fired, and an order note is added recording the full audit trail. The customer is not notified by default — this is intentional, as notifying fraudsters that their order was flagged teaches them which signals to avoid. You can review every cancelled order from the Fraud Shield admin panel and reverse a decision using “Mark as Safe” if you determine a legitimate customer was incorrectly flagged.


