FindIP Shield

Visitor risk detection for your website

Install from npm, add one JavaScript snippet, or use Google Tag Manager to detect VPNs, proxies, Tor, hosting networks, and malicious IPs on every visit — with a risk score and recommendation for each session.

Quickstart

Install in under two minutes

npm and script-tag installation, pinned CDN releases with SRI, what happens automatically, and how to verify the install.

JavaScript SDK

Full API reference

FindIP.init, track, getSession, setConsent, and every configuration option.

Events

Standard events & payloads

The event catalog, auto-detection confidence, and the full payload schema.

Identify users

Attach your user ID & context

Send a hashed user ID and business context via the dataLayer or FindIP.track(), so a risky session traces back to an account in your system.

In-page enforcement

Stop, slow down, challenge, redirect

Switch it on per site and the SDK acts on Shield's recommendation when a risky visitor submits a sign-up, login, checkout or lead form. No snippet change; works on every install type.

Google Tag Manager

Template & dataLayer

The official tag template, Custom HTML alternative, risk results in the dataLayer, and consent wiring.

Cloudflare

No-code edge protection · New

Authorize with Cloudflare, pick one hostname, and Shield deploys one Worker and one route. Watch first, block only what you choose, fails open by design.

WordPress

Official plugin

Install from the WordPress.org directory, pinned SDK with subresource integrity, privacy and consent settings.

WooCommerce

Storefront signals

Product, cart, and checkout risk context with per-event controls — no customer, order, or payment data.

Shopify

Web Pixel app

The FindIP Shield app from the Shopify App Store: strict-sandbox Web Pixel, consent enforced by Shopify.

Privacy Modes

strict / balanced / advanced

What each mode collects, consent integration, and what is never collected in any mode.

Data Collection

Exactly what is sent

Field-level breakdown per privacy mode, form metadata examples, and allowlisted customer context.

Cookies

First-party only

_fip_sid and _fip_vid: purpose, duration, fallbacks when cookies are blocked.

Server Verification

Enforce on the backend

Why browser signals aren't enough for enforcement, and how to verify session risk securely from your backend.

Threat Network

The free-preview data contribution

Exactly what pseudonymized, infrastructure-level sightings free sites contribute — and everything they never contain.

Free Preview Terms

AS IS · your responsibility

Preview status, fair use, the Threat Network contribution, and the full allocation of compliance responsibility.