WordPress and WooCommerce

VPN, proxy and Tor detection for WordPress and WooCommerce

The FindIP Shield plugin adds explainable visitor risk intelligence to a WordPress site in a few minutes: visits, sessions and form activity with VPN, proxy, Tor, hosting and malicious-IP signals, plus cart and checkout context when WooCommerce is active. Without reading form values, passwords or payment fields.

Free Preview · 10,000 events per site per day · No credit card · Terms apply

VPN Proxy Tor Hosting / datacenter Malicious IP WooCommerce checkout context
The problem

Blocking plugins hide the traffic. You still do not know what it was.

Most WordPress security plugins answer one question: block this IP or not. They do it against a list, on every request, and give you a counter of blocked hits. You never learn whether the blocked visitor was a scraper, a customer on a corporate VPN, or a comment spammer that would have been stopped anyway.

Shield answers a different question: what happened on the site, where did it come from, and what would you want to do about that form. It starts by observing. Enforcement, if any, is a per-form choice you make later with the evidence in front of you.

For WooCommerce stores the same plugin adds cart, checkout, payment-failure and order-received context, with no product, price or customer data.

What Shield shows you

The evidence, then the response you choose

Every visit and form submit, explained

Page views, sessions and form activity derived from form attributes only, each with a risk score and reason codes. Consent-aware initialisation with strict or disabled pre-consent behaviour.

Privacy modes you pick in the settings

Strict, balanced or advanced controls how much browser and session context is collected. Suggested disclosure text is provided for the WordPress privacy policy editor.

Responses for the forms Shield discovered

Once events arrive, give a login, registration, contact or checkout form a response in the Shield dashboard: monitor only, slow down, a Turnstile check, or stop. Nothing changes until you do.

Setup

Install on WordPress in three steps

Works with WordPress 6.4 and newer. The plugin loads a pinned SDK build from the FindIP CDN and connects nothing until an administrator saves a valid site key.

Install the plugin

In WordPress go to Plugins, Add New, search for FindIP Shield and activate it. The plugin loads nothing until a site key is saved.

Paste your site key

Create a Shield site for your domain at findip.net and paste the public site key into the plugin settings. Choose strict, balanced or advanced privacy mode and the consent behaviour you need.

Open the dashboard

Visits, sessions and form activity start arriving. With WooCommerce active you also see cart, checkout, payment-failure and order-received context.

Prefer another route? Serve the site through Cloudflare? Add edge monitoring with no plugin at all.

Boundaries

What a risk score is, and what it is not

An assessment, not proof. A VPN, a hosting network or a changing IP is common for privacy-conscious and corporate users too. Shield explains the reasons so you can decide; it does not pass judgement on a person.
Friction, not a security boundary. Anything decided in the browser can be bypassed by someone who controls it. For decisions that matter, verify the session from your server with your secret key.
Unknown is never safe. Where no intelligence was available the status is unknown. Shield fails open: if a decision does not arrive, the form submits as normal.
Questions

Frequently asked

The plugin enqueues one pinned script from the FindIP CDN; events are sent from the visitor's browser as small payloads, and your server makes no lookups of its own.

Not by itself. The plugin reports signals. If you want friction on a specific form, you configure that in the Shield dashboard, per form, and can turn it off at any time. The plugin listing says it plainly: do not block a visitor only because they use a VPN, proxy, Tor or hosting network.

The plugin supports consent-aware initialisation, lets you choose a privacy mode, never sends form values, passwords, payment details or message contents, and ships suggested disclosure text. What is appropriate for your site and jurisdiction remains your call.

On WordPress.org as FindIP Shield, with the source on GitHub under findip-net. WooCommerce stores can use the same plugin; a WooCommerce-specific build is also published on GitHub.

Start by watching one real flow.

Create a free Shield site, install it, and look at the first real event before you decide on any response.

Get my site key

Free Preview · Informational risk signals · You control enforcement