Turn it on
- Go to WooCommerce → Powerups and click Configure on Checkout blocklist.
- Fill in the lists, click Save changes, and switch the power-up on.
Settings
How matching works
- Phone numbers: formatting, a leading 0 or 00, and a country code in front don’t matter. A different area code never matches. Numbers under 7 digits are ignored.
- IP addresses: lines that aren’t an address or a sensible range (wider than /8, or /16 for IPv6) are ignored and listed under the field. IPv4 addresses also match their
::ffff:form.
Which IP address is checked
The blocklist checks the address connecting to your site. Behind a proxy or CDN (such as Cloudflare or a load balancer), that’s the proxy’s address. The IP WooCommerce shows on orders comes from forwarded headers, so the two can differ.- Don’t block the proxy’s IP: that blocks everyone.
- Forwarded headers aren’t trusted by default, because anyone can fake them.
- A developer can pass the real shopper IP with the
apwc_blocklist_ipfilter.
Where it checks
- The classic checkout and the block checkout.
- The classic “Pay for order” page.
Blocked attempts
The Blocked attempts tab (also linked from the Powerups list) lists checkouts the blocklist stopped: the date, Blocked by (email, phone, IP address or account, with the entry that matched), the email and the IP address. It keeps up to 200 entries for 30 days.- Only placing the order is logged, not typing in the form.
- The same attempt repeated within a minute is logged once.
- One IP address adds at most 10 rows every 10 minutes. Further tries from it are counted on its latest row (“+3 more attempts”), so one address can’t push other attempts off the list.
- Emails are kept up to 254 characters, other values up to 200.
The Blocked attempts tab with a few stopped checkouts