arraypress / wp-maxmind-minfraud
A PHP library for integrating with the MaxMind minFraud Score API in WordPress, providing fraud risk scoring (0-99), IP reputation, and email/billing/shipping risk signals. Built around WordPress's HTTP API with transient caching.
Requires
- php: >=8.3
Requires (Dev)
- phpcompatibility/phpcompatibility-wp: ^2.1
- phpunit/phpunit: ^12.0
- squizlabs/php_codesniffer: ^3.13.5
- wp-coding-standards/wpcs: ^3.4
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Score a transaction for fraud risk before you capture the payment.
What it does
MaxMind's minFraud Score takes what you know about an order — the IP, the email, the billing address, the payment method — and returns a risk score from 0 to 100, informed by what it has seen across everyone else using it.
This calls the Score endpoint, hands back a response object, and turns a
failure into a WP_Error rather than an exception, so a checkout can decide
what to do about it rather than dying.
Features
- Get a risk score from 0 to 100 for an order
- Send as much or as little as you have — an IP alone works, more is better
- Read MaxMind's warnings about fields it could not use
- Keep an eye on the credits and funds left on the account
- Get the query id back, for looking a decision up later or disputing it
- Cache answers, and cache failures briefly so an outage is not amplified
Installation
composer require arraypress/wp-maxmind-minfraud
Quick start
Score an order and hold the risky ones for review:
use ArrayPress\MaxMind\MinFraud\Client; $client = new Client( $account_id, $license_key ); $score = $client->check_score( [ 'device' => [ 'ip_address' => $order->ip ], 'email' => [ 'address' => $order->email ], 'billing' => [ 'country' => $order->billing_country, 'postal' => $order->billing_postcode, ], ] ); if ( is_wp_error( $score ) ) { return; // Capture anyway; do not lose the sale to an API outage. } if ( $score->get_risk_score() >= 50 ) { $order->flag_for_review( $score->get_query_id() ); }
The more of the payload you fill in, the better the score. An IP on its own is a weak signal.
What it does not do
It scores, it does not decide. Where the threshold sits is a business question — too low and you turn away real customers, too high and it earns nothing — and it is worth reviewing against your own chargebacks rather than taking a number from a blog post.
Requirements
- PHP 8.3 or later
- WordPress 7.1 or later
- A MaxMind account id and licence key
License
GPL-2.0-or-later