Score a transaction for fraud risk before you capture the payment.
MaxMind's minFraud Score takes what you know about an order — the IP, the email, the billing address, the payment method — and returns a risk score from 0 to 100, informed by what it has seen across everyone else using it.
This calls the Score endpoint, hands back a response object, and turns a
failure into a WP_Error rather than an exception, so a checkout can decide
what to do about it rather than dying.
- Get a risk score from 0 to 100 for an order
- Send as much or as little as you have — an IP alone works, more is better
- Read MaxMind's warnings about fields it could not use
- Keep an eye on the credits and funds left on the account
- Get the query id back, for looking a decision up later or disputing it
- Cache answers, and cache failures briefly so an outage is not amplified
composer require arraypress/wp-maxmind-minfraudScore an order and hold the risky ones for review:
use ArrayPress\MaxMind\MinFraud\Client;
$client = new Client( $account_id, $license_key );
$score = $client->check_score( [
'device' => [ 'ip_address' => $order->ip ],
'email' => [ 'address' => $order->email ],
'billing' => [
'country' => $order->billing_country,
'postal' => $order->billing_postcode,
],
] );
if ( is_wp_error( $score ) ) {
return; // Capture anyway; do not lose the sale to an API outage.
}
if ( $score->get_risk_score() >= 50 ) {
$order->flag_for_review( $score->get_query_id() );
}The more of the payload you fill in, the better the score. An IP on its own is a weak signal.
It scores, it does not decide. Where the threshold sits is a business question — too low and you turn away real customers, too high and it earns nothing — and it is worth reviewing against your own chargebacks rather than taking a number from a blog post.
- PHP 8.3 or later
- WordPress 7.1 or later
- A MaxMind account id and licence key
GPL-2.0-or-later