Leader of the Pack in Miva Merchant Hosting, Zen Cart Hosting, Miva to Zen Cart Conversion and Custom Module Development and Programming    
Miva Hosting Zen Cart Hosting Dedicated Servers Non-eCom Hosting Reseller Program Modules Other Services  
Control Panel Support About Us Legal Notices

 


 • Miva Merchant Modules •

Wolfpaw Hosting LLC has been a Miva Merchant Development partner since 1999 specializing in general and custom modules for all Miva versions. If you need Miva Merchant to perform a specific function or integrate with an in-house system please contact us with your requirements and we'll provide a quote for a custom module.  

WolfPaw Antifraud

WolfPaw's Fraud Screening and Detection - Version 10.8

Since 2009 the credit card fraud solution trusted by Miva in their own stores, by apps.miva.com, and by hundreds of merchants worldwide.

Block Fraud Before It Costs You

Pre-payment fraud screening powered by MaxMind's minFraud network. Every order is screened in real time — before your payment gateway is contacted. No order created, no payment captured, no chargeback.

Why Pre-Payment Screening?

Most fraud tools flag orders after payment. We block them before.

Orders blocked before checkout — High-risk orders are stopped before your payment gateway is contacted. No authorization fees, no chargebacks, no orders to reverse.
Card testing bots shut down automatically — IP velocity protection detects and blocks bots that submit hundreds of stolen card numbers in rapid succession. Blocked IPs consume zero MaxMind queries.
Smart query caching — When customers retry checkout with the same contact and address data, cached results are reused without consuming another MaxMind query.
Detailed email alerts — Color-coded HTML emails with risk score, customer details, IP analysis, and the full MaxMind response. Configurable thresholds let you choose which orders trigger notifications.
IP whitelisting with CIDR support — Whitelist trusted IPs so phone and manual orders bypass MaxMind screening. Supports individual addresses and CIDR ranges for both IPv4 and IPv6.
Google Storebot auto-whitelist — Automatically detects and whitelists Google Shopping verification tests using published CIDR ranges, reverse DNS, and IP caching. Zero MaxMind queries consumed.
Inventory protection — Fraudulent orders are blocked before payment, so they never reserve or deplete your available inventory.
Country blocking — Configure blocked countries in your MaxMind account. Orders from blocked countries automatically receive 100% risk scores and are declined.
Works behind CDNs and proxies — Automatically detects the real customer IP behind CloudFlare, Akamai, AWS, nginx, and other services for accurate geolocation and velocity tracking.
GDPR and CCPA compliant — Fraud prevention is recognized as a legitimate interest under GDPR and is explicitly permitted under the California Consumer Privacy Act.

What Merchants Are Saying:

"I can't imagine a merchant wanting to be online without this fraud protection module."
Rick Wilson, CEO, Miva Inc.

"Some criminal was using my website to test credit card numbers. Your module has saved my business."
Joe Knoche, Echo Records

"We have been using your app for four years and have not had a chargeback. Love it."
Bob Tenney, thethreadexchange.com

"I've been using this module VERY successfully for several years now in our Miva store."
Cale Reeder, cozywinters.com

Real-World Results: Card Testing Bot Stopped Cold

A merchant's store was hit by a card testing bot — 105 checkout attempts in under 20 minutes using randomized names, junk email addresses, and rotating IP addresses. Here's what happened with velocity protection enabled:

105 fraud attempts 0 reached payment 92 blocked by velocity $0.07 total cost to stop

Every order scored 99% risk and was declined instantly before reaching the payment gateway. After 5 declines, velocity protection blocked the IP. The remaining 92 attempts consumed zero MaxMind queries. Session invalidation forced the bot to rebuild its cart from scratch on every attempt.

When the bot rotated to a second IP, velocity caught it again. The bot gave up after about 20 minutes. Total cost: 13 MaxMind queries at approximately 7 cents.

New in Version 10.8

Google Storebot Auto-Whitelist — Google's Storebot verifies your Google Shopping product listings by running checkout tests on your store. Without auto-whitelisting, these tests consume MaxMind queries and trigger velocity blocks. The module now automatically detects and whitelists verified Google Storebot traffic using published CIDR ranges, reverse DNS lookups via Google's DNS-over-HTTPS service, and a Least Frequently Used (LFU) cache for instant recognition of returning IPs. Spoofed Storebot user agents from unverified IPs are screened normally. Enable with a single checkbox in the admin panel.

Storebot Email Notifications — Receive a single alert when Google Storebot activity begins each day, followed by a summary the next morning with a complete breakdown: total checkout tests, unique IPs, and how each was verified (CIDR, cached DNS, or new reverse DNS lookup). Anti-flooding limits notifications to two emails per active day — just the information you need without the noise.

Screening Statistics Dashboard — A real-time statistics card in the admin panel with three columns: Today, Yesterday, and All Time. Track total screenings, MaxMind queries consumed, queries saved (by cache, whitelist, Storebot, and velocity), risk accepts and declines, and processing errors. See at a glance how much the module is saving you. Includes a reset button with double-click confirmation, and a preserve option that protects your statistics when switching between module types or reinstalling.

New in Version 10.7

IP Velocity Protection — Detects and blocks IP addresses that repeatedly trigger declined orders. Configure the maximum number of declines allowed within a time window and how long blocked IPs stay locked out. The block duration slides forward with each new attempt, so the attacker must go completely quiet before being released. Includes a velocity tracking table in the admin panel with view and clear controls.

Session Invalidation — When velocity protection blocks an IP, the module invalidates the customer's checkout session. This prevents sophisticated bot attacks where different IPs are used to set up the cart and submit payment. Without a valid session, the checkout is dead.

Daily Log Files with Admin Viewer — Logs are now stored as one file per day (UTC-dated) with automatic retention and purging. A built-in log viewer in the admin panel lets you browse and view log files without FTP access. Every screening event is logged with basket ID, order ID, risk scores, velocity tracking counts, and processing error dispositions.

UTC Timestamps Everywhere — All timestamps in logs, emails, and the admin UI use UTC for consistency. Miva servers run in Florida and California, merchants can be anywhere — UTC is the only time that means the same thing to everyone looking at the data.

Enhanced Email Notifications — New amber color scheme for velocity block alerts. Pending order ID now included in basket information. Collapsible technical details section with complete MaxMind response.

Continuing Features

Redesigned Admin Interface — Modern card-based layout with 12 configuration cards. Settings grouped logically with helpful descriptions. One-click Test Connection button verifies your MaxMind credentials instantly.

Professional HTML Email Notifications — Responsive email templates with color-coded alerts (red for declined, green for accepted, teal for whitelisted). Includes complete order details, customer info, shipping/billing addresses, and MaxMind analysis.

Query Caching — Save money on MaxMind queries. When customers browse, add items, and check shipping costs, cached results are reused unless address information changes. Cache is automatically cleared when you change the decline threshold or whitelist. Configurable expiration from 0-60 minutes.

CIDR Notation for IP Whitelisting — Unified IPv4/IPv6 whitelist field supports standard CIDR notation. Whitelist entire networks with entries like 192.168.1.0/24 or 2001:db8::/32.

Enhanced IP Detection — Automatically detects customer IPs behind CloudFlare, Akamai, nginx, and other services. Checks CF-Connecting-IP, True-Client-IP, X-Real-IP, and X-Forwarded-For headers.

Two Module Versions — System Extension for standard stores, plus a Component/Item version for custom one-page checkouts or heavily modified stores.

Three minFraud Service Levels — Choose Score (basic risk score), Insights (detailed risk factors), or Factors (complete analysis). Switch anytime based on your needs.

IPv6 compatibility — a top asked-for feature. Allows analysis of IPv6 incoming connections and IPv6 whitelisting.

Country Blocking — Configure blocked countries in your MaxMind account. Blocked countries automatically receive 100% risk scores.

How the Module Works

MaxMind's minFraud system analyzes over 80 fraud indicators for each transaction, including geographic distance between the customer's IP and billing address, high-risk IP analysis, open proxy detection, free/high-risk email identification, phone number verification, shipping remailer detection, and behavioral patterns. The result is a risk score from 0-100% indicating the probability that an order is fraudulent.

You set your thresholds for email notifications and automatic declines. The module handles everything else — protecting your business while legitimate customers check out normally.

This module will help stop credit card testing and fraudulent orders. It can save you money on authorization fees, improve your merchant decline ratio, refund ratio and chargebacks - and may qualify you for lower credit card fees.

The module sends merchants a fraud analysis email for each potential order or for only those exceed that exceed a preset risk score. The module will also block potential orders that exceed a preset risk score before they reach the payment gateway.


$179.95 $149.95 / year
Annual license • Free upgrades for registered v10.x module owners • For Miva v10.x and higher • Installation Support Available
v9.0 and v9.5 users - contact us for special upgrade pricing
Requires MaxMind minFraud account: ~$25 per 5,000 queries (less than ½¢ each)

Purchase or Renew License View Documentation

Download Latest Version  |  New to MaxMind? Get Free Trial with 1,000 queries

- copyright © 1998-2026 Wolfpaw Hosting LLC., all rights reserved -