SentinelGuard — Ecommerce & Checkout Protection Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
SentinelGuard focuses on the security issues that actually cost ecommerce stores money: card testing, checkout skimmers (Magecart), fake admin accounts, and unauthorized payment gateway changes.
While standard firewalls block basic network attacks, SentinelGuard looks at order patterns, checkout behavior, and payment flows to spot ecommerce abuse.
Note: SentinelGuard is an application-level ecommerce defense layer. It is built to complement network-level edge WAFs (such as Cloudflare) and payment gateway fraud tools (such as Stripe Radar), not replace them.
Recommended Deployment Lifecycle
- Observe (Days 1–14): Install and run in default Observe mode. SentinelGuard logs threat patterns, card testing signals, and scanner telemetry without modifying or blocking any buyer checkout attempts.
- Review: Inspect the findings timeline in your WordPress admin to understand your store’s normal checkout baselines.
- Protect: Switch to Protect mode for active soft-throttling on suspicious payment retries while keeping real shoppers safe.
Key Features
- Pre-Gateway Checks: Scans checkout requests before they hit your payment processor, helping you avoid gateway penalty fees.
- Smart Baselines: Compares incoming orders against your store’s normal 60-day averages instead of using strict, easily broken rules.
- Observe Mode: By default, it just logs suspicious activity without blocking real customers, so you can test it safely.
- Skimmer Detection: Scans your frontend JavaScript and database for payment field harvesting (
card,cvv), keyloggers, and malicious eval scripts. - Card Testing Defense: Tracks failed payments per IP and email to stop carding bots early.
- Gateway Credential Alarms: Alerts you immediately if someone changes your Stripe or PayPal payout keys.
- Stealth Admin Scanning: Checks the database directly to find hidden admin accounts that bypass the normal WordPress user list.
- Safe Quarantine: Suspicious files are safely isolated (base64 encoded) and can be restored with one click.
- HPOS Ready: Fully supports WooCommerce High-Performance Order Storage.
External Services Disclosure
This plugin uses third-party services to check for vulnerabilities and provide AI-assisted security summaries.
-
WordPress.org APIs (
api.wordpress.org):- Data sent: WP version, plugin/theme slugs & versions.
- When: During security scans to verify core checksums.
- Terms & Privacy: https://wordpress.org/about/privacy/
-
Patchstack Vulnerability Database (
api.patchstack.com— Optional):- Data sent: WP version, plugin/theme slugs.
- When: Only if you enter your Patchstack API key in Settings.
- Terms: https://patchstack.com/terms-and-conditions/
- Privacy: https://patchstack.com/privacy-policy/
-
WPScan Database (
wpscan.com— Optional):- Data sent: WP version, plugin/theme slugs.
- When: Only if you enter your WPScan API key in Settings.
- Terms: https://wpscan.com/terms/
- Privacy: https://automattic.com/privacy/
-
OpenAI API (
api.openai.com— Optional):- Data sent: Short, flagged code snippets (no user/store data).
- When: Only if you enter your OpenAI API key to get plain-English explanations of findings.
- Terms: https://openai.com/policies/terms-of-use/
- Privacy: https://openai.com/policies/privacy-policy/
-
Anthropic API (
api.anthropic.com— Optional):- Data sent: Short, flagged code snippets.
- When: Only if you enter your Anthropic API key.
- Terms: https://www.anthropic.com/legal/commercial-terms
- Privacy: https://www.anthropic.com/legal/privacy
-
Google Gemini API (
generativelanguage.googleapis.com— Optional):- Data sent: Short, flagged code snippets.
- When: Only if you enter your Google Gemini API key.
- Terms: https://ai.google.dev/gemini-api/terms
- Privacy: https://policies.google.com/privacy
-
Webhook Notifications (Optional):
- Data sent: Alerts (e.g., “Suspicious login detected”).
- When: Only if you configure a custom webhook URL (like Slack/Discord).
Screenshots
SentinelGuard Dashboard – Real-time active threats, findings table, detection engines, and manual scan triggers.
General Settings – Protection levels, site role configuration, data retention, and baseline WordPress hardening toggles.
Scanning & Intelligence – Automated scan schedule, scan depth, path exclusion rules, and vulnerability database API keys.
Threat Detection Engines – Real-time status cards for skimmer scanning, card testing defense, and admin account monitoring.

