Bot & fraud protection for WordPress
A free plugin with a full admin panel. Identify every visitor and block bots and fraud on login, registration, comments and WooCommerce checkout — verified server-side, fail-open.
Your highest-risk forms, covered
Login
Stop credential stuffing and bot sign-ins before they reach wp-admin.
Registration
Block fake-account and multi-accounting signups at the door.
Comments & contact forms
Cut spam and comment floods with honeypot, timing and content analysis — including Cyrillic/CJK detection that catches Russian & Chinese spam bots.
WooCommerce checkout
Flag high-risk and bot orders before they’re placed.
Live in three steps
Download & upload
Grab the ZIP below, then Plugins → Add New → Upload → Activate.
Add your keys
In the new Prynt menu, paste your API endpoint, public key and secret key.
Choose & protect
Pick which forms to protect, set Monitor or Block, and save. Done.
What people use it for
Real ways WordPress and WooCommerce owners put Prynt to work.
WooCommerce & stores
Stop card-testing runs at checkout
Fraudsters use your checkout to test stolen card numbers, firing dozens of small orders in minutes. Your payment gateway racks up failed authorizations, fees pile up, and your account gets flagged as risky.
Cut chargebacks from fraudulent orders
Orders placed with stolen cards or by someone hiding their real location turn into chargebacks weeks later. You lose the product, the shipping, and often a chargeback fee on top.
Shut down coupon and promo-code abuse
A single person spins up throwaway emails to claim a one-per-customer coupon or first-order discount over and over, draining a promo you meant for genuine new customers.
Block fake signups created just to farm discounts
Bots and discount hunters mass-create accounts to grab welcome credits, loyalty points, or referral bonuses. Your customer list fills with fake accounts and your rewards budget gets spent on nobody.
Keep scalper bots off limited drops
On a limited release or restock, resale bots grab all the inventory in seconds, checking out faster than any human. Real fans get shut out and end up seeing your product on resale sites minutes later.
Membership & community
Stop credential-stuffing on your member login
Someone is hammering your login page with lists of stolen email-and-password combos, trying to break into your members' accounts. Real members get locked out, and you get support tickets and password-reset floods.
Keep fake registrations out of your community
Your free sign-up form fills up with junk accounts created by bots. They pollute your member list, skew your numbers, and are often the first step before spam or scams hit your forum.
Shut down comment and forum spam floods
Bots blast your blog comments and forum threads with links, ads, and scams faster than you can moderate. Your moderation queue is buried and genuine discussion gets drowned out.
Catch paid-membership account sharing
One paid membership gets passed around a whole group, or the login is sold and used by dozens of people. You lose the subscription revenue those extra users should be paying.
Stop free-trial and coupon abuse from multi-accounting
The same person keeps making new accounts to grab your free trial, first-month discount, or new-member coupon over and over, so a perk meant to attract real customers just gets farmed.
Small business & agencies
Stop the contact-form and lead spam flooding your inbox
Every day your "Contact Us" and quote-request forms fill up with junk submissions from bots, and the real leads get buried under fake ones you have to sort through by hand.
Shut down brute-force login attempts on wp-admin
Bots hammer your WordPress login page around the clock, guessing passwords over and over. It slows the site down and it only takes one weak password to let them in.
Get analytics you can actually trust
Your visitor numbers look busy, but a big chunk is bot traffic. Bounce rates, conversion rates, and "which page is popular" are all skewed, so you can't tell what's really working.
Protect every client site from one dashboard
As an agency you manage a dozen or more WordPress sites, and each one is a separate target for spam and bot attacks. Setting up and checking protection site-by-site eats hours you don't have.
Simple "install and forget" fraud reduction
You run the business, not the website's security. You want spam and fake signups to drop without becoming a full-time job or needing a developer on call.
How it works
The browser agent identifies each visitor and attaches a request ID to the protected form. On submit, your WordPress server verifies the verdict with your secret key — so the browser can’t forge a “safe” result — and blocks bots or high-risk submissions according to your settings. If the API is ever unreachable, verification fails open: a legitimate user is never locked out.
Try it with the demo keys
Want to see it work before wiring your own keys? Point it at the public demo:
Endpoint: https://api.pryntid.com Public key: pk_test_demopublickey0000000001 Secret key: sk_test_demosecretkey0000000001
Leave it on Monitor first — every login/registration shows up under Recent activity in the panel. Flip to Block when you’re ready. Create your own keys in the Prynt console.
Related
All SDKs · Bot detection · Form spam protection · Ecommerce fraud · Docs