WordPress plugin

Bot & fraud protection for WordPress

A free plugin with a full admin panel. Identify every visitor and block bots and fraud on login, registration, comments and WooCommerce checkout — verified server-side, fail-open.

v1.1.0 · free plugin · WordPress 5.6+ · PHP 7.4+ · WooCommerce optional

What it protects

Your highest-risk forms, covered

Login

Stop credential stuffing and bot sign-ins before they reach wp-admin.

Registration

Block fake-account and multi-accounting signups at the door.

Comments & contact forms

Cut spam and comment floods with honeypot, timing and content analysis — including Cyrillic/CJK detection that catches Russian & Chinese spam bots.

WooCommerce checkout

Flag high-risk and bot orders before they’re placed.

Install

Live in three steps

1

Download & upload

Grab the ZIP below, then Plugins → Add New → Upload → Activate.

2

Add your keys

In the new Prynt menu, paste your API endpoint, public key and secret key.

3

Choose & protect

Pick which forms to protect, set Monitor or Block, and save. Done.

Use cases

What people use it for

Real ways WordPress and WooCommerce owners put Prynt to work.

WooCommerce & stores

Stop card-testing runs at checkout

Fraudsters use your checkout to test stolen card numbers, firing dozens of small orders in minutes. Your payment gateway racks up failed authorizations, fees pile up, and your account gets flagged as risky.

HowPrynt gives each visitor a stable device ID and reads bot/headless and datacenter/proxy signals server-side. When one device (or a bot) hammers checkout with rapid attempts, the verdict comes back high-risk and the submission is denied before it hits your payment processor.
SetupTurn on protection for WooCommerce Checkout and set it to Block at a risk score that catches bots and datacenter/proxy traffic. Because it fails open, a real shopper on a bad connection still gets through if the API is unreachable.
ResultCard-testing bursts are blocked at the door, so you pay fewer gateway fees on junk transactions and stay in good standing with your processor.

Cut chargebacks from fraudulent orders

Orders placed with stolen cards or by someone hiding their real location turn into chargebacks weeks later. You lose the product, the shipping, and often a chargeback fee on top.

HowPrynt flags checkout attempts coming through VPN, Tor, proxy, or datacenter connections and links devices that sit behind many different accounts, which are classic fraud patterns. The risky attempts are stopped, and every attempt is logged with its device ID so you have a record.
SetupProtect WooCommerce Checkout in Block mode. Start in Monitor for a week to see what your real traffic looks like, then switch high-risk verdicts to Block once you are comfortable with the score.
ResultFewer fraudulent orders ship out, which means fewer chargebacks, less lost inventory, and a healthier dispute ratio with your bank.

Shut down coupon and promo-code abuse

A single person spins up throwaway emails to claim a one-per-customer coupon or first-order discount over and over, draining a promo you meant for genuine new customers.

HowPrynt recognizes the same device across those different accounts and emails. When one device keeps coming back to redeem a new-customer offer, the device linking signal exposes it even though the email address is new each time.
SetupEnable protection on Registration and Checkout in Block mode, so repeat redemptions from the same flagged device are denied. Use Monitor first if you want to eyeball the repeat-device activity before enforcing.
ResultYour discounts actually reach new customers instead of being farmed by one repeat abuser, protecting your margins on every promotion.

Block fake signups created just to farm discounts

Bots and discount hunters mass-create accounts to grab welcome credits, loyalty points, or referral bonuses. Your customer list fills with fake accounts and your rewards budget gets spent on nobody.

HowPrynt detects bot and headless-browser signups at the registration form and identifies when many accounts trace back to one device. The fake registrations are stopped before they ever get a reward balance.
SetupTurn on Registration protection in Block mode with bot detection catching automated signups, and lean on the device-linking signal to catch one person creating many accounts.
ResultA cleaner customer list, a rewards budget spent on real people, and referral or welcome programs that are not quietly bleeding money.

Keep scalper bots off limited drops

On a limited release or restock, resale bots grab all the inventory in seconds, checking out faster than any human. Real fans get shut out and end up seeing your product on resale sites minutes later.

HowPrynt identifies automated and headless traffic and flags datacenter and residential-proxy connections that bots hide behind. Bot checkouts are denied, so stock stays available for shoppers who are actually on a normal browser and connection.
SetupProtect WooCommerce Checkout in Block mode before the drop, tuned to reject bot and datacenter/proxy verdicts. Because it is fail-open, a legitimate rush of real buyers still gets through even under heavy load.
ResultMore of your limited stock reaches real customers instead of scalpers, which protects both your revenue and your reputation with loyal buyers.

Membership & community

Stop credential-stuffing on your member login

Someone is hammering your login page with lists of stolen email-and-password combos, trying to break into your members' accounts. Real members get locked out, and you get support tickets and password-reset floods.

HowPrynt gives every visitor a stable device ID and reads bot, headless-browser, and datacenter/proxy signals at the login form. A script running thousands of attempts from automated tools and rotating proxies looks nothing like a real member on a real phone or laptop, so those attempts get flagged and denied server-side where the browser can't fake the result.
SetupProtect the LOGIN form. Start in Monitor to watch a day of traffic, then switch to Block with the risk score set so bot and datacenter/proxy hits are denied.
ResultAutomated login attacks are turned away at the door, real members sign in normally, and your reset-password and lockout tickets drop.

Keep fake registrations out of your community

Your free sign-up form fills up with junk accounts created by bots. They pollute your member list, skew your numbers, and are often the first step before spam or scams hit your forum.

HowAt the registration form, Prynt checks whether the visitor is a headless bot or coming through a VPN/Tor/datacenter connection typical of mass sign-up scripts. Because the verdict is verified server-side with your secret key, a bot can't spoof a 'looks human' answer to sneak through.
SetupProtect the REGISTRATION form in Block mode, denying high-risk and bot sign-ups. Keep the threshold moderate so a member on a normal VPN isn't caught unfairly.
ResultYour member roster stays real, your welcome emails go to actual people, and you spend far less time deleting fake accounts.

Shut down comment and forum spam floods

Bots blast your blog comments and forum threads with links, ads, and scams faster than you can moderate. Your moderation queue is buried and genuine discussion gets drowned out.

HowPrynt evaluates each comment submission for bot and headless-browser signals and for proxy/datacenter origins that spam runs behind. The device ID also reveals when one device is firing off comments under many names, a classic spam pattern.
SetupProtect the COMMENTS form. Run Block mode so bot-driven submissions are refused, while normal readers posting a comment sail through.
ResultThe spam flood stops before it reaches your queue, moderation becomes manageable, and real conversation stays front and center.

Catch paid-membership account sharing

One paid membership gets passed around a whole group, or the login is sold and used by dozens of people. You lose the subscription revenue those extra users should be paying.

HowPrynt's device linking shows when a single account is being accessed from many different devices, and when one device is logging into many accounts. That pattern is hard to see in normal WordPress logs but stands out clearly with a stable device ID per visitor.
SetupProtect the LOGIN form in Monitor mode and review the device-linking signals to see which memberships are shared across an unusual number of devices before you act.
ResultYou can spot the accounts being shared or resold and follow up, recovering revenue instead of quietly leaking it.

Stop free-trial and coupon abuse from multi-accounting

The same person keeps making new accounts to grab your free trial, first-month discount, or new-member coupon over and over, so a perk meant to attract real customers just gets farmed.

HowEven when someone uses fresh emails, Prynt recognizes the same underlying device and flags when one device is behind many accounts. It also spots trial farmers hiding behind VPNs, Tor, or residential proxies to look like different people in different places.
SetupProtect the REGISTRATION form (and WooCommerce CHECKOUT if trials run through checkout). Use device linking to flag repeat sign-ups from one device, and Block high-risk proxy sign-ups.
ResultTrials and discounts reach genuine new members instead of serial abusers, and your promo budget actually drives real growth.

Small business & agencies

Stop the contact-form and lead spam flooding your inbox

Every day your "Contact Us" and quote-request forms fill up with junk submissions from bots, and the real leads get buried under fake ones you have to sort through by hand.

HowPrynt gives each visitor a stable device ID and checks their submission for bot and headless-browser signals server-side, so a script pretending to be a person gets caught before the message ever reaches you. Because the verdict is verified with your secret key, the bot can't fake a "looks human" result.
SetupProtect the comments/registration and contact submission path. Start in Monitor mode for a week to watch what gets flagged, then switch to Block so high-risk and bot submissions are denied automatically.
ResultYour inbox holds real inquiries again, and you stop wasting time deleting spam or chasing dead leads.

Shut down brute-force login attempts on wp-admin

Bots hammer your WordPress login page around the clock, guessing passwords over and over. It slows the site down and it only takes one weak password to let them in.

HowPrynt inspects each login attempt for bot behavior and risky origins like VPN, Tor, proxy, and datacenter traffic. Automated password-guessing runs almost always come from these sources, so Prynt can turn them away at the door while a normal customer logging in from home sails through.
SetupTurn on protection for the LOGIN form and use Block mode at a risk score you're comfortable with. Fail-open means that if the API is ever unreachable, real users are never locked out.
ResultAutomated login floods are denied before they can guess anything, and legitimate logins keep working without extra steps for your users.

Get analytics you can actually trust

Your visitor numbers look busy, but a big chunk is bot traffic. Bounce rates, conversion rates, and "which page is popular" are all skewed, so you can't tell what's really working.

HowBecause Prynt identifies each visitor with a stable device ID and flags bots, headless browsers, and datacenter traffic, you can see how much of your activity is automated rather than human — instead of treating every hit as a real person.
SetupRun Prynt in Monitor mode so nothing is blocked; it simply logs a verdict for each visitor and form submission. Review the flagged traffic in the admin panel to see how much of your "audience" was never human.
ResultYou finally know how many real people visit and convert, so decisions about pages, ads, and offers are based on genuine humans, not bots.

Protect every client site from one dashboard

As an agency you manage a dozen or more WordPress sites, and each one is a separate target for spam and bot attacks. Setting up and checking protection site-by-site eats hours you don't have.

HowInstall the same free Prynt plugin on each client site and point them all at one Prynt API — your own self-hosted server or the managed cloud. Every site uses the same secret-key-verified checks and the same signals, so you get consistent bot, VPN/proxy, and device-linking protection everywhere.
SetupDeploy the plugin across client sites with a shared API key, protect login, registration, comments, and WooCommerce checkout on each, and standardize on Monitor-then-Block as your rollout playbook per client.
ResultEvery client gets the same solid protection, you configure it the same way each time, and you have one consistent place to reason about what's being blocked.

Simple "install and forget" fraud reduction

You run the business, not the website's security. You want spam and fake signups to drop without becoming a full-time job or needing a developer on call.

HowPrynt is a free plugin with the admin panel built in. It catches bot signups, fake registrations, and risky checkout attempts using server-verified signals, and its fail-open design means a real customer is never accidentally locked out if something goes wrong.
SetupProtect registration and WooCommerce checkout, leave it in Monitor for a short while to build confidence, then flip to Block. After that, there's nothing to babysit — you only glance at the panel when you're curious.
ResultFake signups and fraudulent orders drop off, you set it once, and it quietly keeps working in the background.

How it works

The browser agent identifies each visitor and attaches a request ID to the protected form. On submit, your WordPress server verifies the verdict with your secret key — so the browser can’t forge a “safe” result — and blocks bots or high-risk submissions according to your settings. If the API is ever unreachable, verification fails open: a legitimate user is never locked out.

Try it with the demo keys

Want to see it work before wiring your own keys? Point it at the public demo:

Endpoint:    https://api.pryntid.com
Public key:  pk_test_demopublickey0000000001
Secret key:  sk_test_demosecretkey0000000001

Leave it on Monitor first — every login/registration shows up under Recent activity in the panel. Flip to Block when you’re ready. Create your own keys in the Prynt console.

Related

All SDKs · Bot detection · Form spam protection · Ecommerce fraud · Docs