# WooCommerce Integration

FindIP Shield for WooCommerce adds privacy-conscious visitor risk signals to
a WooCommerce storefront: VPN, proxy, Tor, relay, hosting, datacenter,
malicious-IP, and network-service flags plus a risk score for every session —
without collecting customer, cart, order, or payment data.

## Install

1. Install and activate the **FindIP Shield for WooCommerce** plugin
   (WooCommerce is required; the standalone FindIP Shield WordPress plugin
   must be deactivated first — the two must not run together).
2. In the FindIP dashboard, create a Shield site whose domain matches your
   storefront hostname.
3. In WordPress admin, open **WooCommerce → FindIP Shield**, paste the public
   site key (`pub_…`), and save.
4. Load a storefront page and confirm the first event on your site's Install
   page in the FindIP dashboard.

The plugin pins an exact, immutable Shield SDK build from
`cdn.findip.net` with subresource integrity, so the browser refuses to run a
script that does not match the recorded hash.

## What it tracks

Standard SDK events (`session_start`, `page_view`, automatic form events)
plus WooCommerce storefront signals, each individually toggleable in the
settings page:

| Signal | Event |
|---|---|
| Product page view | `custom` with `event_type: product_view` |
| Cart page view | `custom` with `event_type: cart_view` |
| Item added / removed (classic and Blocks) | `custom` with `event_type: cart_updated` and `action` |
| Checkout page view | `custom` with `event_type: checkout_view` |
| Checkout error / payment failure | `payment_failed` |
| Order received page | `custom` with `event_type: order_received` |

All events carry `integration: woocommerce`. Only coarse page-type context is
sent — never product identifiers, prices, customer fields, or payment data.

## Privacy and consent

- Privacy modes: strict (default), balanced, advanced — identical to the
  Shield SDK modes.
- Consent-aware initialization: with **require consent** enabled, the plugin
  starts in the configured pre-consent behavior (`strict` or `disabled`)
  until your consent tool dispatches a `findip:consent` event.
- Compatible with High-Performance Order Storage (HPOS) and Cart/Checkout
  Blocks; telemetry failures never affect storefront behavior.

## Server-side verification

Risk responses in the browser are informational. For decisions that matter
(order review, fraud holds), verify the session server-side with your secret
key — see the Server Verification page.

---

Canonical page: https://www.findip.net/docs/shield/woocommerce · Markdown: https://www.findip.net/docs/shield/woocommerce.md · All Shield docs in one file: https://www.findip.net/llms-full.txt
