Automation and Risk Score Overview
Understand how Blacklist Manager automation rules and risk scores work together before setting thresholds, actions, and reviews.
Use this article as an overview. It explains how the feature area fits together. Use the linked deep-dive articles when you need exact setup guidance for one rule or signal.
Automation and Risk Score are Premium features for reviewing suspicious WooCommerce orders after they are placed. They help you move from simple yes/no blocking to a safer review workflow: detect a pattern, decide how serious it is, then alert, add to suspects, add to blocklist, or score the order.
Important: Automation rules run after an order is placed. They are different from checkout blocking rules that stop a customer before the order is created.
What Automation Does
Automation checks new orders against patterns that often indicate risk. When a rule matches, the plugin can take one of four actions.
| Action | What happens | When to use it |
|---|---|---|
| Email alert | The site sends an admin email when the rule matches. | Best first choice when you are learning whether a rule fits your store. |
| Add to suspects | The customer details are added to the suspects list for review. | Use when the pattern is concerning but not enough to block automatically. |
| Add to blocklist | The customer details are added to the blocklist. | Use only for rules you trust. This can affect future checkout attempts. |
| Treat as score | The rule does not directly add the customer to a list. Instead, it contributes points to the order risk score. | Best for combining multiple weak signals into one clearer decision. |
What Risk Score Does
Risk Score gives each matching rule a small point value. When a new order is placed, the plugin adds the matching rule scores together and shows the result on the order. Depending on your thresholds, the order can be shown as safe, moderately risky, highly risky, or severe risky.
Risk Score is useful because one signal is not always enough. For example, a different shipping address may be normal. A first-time order may also be normal. But a first-time order with a different shipping address, device identity spread, several failed payment attempts, and a high-risk payment signal deserves more attention.
How Automation and Scoring Work Together
- You enable a rule in Settings > Automation.
- You choose the rule action.
- If you choose Treat as score, the matching score field becomes available in Settings > Scoring.
- You assign a score from 1 to 5 for that rule.
- When a new order matches the rule, the score is added to that order.
- The total score is compared with the thresholds you set.
If a rule is missing from the Scoring tab: go back to Settings > Automation, enable that rule, set its action to Treat as score, save, then return to Settings > Scoring.
Before You Start
- Confirm Blacklist Manager and Blacklist Manager Premium are active.
- Confirm the Premium license is active under YoOhw > Licenses or Settings > YoOhw Licenses.
- Confirm WooCommerce is active.
- Do not enable every rule at once. Start with a small set, review real orders, then expand.
- If your store is already receiving live orders, begin with Email alert, Add to suspects, or Treat as score. Avoid direct Add to blocklist until you trust the rule.
Recommended Setup Path
Use this path for most stores. It gives useful protection without creating too many false positives.
- Go to Blacklist Manager > Settings > Automation.
- Enable two or three rules that match your real problem.
- Set those rules to Treat as score or Add to suspects.
- Save Automation settings.
- Go to Settings > Scoring.
- Enable Enable order risk.
- Assign scores to the visible score rules.
- Save Scoring settings once to calculate the possible total score.
- Set risk score thresholds.
- Place test orders and review the order risk badge/metabox.

Automation Rules Explained
The available rules depend on your store setup and enabled integrations. The table below explains what each rule means and how to start safely.
| Rule | What it checks | Recommended first action | Suggested score |
|---|---|---|---|
| Phone/Email vs Address | The same phone or email appears with a different billing or shipping address than before. | Treat as score | 2-3 |
| Phone/Email vs IP | The same phone or email appears with a different IP address than before. | Treat as score | 1-2 |
| Device vs Email/Phone | The same device is used with a different email or phone. | Treat as score or Add to suspects | 3-4 |
| Device vs Address | The same device is used with a different address. | Treat as score | 2-3 |
| Device identity spread | One device is linked to too many emails, phones, or user accounts. | Treat as score or Add to suspects | 4-5 |
| Billing vs Shipping | The billing and shipping addresses are different. | Email alert or low score | 1 |
| Order value | The order total is much higher than your store average. | Email alert or Treat as score | 2-3 |
| Order attempts | The same customer identity places too many orders in a time window. | Treat as score or Add to suspects | 3-4 |
| Hosting IP | The order is placed from an IP that belongs to a cloud or data center provider. | Treat as score | 2-3 |
| Proxy, VPN or TOR | The customer appears to use a proxy, VPN, or TOR. | Treat as score | 2-3 |
| IP vs Country/Region | The IP country or region does not match the customer address. | Treat as score | 2-3 |
| IP vs Address | The IP coordinates are too far from the billing address coordinates. | Treat as score | 2-4 |
| Card vs Billing country | The payment card country does not match the billing country. | Treat as score or Add to suspects | 3-4 |
| AVS checks | Address Verification Service data from a supported gateway indicates a mismatch or failure. | Treat as score or Add to suspects | 3-5 |
| High risk country | The payment card or configured payment signal is from a country you marked as high risk. | Treat as score | 3-4 |
| PayPal payer vs Customer | The same PayPal payer email appears with different customer details. | Treat as score or Add to suspects | 3-5 |
Rules That Need Extra Setup
Some Automation rules need another setting or integration before they are useful.
- Device rules: enable Device identity in Settings > General.
- IP vs Address: configure Google Maps Geocoding under Settings > Integrations.
- Proxy/VPN, hosting IP, and location checks: configure the required IP/geolocation service if your setup uses one.
- Payment rules: enable Payment detection under Settings > Payments and use a supported payment plugin.
- High risk country: select high risk countries under Settings > Payments > Country settings.
Configure Automation Step By Step
- Open Blacklist Manager > Settings > Automation.
- Read the rule descriptions before enabling them.
- For each rule, check the enable box.
- If the rule has extra inputs, configure them. For example, set the order attempts count and time period, or set the device identity spread limits.
- Choose the action. For first setup, choose Treat as score for most rules.
- Use Add to suspects only for rules you are confident about.
- Avoid Add to blocklist until you have reviewed enough real matches.
- Save settings.
Configure Scoring Step By Step
- Open Blacklist Manager > Settings > Scoring.
- Enable Enable order risk.
- Assign each visible rule a score from 1 to 5.
- Use lower scores for weak signals and higher scores for strong signals.
- Save once to calculate the possible total score.
- Review the Possible total score section. The total can vary by payment gateway.
- Set thresholds for Moderately risky, Highly risky, and Severe risky.
- Save settings again.

Suggested Score Values
Use these as a starting point, then adjust after reviewing your real orders.
| Score | Meaning | Example |
|---|---|---|
| 1 | Weak signal. Useful only when combined with other signs. | First-time order, billing and shipping are different. |
| 2 | Low to medium concern. | Phone/email appears from a different IP, order value is unusually high. |
| 3 | Medium concern. | Address changes for the same email, proxy/VPN signal, IP country mismatch. |
| 4 | Strong concern. | Same device uses different identities, payment country mismatch. |
| 5 | Very strong concern. Usually deserves review immediately. | Device identity spread, AVS failure, repeated suspicious PayPal payer pattern. |
Suggested Thresholds
The Scoring tab shows a possible total score. Use that number to choose thresholds. A practical starting point is:
- Moderately risky: around 25-35% of the possible total score.
- Highly risky: around 50-65% of the possible total score.
- Severe risky: around 75-85% of the possible total score.
Example: if the highest possible total score is 20, you can start with Moderate = 6, High = 11, Severe = 16. If this produces too many false positives, increase the thresholds. If risky orders are still missed, lower them carefully.
What Happens When A Threshold Is Reached
- Safe order: the score is below your first threshold.
- Moderately risky: the score reaches the first threshold. This mainly helps visibility in order review.
- Highly risky: the score reaches the second threshold. The plugin can add the customer to suspects unless auto-actions are turned off.
- Severe risky: the score reaches the third threshold. The plugin can add the customer to the blocklist, and if Automation auto-cancel is enabled, the order can also be canceled.
Turn Off Auto-Actions If You Only Want Visibility
If you want to see risk scores but do not want the plugin to automatically add customers to suspects or blocklist, enable Turn off auto-actions in Settings > Scoring > Additional options.
This is recommended during the first few days of setup. It lets you review scores without changing customer status automatically.
Recommended First Configuration
For most stores, start with this conservative configuration:
- Enable Phone/Email vs Address and set action to Treat as score.
- Enable Phone/Email vs IP and set action to Treat as score.
- If Device identity is enabled, enable Device vs Email/Phone and set action to Treat as score.
- If you see many repeat attempts, enable Order attempts and set action to Treat as score.
- In Scoring, set values around 2, 2, 4, and 3 for those rules.
- Set thresholds conservatively and enable Turn off auto-actions for the first review period.
- After reviewing real orders, disable Turn off auto-actions only if you trust the thresholds.
How To Test
- Create or find a low-value test product.
- Place a first test order using normal details.
- Place a second test order that intentionally changes one field, such as address or IP if you can safely test it.
- Open the order in WooCommerce admin.
- Check the risk score column, risk score metabox, and order notes.
- Confirm the score matches the rule you expected.
- If the score is too high for a normal test order, reduce the rule score or raise thresholds.
How To Review Real Orders
- Sort or scan WooCommerce orders by risk score if the column is available.
- Open the order and review the risk score metabox.
- Look at which rules contributed to the score.
- Check whether the customer history supports the warning.
- If the order is legitimate, reduce the rule score or move that rule to Email alert/Add to suspects instead of scoring high.
- If the order is fraudulent, consider increasing that rule score or lowering thresholds.
Common Problems
| Problem | Likely cause | Fix |
|---|---|---|
| A score rule is missing. | The related Automation rule is not enabled or its action is not Treat as score. | Enable the rule in Automation, set action to Treat as score, save, then return to Scoring. |
| Possible total score is not calculated. | Scoring has not been saved after enabling score rules. | Save Scoring settings once, then set thresholds. |
| Payment score rules are missing. | Payment detection or the related payment rule is not enabled with score action. | Check Settings > Payments and Settings > Automation payment rules. |
| Too many normal orders are marked risky. | Scores are too high or thresholds are too low. | Lower weak rule scores, raise thresholds, or turn off auto-actions. |
| Risky orders are not being caught. | Relevant rules are not enabled, scores are too low, or thresholds are too high. | Enable more relevant rules, increase strong scores, or lower thresholds carefully. |
Best Practices
- Use direct Add to blocklist only for rules that are very reliable for your business.
- Use Treat as score for signals that are useful but not always fraudulent.
- Review at least several real orders before enabling automatic blocklist actions.
- Keep score values understandable. If everything is 5, the score is no longer useful.
- Document your threshold choices so another admin understands why they were selected.
- Revisit scoring after major business changes, such as new countries, new payment gateways, or new checkout flows.
Expected Result
After setup, each new order should show a clear risk level. Low-risk orders should remain easy to process, while suspicious orders should be easier to find, review, and act on without immediately blocking every customer who matches one weak signal.
Review Orders After Scoring Is Enabled
After you enable automation or risk scoring, use the WooCommerce order screens to review what the plugin detected.
- Use the Orders list risk score column to find orders that need attention.
- Open an order and review the Order risk score metabox to understand which checks added points.
- Use Blacklist actions on the edit order page when you want to add the customer to Suspects, block them, or remove an incorrect entry.
Automation Rule Deep Dives
If you need to configure a specific automation rule, use the focused guides instead of relying only on this overview.
Continue from Blacklist Manager Premium documentation to the complete product workflow.
Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.
Did this guide answer your question?
Still stuck?
Open a support request and include this article title, your plugin version, and what you already tried.
Open Support