WebDecoy is now approved and publicly listed on the Shopify App Store. We built the app to connect suspicious storefront activity with the work merchants already do: inspect traffic, investigate repeat activity, and review orders before fulfillment.
Disclosure: I’m the founder of WebDecoy. This post was prepared with AI assistance and checked against our published Shopify implementation and capability documentation.
From a visit to an order review
An IP address alone is a poor reason to reject an order. A VPN is context, not proof of fraud. We combine browser behavior, server-derived request signals, IP enrichment, and interactions with hidden honeypot links and fields to make suspicious activity reviewable.
The integration has three distinct paths:
- Storefront: a Theme App Extension supplies the app embed. Enable WebDecoy Bot Detection in the theme editor and save; there is no script to paste into theme files.
- Checkout: a separate Web Pixel reports supported checkout-funnel events. The theme embed does not run inside Shopify-hosted checkout.
- Orders: the storefront writes a session reference into the cart. When an order is created, matching detections and available actor context can contribute to its risk evidence.
Keeping those paths separate matters. A successful storefront test does not prove that checkout-pixel events arrive, and an order without the relevant session data cannot acquire a reliable browsing history just because the app is installed.
What merchants can inspect
Detection details show scores and supporting signals. Actor profiles group related activity using available fingerprint and session evidence, helping investigate repeat visits across IPs. These are investigative groupings, not guarantees of one unique person.
Flagged Orders provides a review queue with status and notes. Supported plans add order tagging, native Shopify risk assessments with facts, and Shopify Flow triggers. The app also supplies order-risk metafields and an order-details extension.
AI Crawlers and AI Referrals are separate reports: catalog retrieval and a shopper arriving from an AI assistant are different events. Referrals depend on identifiable source information; missing referrers cannot be reconstructed.
Verify collection before enabling a response
After installation:
- Choose a plan through Shopify and enable the theme app embed.
- Open Setup & health, create a labeled storefront test, visit its link, and confirm that the detection arrived.
- Check checkout-pixel delivery separately, accounting for consent and browser conditions.
- Review detections and correlated orders before adding automation.
Test detections are excluded from traffic metrics, order review, and enforcement. Setup checks should not become fake threats in production reports.
Pro and Agency include Shopify Flow triggers. Our downloadable review and staff-notification templates start inactive when imported. Review the settings and enable them for new events when ready.
The order-created handler does not independently cancel orders or block checkout. Cancellation is a separate Flow action that a merchant must deliberately configure and enable.
What this can observe
A scraper that neither executes JavaScript nor touches a decoy can fetch public pages without appearing in storefront reports. This app does not deploy a WAF in front of Shopify-hosted checkout. We report the evidence our collection surfaces actually observe.
Try the Shopify app
The Free plan includes 500 detections per month. Starter is $59 USD/month, Pro $149, and Agency $449. Starter and Pro currently list 14-day trials; Shopify shows current pricing and trial availability before plan approval.
Watch the short demo and see the full setup guide. The demo uses a test store and seeded data, not customer results.
Install WebDecoy from the Shopify App Store.
What evidence would your team need before escalating an order for review?
Top comments (0)