The proprietary element here: every option below carries a plain “who this is not for” line, and the comparison counts the review-queue hours and the switching effort that vendor pages leave out.
A Shopify fraud prevention app looks like a simple purchase until you notice that four different products share the name. One scores orders. One scores and then pays you back when it is wrong. One fights chargebacks after the fact. One is a set of rules you maintain yourself. This article is for operators at $3M–$30M revenue on Shopify Plus or a paid subscription platform, where disputes have started to cost real money and someone on your team is spending real hours on order review. If you are below that floor, Shopify’s built-in tools plus a few rules are the sensible starting point, and the rest of this piece will over-serve you.
What does a Shopify fraud prevention app actually do?
A Shopify fraud prevention app receives an order, produces a decision (approve, hold, decline) and pushes that decision back to Shopify as a tag, a hold or a cancellation. That is all. Everything else, including machine-learning claims, device fingerprinting and network data, is how the decision is reached.
Two things separate the products. The first is liability: does the vendor reimburse you when an approved order turns out to be fraud? The second is authority: does the app cancel orders itself, or only advise? A scoring tool with no liability and no authority is a dashboard. A guaranteed-decision service with authority changes how your operations team works.
Fraud prevention also has a second, quieter cost: false declines. Every good customer blocked is revenue you never see in a chargeback report. Any tool you choose should tell you how it reports those, and if it cannot, you are measuring only half the problem. For the wider picture of how detection, rules and disputes fit together, read the sibling piece on ecommerce fraud prevention.
How should you compare the options?
Compare on cost model, liability, review load and exit cost, not on the accuracy percentage a vendor quotes. Accuracy claims are vendor-reported and depend on what the vendor counts as fraud, so they are not comparable between tools.
Pricing shapes differ, and this matters more than any rate card. Some tools charge nothing on top of Shopify, some charge a fee on each screened order, some take a percentage of approved order value, some charge only for disputes they win, and some quote privately. Current prices are not reproduced here because they change; each vendor publishes or quotes its own, and you should get them in writing.
| Option | Cost shape | Takes liability? | Review work left for you | Switching effort |
|---|---|---|---|---|
| Shopify built-in analysis and Shopify Protect | Included with the platform or eligible payment set-up; check Shopify’s documentation | Only where Shopify Protect applies to the order | High: you read and act on risk levels | Low |
| Guaranteed-decision service | Per approved order or percentage of value, often quoted | Yes, within contract terms | Low | High |
| Scoring and rules app | Subscription or per-order, published on the app listing | No | Medium to high | Medium |
| Payment-gateway screening | Bundled with or added to gateway fees | Rarely | Medium | High, because it ties to the gateway |
| Dispute-response automation | Often a share of recovered disputes | No, and it does not prevent orders | Low for disputes, unchanged for review | Low to medium |
| Enterprise machine-learning platform | Quote only | Often | Low | Very high |
Take from the table that liability and switching effort rise together. The tools that take your risk are the ones hardest to remove, because your order flow, your tags and your customer-service macros all end up shaped around them.
1. Shopify’s built-in fraud analysis and Shopify Protect
Shopify’s own analysis is the baseline every store already has. Each order gets a risk level on the order page, with the recommendation to review or, for higher risk, to think twice before fulfilling. It reads signals such as billing and shipping mismatch and IP location. For a fuller walkthrough of what those flags mean, see Shopify fraud analysis.
Shopify Protect is separate: it is a chargeback-protection programme for eligible orders, tied to particular payment methods and store set-up. Eligibility rules, exclusions and fees are Shopify’s to define, so read the current terms in your admin before you count on it.
Where it fits. Stores with a modest order count, low dispute volume and someone who reads the order page daily. It costs nothing to keep and it is the right thing to measure other tools against.
What it does not do. It does not act for you. A high-risk flag is advice, and unless you build a rule in Shopify Flow, the order proceeds to fulfilment while nobody looks. At volume, that is the failure: not a wrong verdict, but an unread one.
Who this is not for. Brands whose review is done by a single person who is also the founder, or teams that ship next-day, since a flag that waits for a human will lose to the pick list. It is also not for subscription brands where one fraudulent first order becomes a recurring problem before anyone notices.
2. Guaranteed-decision fraud services
These services take each order, return approve or decline, and reimburse you if an approved order charges back as fraud. Names in this space include Signifyd, Riskified and NoFraud; product scope and contract terms differ between them and change, so treat any list as a starting point for a shortlist, not an endorsement.
The commercial shape is a fee on each approved order or a percentage of its value, sometimes with a minimum. That fee is paid on all your good orders, which is exactly what you are insuring against the bad ones. Work it out before signing: your fraud loss rate against the fee applied to every approved order.
Where it fits. High-ticket or high-risk catalogues, brands that have been hit by card testing or organised fraud, and teams without anyone to run a review queue. Because the vendor is on the hook, its incentive to decline borderline orders is real, and you should watch that.
What it does not do. A guarantee covers what the contract says, usually fraud-coded disputes on orders the vendor approved. Non-fraud disputes, such as an item never arriving, are often excluded or treated differently. Policy abuse, such as a customer who receives the parcel and then claims otherwise, may also sit outside the cover. Ask for the reason-code list.
Who this is not for. Low-margin catalogues where a per-order fee eats the gross profit on a normal basket, brands with a rare dispute history that would be paying for cover they seldom claim on, and any team unwilling to hand the approve-or-decline authority to an outside system. It is also poor for stores whose customers frequently ship to freight forwarders, because a conservative vendor will decline legitimate orders.
3. Scoring and rules apps from the Shopify App Store
The crowded middle of the App Store is apps that add scores, IP and email checks, velocity limits, block lists and address verification, then tag or hold the order. They are cheaper than a guarantee and the pricing is public on the listing, usually a subscription tiered by order volume.
The decision logic is yours. You choose the threshold at which an order is held, and you own the false declines that threshold creates. That is a benefit for a team with a clear picture of its fraud and a cost for a team that does not have one. If you need a definition of what these tools do versus a full detection stack, ecommerce fraud detection software covers it.
Where it fits. Stores with a specific, repeating fraud pattern, such as one shipping-address cluster or mismatched email domains, and an operations person who tunes rules weekly.
What it does not do. It does not reimburse you. A missed fraudster is your loss in full, and the dispute fee is yours too. It also does not fix a bad threshold: set it too tight and you decline good customers quietly, with no chargeback record to show you what you lost.
Who this is not for. Teams without weekly time to review held orders and adjust rules. A rules app left alone for six months turns into a list of exceptions nobody can explain. It is also the wrong choice for brands that want fraud to become someone else’s problem.
4. Payment-gateway screening
If your store takes payments through a gateway that provides its own screening, that screening runs on the payment before Shopify sees an outcome. Its strength is the data: a gateway sees payment attempts across many merchants, which a Shopify app on its own cannot.
Whether a given gateway exposes screening on your plan, at what cost, and with what controls for you, differs by provider. Look at the gateway’s documentation and ask your account manager which rules you can edit. On Shopify, also confirm how the gateway’s decision reaches the order, because a payment that is declined is not an order that gets tagged.
Where it fits. Brands already on a non-Shopify gateway for reasons such as rates or multi-currency, who want screening without another vendor.
What it does not do. It generally screens the payment, not the whole order. Shipping-address risk, account history and post-purchase behaviour are often outside its view unless you connect them. It also gives you a decision, not a review workflow.
Who this is not for. Stores on Shopify Payments who have no gateway-level screening to switch on, and brands who might change gateway within a year. Screening logic tied to the processor is the hardest to carry with you when you leave.
5. Dispute-response automation
This category does not prevent an order from being fraudulent. It assembles evidence and files responses to chargebacks you have already received, sometimes on a share-of-recovery fee. Chargeflow is one example. What these vendors say about recovery rates is vendor-reported; treat it as a claim to test on your own disputes, not a benchmark.
The mechanics matter. A dispute has a deadline set by the card network and issuer, and the evidence that wins differs by reason code. Tools in this category pull order, shipping and customer-contact data into a packet. The result depends on what evidence you actually have: proof of delivery, signed receipts, customer communications. For the process behind that, see ecommerce chargebacks.
Where it fits. Brands that are already fighting disputes by hand and losing hours to it, or where the evidence exists but nobody has time to file it.
What it does not do. It leaves the fraud rate unchanged. The order was placed, the goods shipped, and this tool recovers what it can afterwards. It also cannot invent evidence. If your delivery confirmation is missing, so is the defence.
Who this is not for. Brands whose main issue is fraud volume rather than dispute handling, and brands whose disputes are mostly genuine service failures, where the fix is fulfilment, not paperwork. Card-network monitoring programmes react to dispute ratios, so a tool that wins some disputes afterwards may not protect you from the count itself; confirm with your acquirer how the ratio is measured.
6. Enterprise machine-learning platforms
At the top of the range sit platforms sold by quote to larger merchants, combining decisioning, account-takeover protection, policy-abuse rules and returns screening. Forter is one such vendor, and others exist. Pricing is not published, so the only route to a number is a sales process.
At $3M–$30M, most stores are on the lower edge of what these vendors court. That does not rule them out, particularly for a brand with international volume or a high-risk catalogue, but the sales cycle and integration work are heavier than for an app you install from the store.
Where it fits. Multi-market brands with several storefronts, meaningful account-takeover or promotion abuse, and a team with an engineer to own the integration.
What it does not do. It does not remove the need for your own operational rules. Someone still owns exceptions, VIP allow-lists and what happens to a held order at the weekend.
Who this is not for. Brands near the $3M floor with one storefront and a straightforward catalogue. The integration and contract length are a poor trade for a fraud problem that a rules app or a guarantee would contain.
What does a review queue cost you in hours?
Review time is the cost most comparisons leave out, and you can estimate it in ten minutes. Take the number of orders a tool would hold in a month, multiply by minutes per review, and convert to hours.
Here is an illustrative example, with hypothetical numbers. A store holds 1,000 orders a month for review and spends 2 minutes on each. That is 2,000 minutes, or about 33 hours, close to a full working week of one person’s attention each month. Halve the hold rate with a better-tuned rule and you free about 17 hours. Double the minutes per review because the order data is scattered across three tabs and the same tool costs you 67 hours.
Use your own figures, not these. The point is that a cheap rules app with a high hold rate can cost more in labour than a guarantee costs in fees. Put both on one line: monthly fee plus review hours at a loaded hourly cost, against fee-per-order on approved volume. If you do not know your hold rate, that is metric to confirm and the first number to pull from your order tags.
What breaks when you install one?
Three things go wrong at installation, and none of them are the app’s fault.
Two systems both decide. Shopify’s own risk flag, a Shopify Flow rule and the new app all try to hold or cancel the same order, and the customer receives a cancellation and a confirmation within the same hour. Give exactly one system the authority to cancel. Everything else tags and advises.
The verdict arrives after fulfilment. If a decision is returned by webhook and your 3PL pulls orders on a schedule, a “decline” can land after the parcel has left. Check how long undecided orders wait and set fulfilment to hold until a verdict is present. Your 3PL integration is often where this fails, so test it with a deliberately held test order.
Subscriptions and wallets go unscreened. Renewal orders created by a subscription app may skip screening, and some wallet payments carry different data. Ask each vendor which order sources and payment methods are covered, in writing. This gap is where a fraudster who passes the first order keeps billing.
How hard is it to switch fraud tools later?
Switching effort depends on how deeply the tool has been written into your operations. A rules app leaves tags and a few Shopify Flow rules behind. A guaranteed-decision service leaves tags, cancellation logic, customer-service macros and a contract with a notice period. A gateway-level tool leaves your payment set-up.
Before choosing, write down what you would need to export: the decision history, order IDs, dispute outcomes, allow-lists and any custom rules. Ask about retention and export format at signing. When you leave, pending disputes on orders the old vendor approved still belong to its guarantee, so agree in advance how long after termination that cover continues.
A practical safeguard is to run any new tool in observe-only mode for one dispute window, tagging verdicts without acting on them. Compare its verdicts with what actually charged back. It costs a few weeks and is the cheapest evidence you will get.
Which option should you pick?
Pick by the problem you can prove in your own data. If disputes are rare and the review queue is small, stay on Shopify’s built-in analysis and add Shopify Flow rules for the specific pattern you can see. If nobody has time to review orders, a guaranteed-decision service moves the work and the risk to the vendor, at a per-order price. If you have a narrow, repeating pattern and a person who tunes rules, a scoring app is enough.
If disputes are already arriving and evidence exists, add dispute automation regardless of which prevention tool you pick, because the two do different jobs. And if you sell in several markets with account-takeover or promotion abuse, the enterprise route deserves a sales call.
One opinion a vendor would not write: most brands at this size buy too much tool for the fraud they have, and too little process for the orders they hold. A named owner, a documented hold rule and a weekly look at declined good customers do more than an upgrade in tier.
For the broader field of tools beyond Shopify apps, the sibling article on ecommerce fraud detection software covers detection stacks in general.
Choosing and running a fraud app is a fraud and chargebacks problem: liability, review hours, dispute evidence and false declines all sit in one loop, and fixing one in isolation moves the cost to another. Pointerflow’s fraud and chargebacks service is built around that loop, from measuring your own hold and dispute data to setting a single decision authority and the evidence routine behind it.
Sources
- No external figures are quoted. The article is written from the long-standing structure of card disputes, Shopify’s documented fraud analysis and the pricing shapes vendors use; the review-time arithmetic is labelled illustrative and uses hypothetical numbers.