All segments

Shopify Fraud Prevention App: How to Choose One

Choosing a Shopify fraud prevention app at $3M+ revenue: six options compared on cost model, fit and switching effort, each with who it is not for.

  • Published
  • Reading time 14 min read
  • Author Nafiul Hasan
Shopify Fraud Prevention App: How to Choose One. Diagram: what clears the floor. RECOVER Shopify Fraud Prevention App: Howto Choose One THE FLOOR pointerflow.com

Short answer

A Shopify fraud prevention app is chosen on three things: how it charges (per order, per decision or per chargeback), whether it takes liability for approved orders, and how hard it is to remove later. Six approaches exist, from Shopify's built-in analysis to guaranteed-decision services, and each fits a different order profile.

The proprietary element here: every option below carries a plain “who this is not for” line, and the comparison counts the review-queue hours and the switching effort that vendor pages leave out.

A Shopify fraud prevention app looks like a simple purchase until you notice that four different products share the name. One scores orders. One scores and then pays you back when it is wrong. One fights chargebacks after the fact. One is a set of rules you maintain yourself. This article is for operators at $3M–$30M revenue on Shopify Plus or a paid subscription platform, where disputes have started to cost real money and someone on your team is spending real hours on order review. If you are below that floor, Shopify’s built-in tools plus a few rules are the sensible starting point, and the rest of this piece will over-serve you.

What does a Shopify fraud prevention app actually do?

A Shopify fraud prevention app receives an order, produces a decision (approve, hold, decline) and pushes that decision back to Shopify as a tag, a hold or a cancellation. That is all. Everything else, including machine-learning claims, device fingerprinting and network data, is how the decision is reached.

Two things separate the products. The first is liability: does the vendor reimburse you when an approved order turns out to be fraud? The second is authority: does the app cancel orders itself, or only advise? A scoring tool with no liability and no authority is a dashboard. A guaranteed-decision service with authority changes how your operations team works.

Fraud prevention also has a second, quieter cost: false declines. Every good customer blocked is revenue you never see in a chargeback report. Any tool you choose should tell you how it reports those, and if it cannot, you are measuring only half the problem. For the wider picture of how detection, rules and disputes fit together, read the sibling piece on ecommerce fraud prevention.

How should you compare the options?

Compare on cost model, liability, review load and exit cost, not on the accuracy percentage a vendor quotes. Accuracy claims are vendor-reported and depend on what the vendor counts as fraud, so they are not comparable between tools.

Pricing shapes differ, and this matters more than any rate card. Some tools charge nothing on top of Shopify, some charge a fee on each screened order, some take a percentage of approved order value, some charge only for disputes they win, and some quote privately. Current prices are not reproduced here because they change; each vendor publishes or quotes its own, and you should get them in writing.

OptionCost shapeTakes liability?Review work left for youSwitching effort
Shopify built-in analysis and Shopify ProtectIncluded with the platform or eligible payment set-up; check Shopify’s documentationOnly where Shopify Protect applies to the orderHigh: you read and act on risk levelsLow
Guaranteed-decision servicePer approved order or percentage of value, often quotedYes, within contract termsLowHigh
Scoring and rules appSubscription or per-order, published on the app listingNoMedium to highMedium
Payment-gateway screeningBundled with or added to gateway feesRarelyMediumHigh, because it ties to the gateway
Dispute-response automationOften a share of recovered disputesNo, and it does not prevent ordersLow for disputes, unchanged for reviewLow to medium
Enterprise machine-learning platformQuote onlyOftenLowVery high

Take from the table that liability and switching effort rise together. The tools that take your risk are the ones hardest to remove, because your order flow, your tags and your customer-service macros all end up shaped around them.

1. Shopify’s built-in fraud analysis and Shopify Protect

Shopify’s own analysis is the baseline every store already has. Each order gets a risk level on the order page, with the recommendation to review or, for higher risk, to think twice before fulfilling. It reads signals such as billing and shipping mismatch and IP location. For a fuller walkthrough of what those flags mean, see Shopify fraud analysis.

Shopify Protect is separate: it is a chargeback-protection programme for eligible orders, tied to particular payment methods and store set-up. Eligibility rules, exclusions and fees are Shopify’s to define, so read the current terms in your admin before you count on it.

Where it fits. Stores with a modest order count, low dispute volume and someone who reads the order page daily. It costs nothing to keep and it is the right thing to measure other tools against.

What it does not do. It does not act for you. A high-risk flag is advice, and unless you build a rule in Shopify Flow, the order proceeds to fulfilment while nobody looks. At volume, that is the failure: not a wrong verdict, but an unread one.

Who this is not for. Brands whose review is done by a single person who is also the founder, or teams that ship next-day, since a flag that waits for a human will lose to the pick list. It is also not for subscription brands where one fraudulent first order becomes a recurring problem before anyone notices.

2. Guaranteed-decision fraud services

These services take each order, return approve or decline, and reimburse you if an approved order charges back as fraud. Names in this space include Signifyd, Riskified and NoFraud; product scope and contract terms differ between them and change, so treat any list as a starting point for a shortlist, not an endorsement.

The commercial shape is a fee on each approved order or a percentage of its value, sometimes with a minimum. That fee is paid on all your good orders, which is exactly what you are insuring against the bad ones. Work it out before signing: your fraud loss rate against the fee applied to every approved order.

Where it fits. High-ticket or high-risk catalogues, brands that have been hit by card testing or organised fraud, and teams without anyone to run a review queue. Because the vendor is on the hook, its incentive to decline borderline orders is real, and you should watch that.

What it does not do. A guarantee covers what the contract says, usually fraud-coded disputes on orders the vendor approved. Non-fraud disputes, such as an item never arriving, are often excluded or treated differently. Policy abuse, such as a customer who receives the parcel and then claims otherwise, may also sit outside the cover. Ask for the reason-code list.

Who this is not for. Low-margin catalogues where a per-order fee eats the gross profit on a normal basket, brands with a rare dispute history that would be paying for cover they seldom claim on, and any team unwilling to hand the approve-or-decline authority to an outside system. It is also poor for stores whose customers frequently ship to freight forwarders, because a conservative vendor will decline legitimate orders.

3. Scoring and rules apps from the Shopify App Store

The crowded middle of the App Store is apps that add scores, IP and email checks, velocity limits, block lists and address verification, then tag or hold the order. They are cheaper than a guarantee and the pricing is public on the listing, usually a subscription tiered by order volume.

The decision logic is yours. You choose the threshold at which an order is held, and you own the false declines that threshold creates. That is a benefit for a team with a clear picture of its fraud and a cost for a team that does not have one. If you need a definition of what these tools do versus a full detection stack, ecommerce fraud detection software covers it.

Where it fits. Stores with a specific, repeating fraud pattern, such as one shipping-address cluster or mismatched email domains, and an operations person who tunes rules weekly.

What it does not do. It does not reimburse you. A missed fraudster is your loss in full, and the dispute fee is yours too. It also does not fix a bad threshold: set it too tight and you decline good customers quietly, with no chargeback record to show you what you lost.

Who this is not for. Teams without weekly time to review held orders and adjust rules. A rules app left alone for six months turns into a list of exceptions nobody can explain. It is also the wrong choice for brands that want fraud to become someone else’s problem.

4. Payment-gateway screening

If your store takes payments through a gateway that provides its own screening, that screening runs on the payment before Shopify sees an outcome. Its strength is the data: a gateway sees payment attempts across many merchants, which a Shopify app on its own cannot.

Whether a given gateway exposes screening on your plan, at what cost, and with what controls for you, differs by provider. Look at the gateway’s documentation and ask your account manager which rules you can edit. On Shopify, also confirm how the gateway’s decision reaches the order, because a payment that is declined is not an order that gets tagged.

Where it fits. Brands already on a non-Shopify gateway for reasons such as rates or multi-currency, who want screening without another vendor.

What it does not do. It generally screens the payment, not the whole order. Shipping-address risk, account history and post-purchase behaviour are often outside its view unless you connect them. It also gives you a decision, not a review workflow.

Who this is not for. Stores on Shopify Payments who have no gateway-level screening to switch on, and brands who might change gateway within a year. Screening logic tied to the processor is the hardest to carry with you when you leave.

5. Dispute-response automation

This category does not prevent an order from being fraudulent. It assembles evidence and files responses to chargebacks you have already received, sometimes on a share-of-recovery fee. Chargeflow is one example. What these vendors say about recovery rates is vendor-reported; treat it as a claim to test on your own disputes, not a benchmark.

The mechanics matter. A dispute has a deadline set by the card network and issuer, and the evidence that wins differs by reason code. Tools in this category pull order, shipping and customer-contact data into a packet. The result depends on what evidence you actually have: proof of delivery, signed receipts, customer communications. For the process behind that, see ecommerce chargebacks.

Where it fits. Brands that are already fighting disputes by hand and losing hours to it, or where the evidence exists but nobody has time to file it.

What it does not do. It leaves the fraud rate unchanged. The order was placed, the goods shipped, and this tool recovers what it can afterwards. It also cannot invent evidence. If your delivery confirmation is missing, so is the defence.

Who this is not for. Brands whose main issue is fraud volume rather than dispute handling, and brands whose disputes are mostly genuine service failures, where the fix is fulfilment, not paperwork. Card-network monitoring programmes react to dispute ratios, so a tool that wins some disputes afterwards may not protect you from the count itself; confirm with your acquirer how the ratio is measured.

6. Enterprise machine-learning platforms

At the top of the range sit platforms sold by quote to larger merchants, combining decisioning, account-takeover protection, policy-abuse rules and returns screening. Forter is one such vendor, and others exist. Pricing is not published, so the only route to a number is a sales process.

At $3M–$30M, most stores are on the lower edge of what these vendors court. That does not rule them out, particularly for a brand with international volume or a high-risk catalogue, but the sales cycle and integration work are heavier than for an app you install from the store.

Where it fits. Multi-market brands with several storefronts, meaningful account-takeover or promotion abuse, and a team with an engineer to own the integration.

What it does not do. It does not remove the need for your own operational rules. Someone still owns exceptions, VIP allow-lists and what happens to a held order at the weekend.

Who this is not for. Brands near the $3M floor with one storefront and a straightforward catalogue. The integration and contract length are a poor trade for a fraud problem that a rules app or a guarantee would contain.

What does a review queue cost you in hours?

Review time is the cost most comparisons leave out, and you can estimate it in ten minutes. Take the number of orders a tool would hold in a month, multiply by minutes per review, and convert to hours.

Here is an illustrative example, with hypothetical numbers. A store holds 1,000 orders a month for review and spends 2 minutes on each. That is 2,000 minutes, or about 33 hours, close to a full working week of one person’s attention each month. Halve the hold rate with a better-tuned rule and you free about 17 hours. Double the minutes per review because the order data is scattered across three tabs and the same tool costs you 67 hours.

Use your own figures, not these. The point is that a cheap rules app with a high hold rate can cost more in labour than a guarantee costs in fees. Put both on one line: monthly fee plus review hours at a loaded hourly cost, against fee-per-order on approved volume. If you do not know your hold rate, that is metric to confirm and the first number to pull from your order tags.

What breaks when you install one?

Three things go wrong at installation, and none of them are the app’s fault.

Two systems both decide. Shopify’s own risk flag, a Shopify Flow rule and the new app all try to hold or cancel the same order, and the customer receives a cancellation and a confirmation within the same hour. Give exactly one system the authority to cancel. Everything else tags and advises.

The verdict arrives after fulfilment. If a decision is returned by webhook and your 3PL pulls orders on a schedule, a “decline” can land after the parcel has left. Check how long undecided orders wait and set fulfilment to hold until a verdict is present. Your 3PL integration is often where this fails, so test it with a deliberately held test order.

Subscriptions and wallets go unscreened. Renewal orders created by a subscription app may skip screening, and some wallet payments carry different data. Ask each vendor which order sources and payment methods are covered, in writing. This gap is where a fraudster who passes the first order keeps billing.

How hard is it to switch fraud tools later?

Switching effort depends on how deeply the tool has been written into your operations. A rules app leaves tags and a few Shopify Flow rules behind. A guaranteed-decision service leaves tags, cancellation logic, customer-service macros and a contract with a notice period. A gateway-level tool leaves your payment set-up.

Before choosing, write down what you would need to export: the decision history, order IDs, dispute outcomes, allow-lists and any custom rules. Ask about retention and export format at signing. When you leave, pending disputes on orders the old vendor approved still belong to its guarantee, so agree in advance how long after termination that cover continues.

A practical safeguard is to run any new tool in observe-only mode for one dispute window, tagging verdicts without acting on them. Compare its verdicts with what actually charged back. It costs a few weeks and is the cheapest evidence you will get.

Which option should you pick?

Pick by the problem you can prove in your own data. If disputes are rare and the review queue is small, stay on Shopify’s built-in analysis and add Shopify Flow rules for the specific pattern you can see. If nobody has time to review orders, a guaranteed-decision service moves the work and the risk to the vendor, at a per-order price. If you have a narrow, repeating pattern and a person who tunes rules, a scoring app is enough.

If disputes are already arriving and evidence exists, add dispute automation regardless of which prevention tool you pick, because the two do different jobs. And if you sell in several markets with account-takeover or promotion abuse, the enterprise route deserves a sales call.

One opinion a vendor would not write: most brands at this size buy too much tool for the fraud they have, and too little process for the orders they hold. A named owner, a documented hold rule and a weekly look at declined good customers do more than an upgrade in tier.

For the broader field of tools beyond Shopify apps, the sibling article on ecommerce fraud detection software covers detection stacks in general.

Choosing and running a fraud app is a fraud and chargebacks problem: liability, review hours, dispute evidence and false declines all sit in one loop, and fixing one in isolation moves the cost to another. Pointerflow’s fraud and chargebacks service is built around that loop, from measuring your own hold and dispute data to setting a single decision authority and the evidence routine behind it.

Sources

  • No external figures are quoted. The article is written from the long-standing structure of card disputes, Shopify’s documented fraud analysis and the pricing shapes vendors use; the review-time arithmetic is labelled illustrative and uses hypothetical numbers.

Frequently asked

Does a fraud app replace Shopify's built-in fraud analysis?

Usually it sits beside it. Shopify's analysis still runs on each order and still shows in the admin. A third-party app adds its own decision, which you can act on through order tags, holds or automatic cancellation. Decide which signal wins when the two disagree before you go live.

What is a chargeback guarantee and who pays if it fails?

A guarantee means the vendor reimburses the disputed order value on approved orders that later charge back as fraud. The contract defines which reason codes qualify, which orders are excluded and how fast you must submit. Read the exclusions first. Non-fraud disputes such as 'item not received' are often outside the cover.

Can I run two fraud apps at once?

You can, but two apps that both cancel or hold orders will fight. Run the second in observe-only mode, tag its verdicts, and compare them against real outcomes for a full dispute window before letting it act. Never give two tools authority to cancel the same order.

How long before I know the app is working?

Card disputes arrive weeks or months after the order, so a clean first fortnight proves little. Measure decline rate, review-queue size and false-decline complaints immediately, and judge chargebacks only after a full dispute window has passed for the orders the app screened.

Should I block by country or postcode instead of buying an app?

Blanket blocks are cheap and blunt. They stop some fraud and also stop real customers, gift buyers and travellers. Use them for a specific, evidenced pattern, such as one freight-forwarder address cluster, and expire the rule after a review date rather than letting it accumulate.

What does a fraud app do to checkout speed?

Most screening runs after the customer clicks pay, so the shopper rarely sees it. The cost appears elsewhere: a held order ships later. Ask the vendor how long undecided orders wait and whether the decision is synchronous or returned by webhook.

Do fraud apps work with Shop Pay and wallets?

Coverage varies by app and by payment method. Wallet payments can carry different data than a typed card, which changes what a tool can score. Ask each vendor, in writing, which payment methods are screened and which are passed through unscored.

How do I compare a percentage fee with a per-order fee?

Model it on your own order file. Take last month's orders, apply each fee shape to the approved ones, and add the cost of the manual reviews each tool leaves you. Compare total cost against the chargebacks and false declines you currently absorb. Vendor calculators use their own assumptions.

Is a fraud app worth it for a store with very few chargebacks?

Sometimes not. If disputes are rare, the built-in signals plus a few rules may cost less than any per-order fee. The app earns its place when review time, dispute fees or card-network monitoring thresholds start to bite. Count those three before you sign.

What should I export before I cancel a fraud vendor?

Export the decision history, order IDs, dispute outcomes and any custom rules or allow-lists. Without them, the next tool starts blind and you lose the evidence for pending disputes. Ask about data retention and export format at signing, when you still have leverage.

Next step

Is this your fraud & chargebacks problem, or a symptom of another one?

Bring your numbers — the churn split, the decline rate, whatever your flows are earning — and we will tell you which of them is the expensive one.

Book a call →