Customer Blocklist for WooCommerce
Block customers by email, domain, phone, address, IP address or account. Refused at classic and block checkout and on PayPal express buttons.

What it does
Some customers you do not want to serve again. PluginCity Customer Blocklist for WooCommerce lets you block an email address, a whole email domain, a phone number, a postal address, an IP address or a customer account, and refuses their order at the classic checkout, at the Checkout block, and on PayPal's express buttons. The pay page for an existing order is refused too.
You write the message they see. Add a customer to the blocklist from their order with one click, and keep a log of blocked attempts for as many days as you choose, up to a year. It turns away repeat problem customers. It does not detect fraud for you.
A blocklist entry can be an email address, a whole email domain, a wildcard pattern such as bot-*@example.com, a phone number, a postal address, an IP address, a range of IP addresses or a customer account. A domain such as mailinator.com can be blocked. A mail service used by millions, such as gmail.com, cannot, because that would turn away far more than one customer: block that customer's address instead.
The list is matched the way a person would match it, not the way a computer compares text. Dots and plus tags in a Gmail address, capital letters, stray spaces, hidden characters, brackets in a phone number and "St." for "Street" all come out the same, so the easy ways round a list do not work. A genuinely different address is still a different address, so block the phone number, the postal address or the IP address as well to catch someone who changes one detail.
A blocked customer is refused at the classic checkout and at the Checkout block, whether they are a guest or signed in, and on the pay page for an order that already exists. Where a payment method builds its order through WooCommerce's checkout or the Store API, it is refused there like any other. PayPal's express buttons are refused when pressed by someone the shop already knows, such as a signed-in customer. For a guest the shop learns who is paying only when PayPal says so, and the order is refused then, before any payment is taken. Any other code that builds an order for a customer is stopped before a payment can be taken, and the order is removed. Orders you or your staff create in wp-admin, through the REST API with a staff key or from the command line are never blocked.
The customer reads one neutral sentence that you write, the same whichever detail matched. It never says which detail matched, so it never tells anyone which of their details to change. Blocked email addresses and IP addresses can also be stopped from registering an account, and you can add a customer to the blocklist from their order with one click. Blocked attempts are logged, and the log is deleted after the number of days you choose. The whole blocklist can be imported and exported as a CSV file.
An IP address can be shared by a whole office or a mobile network, so it starts unticked when you add from an order. Whether it sees the right address depends on how your shop reads IP addresses: behind a proxy or content delivery network, leave IP reading on WooCommerce's setting, and on a shop with neither, choose the connection only, because the other setting trusts headers a visitor can write.
A blocklist is personal data: it holds email addresses, phone numbers, postal addresses and IP addresses of named people. It stays on your own website and is sent nowhere. The plugin adds wording for your privacy policy and joins the WordPress export and erasure tools. Erasing someone removes them from the log and leaves their blocklist entry, which you may be entitled to keep to protect your shop, and which you can remove yourself.
Pro lets a match do less than refuse. For each kind of entry you choose whether to turn the customer away, hold the order for review, or let it through with a note. A held order is put On hold with a note saying why, and stays on hold, whatever a payment gateway does afterwards, until you release it from the order screen or from the Held orders list with one click. The customer is let through to pay, so payment is taken or not as your gateway decides, so if you would rather not take the money at all, leave that kind of entry on turn them away. On hold is the only status offered. Awaiting payment is not, because a gateway would still take the money.
Pro can also score customers on risk. You give each sign of trouble a number of points (refunded and cancelled orders, chargebacks you record, failed payments, disposable email addresses, billing and shipping in different countries, and large orders) and set three lines: the points at which an order is flagged, held, or the customer is turned away. A sign worth nought is not looked for. Counts come from the customer's earlier orders with the same email address or account. These are points you set yourself and nothing is asked of any outside service, and the list of disposable email domains ships with the plugin. WooCommerce has no chargeback status of its own, so a chargeback is an order you mark with Record a chargeback, and nothing is guessed from a gateway's notes. Risk scoring and automatic blocking both start switched off.
Automatic blocking adds a customer to the blocklist after a full refund, a recorded chargeback or too many cancellations. If you use Order Cancellation for WooCommerce, it can count only the cancellations made through that plugin. If you do not, it counts every cancelled order except unpaid orders that WooCommerce cancelled on its own clock. It does not need Order Cancellation.
A block can end by itself. Choose how long when you add an entry, or set a number of days for automatic blocks, and the entry stops counting the moment its time is up. Each entry can carry a reason. An audit log records every addition, removal, hold and release and who did it, and the shop manager can be emailed about them. Entries can be imported, listed and removed over the REST API, up to 500 entries in a request, and a CSV file can be imported with WP-CLI. Pro's own settings travel with the settings export.
If a Pro licence lapses, nothing is deleted and nothing breaks. Pro's settings, reasons and audit log stay saved and on screen, where you can read them but not change them, and anyone on the blocklist goes back to being turned away. Orders already on hold stay on hold until you release them, and you can release them while the licence is lapsed. Temporary blocks stop ending by themselves, so an entry set to expire stays on the list until you remove it. Renewing switches it all back on exactly as you left it.
See it in action
What the plugin does
- Block email addresses, whole email domains and wildcard patterns such as bot-*@example.com
- Block phone numbers, postal addresses, IP addresses and IP ranges, and customer accounts
- Gmail dots, plus tags, capital letters and spacing are read as the same address
- Refused at the classic checkout and at the Checkout block, for guests and signed-in customers
- PayPal's express buttons refused (at the press when the shop already knows who is buying, otherwise before any payment is taken), and any wallet button that builds its order through WooCommerce
- The pay page for an existing order is refused too
- Blocked email addresses and IP addresses can be stopped from registering an account
- Add a customer to the blocklist from their order, with one click
- A message you write yourself, the same whichever detail matched
- A log of blocked attempts, kept for the number of days you choose
- Blocklist import and export as a CSV file
- Settings import and export
- WordPress personal data export and erasure tools
- High-Performance Order Storage and block checkout compatible
- Any other code that builds an order for a customer is stopped before a payment can be taken, and the order is removed
- Orders you or your staff create in wp-admin, through the REST API with a staff key or from the command line are never blocked
- Erasing a person removes them from the log and leaves their blocklist entry, which you can remove yourself
- Hold an order for review, or flag it with a note, instead of refusing it, for each kind of entry you choose
- Release a held order from the order screen or the Held orders list with one click
- Risk scoring from refunded and cancelled orders, chargebacks you record, failed payments, disposable email addresses, billing and shipping in different countries and large orders, with the points and the flag, hold and refuse lines set by you
- Automatic blocking after a full refund, a recorded chargeback or too many cancellations, which counts cancellations made through Order Cancellation for WooCommerce if you use it and does not need it
- Temporary blocks that end by themselves, with a reason on each entry
- An audit log of every addition, removal, hold and release, and who did it
- Email alerts to the shop manager
- Import, list and remove entries over the REST API (up to 500 entries per request), and import a file with WP-CLI
- Pro's own settings travel with the settings export
- A lapsed licence deletes nothing: Pro's settings stay on screen to read but cannot be changed, blocked customers are still turned away, held orders stay held until you release them (which still works), and temporary blocks stop ending by themselves
Pricing
Every Pro plan is the same plugin with every feature. The only difference is how many sites you can run it on.
Single site
One site, with a year of updates and support.
$49/year
Secure checkout. Cancel any time.
5 sites
Most popularUp to 5 sites, with a year of updates and support.
$99/year
Secure checkout. Cancel any time.
25 sites
Up to 25 sites, with a year of updates and support.
$199/year
Secure checkout. Cancel any time.
Need more than 25 sites? Get in touch about a custom licence.
Frequently asked questions
Does it work with the Checkout block?
Yes. The block checkout is refused through WooCommerce's Store API, with your message shown in the checkout's own error banner.
Where is a blocked customer refused?
At the classic checkout and at the Checkout block, for guests and signed-in customers. On the pay page for an existing order. Wherever a payment method builds its order through WooCommerce's checkout or the Store API. At a PayPal express button when it is pressed by someone the shop already knows, such as a signed-in customer.
What about PayPal's express buttons and other ways of paying?
PayPal's express buttons are refused when pressed by someone the shop already knows, such as a signed-in customer. For a guest the shop learns who is paying only when PayPal says so, and the order is refused then, before any payment is taken. Any other code that builds an order for a customer is stopped before a payment can be taken, and the order is removed.
Can someone get round it by changing an email address?
Not by changing capitals, dots in a Gmail address, a plus tag or spacing. A genuinely different address is a different address. Block the phone number, the postal address or the IP address as well to catch someone who changes one detail.
Can it block a whole domain?
Yes, for a domain such as mailinator.com. It will not let you block a mail service used by millions, such as gmail.com, because that would turn away far more than one customer. Block their address instead.
Is an IP address a safe thing to block?
An address can be shared by a whole office or a mobile network, so it starts unticked when you add from an order. Whether it sees the right address depends on how your shop reads IP addresses. Behind a proxy or content delivery network, leave IP reading on WooCommerce's setting, and on a shop with neither, choose the connection only, because the other setting trusts headers a visitor can write.
What about orders I create myself?
They are never blocked. Staff placing an order in wp-admin, through the REST API with a staff key or from the command line are the shop's own decision.
Is a blocklist personal data?
Yes. It holds email addresses, phone numbers, postal addresses and IP addresses of named people. It stays on your own website and is sent nowhere. The plugin adds wording for your privacy policy and joins the WordPress export and erasure tools. Erasing someone removes them from the log and leaves their blocklist entry, which you may be entitled to keep to protect your shop, and which you can remove yourself.
What does hold for review do?
In Pro. The customer is let through to pay, and the order is put on hold with a note saying why. It stays on hold, whatever a payment gateway does afterwards, until you release it. Payment is taken or not as your gateway decides, so if you would rather not take the money at all, leave that kind of entry on turn them away. Changing the status yourself in wp-admin also ends the hold. An order is never held without a reason on it.
Can an order be set to awaiting payment instead of on hold?
No. Awaiting payment means a gateway would still take the money. On hold is the status that means do not do anything with this yet, and it is the only one offered.
How does risk scoring work?
In Pro. You give each sign of trouble a number of points, and three lines: the points at which an order is flagged, held, or the customer is turned away. A sign worth nought is not looked for. Counts come from the customer's earlier orders with the same email address or account. Nothing is asked of any outside service, and the list of disposable email domains ships with the plugin and can be changed with a filter.
What counts as a chargeback?
An order you mark with Record a chargeback in the order actions, or one your own code marks by calling the cblwc_pro_record_chargeback action with the order id. WooCommerce has no chargeback status of its own, so nothing is guessed from a gateway's notes.
Do I need Order Cancellation for WooCommerce?
No. If you use it, automatic blocking can count only the cancellations made through it. If you do not, choose to count every cancelled order, except unpaid orders that WooCommerce cancelled on its own clock.
Can a block end by itself?
In Pro. Choose how long when you add an entry, or set a number of days for automatic blocks. The entry stops counting the moment its time is up and is removed within the hour.
Can I add entries from another system?
In Pro. The REST API at /wp-json/cblwc/v1/entries takes up to 500 entries at a time, and wp cblwc import file.csv reads a CSV file. Both need a signed-in user who may manage WooCommerce.
Does it work with High-Performance Order Storage?
Yes, with it on or off.
What happens to my list if I delete the plugin?
It stays, unless you tick the box under Your data. A list built up over months should survive a reinstall.
Does it need a licence key?
Pro needs a licence key for its updates and to keep its settings editable. The blocklist and its log stay on your own website and are sent nowhere.
What happens if my Pro licence lapses?
Nothing is deleted and nothing breaks. Pro's settings, reasons and audit log stay saved and on screen, where you can read them but not change them, and anyone on the blocklist goes back to being turned away. Orders already on hold stay on hold until you release them, and you can release them while the licence is lapsed. Temporary blocks stop ending by themselves, so an entry set to expire stays on the list until you remove it. Renewing switches it all back on exactly as you left it.
What happens if I deactivate WooCommerce?
The plugin steps aside and shows a notice. It does not fatally error, and your list and settings are waiting when WooCommerce comes back.
More plugins

Estimated Delivery Dates for WooCommerce
Tell customers when their order will arrive, and your team when it has to leave. Estimates on the product page, cart, checkout and emails.

Free Shipping Bar for WooCommerce
Show customers how close they are to free shipping, with a progress bar on the cart, at checkout and in the mini-cart.

Delivery Instructions for WooCommerce
Gives customers one clear box at checkout for delivery or shipping instructions, on the classic checkout and the Checkout block, and shows what they wrote on the order and in your emails.