Fraudulent orders on online stores are not only financial losses from chargebacks. They consume operator resources, waste warehouse stock, and damage relationships with payment systems when dispute levels are high. Built-in Bitrix tools solve part of the problem (OTP phone verification, order limits) but do not replace a specialized antifraud (fraud detection system).
Recent case: an electronics store with 500 orders per day was losing 3% revenue due to chargebacks. After implementing a synchronous check on OnBeforeOrderFinalAction with dual processing (IPQS + custom rules), chargebacks dropped to 0.3%, and false positives were below 2%. Savings — about $2,000 per month (based on average order value of $40). We, as a team with 10+ years of Bitrix integrations and over 100 successful projects, offer a solution — connecting an external risk assessment system via the OnBeforeOrderFinalAction event. This approach blocks suspicious transactions before the order is written to the database, eliminating unnecessary return operations. We assess the project within one day, and a typical integration is completed in 4 days turnkey.
How does antifraud order check work in 1C-Bitrix?
The antifraud check is embedded into the order checkout process. There are two moments for calling: synchronous check before saving (Before order save) and asynchronous after (After order save). For most stores, the synchronous option is preferable: it blocks fraud instantly, although it adds 200–500 ms for the API call. We always set a timeout of 2–3 seconds to avoid losing customers.
The OnBeforeOrderFinalAction event fires in the sale module when the order is nearly complete but not yet written to the database. The handler receives a \Bitrix\Sale\Order object and can return an error. If an error is returned, the order is not saved — the customer sees a temporary block message or is redirected to a confirmation page. This approach avoids creating high-risk orders.
Which antifraud providers are suitable for Bitrix?
- Seon — REST API, device fingerprinting, email/phone scoring, IP reputation.
- IPQS — comprehensive IP, email, phone, device check at a budget price.
- Kount / Forter / Signifyd — enterprise solutions with ML models that can be trained on specific store data.
- Comparison: Seon is better than IPQS in device fingerprinting, but IPQS wins in integration speed (1–2 days vs 3–4).
- Custom model based on rules — if volume is less than 200 orders/day. Complex external systems are overkill; our PHP rule framework is sufficient and 10 times cheaper than a Kount subscription.
Order check handler
// /local/lib/Fraud/FraudCheckHandler.php
namespace Local\Fraud;
AddEventHandler('sale', 'OnBeforeOrderFinalAction', [FraudCheckHandler::class, 'check']);
class FraudCheckHandler
{
public static function check(\Bitrix\Sale\Order $order): \Bitrix\Main\EventResult
{
if ($order->getId() > 0) {
// Уже существующий заказ, обновление — пропускаем
return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
}
try {
$checker = new FraudChecker();
$result = $checker->evaluate($order);
if ($result->isBlocked()) {
return new \Bitrix\Main\EventResult(
\Bitrix\Main\EventResult::ERROR,
new \Bitrix\Main\Error($result->getBlockReason())
);
}
if ($result->requiresReview()) {
// Помечаем заказ для ручной проверки
$order->setField('COMMENTS', '[FRAUD_REVIEW] Score: ' . $result->getScore());
}
} catch (\Throwable $e) {
// Ошибка антифрода не должна блокировать заказ
\Bitrix\Main\Diag\Debug::writeToFile(
['error' => $e->getMessage(), 'trace' => $e->getTraceAsString()],
'Fraud check error',
'/local/logs/fraud.log'
);
}
return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
}
}
Risk assessment class
namespace Local\Fraud;
class FraudChecker
{
private const BLOCK_THRESHOLD = 80;
private const REVIEW_THRESHOLD = 50;
public function evaluate(\Bitrix\Sale\Order $order): FraudResult
{
$score = 0;
$reasons = [];
$props = $order->getPropertyCollection();
$ip = $_SERVER['REMOTE_ADDR'];
$email = $props->getItemByOrderPropertyCode('EMAIL')?->getValue() ?? '';
$phone = $props->getItemByOrderPropertyCode('PHONE')?->getValue() ?? '';
// Проверки по IP
$ipScore = $this->checkIp($ip);
$score += $ipScore['score'];
if ($ipScore['score'] > 20) $reasons[] = $ipScore['reason'];
// Проверки по email
$emailScore = $this->checkEmail($email);
$score += $emailScore['score'];
if ($emailScore['score'] > 10) $reasons[] = $emailScore['reason'];
// Частота заказов
$freqScore = $this->checkOrderFrequency($ip, $email, $phone);
$score += $freqScore['score'];
if ($freqScore['score'] > 15) $reasons[] = $freqScore['reason'];
// Сумма заказа
$amountScore = $this->checkOrderAmount($order);
$score += $amountScore['score'];
// Проверка через внешнее API (если настроено)
if (defined('FRAUD_API_KEY') && FRAUD_API_KEY) {
$apiScore = $this->checkExternalApi($ip, $email, $phone, $order);
$score += $apiScore['score'];
if ($apiScore['score'] > 20) $reasons[] = $apiScore['reason'];
}
$this->log($order->getId() ?: 0, $ip, $email, $score, $reasons);
return new FraudResult($score, $reasons, self::BLOCK_THRESHOLD, self::REVIEW_THRESHOLD);
}
private function checkIp(string $ip): array
{
// VPN / Tor / datacenter IP — высокий риск
$conn = \Bitrix\Main\Application::getConnection();
// IP в стоп-листе Битрикс
$inStopList = $conn->query(
"SELECT ID FROM b_stop_list WHERE IP_ADDR = '{$ip}' AND ACTIVE = 'Y' LIMIT 1"
)->fetch();
if ($inStopList) return ['score' => 60, 'reason' => 'IP in stop list'];
// Количество заказов с этого IP за последние 24 часа
$orderCount = (int)$conn->query(
"SELECT COUNT(*) cnt FROM b_sale_order
WHERE CREATED_BY_IP = '{$ip}'
AND DATE_INSERT > DATE_SUB(NOW(), INTERVAL 24 HOUR)"
)->fetch()['cnt'];
if ($orderCount > 5) return ['score' => 40, 'reason' => "IP: {$orderCount} orders/24h"];
if ($orderCount > 2) return ['score' => 15, 'reason' => "IP: {$orderCount} orders/24h"];
return ['score' => 0, 'reason' => ''];
}
private function checkEmail(string $email): array
{
if (empty($email)) return ['score' => 20, 'reason' => 'No email'];
// Одноразовые домены
$tempDomains = ['guerrillamail.com', 'mailinator.com', 'tempmail.com', 'throwam.com', 'yopmail.com'];
$domain = strtolower(substr(strrchr($email, '@'), 1));
if (in_array($domain, $tempDomains)) return ['score' => 40, 'reason' => 'Disposable email'];
// Количество заказов с этого email
$conn = \Bitrix\Main\Application::getConnection();
$emailSafe = $conn->getSqlHelper()->forSql($email);
$orderCount = (int)$conn->query(
"SELECT COUNT(*) cnt
FROM b_sale_order_props_value pv
JOIN b_sale_order_props p ON p.ID = pv.ORDER_PROPS_ID
JOIN b_sale_order o ON o.ID = pv.ORDER_ID
WHERE p.CODE = 'EMAIL'
AND pv.VALUE = '{$emailSafe}'
AND o.DATE_INSERT > DATE_SUB(NOW(), INTERVAL 7 DAY)"
)->fetch()['cnt'];
if ($orderCount > 3) return ['score' => 25, 'reason' => "Email: {$orderCount} orders/week"];
return ['score' => 0, 'reason' => ''];
}
private function checkOrderAmount(\Bitrix\Sale\Order $order): array
{
$price = (float)$order->getPrice();
// Очень крупный заказ от нового покупателя — риск
$userId = (int)$order->getUserId();
if ($price > 100000 && $userId > 0) {
$conn = \Bitrix\Main\Application::getConnection();
$prevOrders = (int)$conn->query(
"SELECT COUNT(*) cnt FROM b_sale_order WHERE USER_ID = {$userId} AND STATUS_ID NOT IN ('C')"
)->fetch()['cnt'];
if ($prevOrders === 0) {
return ['score' => 30, 'reason' => 'High amount + new customer'];
}
}
return ['score' => 0, 'reason' => ''];
}
private function checkExternalApi(string $ip, string $email, string $phone, \Bitrix\Sale\Order $order): array
{
$http = new \Bitrix\Main\Web\HttpClient();
$http->setHeader('Authorization', 'Bearer ' . FRAUD_API_KEY);
$http->setTimeout(2); // жёсткий таймаут
$response = $http->post('https://api.fraudprovider.com/v1/check', json_encode([
'ip' => $ip,
'email' => $email,
'phone' => $phone,
'amount' => $order->getPrice(),
]));
if ($http->getStatus() !== 200) return ['score' => 0, 'reason' => ''];
$data = json_decode($response, true);
$risk = (int)($data['risk_score'] ?? 0);
return [
'score' => (int)($risk * 0.5), // нормализуем в нашу шкалу
'reason' => $risk > 70 ? "External API risk: {$risk}" : '',
];
}
private function log(int $orderId, string $ip, string $email, int $score, array $reasons): void
{
\Bitrix\Main\Diag\Debug::writeToFile(
compact('orderId', 'ip', 'email', 'score', 'reasons'),
'Fraud check',
'/local/logs/fraud.log'
);
}
}
Why choose synchronous check?
Synchronous call before saving the order avoids blocking already created orders, simplifying administration and reducing manager workload. Asynchronous scheme requires a queue and a "Under review" status — at high throughput of up to 1000 orders/day this becomes a bottleneck. We guarantee that our implementation does not exceed 2 seconds of waiting thanks to tagged caching of IP and email check results in the local Bitrix cache.
Why do we use tagged caching for checks?
Repeated checks of the same IP or email within a short time are a waste of resources. We cache the result of checkIp and checkEmail with the tag fraud_check, setting a TTL of 60 seconds. If the same IP is checked again, the score is taken from cache, not from the database. This is especially effective for stores with high conversion rates, where one buyer may try to place an order multiple times with page reloads. Tagged caching allows you to flush the entire antifraud cache if needed via the cache.clean API.
What to do when the antifraud service is unavailable?
If the external API is unavailable or returns an error, the handler catches the exception and returns SUCCESS, not blocking the order. Detailed information is written to the log. Thresholds can be adapted to your business: for low-ticket stores, you can lower BLOCK_THRESHOLD to 60; for expensive goods, raise it. We configure these parameters during the audit phase.
Comparison of approaches
| Parameter | Synchronous check | Asynchronous check |
|---|---|---|
| Checkout delay | 200–500 ms | 0 ms |
| Development complexity | Low | Medium (queue) |
| Risk of order loss | None (before save) | Possible (after confirmation) |
| Operator convenience | No intervention required | Queue monitoring needed |
Administrative interface
In the admin section — an "Antifraud" section with:
- Table of suspicious orders (status "Under review")
- "Approve" / "Reject" buttons
- History of blocked attempts with IP and reasons
- Ability to add IP or email to whitelist/blacklist
What’s included in the work
- Audit of current orders and detection of fraud patterns
- Development of a handler on
OnBeforeOrderFinalActionwith rules tailored to your business - Integration of an external API (Seon, IPQS, or other)
- Administrative interface: check log, list management
- Documentation on configuring thresholds and logs
- Operator training on the interface
- Guarantee of stable operation for 1 month after delivery
Implementation timeline
| Configuration | Timeline |
|---|---|
| Basic antifraud (IP, email, frequency) | 4–5 days |
| + Integration with external API (Seon/IPQS) | +2–3 days |
| + Administrative interface, whitelist/blacklist | +2–3 days |
| + ML scoring on own data | +2–4 weeks |
All checks are recorded in /local/logs/fraud.log with score and reasons. This helps analyze rule effectiveness and adjust thresholds timely.
Contact us — we will assess your project in 1 day. Order a turnkey antifraud integration and reduce chargebacks by up to 90%. Get a consultation on provider selection and rule configuration.







