{"id":240944,"date":"2025-07-28T09:49:36","date_gmt":"2025-07-28T09:49:36","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cartshark-security\/"},"modified":"2026-09-17T14:41:51","modified_gmt":"2026-09-17T14:41:51","slug":"cartshark-security","status":"publish","type":"plugin","link":"https:\/\/roh.wordpress.org\/plugins\/cartshark-security\/","author":15473312,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.17","stable_tag":"1.0.17","tested":"7.1.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"CartShark Security","header_author":"RapidSpike \/ CartShark Team","header_description":"Advanced web-skimming detection and protection for WooCommerce and other WordPress ecommerce platforms","assets_banners_color":"191f26","last_updated":"2026-09-17 14:41:51","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/cartshark.rapidspike.com","header_author_uri":"https:\/\/www.rapidspike.com\/cartshark","rating":5,"author_block_rating":0,"active_installs":0,"downloads":596,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.15":{"tag":"1.0.15","author":"rapidspike","date":"2025-07-28 09:50:42","revision":3335242},"1.0.16":{"tag":"1.0.16","author":"rapidspike","date":"2026-04-16 13:06:51","revision":3508087},"1.0.17":{"tag":"1.0.17","author":"rapidspike","date":"2026-09-17 14:41:51","revision":3700456}},"upgrade_notice":{"1.0.17":"<p>Compatibility release for WordPress 7.1, PHP 8.4 and current WooCommerce. Fixes WooCommerce feature compatibility detection and stops deactivation from clearing your connection settings.<\/p>","1.0.13":"<p>Improves onboarding and fixes some minor UI issues in the admin dashboards.<\/p>","1.0.0":"<p>First stable release. Adds tracker and Magecart detection for WooCommerce sites.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3335265,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3335265,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3335265,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3335265,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.15","1.0.16","1.0.17"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"CartShark admin login screen","2":"Dashboard with tracker stats and alerts"}},"plugin_section":[],"plugin_tags":[245444,25524,600,245443,286],"plugin_category":[45,54],"plugin_contributors":[141656],"plugin_business_model":[],"class_list":["post-240944","plugin","type-plugin","status-publish","hentry","plugin_tags-magecart","plugin_tags-pci-compliance","plugin_tags-security","plugin_tags-web-skimming","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-rapidspike","plugin_committers-rapidspike"],"banners":{"banner":"https:\/\/ps.w.org\/cartshark-security\/assets\/banner-772x250.png?rev=3335265","banner_2x":"https:\/\/ps.w.org\/cartshark-security\/assets\/banner-1544x500.png?rev=3335265","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/cartshark-security\/assets\/icon-128x128.png?rev=3335265","icon_2x":"https:\/\/ps.w.org\/cartshark-security\/assets\/icon-256x256.png?rev=3335265","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>CartShark is a SaaS security monitoring platform for eCommerce websites. This plugin helps users connect their site to the CartShark platform, where monitoring and threat detection occurs.<\/p>\n\n<p>CartShark protects your eCommerce store from <strong>web skimming<\/strong> (Magecart) attacks. These attacks inject malicious JavaScript into your website to steal credit card data at checkout. CartShark prevents this by monitoring scripts in real-time and alerting you to suspicious behavior.<\/p>\n\n<p><strong>Key Features:<\/strong>\n- \ud83d\udee1\ufe0f Detect Magecart and web skimming threats\n- \ud83d\udd0d Monitor third-party JavaScript on your store\n- \ud83d\udcca View security stats in a simple dashboard\n- \ud83d\udd14 Receive alerts via email, Slack, WhatsApp, voice, and more\n- \u2705 Supports PCI DSS v4 compliance\n- \ud83d\udd0c Works seamlessly with WooCommerce<\/p>\n\n<p>CartShark is designed to be <strong>plug-and-play<\/strong>\u2014simply install, activate, and follow the onboarding process to get started.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects your site to CartShark, a third-party SaaS security monitoring\nservice operated by RapidSpike. The plugin is a connector: monitoring and threat\nanalysis happen on the CartShark platform, not on your site. The plugin does not\nfunction without this service.<\/p>\n\n<p><strong>What the plugin sends, and when:<\/strong><\/p>\n\n<ul>\n<li>When you log in from the plugin: your CartShark email address and password are sent to\napi.rapidspike.com to authenticate you, along with an identifier noting the login came\nfrom WordPress. Your CartShark API keys are then retrieved and stored, encrypted, in\nyour site's database.<\/li>\n<li>When you connect your site: your site's domain name and site title are sent to\nCartShark so the website can be registered against your account. You are redirected to\ncartshark.rapidspike.com to complete onboarding, and a short-lived token is passed to\nsign you in there.<\/li>\n<li>While using the dashboard: authenticated requests are made to api.rapidspike.com to\nretrieve your subscription status, registered websites, detection statistics, pageview\ntotals and the list of detected endpoints. These requests are signed with your API\nkeys and happen only in the WordPress admin.<\/li>\n<li>On your public pages: the plugin embeds the CartShark tracker script, which is served\nby CartShark and runs in your visitors' browsers. It reports on the scripts and\nthird-party endpoints loading on the page so CartShark can detect unauthorised or\nmalicious JavaScript. Embedding can be turned off at any time under CartShark &gt;\nSettings.<\/li>\n<\/ul>\n\n<p>No customer order data, payment details or personal data from your store is sent to\nCartShark by this plugin.<\/p>\n\n<p>Service provider: RapidSpike Ltd.\nTerms of Use: https:\/\/www.rapidspike.com\/terms-conditions\/\nPrivacy Policy: https:\/\/www.rapidspike.com\/privacy-policy\/<\/p>\n\n<h3>Terms of Use<\/h3>\n\n<p>By using this plugin, you agree to the CartShark Terms of Use:\nhttps:\/\/www.rapidspike.com\/terms-conditions\/<\/p>\n\n<p>The RapidSpike Privacy Policy applies to data processed by the CartShark service:\nhttps:\/\/www.rapidspike.com\/privacy-policy\/<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPLv2 or later.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/cartshark<\/code> or install it via the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' menu.<\/li>\n<li>Go to the CartShark admin menu and:\n\n<ul>\n<li>Sign up or log in to your CartShark account<\/li>\n<li>Once your account is connected, setup happens automatically<\/li>\n<\/ul><\/li>\n<li>You're protected! View your dashboard for threat data and logs.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20a%20paid%20service%3F\"><h3>Is this a paid service?<\/h3><\/dt>\n<dd><p>Yes, CartShark is a paid SaaS platform. A free trial is available. This plugin is used to connect your site to the CartShark service, where monitoring and analysis are performed.<\/p><\/dd>\n<dt id=\"is%20there%20a%20free%20trial%3F\"><h3>Is there a free trial?<\/h3><\/dt>\n<dd><p>Yes. Every account starts with a 7-day free trial. After the trial, you can choose a subscription plan.<\/p><\/dd>\n<dt id=\"what%20happens%20after%20the%20trial%3F\"><h3>What happens after the trial?<\/h3><\/dt>\n<dd><p>Monitoring continues on CartShark for paid users. If you do not upgrade, monitoring will pause, but this plugin will remain installed with no locked functionality.<\/p><\/dd>\n<dt id=\"does%20cartshark%20slow%20down%20my%20site%3F\"><h3>Does CartShark slow down my site?<\/h3><\/dt>\n<dd><p>No. CartShark\u2019s tracking code is lightweight and does not impact performance.<\/p><\/dd>\n<dt id=\"is%20it%20pci%20compliant%3F\"><h3>Is it PCI compliant?<\/h3><\/dt>\n<dd><p>Yes. CartShark helps merchants align with PCI DSS v4 by detecting unauthorized JavaScript that could skim customer data.<\/p><\/dd>\n<dt id=\"what%20data%20is%20collected%3F\"><h3>What data is collected?<\/h3><\/dt>\n<dd><p>CartShark only monitors scripts and third-party services loading on your store to detect suspicious activity.<\/p><\/dd>\n<dt id=\"how%20do%20alerts%20work%3F\"><h3>How do alerts work?<\/h3><\/dt>\n<dd><p>You can configure alerts to be sent via multiple channels: Email, Slack, WhatsApp, Voice Call, and PagerDuty.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>Fixed WooCommerce HPOS and Cart &amp; Checkout blocks compatibility never being declared<\/li>\n<li>Fixed deactivation clearing stored credentials and settings; data is now only removed on uninstall<\/li>\n<li>Fixed the internal version constant being out of step with the plugin version<\/li>\n<li>Hardened the login endpoint against malformed requests on PHP 8<\/li>\n<li>Admin styles and scripts now load only on CartShark screens<\/li>\n<li>Bundled webfonts locally instead of loading them from Google Fonts<\/li>\n<li>Admin interface strings are now translatable<\/li>\n<li>Documented the external service the plugin connects to, and corrected a dead Terms of Use link<\/li>\n<li>Tested up to WordPress 7.1, PHP 8.4 and WooCommerce 11.1<\/li>\n<\/ul>\n\n<h4>1.0.16<\/h4>\n\n<ul>\n<li>Identify WordPress as the vendor when authenticating with the CartShark platform<\/li>\n<\/ul>\n\n<h4>1.0.15<\/h4>\n\n<ul>\n<li>Fixed an issue with tracker embedding<\/li>\n<\/ul>\n\n<h4>1.0.14<\/h4>\n\n<ul>\n<li>Updated Charts.js to version 4.5.0<\/li>\n<li>Minor security fixes<\/li>\n<\/ul>\n\n<h4>1.0.13<\/h4>\n\n<ul>\n<li>Improved onboarding flow for new users<\/li>\n<li>Fixed compatibility with WordPress 6.5<\/li>\n<li>Minor UI fixes in the admin dashboard<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Tracker integration<\/li>\n<li>WooCommerce support<\/li>\n<li>Dashboard interface<\/li>\n<\/ul>","raw_excerpt":"Protect your store from Magecart-style web skimming attacks. CartShark tracks and alerts on malicious JavaScript that could steal customer card data.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/240944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=240944"}],"author":[{"embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rapidspike"}],"wp:attachment":[{"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=240944"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=240944"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=240944"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=240944"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=240944"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/roh.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=240944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}