Descripció
CartShark is a SaaS security monitoring platform for eCommerce websites. This plugin helps users connect their site to the CartShark platform, where monitoring and threat detection occurs.
CartShark protects your eCommerce store from web skimming (Magecart) attacks. These attacks inject malicious JavaScript into your website to steal credit card data at checkout. CartShark prevents this by monitoring scripts in real-time and alerting you to suspicious behavior.
Key Features:
– 🛡️ Detect Magecart and web skimming threats
– 🔍 Monitor third-party JavaScript on your store
– 📊 View security stats in a simple dashboard
– 🔔 Receive alerts via email, Slack, WhatsApp, voice, and more
– ✅ Supports PCI DSS v4 compliance
– 🔌 Works seamlessly with WooCommerce
CartShark is designed to be plug-and-play—simply install, activate, and follow the onboarding process to get started.
External Services
This plugin connects your site to CartShark, a third-party SaaS security monitoring
service operated by RapidSpike. The plugin is a connector: monitoring and threat
analysis happen on the CartShark platform, not on your site. The plugin does not
function without this service.
What the plugin sends, and when:
- When you log in from the plugin: your CartShark email address and password are sent to
api.rapidspike.com to authenticate you, along with an identifier noting the login came
from WordPress. Your CartShark API keys are then retrieved and stored, encrypted, in
your site’s database. - When you connect your site: your site’s domain name and site title are sent to
CartShark so the website can be registered against your account. You are redirected to
cartshark.rapidspike.com to complete onboarding, and a short-lived token is passed to
sign you in there. - While using the dashboard: authenticated requests are made to api.rapidspike.com to
retrieve your subscription status, registered websites, detection statistics, pageview
totals and the list of detected endpoints. These requests are signed with your API
keys and happen only in the WordPress admin. - On your public pages: the plugin embeds the CartShark tracker script, which is served
by CartShark and runs in your visitors’ browsers. It reports on the scripts and
third-party endpoints loading on the page so CartShark can detect unauthorised or
malicious JavaScript. Embedding can be turned off at any time under CartShark >
Settings.
No customer order data, payment details or personal data from your store is sent to
CartShark by this plugin.
Service provider: RapidSpike Ltd.
Terms of Use: https://www.rapidspike.com/terms-conditions/
Privacy Policy: https://www.rapidspike.com/privacy-policy/
Terms of Use
By using this plugin, you agree to the CartShark Terms of Use:
https://www.rapidspike.com/terms-conditions/
The RapidSpike Privacy Policy applies to data processed by the CartShark service:
https://www.rapidspike.com/privacy-policy/
License
This plugin is licensed under the GPLv2 or later.
Instal·lació
- Upload the plugin folder to
/wp-content/plugins/cartsharkor install it via the WordPress Plugins screen. - Activate the plugin through the ‘Plugins’ menu.
- Go to the CartShark admin menu and:
- Sign up or log in to your CartShark account
- Once your account is connected, setup happens automatically
- You’re protected! View your dashboard for threat data and logs.
PMF
-
Is this a paid service?
-
Yes, CartShark is a paid SaaS platform. A free trial is available. This plugin is used to connect your site to the CartShark service, where monitoring and analysis are performed.
-
Is there a free trial?
-
Yes. Every account starts with a 7-day free trial. After the trial, you can choose a subscription plan.
-
What happens after the trial?
-
Monitoring continues on CartShark for paid users. If you do not upgrade, monitoring will pause, but this plugin will remain installed with no locked functionality.
-
Does CartShark slow down my site?
-
No. CartShark’s tracking code is lightweight and does not impact performance.
-
Is it PCI compliant?
-
Yes. CartShark helps merchants align with PCI DSS v4 by detecting unauthorized JavaScript that could skim customer data.
-
What data is collected?
-
CartShark only monitors scripts and third-party services loading on your store to detect suspicious activity.
-
How do alerts work?
-
You can configure alerts to be sent via multiple channels: Email, Slack, WhatsApp, Voice Call, and PagerDuty.
Ressenyes
Col·laboradors i desenvolupadors
«CartShark Security» és programari de codi obert. La següent gent ha col·laborat en aquesta extensió.
Col·laboradorsTraduïu «CartShark Security» a la vostra llengua.
Interessats en el desenvolupament?
Navegueu pel codi, baixeu-vos el repositori SVN, o subscriviu-vos al registre de desenvolupament per fisl de subscripció RSS.
Registre de canvis
1.0.17
- Fixed WooCommerce HPOS and Cart & Checkout blocks compatibility never being declared
- Fixed deactivation clearing stored credentials and settings; data is now only removed on uninstall
- Fixed the internal version constant being out of step with the plugin version
- Hardened the login endpoint against malformed requests on PHP 8
- Admin styles and scripts now load only on CartShark screens
- Bundled webfonts locally instead of loading them from Google Fonts
- Admin interface strings are now translatable
- Documented the external service the plugin connects to, and corrected a dead Terms of Use link
- Tested up to WordPress 7.1, PHP 8.4 and WooCommerce 11.1
1.0.16
- Identify WordPress as the vendor when authenticating with the CartShark platform
1.0.15
- Fixed an issue with tracker embedding
1.0.14
- Updated Charts.js to version 4.5.0
- Minor security fixes
1.0.13
- Improved onboarding flow for new users
- Fixed compatibility with WordPress 6.5
- Minor UI fixes in the admin dashboard
1.0.0
- Initial release
- Tracker integration
- WooCommerce support
- Dashboard interface
