Cloee Docs
Paymenter ExtensionsSafeGuard

Features

This page dives deeper into what each subsystem offers and how they interact.

This page dives deeper into what each subsystem offers and how they interact.

Registration & Onboarding

  • Name heuristic scoring – rejects junk names using bigram and structure analysis with a configurable minimum score.
  • Disposable email detection – cross-checks against the built-in blocklist (manual + remote data) before accounts are created.
  • Per-IP account limits – cap the number of sign-ups allowed from a single address within your Paymenter instance.
  • VPN/Proxy/Tor screening – integrates with vpnapi.io and caches safe responses to keep the UX fast.
  • Password policy enforcement – configurable minimum length plus uppercase/lowercase/number/symbol requirements; violations surface directly on the registration form.

Login Defense

  • Fail2Ban-style throttling – configurable strikes, window, and temporary ban duration. Tracks by email + IP/fingerprint, with audit trails in the admin UI.
  • Fingerprinting – uses user agent + accept headers by default, and can defer to custom resolvers via the extension container binding.
  • Email/IP whitelists – Ops and trusted partners can bypass throttles, VPN detection, IP caps, and disposable checks with a single toggle per whitelist entry.

Account Enforcement

  • Suspension workflows – temporary/permanent suspensions with optional IP bans, email notifications, and webhook alerts.
  • IP bans – manual and automated bans, complete with expiration, release notes, and Discord/webhook notifications.
  • User IP logs – append-only historical data with CLI exports for incident response.

Automation & Tooling

  • Disposable sync – hourly scheduler hook plus manual/CLI triggers pull the latest domains from the configured remote list. A grace window prevents accidental upstream deletions from nuking your deny-list.
  • CLI namespace – everything from whitelists to disposable syncs is scriptable via php artisan account-protection:*.
  • Filament admin pages – approachable UI for non-technical teams, mirroring the CLI functionality and providing at-a-glance stats.

Integrations

  • Webhook notifications – Discord-compatible payloads and generic JSON for bans, releases, suspensions, and fail2ban events.
  • Extensibility – override bindings (e.g., fingerprint resolver, mail service) or subscribe to Eloquent events to plug Account Protection into custom workflows.

On this page