NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3982 most downloaded on Packagist
MaxMind minFraud API
Last release 2 months ago
21 Jul 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 46 of 46 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
48 releases · first in 2015
Added the residential property to the anonymizer object on MaxMind\MinFraud\Model\IpAddress . This is a GeoIp2\Record\AnonymizerFeed object providing
residential property to the anonymizer object onMaxMind\MinFraud\Model\IpAddress. This is a GeoIp2\Record\AnonymizerFeedconfidence,networkLastSeen, and providerName. It may be populated even when nogeoip2/geoip2 3.4.0 is nowtracking_token to the /device request object. This is thefat_zebra to the payment processor validation.clear to the valid values for the tag parameter on the ReportOne column per quarter.
Added the anonymizer property to MaxMind\MinFraud\Model\IpAddress . This contains anonymizer data from the GeoIP2 Insights response, including VPN det
anonymizer property to MaxMind\MinFraud\Model\IpAddress. Thisbanquest, summit_payments, and yaadpay to the payment processorAdded support for new /email/domain/ outputs in minFraud Insights and Factors responses:
/email/domain/ outputs in minFraud Insights and/email/domain/classification - categorizes the email domain typebusiness, education, government, isp_email)/email/domain/risk - risk score associated with the domain (0.01 to 99)/email/domain/volume - activity level across the minFraud network/email/domain/visit/has_redirect - whether the domain redirects/email/domain/visit/last_visited_on - date of last automated check/email/domain/visit/status - domain status (live, dns_error,network_error, http_error, parked, pre_development)Added securepay to the payment processor validation.
securepay to the payment processor validation.credit_application, fund_transfer, and sim_swap to event type/event/party. This is the party submitting the/payment/method. This is the payment method associatedgeoip2/geoip2 to 3.3.0, which includes new anonymizer and IP riskAdded support for the /billing_phone/matches_postal and /shipping_phone/matches_postal outputs. These are available as the matchesPostal property on M
/billing_phone/matches_postal and/shipping_phone/matches_postal outputs. These are available as thematchesPostal property on MaxMind\MinFraud\Model\Phone.cryptomus to the payment processor validation.\MaxMind\MinFraud now implements JsonSerializable. This returns anlocales and hashEmail options. Pull request by NoéAdded epayco to the payment processor validation.
epayco to the payment processor validation.The minFraud Factors subscores have been deprecated. They will be removed in March 2025. Please see our release notes for more information.
Added support for the new risk reasons outputs in minFraud Factors. The risk reasons output codes and reasons are currently in beta and are subject to
Updated MaxMind\MinFraud\ReportTransaction to make the ip_address parameter optional. Now the tag and at least one of the following parameters must be
MaxMind\MinFraud\ReportTransaction to make the ip_addresstag and at least one of the followingipAddress, maxmindId, minfraudId,transactionId.billingPhone and shippingPhone properties to the minFraud Insightspayconex to the payment processor validation.When calling withDevice with an array, an exception was incorrectly thrown if user_agent was set but session_id was not set. Reported by Gregor Kuhlma
withDevice with an array, an exception was incorrectlyuser_agent was set but session_id was not set. Reported byThis library no longer uses Respect\Validation.
Respect\Validation.with* methods can now be used with named arguments instead of
an array. This provides better editor completion, type checking,
and documentation.hashEmail is used.
For example, googlemail.com will become gmail.com.gmail.com email address local parts when
hashEmail is used. For example, f.o.o@gmail.com will become
foo@gmail.com.hashEmail is used. For example, alias@user.fastmail.com will become
user@fastmail.com.yahoo.com email addresses now have aliases removed from
their local part when hashEmail is used. For example,
foo-bar@yahoo.com will become foo@yahoo.com for additional
yahoo.com domains..coms are now removed from email domain names when
hashEmail is used. For example, example.com.com will become
example.com.hashEmail is used. For
example, example.comcom will become example.com.gmail.com domain names with leading digits are now
normalized when hashEmail is used. For example, 100gmail.com will
become gmail.com.gmail.com typos are now normalized when hashEmail is used.
For example, gmali.com will become gmail.com.hashEmail is used, the local part of an email address is now
normalized to NFC.pxp_financial and trustpay to the payment processor validation.IMPORTANT: PHP 8.1 or greater is now required.
rawResponse property on model classes has been removed. Use
the jsonSerialize method instead.geoip2/geoip2 to version that includes the isAnycast property on
GeoIp2\Record\Traits. This property is true if the IP address belongs to
an anycast network. This is available
in minFraud Insights and Factors.Fixed "creation of a dynamic property" deprecation warning on newer PHP versions. Reported by Andrey Lebedev. GitHub #145.
google_pay to the payment processor validation.placetopay to the payment processor validation.The model class names are no longer constructed by concatenating strings. This change was made to improve support for tools like PHP-Scoper.
shopify_payments to the payment processor validation.geoip2.phar file.Fixed PHP 8.1 deprecation warning in internal validation classes.
/credit_card/country. This is the country where the issuer
of the card is located. This may be passed instead of
/credit_card/issuer_id_number if you do not wish to pass partial account
numbers or if your payment processor does not provide them.The /credit_card/last_4_digits input has been deprecated in favor of /credit_card/last_digits and will be removed in a future release. last_digits/las…
geoip2/geoip2 to 2.12.0. This adds mobile country code (MCC)
and mobile network code (MNC) to minFraud Insights and Factors responses.
These are available at $response->ipAddress->traits->mobileCountryCode and
$response->ipAddress->traits->mobileNetworkCode. We expect this data to be
available by late January, 2022.minfraud.phar is now generated with Box 3.x.boacomprabokucoregatewayfiservneopayneosurfopenbuckspayserapayvisiontrustlywindcave/credit_card/last_4_digits input has been deprecated in favor of
/credit_card/last_digits and will be removed in a future release.
last_digits/last_4_digits also now supports two digit values in
addition to the previous four digit values./credit_card/issuer_id_number inputs are now supported in
addition to the previously accepted six digit issuer_id_number. In most
cases, you should send the last four digits for last_digits. If you send
an issuer_id_number that contains an eight digit IIN, and if the credit
card brand is not one of the following, you should send the last two digits
for last_digits:
DiscoverJCBMastercardUnionPayVisaAdded datacap to the payment processor validation.
datacap to the payment processor validation.ruleLabel to minFraud output Disposition.was_3d_secure_successful to /credit_card validation.Added the following new values to the payment processor validation:
cardknoxcreditguardcredoraxdlocalonpaysafechargeIMPORTANT: PHP 7.3 or greater is now required.
Respect\Validation has been upgraded from 1.x to 2.1.with() method on MaxMind\MinFraud may now be used when
device and shopping_cart are not set.apple_payaps_paymentshashEmail to
true in the MaxMind\MinFraud constructor's options parameter. When set,
this normalizes the email address and sends an MD5 hash of it to the web
service rather than the plain-text address. Note that the email domain will
still be sent in plain text.->ipAddress->riskReasons. It is
an array of MaxMind\MinFraud\Model\IpRiskReason objects.maxmind/web-service-common has been updated to 0.8.1 to fix an issue when using the reportTransaction method. Reported by Dmitry Malashko. GitHub
maxmind/web-service-common has been updated to 0.8.1 to fix an issue when
using the reportTransaction method. Reported by Dmitry Malashko. GitHub
#99.Added tsys to the payment processor validation.
tsys to the payment processor validation.IMPORTANT: PHP 7.2 or greater is now required.
isResidentialProxy property to GeoIp2\Record\Traits.Added the following new values to the payment processor validation:
cashfreefirst_atlantic_commercekomojupaytmrazorpaysystempay/subscores/device, /subscores/email_local_part and
/subscores/shipping_address outputs. They are exposed as the device,
emailLocalPart and shippingAddress properties on
MaxMind\MinFraud\Model\Subscores.Added support for the Report Transactions API. We encourage the use of this API as we use data received through this channel to continually improve th
Added support for the new credit card output /credit_card/is_business. This indicates whether the card is a business card. It may be accessed via $res
/credit_card/is_business.
This indicates whether the card is a business card. It may be accessed via
$response->creditCard->isBusiness on the minFraud Insights and Factors
response objects.Added support for the new email domain output /email/domain/first_seen. This may be accessed via $response->email->domain->firstSeen on the minFraud I
/email/domain/first_seen.
This may be accessed via $response->email->domain->firstSeen on the
minFraud Insights and Factors response objects./event/time now allows sub-second RFC 3339 timestamps
in the request.cardpayepxAdded support for the /email/is_disposable output. This is available as the isDisposable property on MaxMind\MinFraud\Model\Email.
/email/is_disposable output. This is available as
the isDisposable property on MaxMind\MinFraud\Model\Email./order/amount and /shopping_cart/*/price to
allow 0. This was an inconsistency between this library and the web
service. Reported by Sn0wCrack. GitHub #78.Deprecated emailTenure and ipTenure properties in MaxMind\MinFraud\Model\Subscores.
affirmafterpaycetelemdotpayecommpayg2a_payinteracklarnamercanetpaysafecardemailTenure and ipTenure properties in
MaxMind\MinFraud\Model\Subscores.isHighRisk property in MaxMind\MinFraud\Model\GeoIp2Country.Added the following new values to the payment processor validation:
datacashgocardlesspayeezypaylikepayment_expresssmartdebitsynapsefi->with*() call.Renamed MaxMind user ID to account ID in the code and added support for the new ACCOUNT_ID_REQUIRED error code.
ACCOUNT_ID_REQUIRED error code.ccavenuect_paymentsdalenysoneyposconnect/device/local_time output. This is exposed as
the localTime property on MaxMind\MinFraud\Model\Device./credit_card/is_virtual output. This is exposed as
the isVirtual property on MaxMind\MinFraud\Model\CreditCard.payout_change to the /event/type input validation.Upgraded geoip2/geoip2 dependency. This version adds the isInEuropeanUnion property to MaxMind\MinFraud\Model\GeoIp2Country and GeoIp2\Record\Represen
geoip2/geoip2 dependency. This version adds the
isInEuropeanUnion property to MaxMind\MinFraud\Model\GeoIp2Country
and GeoIp2\Record\RepresentedCountry. This property is true if the
country is a member state of the European Union.cybersourcetransact_prowirecardTLD validation is no longer performed when validating /email/domain in order to better accommodate new gTLDs that the validation library does not yet
/email/domain in
order to better accommodate new gTLDs that the validation library does
not yet know about.bpointcheckout_comemerchantpayheartlandpaywaygeoip2/geoip2 dependency to add support for GeoIP2 Precision
Insights anonymizer fields.Added support for custom inputs. You may set up custom inputs from your account portal.
MaxMind\MinFraud\Model\Address now that
isPostalInCity may be returned for addresses world-wide.firstSeen was added to the Email response model. session_age
and session_id inputs were added to device input validation.american_express_payment_gatewaybluesnapcommdoocuropaymentsebsexacthipaylemon_wayoceanpaymentpaymentwallpayzasecuretradingsolidtrust_payvantivvericheckvposThe disposition was added to the minFraud response models. This is used to return the disposition of the transaction as set by the custom rules for th
Allow /credit_card/token input.
/credit_card/token input.Correctly set the IP address risk for the Score model. Previously, it always returned null.
null.Added the follow new values to the event type validation: email_change and password_reset.
email_change and
password_reset.isset() on model attributes now returns the correct value.First production release. No code changes.
Added the following new values to the payment processor validation: concept_payments, ecomm365, orangepay, and pacnet_services.
concept_payments, ecomm365, orangepay, and pacnet_services.maxmind/web-service-common to 0.3.0. This version uses
composer/ca-bundle rather than our own CA bundle.Upgraded to maxmind/web-service-common that supports setting a HTTP proxy.
maxmind/web-service-common that supports setting a HTTP proxy.BREAKING CHANGE: creditsRemaining has been removed from the web service models and has been replaced by queriesRemaining.
creditsRemaining has been removed from the web service
models and has been replaced by queriesRemaining.queriesRemaining and fundsRemaining. Note that fundsRemaining
will not be returned by the web service until our new credit system is in
place.confidence and lastSeen were added to the Device response model.Added support for the minFraud Factors.
JsonSerializable.ccnow, dalpay, epay (replaces epayeu), payplus, pinpayments,
quickpay, and verepay.PHP 7 support was added. PHP 5.3 support was dropped.
->with* methods. This now correctly throws a validation exception./credit_card/brand/credit_card/type/device/id/email/is_free/email/is_high_riskinput on the Warning response model has been replaced with
inputPointer. The latter is a JSON pointer to the input that caused the
warning.Add new is_gift and has_gift_message inputs to order object.
is_gift and has_gift_message inputs to order object.null values are no longer validated or sent to the web
service.Updated maxmind/web-service-common to version that fixes POST bug.
maxmind/web-service-common to version that fixes POST bug.Updated maxmind/web-service-common to version with fixes for PHP 5.3 and 5.4.
maxmind/web-service-common to version with fixes for PHP 5.3 and
5.4.* First beta release.
* Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →