Card testing on WooCommerce: how to spot it and stop it
A guide for store owners. Updated October 10, 2026.
Card testing is when criminals use your checkout to find out which stolen card numbers still work. A bot places order after order, usually for something cheap. Most payments are declined; the few that go through tell the criminal which cards are live, and those get sold or spent somewhere else.
Your store pays for it: chargebacks and dispute fees on the stolen cards that went through, a fee for every try on some payment plans, and a worse standing with the card companies, which can lead to real customers being declined.
Signs it's happening
- A burst of failed or declined orders, often minutes apart and often at night.
- Lots of orders for the same cheap product, or for tiny amounts.
- Names and email addresses that look made up, or one name with many different cards.
- Your payment provider emails you about unusual declines or disputes.
- Real customers tell you their cards are being declined.
What to do in the next hour (free)
- Don't ship the suspicious orders that went through. Refund them: those cards are stolen, and their owners will dispute the charges.
- Turn on your payment provider's fraud rules. In Stripe, open Radar and turn on blocking for payments that fail the CVC or postal code check. PayPal and others have similar settings.
- Make checkout harder for bots. Add a "prove you're human" check (such as Cloudflare Turnstile or reCAPTCHA) to your checkout.
- Slow down repeat tries. Limit how many checkout attempts one connection can make in a few minutes.
- Tell your payment provider. They have seen this before, they can help, and it shows you're dealing with it.
Why a CAPTCHA on the checkout page often isn't enough
Many card-testing bots never open your checkout page. They send orders straight to WooCommerce: to ?wc-ajax=checkout (the classic checkout) or to the Store API behind the checkout block (/wp-json/wc/store/v1/checkout). A check that only appears on the page never runs for them. They also switch IP addresses and browser names between tries, so blocking one address at a time doesn't keep up, and WooCommerce creates a failed order for every try, which is why you see hundreds of them.
What does work: counting failed payments per connection, per email address and across the whole store, pausing a shopper after a few declines, and, during an attack, only accepting orders from shoppers who actually opened your checkout page. The Store API has its own rate limiting, but it's off until a developer turns it on in code.
How Ropeline Pro stops it, automatically
Ropeline Pro is a WordPress plugin that watches your WooCommerce checkout and steps in on its own:
- 3 failed payments from one connection or one email address in an hour: that shopper's checkout pauses for an hour.
- More than 6 checkout tries from one connection in 10 minutes: they're asked to wait 10 minutes.
- 10 failed payments across your store in an hour: attack mode for 2 hours. Only shoppers who opened your real checkout page can pay, which stops bots that send orders straight to checkout. You get an email when it starts.
- It protects you from the first attack, even during Ropeline's first-week learning mode.
- Returning customers who have paid before, and verified AI shopping agents, go straight through.
- Works with the classic checkout, the checkout block and pay-for-order pages, and with WooCommerce's order tables (HPOS). It counts the payments WooCommerce marks as failed, so it works with Stripe, PayPal and other gateways that do.
Store plan: $0 for 14 days, then $15 a month for stores with up to 500 orders a month ($39 up to 3,000, $99 for any size).
Install in a few minutes: download, upload to WordPress, paste your key. Cancel anytime and your site keeps the free plugin.
Start my 2 free weeksQuestions
Will it block my real customers?
It's built not to. A pause only follows repeated declines from the same connection or email. During attack mode, shoppers who go through your checkout page, as almost everyone does, can still pay. If your store's checkout runs on a separate front end (a headless store or an app), you can turn attack mode off.
I'm being card-tested right now. How fast does it work?
As soon as it's installed with your key. The next round of declines triggers the pauses and, if the attack keeps going, attack mode.
Is there a free version?
Yes. The free Ropeline plugin protects your login against password guessing and botnets. Checkout protection is part of Pro.
Further reading: Stripe's guide to card testing explains how these attacks work and how payment providers respond.