Ropeline Try Pro free

Card testing on WooCommerce: how to spot it and stop it

A guide for store owners. Updated October 10, 2026.

Card testing is when criminals use your checkout to find out which stolen card numbers still work. A bot places order after order, usually for something cheap. Most payments are declined; the few that go through tell the criminal which cards are live, and those get sold or spent somewhere else.

Your store pays for it: chargebacks and dispute fees on the stolen cards that went through, a fee for every try on some payment plans, and a worse standing with the card companies, which can lead to real customers being declined.

Signs it's happening

What to do in the next hour (free)

  1. Don't ship the suspicious orders that went through. Refund them: those cards are stolen, and their owners will dispute the charges.
  2. Turn on your payment provider's fraud rules. In Stripe, open Radar and turn on blocking for payments that fail the CVC or postal code check. PayPal and others have similar settings.
  3. Make checkout harder for bots. Add a "prove you're human" check (such as Cloudflare Turnstile or reCAPTCHA) to your checkout.
  4. Slow down repeat tries. Limit how many checkout attempts one connection can make in a few minutes.
  5. Tell your payment provider. They have seen this before, they can help, and it shows you're dealing with it.

Why a CAPTCHA on the checkout page often isn't enough

Many card-testing bots never open your checkout page. They send orders straight to WooCommerce: to ?wc-ajax=checkout (the classic checkout) or to the Store API behind the checkout block (/wp-json/wc/store/v1/checkout). A check that only appears on the page never runs for them. They also switch IP addresses and browser names between tries, so blocking one address at a time doesn't keep up, and WooCommerce creates a failed order for every try, which is why you see hundreds of them.

What does work: counting failed payments per connection, per email address and across the whole store, pausing a shopper after a few declines, and, during an attack, only accepting orders from shoppers who actually opened your checkout page. The Store API has its own rate limiting, but it's off until a developer turns it on in code.

How Ropeline Pro stops it, automatically

Ropeline Pro is a WordPress plugin that watches your WooCommerce checkout and steps in on its own:

Store plan: $0 for 14 days, then $15 a month for stores with up to 500 orders a month ($39 up to 3,000, $99 for any size).

Install in a few minutes: download, upload to WordPress, paste your key. Cancel anytime and your site keeps the free plugin.

Start my 2 free weeks

Questions

Will it block my real customers?

It's built not to. A pause only follows repeated declines from the same connection or email. During attack mode, shoppers who go through your checkout page, as almost everyone does, can still pay. If your store's checkout runs on a separate front end (a headless store or an app), you can turn attack mode off.

I'm being card-tested right now. How fast does it work?

As soon as it's installed with your key. The next round of declines triggers the pauses and, if the attack keeps going, attack mode.

Is there a free version?

Yes. The free Ropeline plugin protects your login against password guessing and botnets. Checkout protection is part of Pro.

Further reading: Stripe's guide to card testing explains how these attacks work and how payment providers respond.