How-to › Fix common problems

How to Stop Card-Testing Bots at Checkout

Stop bots from testing stolen cards at your checkout. You read the status, choose a level, add a human check, set the attack reaction and review flagged orders. 9 parts.

Quick links

Where to find it:WP Admin › EasyCart › Settings › Checkout protection

Before you start

What card testing is

What bots do, what it costs you and how WP EasyCart stops it.

What card testing is and how the protection works

What you need and what it costs you

no stored settings

What you need. An up to date WP EasyCart. Checkout protection is free on every edition and is on by default at the Standard level for every store. The human check needs a free Cloudflare or Google account.

The attack. Bots use checkouts to find out which stolen card numbers still work. They try many cards, often for a very small amount, such as a $1 donation. Every attempt costs you a gateway fee. The tests that succeed become disputes, and enough disputes can get your payouts held.

The defence. WP EasyCart counts failed payments from each device, network address, email and card. Too many in a short time pauses that source. When declines spike across the whole store, it calls an attack. Every shopper then gets a quick human check until things calm down, and you get an email.

You set it up in five steps: read the status, choose a level, add the human check, set what happens in an attack and know what to do when one starts.

💡 Note: A bot does not need to buy anything. A declined test still costs you a gateway fee, so stopping the attempts is worth more than refunding the sales.

Set it up

Four steps

Read the status, choose a level, add the human check and set the attack reaction.

Step 1. Read the Status card

Settings › Checkout protection

no stored settings

Open EasyCart › Settings › Checkout protection. The Status card shows a shield for the last seven days:

Protected with your level, such as Standard level.
Under attack with the time extra checks run until.
Watching only or Not protected if you chose those levels.

Four figures sit beside it: payment attempts stopped, payments declined by the bank, attacks stopped, and paused shoppers who later paid. The last one is the number to watch. It counts real customers your limits caught. A zero is good.

Buttons let you turn extra checks on, end them, or keep them on for 24 hours. Diagnostics also shows a row when protection is off, only watching or waiting for its database table.

Settings › Checkout protection › Status.
Settings › Checkout protection › Status.

Step 2. Choose a protection level

Standard suits almost every store

no stored settings

The Level pills in the Protection level section are Off, Watch only, Relaxed, Standard, Strict and Custom. A note under them spells out the numbers for the level you pick.

Standard ( the default ): a shopper can fail 5 payments in 10 minutes, 10 in a day, before a 1 hour pause. A card that fails 5 times in a day is refused until the next day. Real shoppers almost never meet it.
Relaxed: 8 failures in 10 minutes, 20 a day, a 30 minute pause. For stores where many shoppers share one network, such as a school or an office.
Strict: 3 failures, 6 a day, a 24 hour pause, and a payment from a session that never opened your checkout page gets a human check. For stores that have been attacked or sell cheap items bots like.
Watch only stops nothing and records what Standard would have stopped, so you can see it before you switch on. Off removes all limits and is not recommended.
Custom lets you set failed payments per shopper, the time window, the pause, failures per card per day and the attack trigger.

Limit gift card and coupon guessing is on by default. Ten wrong codes in ten minutes pauses code entry for that shopper for an hour. Bots guess gift card numbers the same way they test cards.

Settings › Checkout protection › Protection level.
Settings › Checkout protection › Protection level.

💡 Note: Start on Standard. Change it only if real customers are being paused ( Relaxed ) or attacks are still getting through ( Strict ).

Step 3. Add the human check

Cloudflare Turnstile or Google reCAPTCHA v2

no stored settings

Limits slow a bot down. A human check stops it, because every attempt needs a pass that bots cannot produce in bulk. Most people see a small box that ticks itself. A few are asked to click a checkbox. It only shows above Place order, and only when needed.

In the Human check section, When to ask has three choices: Never, When something looks wrong ( recommended, and the default ), and Every payment. The middle one asks only after a decline, during an attack, or when a payment did not come from your checkout page.

Check provider. Choose Cloudflare Turnstile, which is free with no monthly limit and usually invisible, and works even if your site does not use Cloudflare. In your free Cloudflare account, open Turnstile, add a widget, add this site’s domain and choose Managed mode. Paste the Turnstile site key and the Turnstile secret key. The secret stays on your server.

Or choose Google reCAPTCHA. It uses the reCAPTCHA v2 checkbox keys from Settings › Accounts. Its free tier ends at 10,000 checks a month, which one attack can use up in hours, so Turnstile is the better choice.

Under Test your keys, press Show a test check to see the check exactly as shoppers get it and confirm your secret key with the provider. If the provider is down, payments are never blocked. They go on under stricter limits, and the page tells you. Without keys, protection still works: during an attack, payments that did not come from your checkout page are refused rather than checked.

Settings › Checkout protection › Human check.
Settings › Checkout protection › Human check.

💡 Note: The Payments must come from your checkout page option in Advanced is safe with caching plugins, because the checkout always loads fresh.

Step 4. Decide what happens in an attack

Alerts, extra checks and flagged orders

no stored settings

The During an attack section controls the store’s automatic reaction. At Standard, an attack is 8 declines across the whole store within 15 minutes, at least 3 times your usual rate over the last 30 days, so a busy store does not trip it on a normal day.

Failed payments allowed during an attack ( default 5 ): per shopper, before a 1 hour pause. With the human check on, bots are stopped by the check, so this mainly protects customers who mistype.
Keep extra checks on for: 30 minutes, 1 hour, 4 hours or 24 hours after the last sign of an attack. Then everything goes back to normal by itself.
Email me when an attack starts and ends ( on ): one email when it starts, with what to do, and a summary when it is over, never more than one an hour. Send alerts to takes other addresses. Left empty it uses your store notification addresses, or the WordPress admin email. Press Send a test alert to see one.
Flag orders that might be card tests ( on ): a payment that goes through during an attack, from a shopper who had declines first, is tagged Possible card test.

While an attack is on, a red banner runs across every WP EasyCart screen with buttons to see what is happening, keep extra checks on for 24 hours, or end them now.

Settings › Checkout protection › During an attack.
Settings › Checkout protection › During an attack.

Keep it running

When it happens

Review flagged orders, what to do in an attack, real customers who get paused and what to check when it misbehaves.

Review flagged orders

Refund a suspected test before it becomes a dispute

no stored settings

A flagged order shows a red Possible card test notice at the top of its order screen: this payment went through during a card-testing attack, after declined payments from the same shopper. If you do not recognise the customer, refund it before you ship anything. A quick refund stops it becoming a dispute.

Once your store has flagged an order, Orders gains a Card tests tile, which counts flagged orders from the last 30 days that are not yet refunded, cancelled or declined. There is also a Checkout protection filter with Possible card tests. The Status card links to the same list as Tagged orders to review. The flag clears once the order is refunded or cancelled.

⚠️ Careful: Do not ship a flagged order until you have checked it. Shipping to a stolen card is a lost product and a dispute.

What to do during an attack

A short checklist

no stored settings

Protection is already working. You do not need to do anything right now. If you want to help it:

1. Open Checkout protection and read the Status card. Press Keep extra checks on for 24 hours if the attack looks set to continue.
2. Check that the human check has working keys. Press Show a test check. An attack without keys is handled by refusing suspect payments, which is harsher on real customers.
3. Open Activity and filter to Declined, Stopped or Attacks. Each row shows what happened, where, and a shortened form of the shopper. Press Block on a source, or add network addresses, addresses and email domains such as @example.com to Always block in the Trusted & blocked section. Blocked shoppers only ever see the simple declined message.
4. Review the Card tests tile and refund what you do not recognise.
5. Look at your payment processor’s dashboard. Stripe, Square and PayPal all screen payments on their side, and their fraud tools, such as Stripe Radar and security-code and address checks, add a second layer. Ask your processor what it recommends if fees are rising. Leave the WP EasyCart webhook working, so declines in the payment form reach the Activity list.
6. Raise minimums. The page warns you when a donation product has a minimum under 5. Bots love $1 donations, and a higher minimum makes your store a poor target.
7. Afterward, look at paused shoppers who later paid. If it is not zero, consider Relaxed.

Settings › Checkout protection › Trusted & blocked.
Settings › Checkout protection › Trusted & blocked.

If a real customer is paused

Unpause, allow and reword

no stored settings

A paused shopper sees a friendly message and can pay again after the pause, or straight away after passing the human check. If they contact you:

Unpause them. In Trusted & blocked, the Paused right now list shows every source that hit a limit and when it ends. Press Unpause. Clear all pauses in the Advanced section lets everyone try again at once.
Never limit your own network. Add your office or phone-order desk address to Never limit these network addresses, one per line, ranges such as 198.51.100.0/24 allowed. Signed-in store staff are never limited.
Trust returning customers ( on ) gives signed-in customers who have paid you before double the limits.
Reword the messages. Edit the declined, paused and human-check wording in the Language editor, section Checkout Protection. In the What shoppers see section, Declined payment message is Simple by default. Keep it, because a bank’s reason tells a card tester about a card.

If it does not work

Symptoms and fixes

no stored settings

Real shoppers keep getting paused. Check the address WP EasyCart sees for visitors, under Advanced, How visitors reach your site. If your site is behind a proxy or a CDN and the address is wrong, every shopper looks like the same person. Leave it on Automatic unless your host told you otherwise. If many shoppers share a network, choose Relaxed.

The check does not appear. The keys are not saved, or the provider is unreachable. Use Show a test check. With When to ask on the middle choice, the check only shows when something looks wrong.

Declines are not being counted. Stripe reports declines through its webhook, so make sure the webhook works. See the payment errors guide.

Activity and the Status card are empty. A store with no declines has nothing to show. If the page says its database table has not been created, load any WP EasyCart admin screen, or use the repair link on Diagnostics.

You want the defaults back. Press Reset to recommended in Advanced. It restores Standard, the smart human check and the attack settings and keeps your keys and lists.

Need us? Open a request in your account.

Keep going

Related panels

Payment

Gateway setup, the second layer of defence.

Order Management

Find, review and refund flagged orders.

Accounts

Where the reCAPTCHA keys live.

Language

Reword the declined and paused messages.

Ready to run your store on WP EasyCart?

Everything in this guide works with the free plugin. PRO and Premium add subscriptions, memberships, wholesale pricing and more. Try every PRO feature free for 14 days.

The WP EasyCart admin: orders and offers
Updated on September 30, 2026