Description
Checkout Shield stops fake checkout orders and card testing attacks — the kind that bypass your CAPTCHA.
Card testing bots don’t fill out your checkout form. They hit your store’s checkout API directly, completely skipping any reCAPTCHA or hCaptcha you’ve set up. That’s why CAPTCHA alone doesn’t stop them.
This plugin verifies that every checkout request comes from a real browser session. Bots that can’t prove they loaded your checkout page get blocked before WooCommerce processes the order.
Why Store Owners Choose This Plugin
- Catches what CAPTCHA misses — blocks bots hitting your checkout API directly
- Works with any caching — LiteSpeed, Cloudflare, WP Rocket, W3TC — no conflicts
- Nothing to configure — no rules to write and no thresholds to tune
- Never blocks your customers by mistake — it checks that your checkout is working before it blocks anything, and stands down if that ever stops being true
- No external services — everything runs on your server, no subscriptions
- Adds milliseconds — the check is local, with no third-party call to wait on
Features (Free)
- Automatic bot blocking — no rules to configure; it arms itself once it has seen one checkout on your store work
- 4 protection levels — Learning, Permissive, Balanced, and Strict — choose how aggressive you want to be
- Dashboard overview — see blocked vs verified orders at a glance with a 7-day chart
- Order status tracking — know which orders were flagged, passed, or blocked
- IP whitelist — let trusted addresses through, supports CIDR notation
- API key authentication — for headless and custom checkout setups
- Works with all checkout types — classic, block-based, and all payment gateways
- HPOS compatible — works with High-Performance Order Storage
- WooCommerce logging — full integration with WooCommerce Status logs
Pro Features
Take control with advanced tools:
- 3-level logging control — turn logging off, log blocked attempts only, or log everything
- Recent blocks feed — last 50 blocked attempts on your dashboard with email, payment method, and reason
- Automatic CDN/proxy detection — identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai
- Stronger permissive mode — tighter bot detection with referrer verification
- Checkout details in logs — see which email and payment method bots tried to use
- Customer blocklist — block repeat offenders by email, name, address, phone, IP, or postal code
- One-click order blocking — block a customer directly from any order screen
Captures d’écrans



Installation
- Upload the plugin files to
/wp-content/plugins/carticy-checkout-shield-for-woocommerce/ - Activate the plugin through the ‘Plugins’ menu in WordPress
- Open your own checkout page and submit it once
That third step is what arms it. Until one checkout on your store has been seen working, nothing is blocked — that is deliberate, so that switching protection on can never turn every customer away. The order does not have to complete; a submission that WooCommerce rejects for any other reason still arms it. Your dashboard says which of the two states the store is in.
Optional: Go to WooCommerce Settings Advanced Checkout Shield to adjust settings.
Requirements
- WordPress 6.0+
- WooCommerce 8.0+
- PHP 8.0+
FAQ
-
Does this slow down checkout?
-
No. Validation happens locally in microseconds. No external API calls, no waiting on third-party services.
-
Will this block real customers?
-
It is built so it cannot. Before blocking anything it waits until it has seen a
checkout on your store carry its proof successfully, and if that ever stops
happening — a theme update, a caching layer serving a stored checkout page — it
pauses blocking on its own and tells you, rather than turning customers away. If
you still want to watch first, Learning mode logs what would be blocked without
blocking anyone. -
I sent a test bot request and it went through. Is it broken?
-
Almost certainly not. Protection stays inactive until one checkout on your store
has been seen working, so a test request sent before that will pass. Open your
own checkout page and submit it once, then try your test again. Your dashboard
says which state the store is in. -
Does it work with Block Checkout?
-
Yes. Works with both classic checkout and the newer block-based checkout.
-
What about PayPal, Stripe, and other payment gateways?
-
All major gateways work normally. Payment confirmations from gateways aren’t affected by checkout validation.
-
I run a headless store. Will this break my setup?
-
Not if you configure it. Add your frontend’s server IP to the whitelist, or use API key authentication. Both options let legitimate automated requests through.
-
Do I still need CAPTCHA?
-
Up to you. This plugin catches bots that CAPTCHA misses (the ones hitting your API directly). You can use both together, or drop CAPTCHA entirely to reduce checkout friction.
-
How do I know it’s working?
-
The dashboard widget is the quick answer. It tells you whether protection is
armed yet, and counts what happened: blocked, passed, and not checked. « Not
checked » means a submission was let through because the check was not yet
trustworthy — it is separated from « passed » on purpose, so a bot-shaped request
is never counted as a happy customer.For the detail behind any of it, go to WooCommerce Status Logs and filter by
« carticy-checkout-shield ».
Avis
Contributeurs/contributrices & développeurs/développeuses
« Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing » est un logiciel libre. Les personnes suivantes ont contribué à cette extension.
ContributeursLe développement vous intéresse ?
Parcourir le code, consulter le SVN dépôt, ou s’inscrire au journal de développement par RSS.
Journal des modifications
1.2.1
- For new stores, the dashboard widget now says when protection is not blocking immediately. It waits until it has seen one checkout on your store work before it blocks anything.
- Added a separate « not checked » count.
- Clearer setup instructions.
1.2.0
- Stronger bot detection: checkout proof is now issued and signed by your site rather than created in the browser
- Fewer false positives — cookie-blocking browsers, a second checkout tab, a page left open, and JavaScript errors elsewhere on the page no longer stop a genuine order
- Protection now calibrates itself and pauses automatically if proof stops reaching your checkout, resuming on its own
- Added an admin notice whenever protection pauses, so it is never off without you knowing
- Improved Strict and Permissive modes, with clearer descriptions in settings
- Paying for an order from an emailed payment link now works in every mode
- Lighter checkout page: removed a redundant client-side watcher and a duplicate hidden field
- Blocked attempts now report what the submission was missing, and the dashboard stores only the details it displays
- Improved reliability on newly installed sites and restored backups
1.1.1
- Fixed unescaped Unicode characters appearing as raw escape sequences in admin labels and placeholders (Pro)
1.1.0
- Default mode changed to Balanced (was Learning)
- Added smart logging with 3 levels: off, blocks only, and detailed (Pro)
- Added recent blocks feed on the dashboard showing last 50 blocked attempts (Pro)
- Added automatic CDN/proxy detection for Cloudflare, Sucuri, and Akamai (Pro)
- Added enhanced permissive mode with referrer verification (Pro)
- Added checkout details (email, payment method) in log entries (Pro)
- Added one-click order blocking from any order screen (Pro)
- Added upgrade prompts for Pro features
- Improved plugin title and description for better discoverability
- Removed « Carticy » from user-facing plugin name
1.0.0
- Initial release
- Bot detection for checkout protection
- Four protection modes (learning, permissive, balanced, strict)
- IP whitelist with CIDR support
- API key authentication for headless checkout
- Proxy/CDN support
- WooCommerce logging integration
- Dashboard statistics widget
- Orders list shield status column
- HPOS compatibility
- Block checkout compatibility
