{"id":276707,"date":"2026-01-25T12:16:58","date_gmt":"2026-01-25T12:16:58","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/carticy-checkout-shield-for-woocommerce\/"},"modified":"2026-08-14T00:11:19","modified_gmt":"2026-08-14T00:11:19","slug":"carticy-checkout-shield-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/fa.wordpress.org\/plugins\/carticy-checkout-shield-for-woocommerce\/","author":23432479,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.1","stable_tag":"1.3.1","tested":"7.0.4","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"Checkout Shield for WooCommerce \u2013 Stop Fake Orders, Spam Bots & Card Testing","header_author":"Carticy","header_description":"Protects WooCommerce stores from card testing and fake order attacks using stateless bot detection.","assets_banners_color":"f4f2fa","last_updated":"2026-08-14 00:11:19","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/alikhallad.com\/donations\/donation-form\/","header_plugin_uri":"https:\/\/carticy.com\/checkout-shield","header_author_uri":"https:\/\/carticy.com","rating":5,"author_block_rating":0,"active_installs":300,"downloads":1806,"num_ratings":5,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"carticy","date":"2026-01-25 12:16:35"},"1.1.0":{"tag":"1.1.0","author":"carticy","date":"2026-03-08 12:38:30"},"1.1.1":{"tag":"1.1.1","author":"carticy","date":"2026-05-24 09:58:12"},"1.2.1":{"tag":"1.2.1","author":"carticy","date":"2026-08-07 17:08:30"},"1.3.0":{"tag":"1.3.0","author":"carticy","date":"2026-08-09 18:59:00"},"1.3.1":{"tag":"1.3.1","author":"carticy","date":"2026-08-14 00:11:19"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":5},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3446515,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon.svg":{"filename":"icon.svg","revision":3446515,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3446515,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3446515,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.1","1.2.1","1.3.0","1.3.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3446515,"resolution":"1","location":"assets","locale":"","width":2312,"height":948},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3446515,"resolution":"2","location":"assets","locale":"","width":1093,"height":551},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3446515,"resolution":"3","location":"assets","locale":"","width":2193,"height":763}},"screenshots":{"1":"Settings page - Configure protection mode and options","2":"Dashboard widget - Monitor blocked and passed requests","3":"Orders column - View shield status for each order"}},"plugin_section":[262246],"plugin_tags":[166108,3148,12891,600,286],"plugin_category":[45,54],"plugin_contributors":[141250,253398],"plugin_business_model":[],"class_list":["post-276707","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-bot-protection","plugin_tags-checkout","plugin_tags-fraud","plugin_tags-security","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-alikhallad","plugin_contributors-carticy","plugin_committers-carticy"],"banners":{"banner":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/banner-772x250.png?rev=3446515","banner_2x":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/banner-1544x500.png?rev=3446515","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/icon.svg?rev=3446515","icon":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/icon.svg?rev=3446515","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/screenshot-1.png?rev=3446515","caption":"Settings page - Configure protection mode and options"},{"src":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/screenshot-2.jpg?rev=3446515","caption":"Dashboard widget - Monitor blocked and passed requests"},{"src":"https:\/\/ps.w.org\/carticy-checkout-shield-for-woocommerce\/assets\/screenshot-3.jpg?rev=3446515","caption":"Orders column - View shield status for each order"}],"raw_content":"<!--section=description-->\n<p><strong>Checkout Shield<\/strong> blocks the scripted checkout submissions that CAPTCHA never sees.<\/p>\n\n<p>Card testing bots don't fill out your checkout form. They hit your store's checkout API directly, completely skipping any reCAPTCHA or hCaptcha you've set up. That's why CAPTCHA alone doesn't stop them.<\/p>\n\n<p>Your site signs a proof into the checkout page it serves. A submission that carries that proof loaded the page; one that doesn't, didn't. Submissions with no valid proof are stopped before WooCommerce processes the order.<\/p>\n\n<h4>What this stops, and what it does not<\/h4>\n\n<p>Being straight about this is more useful than a bigger promise.<\/p>\n\n<p><strong>It stops<\/strong> anything that posts to your checkout without loading the checkout page first: curl scripts, direct Store API calls, replayed form posts, and the card testing runs that work this way. This is the large majority of automated checkout abuse, and it is the part CAPTCHA misses.<\/p>\n\n<p><strong>It does not stop<\/strong> a bot that drives a real browser. Something that genuinely loads your checkout page receives a genuine proof, because that is exactly what the proof records. Once loaded, that proof stays valid for the life of the shopping session, so a script can reuse it. No proof of this kind can tell the second submission from the first, since the thing being proven is identical.<\/p>\n\n<p>For that tier you want a bot mitigation service in front of the site (Cloudflare Bot Fight Mode, Sucuri) alongside this plugin. What this plugin can do is show you when it is happening: the dashboard reports payments that failed repeatedly from a single checkout visit, which is what working through stolen card numbers looks like.<\/p>\n\n<h4>Why Store Owners Choose This Plugin<\/h4>\n\n<ul>\n<li><strong>Catches what CAPTCHA misses<\/strong> \u2014 blocks bots hitting your checkout API directly, without asking shoppers to prove anything<\/li>\n<li><strong>Works with any caching<\/strong> \u2014 LiteSpeed, Cloudflare, WP Rocket, W3TC \u2014 no conflicts<\/li>\n<li><strong>Nothing to configure<\/strong> \u2014 no rules to write and no thresholds to tune<\/li>\n<li><strong>Never blocks your customers by mistake<\/strong> \u2014 it only starts once it has seen a real checkout on your store work, and if your theme ever stops carrying the proof it detects that, keeps letting real shoppers through, and tells you what to fix<\/li>\n<li><strong>No external services<\/strong> \u2014 everything runs on your server, no subscriptions<\/li>\n<li><strong>Adds milliseconds<\/strong> \u2014 the check is local, with no third-party call to wait on<\/li>\n<\/ul>\n\n<h4>Features (Free)<\/h4>\n\n<ul>\n<li><strong>Automatic bot blocking<\/strong> \u2014 no rules to configure; it arms itself once it has seen one checkout on your store work<\/li>\n<li><strong>4 protection levels<\/strong> \u2014 Learning, Permissive, Balanced, and Strict \u2014 choose how aggressive you want to be<\/li>\n<li><strong>Dashboard overview<\/strong> \u2014 see blocked vs verified orders at a glance with a 7-day chart<\/li>\n<li><strong>Order status tracking<\/strong> \u2014 know which orders were flagged, passed, or blocked<\/li>\n<li><strong>IP whitelist<\/strong> \u2014 let trusted addresses through, supports CIDR notation<\/li>\n<li><strong>API key authentication<\/strong> \u2014 for headless and custom checkout setups<\/li>\n<li><strong>Works with all checkout types<\/strong> \u2014 classic, block-based, and all payment gateways<\/li>\n<li><strong>HPOS compatible<\/strong> \u2014 works with High-Performance Order Storage<\/li>\n<li><strong>WooCommerce logging<\/strong> \u2014 full integration with WooCommerce Status logs<\/li>\n<\/ul>\n\n<h4>Pro Features<\/h4>\n\n<p>Take control with advanced tools:<\/p>\n\n<ul>\n<li><strong>3-level logging control<\/strong> \u2014 turn logging off, log blocked attempts only, or log everything<\/li>\n<li><strong>Recent blocks feed<\/strong> \u2014 last 50 blocked attempts on your dashboard with email, payment method, and reason<\/li>\n<li><strong>Automatic CDN\/proxy detection<\/strong> \u2014 identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai<\/li>\n<li><strong>Stronger permissive mode<\/strong> \u2014 tighter bot detection with referrer verification<\/li>\n<li><strong>Checkout details in logs<\/strong> \u2014 see which email and payment method bots tried to use<\/li>\n<li><strong>Customer blocklist<\/strong> \u2014 block repeat offenders by email, name, address, phone, IP, or postal code<\/li>\n<li><strong>One-click order blocking<\/strong> \u2014 block a customer directly from any order screen<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/carticy.com\/plugins\/checkout-shield-for-woocommerce\/\">Learn more about Pro features<\/a><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/carticy-checkout-shield-for-woocommerce\/<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Open your own checkout page and submit it once<\/li>\n<\/ol>\n\n<p>That third step is what arms it. Until one checkout on your store has been seen\nworking, nothing is blocked \u2014 that is deliberate, so that switching protection on\ncan never turn every customer away. The order does not have to complete; a\nsubmission that WooCommerce rejects for any other reason still arms it. Your\ndashboard says which of the two states the store is in.<\/p>\n\n<p>Optional: Go to WooCommerce \u2192 Settings \u2192 Advanced \u2192 Checkout Shield to adjust settings.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 6.0+<\/li>\n<li>WooCommerce 8.0+<\/li>\n<li>PHP 8.0+<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20slow%20down%20checkout%3F\"><h3>Does this slow down checkout?<\/h3><\/dt>\n<dd><p>No. Validation happens locally in microseconds. No external API calls, no waiting on third-party services.<\/p><\/dd>\n<dt id=\"will%20this%20block%20real%20customers%3F\"><h3>Will this block real customers?<\/h3><\/dt>\n<dd><p>It is built so it cannot. Before blocking anything it waits until it has seen a\ncheckout on your store carry its proof successfully. After that it watches its\nown proof: if a theme update or a page builder ever rebuilds your checkout so\nthe proof stops rendering on it, the plugin notices that on its own, keeps\nletting real shoppers through on the cookie their browser holds, and shows you\nan admin notice saying exactly what to fix \u2014 while your store keeps selling.\nIf you still want to watch first, Learning mode logs what would be blocked\nwithout blocking anyone.<\/p><\/dd>\n<dt id=\"i%20sent%20a%20test%20bot%20request%20and%20it%20went%20through.%20is%20it%20broken%3F\"><h3>I sent a test bot request and it went through. Is it broken?<\/h3><\/dt>\n<dd><p>Almost certainly not. Protection stays inactive until one checkout on your store\nhas been seen working, so a test request sent before that will pass. Open your\nown checkout page and submit it once, then try your test again. Your dashboard\nsays which state the store is in.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20block%20checkout%3F\"><h3>Does it work with Block Checkout?<\/h3><\/dt>\n<dd><p>Yes. Works with both classic checkout and the newer block-based checkout.<\/p><\/dd>\n<dt id=\"what%20about%20paypal%2C%20stripe%2C%20and%20other%20payment%20gateways%3F\"><h3>What about PayPal, Stripe, and other payment gateways?<\/h3><\/dt>\n<dd><p>All major gateways work normally. Payment confirmations from gateways aren't affected by checkout validation.<\/p><\/dd>\n<dt id=\"i%20run%20a%20headless%20store.%20will%20this%20break%20my%20setup%3F\"><h3>I run a headless store. Will this break my setup?<\/h3><\/dt>\n<dd><p>Not if you configure it. Add your frontend's server IP to the whitelist, or use API key authentication. Both options let legitimate automated requests through.<\/p><\/dd>\n<dt id=\"do%20i%20still%20need%20captcha%3F\"><h3>Do I still need CAPTCHA?<\/h3><\/dt>\n<dd><p>Up to you. This plugin catches bots that CAPTCHA misses (the ones hitting your API directly). You can use both together, or drop CAPTCHA entirely to reduce checkout friction.<\/p><\/dd>\n<dt id=\"i%27m%20still%20getting%20spam%20orders%20with%20this%20active.%20why%3F\"><h3>I'm still getting spam orders with this active. Why?<\/h3><\/dt>\n<dd><p>Two causes, and the dashboard tells you which one you have.<\/p>\n\n<p><strong>Something is reusing one checkout visit.<\/strong> It loaded your checkout page for\nreal and is reusing the proof it was given. That proof is valid, so this plugin\npasses it, exactly as it would for a shopper who retried a declined card. Look\nat \"Repeated payment failures from one checkout visit\" on the dashboard widget:\nseveral failures against a single visit inside a day is what card testing looks\nlike. You can set a limit under WooCommerce, Settings, Advanced, Checkout Shield\nto turn those submissions away, and a bot mitigation service in front of the\nsite is the layer that stops them arriving at all.<\/p>\n\n<p><strong>The orders were never placed through your checkout at all.<\/strong> If someone has\ngained access to your WordPress they can create orders directly, and no plugin\nthat inspects checkout submissions can see that happen. Signs worth checking are\nadministrator accounts you do not recognise, posts you did not publish, and\nrecently modified plugin or theme files.<\/p>\n\n<p>Neither case means protection is off. Check the \"blocked\" count on the dashboard\nwidget to see what it is stopping.<\/p><\/dd>\n<dt id=\"how%20do%20i%20know%20it%27s%20working%3F\"><h3>How do I know it's working?<\/h3><\/dt>\n<dd><p>The dashboard widget is the quick answer. It tells you whether protection is\narmed yet, and counts what happened: blocked, passed, and not checked. \"Not\nchecked\" means a submission was let through because the check was not yet\ntrustworthy \u2014 it is separated from \"passed\" on purpose, so a bot-shaped request\nis never counted as a happy customer.<\/p>\n\n<p>For the detail behind any of it, go to WooCommerce \u2192 Status \u2192 Logs and filter by\n\"carticy-checkout-shield\".<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Fixed: a sustained card-testing attack could switch protection off. The safety net that stands down when your checkout genuinely cannot carry its proof was reading a run of failed checks as the signal \u2014 and an attack is a run of failed checks, so enough junk requests during a quiet hour could disarm protection, and the bots that followed were waved through. Protection now stays armed no matter what is thrown at it.<\/li>\n<li>The safety net itself is smarter, not gone: the plugin now watches its own proof render onto your checkout page. If a theme update or page builder ever rebuilds your checkout so the proof stops rendering, it detects that directly, keeps letting real shoppers through on the cookie their browser holds, and shows an admin notice saying what to fix. Bots cannot fake that condition \u2014 loading your checkout page to imitate a shopper is exactly what proves the checkout still works.<\/li>\n<li>Log entries for submissions that were let through without a full check now name the exact reason, so support can read what happened instead of guessing.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Your dashboard now shows when several payments failed from a single checkout visit, which is what card testing looks like, and warns you while it is still happening.<\/li>\n<li>You can now choose to turn away submissions from a checkout visit whose payments keep failing. It is off unless you set a limit, because a trade counter or a gateway declining honest cards can look the same.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>For new stores, the dashboard widget now says when protection is not blocking immediately. It waits until it has seen one checkout on your store work before it blocks anything.<\/li>\n<li>Added a separate \"not checked\" count.<\/li>\n<li>Clearer setup instructions.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Stronger bot detection: checkout proof is now issued and signed by your site rather than created in the browser<\/li>\n<li>Fewer false positives \u2014 cookie-blocking browsers, a second checkout tab, a page left open, and JavaScript errors elsewhere on the page no longer stop a genuine order<\/li>\n<li>Protection now calibrates itself and pauses automatically if proof stops reaching your checkout, resuming on its own<\/li>\n<li>Added an admin notice whenever protection pauses, so it is never off without you knowing<\/li>\n<li>Improved Strict and Permissive modes, with clearer descriptions in settings<\/li>\n<li>Paying for an order from an emailed payment link now works in every mode<\/li>\n<li>Lighter checkout page: removed a redundant client-side watcher and a duplicate hidden field<\/li>\n<li>Blocked attempts now report what the submission was missing, and the dashboard stores only the details it displays<\/li>\n<li>Improved reliability on newly installed sites and restored backups<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed unescaped Unicode characters appearing as raw escape sequences in admin labels and placeholders (Pro)<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Default mode changed to Balanced (was Learning)<\/li>\n<li>Added smart logging with 3 levels: off, blocks only, and detailed (Pro)<\/li>\n<li>Added recent blocks feed on the dashboard showing last 50 blocked attempts (Pro)<\/li>\n<li>Added automatic CDN\/proxy detection for Cloudflare, Sucuri, and Akamai (Pro)<\/li>\n<li>Added enhanced permissive mode with referrer verification (Pro)<\/li>\n<li>Added checkout details (email, payment method) in log entries (Pro)<\/li>\n<li>Added one-click order blocking from any order screen (Pro)<\/li>\n<li>Added upgrade prompts for Pro features<\/li>\n<li>Improved plugin title and description for better discoverability<\/li>\n<li>Removed \"Carticy\" from user-facing plugin name<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Bot detection for checkout protection<\/li>\n<li>Four protection modes (learning, permissive, balanced, strict)<\/li>\n<li>IP whitelist with CIDR support<\/li>\n<li>API key authentication for headless checkout<\/li>\n<li>Proxy\/CDN support<\/li>\n<li>WooCommerce logging integration<\/li>\n<li>Dashboard statistics widget<\/li>\n<li>Orders list shield status column<\/li>\n<li>HPOS compatibility<\/li>\n<li>Block checkout compatibility<\/li>\n<\/ul>","raw_excerpt":"Blocks scripted checkout submissions that never loaded your checkout page, including the card testing bots that skip CAPTCHA.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/276707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=276707"}],"author":[{"embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/carticy"}],"wp:attachment":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=276707"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=276707"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=276707"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=276707"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=276707"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=276707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}