This is an info Alert.
xpay
  • Product
    • Become Agent-Ready
      • Merchants
        Agentic Commerce — list your store across ChatGPT, Gemini, Claude & Perplexity
      • Publishers
        Monetize your content when AI agents read, cite, or train on it
      • SaaS Companies
        Treat AI agents as first-class customers with agent-priced checkout
    • Monetize
      • Monetize MCP Server
        Charge per call on any MCP server in 2 minutes
      • Monetize AI Agents
        Turn n8n, Zapier, Activepieces workflows into revenue
  • Resources
    • xpay Ecosystem
      • xpay✦ Tools
        1,000+ pay-per-use tools for your AI agents
      • Agent-Ready SaaS Index
        25,481 SaaS scored on agent-buyability
      • SaaS Pricing Database
        Pricing pages indexed across 1,000+ categories
      • Shopify Apps Directory
        Every Shopify app, with its full review history
      • WooCommerce Plugins Directory
        Every WooCommerce plugin, scored on how well it is maintained
      • GitHub
        Open source repositories
    • Agent Building
      • Agent Frameworks
        AI frameworks for building multi-agent systems
      • x402 Integration
        AI frameworks with x402 payment integration
      • Networks
        Blockchain networks supporting x402
    • Company
      • About xpay✦
        Our mission, products, and protocols
      • Blog
        Latest insights and updates
      • Docs
        Complete xpay documentation
  • Pricing
  • Blog
  • Docs
Get Started
  1. xpay✦ Commerce

  2. Directory

  3. WooCommerce plugins

  4. Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing

Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing

Blocks scripted checkout attempts that never loaded your checkout page, including card testing bots that skip CAPTCHA. Classic and block checkout.

300+ active installs
5.0
(5 ratings)
Free on WordPress.org
View on WordPress.orgSupport forum
Will this break my store?

What the WordPress.org registry says about keeping Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing running.

WordPress compatibility
Tested to 7.1
Tested against the WordPress branch in use today.
Last updated
15 days ago
At least 12.6 releases a year since launch. WordPress.org only lists versions still available for download, so the real number may be higher.
Requires PHP
8.0
Your host must be running at least this version.
Requires WordPress
6.0
Requires other plugins
woocommerce
These must be installed and active first.
Contributors
2

300+ active installsWordPress.org reports installs in bands, not exact counts.
Maintenance & trust

Scored on how Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing is looked after — not on how many stores run it.

96

out of 100
Well maintainedSome ratings or support history.

Maintenance
35 / 35
Updated 3 days ago.
WordPress compatibility
20 / 20
Tested to WP 7.1 (current).
Support responsiveness
Not enough data
Only 0 support thread(s) — not enough to judge.
Merchant satisfaction
12 / 15
5.0/5 across 5 rating(s).
Listing transparency
10 / 10
Provides: screenshots, description, homepage
1 of 5 measures had too little evidence to score. They are left out of the total rather than counted as zero — otherwise a plugin would be marked down for being small rather than for being poorly kept.Measured 2026-09-02 from the WordPress.org plugin registry.
Ratings

5.0

5 ratings
5★5
4★0
3★0
2★0
1★0
Every rating WordPress.org holds for this plugin, not a sample. Written reviews live in the plugin's WordPress.org reviews forum.

Checkout Shield blocks the scripted checkout submissions that CAPTCHA never sees.

Card testing bots don’t fill out your checkout form. They hit your store’s checkout API directly, completely skipping any reCAPTCHA or hCaptcha you’ve set up. That’s why CAPTCHA alone doesn’t stop them.

Your site signs a proof into the checkout page it serves. A submission that carries that proof loaded the page; one that doesn’t, didn’t. Submissions with no valid proof are stopped before WooCommerce processes the order.

What this stops, and what it does not

Being straight about this is more useful than a bigger promise.

It stops anything that posts to your checkout without loading the checkout page first: curl scripts, direct Store API calls, replayed form posts, and the card testing runs that work this way. This is the large majority of automated checkout abuse, and it is the part CAPTCHA misses.

It does not stop a bot that drives a real browser. Something that genuinely loads your checkout page receives a genuine proof, because that is exactly what the proof records. Once loaded, that proof stays valid for the life of the shopping session, so a script can reuse it. No proof of this kind can tell the second submission from the first, since the thing being proven is identical.

For that tier you want a bot mitigation service in front of the site (Cloudflare Bot Fight Mode, Sucuri) alongside this plugin. What this plugin can do is show you when it is happening: the dashboard reports payments that failed repeatedly from a single checkout visit, which is what working through stolen card numbers looks like. In Pro it can also act on it. Once a visit crosses a failure limit you set, the source IP is banned for a while so it can’t just start a fresh visit and keep going, and the ban lifts itself, so a bad guess never becomes a permanent lock-out. A determined attacker can still rotate IPs, which is why the service in front of the site stays the front line, but for the common case this turns the pattern off at the source.

Why Store Owners Choose This Plugin

  • Catches what CAPTCHA misses: blocks bots hitting your checkout API directly, without asking shoppers to prove anything
  • Works with any caching: LiteSpeed, Cloudflare, WP Rocket and W3TC, with no conflicts
  • Nothing to configure: no rules to write and no thresholds to tune
  • Never blocks your customers by mistake: it only starts once it has seen a real checkout on your store work, and if your theme ever stops carrying the proof it detects that, keeps letting real shoppers through, and tells you what to fix
  • No external services: everything runs on your server, no subscriptions
  • Adds milliseconds: the check is local, with no third-party call to wait on

Features (Free)

  • Automatic bot blocking: no rules to configure; it arms itself once it has seen one checkout on your store work
  • 4 protection levels: Learning, Permissive, Balanced and Strict, so you choose how aggressive you want to be
  • One place for everything: a dedicated Checkout Shield screen with a live “what’s protected right now” overview, plus your settings and logs
  • Dashboard overview: see blocked vs verified orders at a glance with a 7-day chart
  • Order status tracking: know which orders were flagged, passed, or blocked
  • IP whitelist: let trusted addresses through, supports CIDR notation
  • API key authentication: for headless and custom checkout setups
  • Works with all checkout types: classic, block-based, and all payment gateways
  • HPOS compatible: works with High-Performance Order Storage
  • WooCommerce logging: full integration with WooCommerce Status logs

Pro Features

Pro is about two things: stopping more, and letting you see it happen.

  • Live attack timeline: watch scripted attempts get stopped as they arrive, with the surface, reason, masked email, and IP for each one
  • Test your protection: one button fires the real card-testing request at your own store and shows you it hit a wall, so you never have to wonder whether it’s working
  • Auto-ban repeat offenders: when one visit keeps failing payment past a limit you set, its IP is blocked for a while and then released on its own, so it can’t just start over
  • Registration protection: the same no-CAPTCHA proof on your sign-up forms, plus throwaway-email blocking and per-IP rate limiting, to stop the fake accounts that come before fraud
  • Throwaway email blocking: reject checkouts using a known disposable inbox, with a domain list the plugin keeps up to date for you
  • 3-level logging control: turn logging off, log blocked attempts only, or log everything
  • Recent blocks feed: the last 50 blocked attempts with email, payment method, and reason
  • Automatic CDN/proxy detection: identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai
  • Stronger permissive mode: tighter bot detection with referrer and user-agent checks
  • Checkout details in logs: see which email and payment method bots tried to use
  • Customer blocklist: block repeat offenders by email, name, address, phone, IP, or postal code, all managed from the Checkout Shield screen
  • One-click order blocking: block a customer directly from any order screen

Learn more about Pro features

Does this slow down checkout?

No. Validation happens locally in microseconds. No external API calls, no waiting on third-party services.

Will this block real customers?

It is built so it cannot. Before blocking anything it waits until it has seen a
checkout on your store carry its proof successfully. After that it watches its
own proof: if a theme update or a page builder ever rebuilds your checkout so
the proof stops rendering on it, the plugin notices that on its own, keeps
letting real shoppers through on the cookie their browser holds, and shows you
an admin notice saying exactly what to fix, all while your store keeps selling.
If you still want to watch first, Learning mode logs what would be blocked
without blocking anyone.

The Pro protections are built the same careful way. Auto-banning is off until
you turn it on, only ever kicks in past a failure limit you set, never touches a
whitelisted address, and every ban expires by itself. Registration protection
lets a real browser through on its proof and only stops sign-ups that never
loaded the form, so a shared office or campus connection can’t be locked out by
a busy afternoon.

I sent a test bot request and it went through. Is it broken?

Almost certainly not. Protection stays inactive until one checkout on your store
has been seen working, so a test request sent before that will pass. Open your
own checkout page and submit it once, then try your test again. Your dashboard
says which state the store is in.

Does it work with Block Checkout?

Yes. Works with both classic checkout and the newer block-based checkout.

What about PayPal, Stripe, and other payment gateways?

All major gateways work normally. Payment confirmations from gateways aren’t affected by checkout validation.

I run a headless store. Will this break my setup?

Not if you configure it. Add your frontend’s server IP to the whitelist, or use API key authentication. Both options let legitimate automated requests through.

Do I still need CAPTCHA?

Up to you. This plugin catches bots that CAPTCHA misses (the ones hitting your API directly). You can use both together, or drop CAPTCHA entirely to reduce checkout friction.

I’m still getting spam orders with this active. Why?

Two causes, and the dashboard tells you which one you have.

Something is reusing one checkout visit. It loaded your checkout page for
real and is reusing the proof it was given. That proof is valid, so this plugin
passes it, exactly as it would for a shopper who retried a declined card. Look
at “Repeated payment failures from one checkout visit” on the dashboard widget:
several failures against a single visit inside a day is what card testing looks
like. Open the Checkout Shield menu, then Settings, to set a limit that turns
those submissions away, and in Pro have the source IP banned for a while once it
does. A bot mitigation service in front of the site is the layer that stops them
arriving at all.

The orders were never placed through your checkout at all. If someone has
gained access to your WordPress they can create orders directly, and no plugin
that inspects checkout submissions can see that happen. Signs worth checking are
administrator accounts you do not recognise, posts you did not publish, and
recently modified plugin or theme files.

Neither case means protection is off. Check the “blocked” count on the dashboard
widget to see what it is stopping.

How do I know it’s working?

The Checkout Shield screen is the quick answer. Its Overview tells you whether
protection is armed yet and how many attempts it has stopped, updating as they
happen, and the same figures appear on the dashboard widget. It counts what
happened three ways: blocked, passed, and not checked. “Not checked” means a
submission was let through because the check was not yet trustworthy. That is
kept separate from “passed” on purpose, so a bot-shaped request is never counted
as a happy customer.

In Pro, the Activity tab lists each blocked attempt as it lands, and the
Protection Test button lets you fire a real one at your own store and watch it
get stopped. For the raw detail behind any of it, go to WooCommerce, then Status,
then Logs, and filter by “carticy-checkout-shield”.

Categories
CheckoutSecurity & spam
Plugin details
Version1.4.0
Last updated2026-08-30 9:46am GMT
Added2026-01-25
Requires WordPress6.0
Tested up to7.1
Requires PHP8.0

Tags on WordPress.org
bot protection
checkout
fraud
security
woocommerce
Alternatives
Other plugins in the same categories.
Checkout Field Editor (Checkout Manager) for WooCommerce
400K+ installs
4.9(1,056)
Fluid Checkout for WooCommerce – Lite
20K+ installs
4.9(159)
Wallet for WooCommerce
20K+ installs
4.7(188)
Sliding Cart for WooCommerce by FunnelKit – Skip Cart & Reach WooCommerce Checkout Faster
30K+ installs
5.0(109)
YayPricing – WooCommerce Dynamic Pricing & Discounts
3K+ installs
5.0(72)
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
5K+ installs
4.9(174)
xpay

The agent-readiness stack for the AI shopping era — helping merchants, publishers and SaaS companies get discovered, cited and transacted with by ChatGPT, Perplexity, Claude, Gemini and the custom shopping agents underneath them.

CompanyAgentically Inc. (d/b/a xpay✦)1875 Mission St, Ste 103San Francisco, CA 94103, United Stateslegal@xpay.sh · privacy@xpay.sh
or ask your AI app
Company
About xpayAgency PartnersGitHubDiscordllms.txt
DevelopersDocumentationAPI ReferenceSDKs & LibrariesQuickstart GuideOpenAPI Spec
Stay Updated
Occasional product updates and agent-readiness playbooks from xpay (Agentically Inc.) — typically a couple of emails a month. Double opt-in: we email you a link to confirm before sending anything, and every email has one-click unsubscribe.
Social
  • For Publishers
    • News
    • Finance
    • Dev / Tech
    • Travel
    • View all verticals
  • Agent-Ready Index
    • SaaS Pricing Database
    • Agent-Ready SaaS Index
    • Verified band
    • AI & ML
    • Sales & CRM
  • Products
    • Pricing Widget
    • Monetize MCP Server
    • Paywall
    • Smart Proxy
    • Monetize AI Agents
    • xpay x402 Facilitator
  • Agentic Economy
    • Timeline
    • Resources
    • Manifesto
    • Stack
  • Agentic Commerce
    • Get listed
    • ChatGPT Ads
    • How ChatGPT Ads work
    • ChatGPT Ads · Apparel
    • ChatGPT Ads · Health & Beauty
    • xpay Listings · Amazon + Google
    • Pricing
    • Free audit
    • Shopify
    • WooCommerce
    • Apparel & Accessories
    • Health & Beauty
    • Overview
  • Commerce Index
    • Shopify apps directory
    • Agentic Commerce Ready Index
    • Methodology
    • Pet brands · WooCommerce
    • Pet brands · Shopify
  • Marketplace
    • 🛍️ xpay.deals — agentic storefront for deals
  • Protocols
    • Overview
    • x402
    • MPP
    • UCP
    • ACP
    • AP2
    • TAP
    • A2A
  • Agent Frameworks
    • Overview
    • LangChain
    • CrewAI
    • Claude MCP
    • AutoGPT
    • LangChain vs Mastra
    • LangGraph vs Pydantic AI
  • Company
    • About xpay
    • Blog
    • Docs
    • GitHub
  • Free prompts
    • Ecommerce prompts
    • Email marketing prompts
    • Product description prompts
    • Facebook ad prompts
    • Skincare prompts
    • Supplement prompts
    • Wine prompts
    • Electronics prompts

© 2025 Agentically Inc. All rights reserved.
Privacy PolicyTerms of UseAcceptable Use Policy