xpay✦ Commerce
Directory
WooCommerce plugins
Velocity Guard for WooCommerce – Fraud Protection, Stop Fake Orders & Card Testing
Velocity Guard for WooCommerce – Fraud Protection, Stop Fake Orders & Card Testing
Stop fake orders, card testing attacks, and checkout bots on WooCommerce. Blocks the bots flooding your store with stolen-card $1 charges.
Will this break my store?
What the WordPress.org registry says about keeping Velocity Guard for WooCommerce – Fraud Protection, Stop Fake Orders & Card Testing running.
Tested to 7.0.2
Tested against the WordPress branch in use today.6 days ago
7.4
Your host must be running at least this version.6.4
woocommerce
These must be installed and active first.1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how Velocity Guard for WooCommerce – Fraud Protection, Stop Fake Orders & Card Testing is looked after — not on how many stores run it.
Maintenance
35 / 35WordPress compatibility
20 / 20Support responsiveness
Not enough dataMerchant satisfaction
Not enough dataListing transparency
10 / 10Ratings
No one has rated this plugin on WordPress.org yet. That is a statement about the ratings page, not about the plugin — plenty of well-kept plugins never collect them.
Stop card-testing fraud, fake orders, and checkout bots at your WooCommerce store.
Is your store getting waves of failed orders, $1 stolen-card charges, and surprise payment-processor fees? That’s a card-testing bot attack — and Velocity Guard stops it automatically.
What is card-testing? Criminals buy lists of stolen card numbers and need to find which ones still work. They do it by running hundreds of small orders through real checkouts like yours. Every attempt can cost you a processing fee, and a flood of declines can get your Stripe or PayPal account flagged or frozen. It’s automated — it can hammer your store overnight while you sleep.
What Velocity Guard does: It watches how fast orders arrive from the same shopper, email, or device. A real customer places one order; an attack tool tries dozens in minutes. When Velocity Guard sees that burst, it quietly turns away the extra attempts before they reach your payment processor — the attacker gets nothing and you don’t get billed. Genuine shoppers never notice; the limits sit well above normal buying behavior.
Set it and forget it. Install, activate, done. The defaults are tuned to be invisible to real customers, and it runs entirely on your own site with no account to create.
Under the hood, Velocity Guard tracks how many checkout attempts come from each identity (IP address, email address, session, or combination) inside a sliding time window. Once an identity crosses the configured threshold, further attempts are rejected before WooCommerce ever processes the order — including direct hits to the REST API that skip your normal checkout page. Repeated failed payments auto-blocklist the source for hours.
Free version features
- Sliding-window velocity rules per IP, email, session, or IP+email combination
- Failed-payment auto-blocklist — configurable threshold and lockout duration
- REST API endpoint coverage — protects
/wc/v3/orders,/wc/store/v1/checkout, and/wc/store/checkout(the routes modern card-testing bots target directly) - Proxy-aware IP detection — Cloudflare, Akamai, Fastly, X-Forwarded-For, X-Real-IP, with explicit admin opt-in to prevent header spoofing on sites with no upstream proxy
- Dashboard widget — blocked-attempt counts (24h / 7d / 30d) at a glance
- Event log — every block decision with rule, source IP, and detail
- Manual IP whitelist — exempt staff workstations and test cards (IPv4 + IPv6, validated)
- HPOS-native — built on WooCommerce’s High-Performance Order Storage from day one
- Compatible with classic checkout and Cart/Checkout block
Velocity Guard Pro
Pro upgrades available via the in-plugin Upgrade screen:
- Behavioural device fingerprinting — canvas + audio + envelope fingerprint, cookie-stored. Catches attackers rotating IPs but keeping the same browser. The IP rule alone misses this; fingerprint does not.
- Slack / Discord / email alerts — fires when blocks-per-window crosses your threshold. Per-channel rate limiting so a sustained attack doesn’t spam your inbox.
- Pattern library feed — rule packs sourced from active vulnerability research, applied before velocity counters. Catches obvious bot user agents (curl, headless browsers, scraping frameworks) on the first request.
- 14-day free trial, no credit card required.
A burst of failed or declined orders in a short window — especially overnight, with tiny order totals or odd email addresses — is the signature of a card-testing bot. Attackers run stolen card numbers through your live checkout to find which ones still work. Velocity Guard detects the burst (many attempts from one IP, email, or session in minutes) and turns the extra attempts away before they reach your payment processor.
Very often, yes. A flood of declined authorizations spikes your decline ratio and chargeback risk, which is exactly what gets a Stripe or PayPal account flagged or frozen. Stopping the attempts at the door keeps your decline ratio clean. Velocity Guard rejects the abnormal burst before WooCommerce ever hands the attempt to your gateway, so the declines never hit your processor stats.
Those are card-testing probes. Criminals use a small amount because it’s less likely to trip a bank’s fraud alert, and they only need to know whether the charge succeeds. Every probe can still cost you an authorization/processing fee even when it’s declined. Velocity Guard blocks the repeated attempts so you stop paying fees on fraud traffic.
Each checkout attempt that reaches your gateway can incur a fee, declined or not — so an automated attack racks up fees fast. Because Velocity Guard rejects the abnormal burst before the request reaches your payment processor, the attacker’s attempts never generate billable gateway calls.
No. Velocity Guard runs entirely on your WordPress server. The free version has no external dependencies.
The default thresholds (5 orders per IP per 10 minutes, 3 per email per hour, 3 failed payments before auto-blocklist) are tuned to be invisible to normal shoppers. Every block is logged with rule + source so you can audit and tune per-rule from the settings page. Whitelist your staff IPs to bypass entirely.
Yes. Velocity Guard protects both the classic checkout (woocommerce_checkout_process hook) and the Cart/Checkout block Store API (woocommerce_store_api_checkout_order_processed and rest_pre_dispatch for direct REST hits).
Yes, but you need to tell the plugin which header carries the real client IP. Go to WooCommerce → Velocity Guard → Reverse proxy / CDN and select your provider (Cloudflare uses CF-Connecting-IP, Akamai uses True-Client-IP, etc.). Default is REMOTE_ADDR which is the safe choice when no proxy is in front of your site.
Yes, built HPOS-native from day one. No legacy meta-table queries.
Yes. The plugin won’t activate without WooCommerce 8.0+ active.
The free version stops bots that don’t load your page (curl, scripts, direct API hits without a session cookie) and rate-limits per identity (IP / email / session). Pro adds device fingerprinting (catches attackers that rotate IPs but keep the same browser), real-time alerts, and an updatable pattern library sourced from active vulnerability research.
Velocity Guard stores: timestamps of checkout attempts, source IPs, billing emails, session identifiers, and block reasons. It does NOT store card numbers, CVCs, or any PCI-sensitive data.
Categories
Plugin details
Tags on WordPress.org
