Preventing spam and fraudulent orders in WooCommerce
Practical measures for reducing fake orders in WooCommerce, including account settings, CAPTCHA, checkout rate limiting and working with your payment provider's fraud tools.
Fake orders are a common problem for WooCommerce stores. They waste time, tie up stock, skew your figures and can lead to disputes with your payment provider.
Most spam orders come from bots: automated scripts that submit the checkout over and over, often to test whether stolen card numbers work. This is known as card testing. Others are one-off attempts to place a real-looking order with stolen card details. This guide covers the WooCommerce and WordPress side of reducing both. Decisions about individual payments, refunds and disputes are for you and your payment provider, who will have their own guidance and tools.
Card testing usually leaves a trail of unpaid orders sitting on Pending payment or Failed. If you're not sure whether pending orders are spam or genuine payments that got stuck, our guide to orders stuck on Pending payment explains how to tell the difference.
If you're under attack right now
If you're seeing a sudden flood of failed or suspicious orders, WooCommerce's own guidance for an active card testing attack includes contacting your payment provider so they can tighten security on your account, temporarily switching off guest checkout and temporarily hiding low-priced or "pay what you want" products, which attackers favour.1
It also says to review the transactions and refund any you believe are fraudulent, to help avoid disputes.1 Which payments to refund is a decision to make with your payment provider, since they can see information about each payment that WooCommerce can't.
Tighten account and checkout settings
Under WooCommerce → Settings → Accounts & Privacy, the Enable guest checkout option controls whether people can order without an account. Turning it off means every order needs an account first, which adds a step for bots.2 It also adds a step for real customers, so whether it's worth it depends on how much spam you're getting. Some stores only turn it off during an attack.
Add CAPTCHA to checkout and registration
CAPTCHA checks try to tell humans and bots apart before a form can be submitted. WooCommerce's guidance on card testing recommends adding one to your checkout, and lists plugins supporting Google reCAPTCHA and Cloudflare Turnstile.1 Adding one to your login and registration forms helps too.
You'll need to create a site key and secret key in the CAPTCHA provider's dashboard and enter them in the plugin's settings. Check which checkout your store uses first. Stores set up since WooCommerce 8.3 use the Checkout block by default,3 and some CAPTCHA plugins only support the older shortcode checkout.
Test your checkout thoroughly after adding CAPTCHA. Some setups interfere with the payment step or with certain themes, and some visitors (including people using assistive technology) find certain CAPTCHAs difficult. Check a real customer can still complete an order.
Turn on checkout rate limiting
If your store uses the Checkout block, WooCommerce has built-in rate limiting that you can switch on under WooCommerce → Settings → Advanced → Features, called "Rate limiting Checkout block and Store API". When it's on, the Place Order step is limited to 3 attempts per 60 seconds.4
It limits guests by IP address and logged-in customers by account, so it slows attacks down rather than stopping them completely, particularly attacks that keep changing IP address.4 Treat it as one layer alongside the others. If several of your customers share an office or public network, check they aren't being caught by it.
Use your payment provider's fraud tools
Most of the useful fraud checks happen at your payment provider rather than in WooCommerce. Depending on your provider, these may include checking the card's security code (CVV/CVC), checking the billing address and postcode against the card issuer's records and automatic risk scoring that blocks or flags suspicious payments.
What's available, and how strict to make it, varies between providers and depends on your business, so ask your payment provider which checks are active on your account and what they recommend. WooCommerce's guidance also suggests turning off saved card payments if your payment method supports that setting, since attackers can abuse them.1
Consider an anti-fraud extension
For stores dealing with persistent fraud, WooCommerce lists anti-fraud extensions that can score orders on risk factors and hold or block the riskiest ones based on rules you set.1 Start with gentle rules and tighten them gradually, so you don't block genuine customers. How to deal with orders these tools flag is a decision for you, ideally informed by your payment provider's advice.
Block repeat offenders
If spam keeps coming from particular IP addresses or ranges, you can block them through your host's firewall, a service like Cloudflare or your security plugin. Blocking at the firewall stops the requests reaching WordPress at all. Keep a note of what you block, so you can remove a rule quickly if it turns out to catch real customers. Our guide to dealing with WordPress spam covers blocking abusive traffic across the rest of your site.
Keep your software updated
Outdated versions of WooCommerce, WordPress and payment extensions can have known security problems that attackers exploit. Keeping everything updated is a basic but important layer of defence. Take a backup before updating, and test your checkout afterwards. Our guide to handling a plugin security vulnerability explains how to judge how urgent each update is.
Need help with WooCommerce fraud prevention?
If spam or fraudulent orders are a persistent problem and you'd like help setting up your store's defences, my WooCommerce and WordPress development and emergency WordPress support cover WooCommerce security settings, CAPTCHA and plugin setup. For anything about specific payments, refunds or disputes, your payment provider is the right contact.
How do I prevent and respond to card testing attacks?, WooCommerce. ↩ ↩ ↩ ↩ ↩
class-wc-settings-accounts.php, WooCommerce source code on GitHub. ↩
FAQ: Cart and Checkout Blocks by Default, WooCommerce Developer Blog, 6 November 2023. ↩
Rate limiting for Store API endpoints, WooCommerce Developer Docs. ↩ ↩