Fraud prevention that catches what your gateway misses.
Gatekeep detects card testing attacks on WooCommerce by correlating payment attempts across orders — not one at a time. Your gateway approves or declines a single transaction. Gatekeep watches the pattern those declines make.
Last updated: August 2026 · Written & verified by the GatekeepWP team
Measured against an attacker who knew the thresholds.
We red-teamed our own detector with full knowledge of its source. These are the results, including the one we could not beat.
| Attack | Caught at |
|---|---|
| One card under many email addresses | 3rd attempt |
| Several cards from one buyer, no completed sale | 3rd attempt |
| Slow drip — one card every 25 hours | 8th attempt |
| Aged “trusted” account, then a burst | 13th attempt |
| Fresh IP, email and card every time | Blocked on a quiet shop, flagged on a busy one |
| Fully rotated and one card a day | Not caught — stated openly |
That last pattern is indistinguishable from a quiet legitimate shop without pooling data across sites, which we do not do. It ships as a scenario in the testing lab so you can see the limit yourself.
It cannot fire while your shop is selling.
Every rule is gated on whether sales are completing in the same window — so a trading shop is excluded by that fact, which matters most on the day a false block would cost you the most.
A 300-order Black Friday rush
Verified: a genuine flash-sale spike with a normal decline rate is untouched.
Subscription dunning
Dozens of renewals failing the same morning, from customers who have already bought.
The nervous buyer
Three declines on one card before it works. One card is never many cards.
A second card
The first expired, the second works. Ordinary, and treated as such.
A shared family card
Two addresses, one card, in a household. Not the shape of a rotation run.
Your returning customers
Anyone with purchase history is exempt from the counts that trigger a block.
Rehearse an attack without touching a card.
Card testing is the one protection you cannot verify by using it — testing it for real means pushing card numbers through your own checkout, which is the attack.
It writes the pattern, not the payment
The lab creates the attempt rows an attack would leave, runs the real detector over them, scores it, then deletes them. No card, no gateway, no payment.
It tells you if your gateway is blind
Stripe does not expose a card fingerprint the way most merchants assume. The lab reports whether card-level rules are live on your shop or whether it is running on velocity signals alone.
It can score your real traffic
Replay your own recent declining identities in dry-run to answer the other question: is anything already happening to me?
Nothing leaves your site. Including the hard cases.
Most fraud tools work by sending your customers' details to a shared reputation network. That is genuinely more powerful — it is the only thing that catches the slow rotating attacker above — and it also turns your buyers' addresses, emails and order history into somebody else's dataset.
We chose the other side. Detection happens in your database, identities are hashed, and the price is one attack pattern we tell you about openly rather than quietly failing to catch.
Install and licence
Gatekeep free, then the Pro companion. No account with us required for the free engine.
Run Monitor Mode
Records verdicts without blocking, so you can watch it against your own traffic for a week first.
Rehearse in the lab
Fire the attack scenarios at your own shop and read the reasoning behind each verdict.
Let it act
One switch. And one more to release every cooldown if you ever need to open the gates.
Before you buy.
No — it sits in front of them. Gateway rules judge one transaction; this judges the pattern across many. Most shops want both, and they catch different things.
It is built not to, and the specific cases it was tested against are listed on this page. Every rule requires near-zero completed sales in the same window, so a shop that is trading normally is excluded. Monitor Mode lets you confirm that on your own traffic before it blocks anything.
Yes, with one caveat we would rather state up front. Stripe does not record a card fingerprint on the order, so card-level rules read WooCommerce's own saved payment tokens instead. Where those are unavailable, detection runs on velocity signals. The built-in lab tells you which mode your shop is in rather than letting you assume.
It reads WooCommerce's own payment token data rather than any one gateway's private fields, so it is gateway-agnostic: Stripe, PayPal, Braintree, Square and PPCP all work. There is a filter for anything unusual.
No. Identities are hashed locally and nothing is transmitted anywhere. That is the deliberate trade described above — it costs us one class of attack and it means your order data stays yours.
No. It hooks the order lifecycle, not your templates — nothing visible is added to the checkout and buyers see no extra step.
Stop the run before the chargebacks.
Card testing detection is part of Gatekeep Pro, alongside the anti-spam engine that protects your forms, logins and registrations.