Skip to content
Home PricingFree forever, paid adds live intelligence Akismet alternative reCAPTCHA alternative All comparisons IntegrationsAll 33, and how each one is protected WooCommerce protection Contact Form 7 Elementor Documentation Sign in
WooCommerce fraud prevention

Fraud prevention that catches what your gateway misses.

Gatekeep detects card testing attacks on WooCommerce by correlating payment attempts across orders — not one at a time. Your gateway approves or declines a single transaction. Gatekeep watches the pattern those declines make.

Quick answer: Gatekeep Pro is a WooCommerce fraud prevention plugin that stops card testing and carding attacks by scoring an identity across orders — distinct cards, fresh identities, and no completed sales. Detection runs in your own database and no customer data leaves your site.
Nothing sent to third parties·Gateway-agnostic·30-day money-back

Last updated: August 2026 · Written & verified by the GatekeepWP team

What it catches

Measured against an attacker who knew the thresholds.

We red-teamed our own detector with full knowledge of its source. These are the results, including the one we could not beat.

AttackCaught at
One card under many email addresses3rd attempt
Several cards from one buyer, no completed sale3rd attempt
Slow drip — one card every 25 hours8th attempt
Aged “trusted” account, then a burst13th attempt
Fresh IP, email and card every timeBlocked on a quiet shop, flagged on a busy one
Fully rotated and one card a dayNot caught — stated openly

That last pattern is indistinguishable from a quiet legitimate shop without pooling data across sites, which we do not do. It ships as a scenario in the testing lab so you can see the limit yourself.

What it leaves alone

It cannot fire while your shop is selling.

Every rule is gated on whether sales are completing in the same window — so a trading shop is excluded by that fact, which matters most on the day a false block would cost you the most.

A 300-order Black Friday rush

Verified: a genuine flash-sale spike with a normal decline rate is untouched.

Subscription dunning

Dozens of renewals failing the same morning, from customers who have already bought.

The nervous buyer

Three declines on one card before it works. One card is never many cards.

A second card

The first expired, the second works. Ordinary, and treated as such.

A shared family card

Two addresses, one card, in a household. Not the shape of a rotation run.

Your returning customers

Anyone with purchase history is exempt from the counts that trigger a block.

The testing lab

Rehearse an attack without touching a card.

Card testing is the one protection you cannot verify by using it — testing it for real means pushing card numbers through your own checkout, which is the attack.

It writes the pattern, not the payment

The lab creates the attempt rows an attack would leave, runs the real detector over them, scores it, then deletes them. No card, no gateway, no payment.

It tells you if your gateway is blind

Stripe does not expose a card fingerprint the way most merchants assume. The lab reports whether card-level rules are live on your shop or whether it is running on velocity signals alone.

It can score your real traffic

Replay your own recent declining identities in dry-run to answer the other question: is anything already happening to me?

The trade we made

Nothing leaves your site. Including the hard cases.

Most fraud tools work by sending your customers' details to a shared reputation network. That is genuinely more powerful — it is the only thing that catches the slow rotating attacker above — and it also turns your buyers' addresses, emails and order history into somebody else's dataset.

We chose the other side. Detection happens in your database, identities are hashed, and the price is one attack pattern we tell you about openly rather than quietly failing to catch.

01

Install and licence

Gatekeep free, then the Pro companion. No account with us required for the free engine.

02

Run Monitor Mode

Records verdicts without blocking, so you can watch it against your own traffic for a week first.

03

Rehearse in the lab

Fire the attack scenarios at your own shop and read the reasoning behind each verdict.

04

Let it act

One switch. And one more to release every cooldown if you ever need to open the gates.

Questions

Before you buy.

No — it sits in front of them. Gateway rules judge one transaction; this judges the pattern across many. Most shops want both, and they catch different things.

It is built not to, and the specific cases it was tested against are listed on this page. Every rule requires near-zero completed sales in the same window, so a shop that is trading normally is excluded. Monitor Mode lets you confirm that on your own traffic before it blocks anything.

Yes, with one caveat we would rather state up front. Stripe does not record a card fingerprint on the order, so card-level rules read WooCommerce's own saved payment tokens instead. Where those are unavailable, detection runs on velocity signals. The built-in lab tells you which mode your shop is in rather than letting you assume.

It reads WooCommerce's own payment token data rather than any one gateway's private fields, so it is gateway-agnostic: Stripe, PayPal, Braintree, Square and PPCP all work. There is a filter for anything unusual.

No. Identities are hashed locally and nothing is transmitted anywhere. That is the deliberate trade described above — it costs us one class of attack and it means your order data stays yours.

No. It hooks the order lifecycle, not your templates — nothing visible is added to the checkout and buyers see no extra step.

Stop the run before the chargebacks.

Card testing detection is part of Gatekeep Pro, alongside the anti-spam engine that protects your forms, logins and registrations.

Free plugin forever·No visitor data sent anywhere·30-day money-back