Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing
Checkout Shield blocks the scripted checkout submissions that CAPTCHA never sees. Card testing bots don’t fill out your checkout form. They hit your store’s checkout API directly, completely skipping any reCAPTCHA or hCaptcha you’ve set up. That’s why CAPTCHA alone doesn’t stop them. Your site signs a proof into the checkout page it serves. A submission that carries that proof loaded the page; one that doesn’t, didn’t. Submissions with no valid proof are stopped before WooCommerce processes the order. What this stops, and what it does not Being straight about this is more useful than a bigger promise. It stops anything that posts to your checkout without loading the checkout page first: curl scripts, direct Store API calls, replayed form posts, and the card testing runs that work this way. This is the large majority of automated checkout abuse, and it is the part CAPTCHA misses. It does not stop a bot that drives a real browser. Something that genuinely loads your checkout page receives a genuine proof, because that is exactly what the proof records. Once loaded, that proof stays valid for the life of the shopping session, so a script can reuse it. No proof of this kind can tell the second submission from the first, since the thing being proven is identical. For that tier you want a bot mitigation service in front of the site (Cloudflare Bot Fight Mode, Sucuri) alongside this plugin. What this plugin can do is show you when it is happening: the dashboard reports payments that failed repeatedly from a single checkout visit, which is what working through stolen card numbers looks like. In Pro it can also act on it. Once a visit crosses a failure limit you set, the source IP is banned for a while so it can’t just start a fresh visit and keep going, and the ban lifts itself, so a bad guess never becomes a permanent lock-out. A determined attacker can still rotate IPs, which is why the service in front of the site stays the front line, but for the common case this turns the pattern off at the source. Why Store Owners Choose This Plugin Catches what CAPTCHA misses: blocks bots hitting your checkout API directly, without asking shoppers to prove anything Works with any caching: LiteSpeed, Cloudflare, WP Rocket and W3TC, with no conflicts Nothing to configure: no rules to write and no thresholds to tune Never blocks your customers by mistake: it only starts once it has seen a real checkout on your store work, and if your theme ever stops carrying the proof it detects that, keeps letting real shoppers through, and tells you what to fix No external services: everything runs on your server, no subscriptions Adds milliseconds: the check is local, with no third-party call to wait on Features (Free) Automatic bot blocking: no rules to configure; it arms itself once it has seen one checkout on your store work 4 protection levels: Learning, Permissive, Balanced and Strict, so you choose how aggressive you want to be One place for everything: a dedicated Checkout Shield screen with a live “what’s protected right now” overview, plus your settings and logs Dashboard overview: see blocked vs verified orders at a glance with a 7-day chart Order status tracking: know which orders were flagged, passed, or blocked IP whitelist: let trusted addresses through, supports CIDR notation API key authentication: for headless and custom checkout setups Works with all checkout types: classic, block-based, and all payment gateways HPOS compatible: works with High-Performance Order Storage WooCommerce logging: full integration with WooCommerce Status logs Pro Features Pro is about two things: stopping more, and letting you see it happen. Live attack timeline: watch scripted attempts get stopped as they arrive, with the surface, reason, masked email, and IP for each one Test your protection: one button fires the real card-testing request at your own store and shows you it hit a wall, so you never have to wonder whether it’s working Auto-ban repeat offenders: when one visit keeps failing payment past a limit you set, its IP is blocked for a while and then released on its own, so it can’t just start over Registration protection: the same no-CAPTCHA proof on your sign-up forms, plus throwaway-email blocking and per-IP rate limiting, to stop the fake accounts that come before fraud Throwaway email blocking: reject checkouts using a known disposable inbox, with a domain list the plugin keeps up to date for you 3-level logging control: turn logging off, log blocked attempts only, or log everything Recent blocks feed: the last 50 blocked attempts with email, payment method, and reason Automatic CDN/proxy detection: identifies real visitor IPs behind Cloudflare, Sucuri, or Akamai Stronger permissive mode: tighter bot detection with referrer and user-agent checks Checkout details in logs: see which email and payment method bots tried to use Customer blocklist: block repeat offenders by email, name, address, phone, IP, or postal code, all managed from the Checkout Shield screen One-click order blocking: block a customer directly from any order screen Learn more about Pro features
Top keywords
- checkout18×2.09%
- proof9×1.05%
- store6×0.70%
- blocked5×0.58%
- bot5×0.58%
- email5×0.58%
- ip5×0.58%
- order5×0.58%
- real5×0.58%
- api4×0.47%
- blocking4×0.47%
- blocks4×0.47%
Additional Terms Lite for WooCommerce
Formerly known as Woo Additional Terms, trusted by WooCommerce stores since 2017. Make sure customers actually agree to your policies before they can place an order. Additional Terms Lite for WooCommerce adds a dedicated “I agree” checkbox to your checkout so shoppers must acknowledge your refund policy, privacy notice, age restriction, delivery terms, or any other policy that matters to your store. Every acceptance is saved with the WooCommerce order, so you have a record if a question or dispute ever comes up. Setup takes about two minutes. Write your checkbox text, optionally link a policy page, decide whether it is required, and save. No coding, no page builder, no fuss. This is useful when you want to: Get explicit agreement to a specific policy at checkout. Add a second agreement alongside the default WooCommerce terms checkbox. Link the checkbox to a policy page customers can read without leaving checkout. Keep a record of what each customer accepted with their order. Reduce refund disputes, chargebacks, and avoidable support messages. Get explicit consent to your policies at checkout WooCommerce ships with a single terms and conditions checkbox tied to one page. That is fine until you need customers to explicitly agree to something specific, such as a no-refund sale, a pre-order delay, an age-restricted item, a subscription renewal, or a cash-on-delivery instruction. Additional Terms gives you that dedicated, purpose-built agreement and keeps a clear record of it on the order. You decide whether the checkbox is required, so customers cannot complete checkout until they tick the box, or you can leave it optional when you only need to surface a notice. Link and display your terms your way Point the checkbox at any policy page and drop it into the label with the {{additional-terms}} smart tag. The tag is replaced with a clickable link to that page at checkout. Customers can read the linked terms without leaving checkout. Open them in a modal, embed them directly above the checkbox, or open them in a new tab, whichever suits your store. Keep a record of every acceptance When a customer places an order, their agreement is saved to the WooCommerce order notes. That gives you a clearer record of which checkout agreement was accepted, which helps with internal review, customer support, and dispute prevention. Works with classic and block checkout On classic [woocommerce_checkout] stores, the checkbox appears right beside the standard terms area. Using the WooCommerce Checkout Block? Add the dedicated Additional Terms block inside the checkout layout and position it exactly where you want it. Built for real store situations Additional Terms Lite for WooCommerce is designed for the agreements WooCommerce merchants actually need: refund and cancellation policies, age-restricted products, pre-orders, digital downloads, subscription terms, liability waivers, warranty acknowledgements, privacy and GDPR consent, and payment-method notices for bank transfer, cash on delivery, manual payments, or financing. The plugin is translation-ready and includes configuration support for multilingual stores using WPML and Polylang. Lite features Add an “I agree” checkbox to WooCommerce checkout. Make the checkbox required, or leave it optional. Show a custom validation message when a required checkbox is not accepted. Link the checkbox label to a selected terms page using the {{additional-terms}} smart tag. Display linked terms in a modal, embedded above the checkbox, or in a new tab. Enable or disable the checkbox without deleting your saved settings. Show the checkbox on the classic WooCommerce checkout shortcode. Add the dedicated Additional Terms block inside the WooCommerce Checkout Block. Save customer acceptance details in the WooCommerce order notes. HPOS compatible. Translation-ready with WPML and Polylang support. Need more control? Upgrade to Additional Terms Pro The free plugin handles a single agreement well. Additional Terms Pro is built for stores that need more than one policy, want the right terms to appear at the right moment, and need records that hold up. Upgrade to Additional Terms Pro to unlock the full workflow. With Additional Terms Pro, you can: Add every agreement your store needs Create unlimited terms checkboxes, a dedicated agreement for every policy, product line, or scenario. Show a checkbox on the cart, the checkout, or both. Set default checkbox states for optional agreements. Link a checkbox to any post type, not only standard WordPress pages. Insert ready-made message templates for your checkbox label and error text, then edit them to taste. Show the right terms to the right customer Use smart conditional display so a checkbox only appears when it is relevant. Match on cart contents: products, categories, tags, WooCommerce brands, product types, or shipping classes. Match on applied coupons, so a checkbox appears only when a specific coupon has been added to the cart. Match on cart totals and weight: subtotal, total, discount total, shipping total, or cart weight. Match on the chosen payment gateway, shipping location, or billing location. Match on user role or the day of the week. Match on URL parameters from campaign, affiliate, or custom links. Copy conditions from one checkbox to another so you never rebuild the same rules. Use Hidden Cart Matching for custom checkout layouts where a theme or builder hides or changes products. Keep proof that holds up Show an acceptance summary on the WooCommerce order details screen. Display the accepted terms inside WooCommerce order emails. Attach a downloadable PDF receipt of the accepted terms to the confirmation email. Record the exact terms text, plus the customer’s IP address and device, at the moment of acceptance. Set up faster and manage smarter Draft a structured Terms and Conditions document with the guided Terms Generator. Import and export your settings to move a configuration between stores. Receive premium updates and priority support through WooCommerce.com. If your store needs multiple agreements, product-specific or payment-specific terms, conditional display, or clearer records of what customers accepted at checkout, Additional Terms Pro is the best upgrade path.