WPIntell

Source evidence

A Way to Curb Carding Attacks?

Rate limiting UI for WooCommerce · support · 2025-01-03T17:09:00+00:00

complaintsentiment
highseverity
0.97relevance
1replies
Evidence onlycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

1 / 1 rows with source links

100.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

0 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
raymichels unresolved
Would this be a good way to curb manual carding attacks? I have a security plugin to deal with bot attacks, but we have since gotten fake accounts created on our site so individuals can manually test card numbers. I would like to limit checkout attempts to ~5 attempts per hour, but since this plugin refers to the API endpoints, I wasn’t sure if this would apply to the default WooCommerce checkout. Unfortunately, we’re not using WooPayments, and if this option doesn’t end up being an option then I’ll reach out to our gateway plugin for support. Thanks a bunch! We use a plugin called Checkout Rate Limiter to prevent carding attacks. Though it hasn’t been updated in a while, it works great and logs attacks it has stopped. Settings allow configurable time limit blocks for the first, second and third attempts which should work for you. See https://github.com/brianhenryie/bh-wc-checkout-rate-limiter/ for details.

Comments

1 shown
captaincrank 2025-06-10T10:35:00+00:00

We use a plugin called Checkout Rate Limiter to prevent carding attacks. Though it hasn’t been updated in a while, it works great and logs attacks it has stopped. Settings allow configurable time limit blocks for the first, second and third attempts which should work for you. See https://github.com/brianhenryie/bh-wc-checkout-rate-limiter/ for details.