Included in Premium and Business

Card Testing Protection: Stop Bots From Testing Stolen Cards on Your Checkout

Criminals use small online stores to find out which stolen cards still work. Every attempt goes through your payment account, and too many failed payments can get that account restricted or closed. We put protection in front of your checkout, so bots are stopped before they reach your payment provider.

Works with your current payment provider
No puzzles for real customers
Set up and maintained by our engineers

What Is Card Testing?

Card testing, also called carding, is a type of fraud where criminals check stolen card details by making small payments on real websites. A script fills in your checkout again and again, each time with a different card. Most payments fail. The few that go through tell the criminals which cards are still active.

The cards were not stolen from your store. Your store is simply the tool used to check them, and you are the one who pays for it.

How a Card Testing Attack Works

1

Stolen cards are bought in bulk

Card details stolen in data breaches, by phishing and by malware are sold in large lists. Many cards in a list are already blocked or expired, so buyers need to know which ones still work.

2

A bot looks for an easy checkout

Scripts search for stores with guest checkout, cheap products or donation forms with a free amount, and no limits on payment attempts.

3

The bot makes small payments

It adds the cheapest item to the cart and pays with one card after another, often from many IP addresses, so the orders look like they come from different shoppers.

4

Your payment provider checks every card

Each attempt goes to Stripe, PayPal or your bank. Most are declined and a few are approved, and every result is recorded against your merchant account.

5

Working cards are used or sold

Cards that pass are used for large purchases elsewhere or sold again at a higher price as "checked" cards.

Why Criminals Test Cards on Small Websites

They do not want your products. They want a checkout that lets them try many cards quickly without being stopped.

Little or no protection

Large stores have fraud teams and strict limits. Many small stores accept any number of payment attempts from anyone.

Small amounts go unnoticed

A small charge rarely makes a cardholder call the bank, so the card stays active for the real fraud later.

Guest checkout and open forms

No account, no login, no limits. Donation forms and gift vouchers with a custom amount are especially popular.

Hidden checkout routes

Many shop platforms have background routes that accept orders without loading the checkout page. Bots use them to skip protection added to the page itself.

Attacks run on autopilot

One script can try hundreds of cards an hour and change its IP address every few attempts. Others test slowly for weeks to stay unnoticed.

Nobody is watching

Attacks often start at night or at the weekend, when nobody checks new orders until the damage is done.

Who Is Most at Risk

Online shops

Especially stores with low-price products and guest checkout.

Charities and donation forms

Forms where the donor chooses the amount are a favorite target.

Hotels, restaurants and gift vouchers

A voucher page is often the only place on the site that takes card payments, and nobody watches it closely.

Membership sites and online courses

Sign-up forms that check a card for a free trial or a first payment.

Event and ticket sales

Cheap tickets and many small orders make an attack easy to miss.

Subscription services

Forms that save a card for recurring billing let criminals check a card without charging it.

What a Card Testing Attack Can Cost You

The cards are not yours, but the payment account is. This is what usually follows an attack.

Fees for payments you never wanted

Depending on your provider and plan, you can be charged for authorization attempts, including declined ones. Test payments that go through are often disputed by the real cardholder, and each dispute usually comes with a fee.

Refunds, disputes and fraud reports

Successful test payments have to be found and refunded quickly. Those you miss turn into fraud reports and disputes that count against your account.

Real customers get declined

Banks start to see your store as risky. Even after the attack stops, more payments from genuine customers can be declined.

Card network monitoring

A long or large attack can put your account into the card networks' monitoring programs, with extra fees and stricter rules.

Lost time and a slower website

Hundreds of failed order emails, fake orders holding stock or bookings, a website slowed down by bot traffic, and hours spent cleaning up and talking to your payment provider.

How It Usually Looks

Every attack is different, but most follow one of these patterns.

The overnight burst

A small gift shop wakes up to hundreds of failed orders for its cheapest item, all placed between 2 and 5 a.m. A few payments went through. The payment provider holds the payouts while it reviews the account.

The donation flood

A local charity's donation form receives hundreds of tiny donations in an hour, each from a different card. Weeks later, the ones that went through come back as disputes, each with a fee.

The slow test

An event ticket website gets a few payment attempts a week from the same visitor, each with a new card. Nobody notices until the payment provider asks about the rising number of declines.

Signs Your Checkout Is Being Used for Card Testing

Many failed orders in a short time, often for the same cheap product
Small payments of the same amount from different cards
Customer names and email addresses that look random or do not match
A burst of "payment failed" or "failed order" emails
Orders from countries where you do not sell
An email from your payment provider about unusual activity or a high decline rate

Seeing this right now? Contact us and we will help you stop the attack.

How Card Testing Protection Works

Stripe, PayPal and other providers have their own fraud filters, but they see a payment only after it leaves your website. Our protection works on your website, before card details are sent to the provider. Several layers work together, because a single rule, such as blocking one IP address, is easy for bots to get around.

Invisible human check

Every payment attempt has to pass a check that tells people and bots apart. Real customers do not solve puzzles. Scripts are stopped before the payment is sent.

Limits on payment attempts

Too many attempts or failed cards from one visitor in a short time trigger a pause. Limits are set for your store, so a real customer can still retry a mistyped card.

Every card entry point covered

We protect the checkout page, the background routes that can create orders without it, the "add payment method" page in customer accounts, and your payment and donation forms.

Attack sources blocked

Our website firewall blocks the IP addresses and networks taking part in an attack across your whole website.

Alerts when declines spike

If failed payments jump, you and our team get an alert, so you know about an attack while it is happening, not at the end of the month.

Set up by our engineers

We install and configure the protection for your platform and payment provider, test it and keep it up to date. No code changes on your side.

Works With Your Store and Payment Provider

We have ready solutions for all popular platforms and shop extensions. For anything else, we integrate the protection on request.

WordPress

WooCommerce, Easy Digital Downloads, WP Simple Pay, GiveWP, MemberPress, Paid Memberships Pro, and payment forms in WPForms and Gravity Forms

Joomla

VirtueMart, HikaShop, J2Commerce (formerly J2Store) and JoomShopping

Magento

Magento Open Source and Adobe Commerce

OpenCart

OpenCart 3 and 4

PrestaShop

PrestaShop 1.7, 8 and 9

Drupal

Drupal Commerce

Other platforms

Shopware, CS-Cart, WHMCS and custom-built stores: on request

Payment providers: Stripe, PayPal, WooPayments, Square, Braintree, Authorize.net, Mollie, Worldpay and others. The protection works on your website, so it does not depend on the provider.

Get Protected in 3 Steps

1

Choose Premium or Business

Card Testing Protection is included in both plans, together with malware scanning, the website firewall and our other security features.

2

Tell us about your store

Let us know your platform and payment provider and send us access details. Already on Premium or Business? Just contact our support.

3

We set it up and test it

Our engineer installs and tests the protection and turns on alerts. Your checkout keeps working as usual for real customers.

Card Testing Protection Pricing

Card Testing Protection is not sold on its own. It is included in our Premium and Business security plans, together with everything else that keeps your website safe.

Business

$99.95 USD/month
Enterprise and high-traffic sites
Everything in Premium
Review of your payment provider's fraud settings with our engineer
Monthly report on blocked payment attempts
Incident review after every attack
Malware scanning every 1, 3, 6 or 12 hours
Support response in 1 hour
Get Business

Compare all plans

Frequently Asked Questions

What is card testing?

Card testing is fraud where criminals check stolen card details by making small payments on real websites. They use the results to find the cards that still work, then use or sell those cards elsewhere.

My store is small. Why would anyone attack it?

Because it is small. Criminals look for checkouts with no limits and nobody watching. They do not need your products, only a place to try cards quickly.

Doesn't my payment provider already protect me?

Providers like Stripe and PayPal block many fraudulent payments, but they only see a payment after it leaves your website, and the attempts that reach the banks still affect your account. Stripe's own guide on card testing recommends adding protection on the website itself, such as a CAPTCHA and rate limits. That is what we do.

Will my customers notice anything?

No. Real customers check out as usual and do not solve puzzles. Limits are set so that a customer who mistypes a card number can try again.

Which platforms do you support?

WordPress (WooCommerce, Easy Digital Downloads, payment and donation forms), Joomla (VirtueMart, HikaShop, J2Commerce, JoomShopping), Magento, OpenCart, PrestaShop and Drupal Commerce. For other platforms and custom-built stores, we integrate the protection on request.

Does it work with my payment provider?

Yes. The protection works on your website before the payment request is sent, so it works with Stripe, PayPal, WooPayments, Square, Braintree, Authorize.net, Mollie, Worldpay and other providers.

Can my payment account really be closed because of card testing?

Yes. Providers measure your declines, fraud reports and disputes. A card testing attack raises declines at once, and fraud reports and disputes follow. The usual first steps are a review and held payouts, and if the problem continues, the provider can limit or close the account.

What should I do if an attack is happening right now?

Contact us straight away and we will help you stop it. Refund any test payments that went through, so they do not turn into disputes, and let your payment provider know you are dealing with the attack.

I am already on Premium or Business. How do I turn it on?

Contact our support with your website address, platform and payment provider. Our engineer will set up the protection and let you know when it is active.

Is it available on the Basic or Standard plan?

No. Card Testing Protection is included in Premium and Business only. You can upgrade your plan at any time.

Do you need access to my payment account?

No. The protection works on your website. On the Business plan, we review your provider's fraud settings together with you, and you stay in control of the account.

Protect Your Checkout Before the Next Attack

Card testing can start on any day and on any store. Premium and Business include Card Testing Protection, set up by our engineers.

Live Chat Support
Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience. See our policy Accept