Checkout Bouncer

The WooCommerce checkout scanner maps your live checkout, works out what actually renders it, hunts for duplicate checkout pages you forgot about, and checks whether the Store API checkout route is sitting there wide open. Then it tells you which of those routes a bot can walk through with nothing scoring it.

Free. It ships inside the plugin and runs in your own WordPress admin. It reports first and changes nothing until you press a button.

Your checkout is not one page. It is several doors.

You installed a captcha plugin. Fake orders are still landing and your gateway is still logging failed authorisations in bursts of forty. Both of those things can be true at the same time, because the checkout you see in your browser is only one of the ways an order gets created on your store.

The WooCommerce block checkout does not run the classic checkout hooks. It submits through the Store API. A captcha that only listens on the classic hooks never sees those orders at all, so it reports zero blocks and looks like it is working perfectly. Meanwhile there are the pages nobody remembers: the duplicate checkout a page builder left behind, the old one-page checkout, the copy made for a campaign. They still create real orders with real money attached.

The WooCommerce checkout scanner finds every one of those doors and tells you the status of each. Detect, then protect, then block what should not be open at all.

What the WooCommerce checkout scanner tells you about your store

Six checks, in plain English, each one ending in a decision you can act on.

Which page is really your checkout

It finds the active checkout page WooCommerce is actually sending customers to, not the one you assume it is using.

What renders it

Block checkout, classic shortcode, or one of six page builders: Elementor, Divi, WPBakery, Beaver, Bricks, Oxygen. The renderer decides how the token has to travel.

Whether the Store API is exposed

It checks whether the Store API checkout route answers requests. That route creates orders whether or not anyone ever loads your checkout page.

Rogue duplicate checkouts

It searches the rest of the site for other pages that carry a working checkout, the case duplicate and rogue checkout pages sets out in full. Old copies, builder duplicates, campaign clones. Each one is a second front door.

Settings that verify nothing

A missing secret key, a threshold set so low that nothing can ever fail. The badge is on the page, the verification is not happening. The scanner says so.

What to do about each one

Every WooCommerce checkout scanner finding ends with a one-click Protect or Block. No config files, no snippets, no support ticket.

What a scan report looks like

This is an example, not a live scan of your store. It is a fairly ordinary result for a shop that migrated to the block checkout, kept the old page around, and installed a captcha plugin two years ago.

7surfaces found
4unprotected
2critical findings
1already blocked
What to do about each one
SurfaceWhereStatusSeverityOffered action
Classic checkout/checkout/ (shortcode)protectedokNone needed
Block checkout/checkout/ (Checkout block)unprotectedcriticalProtect
Store API/wp-json/wc/store/v1/checkoutunprotectedcriticalProtect or Block
Pay for orderorder-pay endpointunprotectedwarningProtect
Add payment method/my-account/add-payment-method/not foundokNone needed
Duplicate page/checkout-2/ (Elementor)unprotectedwarningBlock
Duplicate page/secure-checkout/ (WPBakery)blockedokAlready blocked

Configuration findings from the same scan

  • critical: Secret key is empty. The front end collects tokens and nothing verifies them.
  • warning. Score threshold is 0.1. At that setting almost nothing can ever fail. Google recommends 0.5.
  • notice. reCAPTCHA is limited to checkout screens. v3 scores a visitor on whole-site behaviour, so sitewide loading gives Google more to work with.
  • ok. Order-rate throttle is enabled and running in monitor mode: it logs what it would have blocked without blocking it yet.

How to read the report

Statuses

  • protected means a token travels with the request and the order is scored before it is created.
  • unprotected: the surface is reachable and can create an order, and nothing is being verified.
  • blocked. The route or page is hard-blocked. The Store API checkout route can return 404 or 403; a rogue duplicate page is closed off.
  • not found means the surface does not exist on this store, so there is nothing to protect.

Severities

  • ok (nothing to do here).
  • notice: it works, but there is a better setting available.
  • warning. A real gap. Not the front door, but a bot that goes looking will find it.
  • critical: an unprotected route that can create a live, paid order right now.

Every finding comes with a button

A list of problems is not much use on a Tuesday morning. Each finding in the report ends with the action that fixes it.

Protect

For surfaces that can carry a token. reCAPTCHA v3 is attached to that route and every submission is scored before an order is created. On the block checkout that means registering Store API endpoint data so the token travels with the request, which is the part several widely-installed captcha plugins still do not do.

Block

For routes that should not be open at all. The Store API checkout route can be hard-blocked with a 404 or a 403, and rogue duplicate checkout pages can be closed. The scanner never offers to block your store’s own active checkout.

Every pass, fail and block after that lands in the events table, with pass and fail counts, top block reasons and a CSV export when you need to show your payment provider what changed.

Run the scan on your own store today

The WooCommerce checkout scanner is not a separate product. It ships inside the free plugin and runs against your live site from your WordPress admin. Five minutes, start to finish.

  1. Install Checkout Bouncer. The WordPress.org version is free and fully functional.
  2. Open the Checkout Bouncer screen in your WordPress admin and run the scan. It reports; it does not change anything on its own.
  3. Work down the findings. Press Protect on the surfaces that should stay open, Block on the ones that should not exist.
  4. Add your free Google reCAPTCHA v3 keys and set the score threshold. 0.5 is Google’s recommendation.
  5. Turn on the order-rate throttle in monitor mode for a day, look at what it would have stopped, then let it block.

Live now

Scan your checkout now

Enter your store address. The scan reads only what any visitor can see: your home page, your checkout page, and whether the Store API checkout route answers. It never signs in, never posts anything, and never touches your orders. Nothing is stored.

An outside scan can only see so much. It cannot read your WooCommerce settings, so it may miss a checkout at a custom address or one served from a cache. The scanner inside the free plugin reads your configuration directly, finds rogue duplicate checkout pages, and gives you a one-click Protect or Block on every finding.

What the scanner does not do

Worth knowing before you install, so nothing is a surprise afterwards.

  • It maps how orders can enter your store. It is not a firewall and not a malware scanner.
  • It covers the checkout. The plugin leaves login, registration, comments and contact forms alone.
  • Protection is Google reCAPTCHA v3 only. No v2 checkbox, no hCaptcha, no Turnstile.
  • You need free reCAPTCHA v3 keys from Google before any scoring can happen. The scan will tell you if they are missing or half-configured.
  • It requires WordPress 6.2 or later, PHP 7.4 or later, and WooCommerce 7.0 or later. HPOS and the block checkout are both supported.

Questions people ask before scanning

Does running the scan change anything on my site?

No. The scan reads your site and reports what it finds. Nothing changes until you press Protect or Block on a specific finding, and each of those actions applies to that one surface.

My checkout is built with Elementor. Will it find it?

Yes. The scanner recognises checkouts rendered by Elementor, Divi, WPBakery, Beaver, Bricks and Oxygen, as well as the block checkout and the classic shortcode. Knowing the renderer matters, because it decides how the reCAPTCHA token has to be attached to the submission.

If I block the Store API checkout route, will my checkout stop working?

Only block that route if nothing on your store legitimately uses it. If your live checkout is the block checkout, it submits through the Store API, so choose Protect instead: the token then travels with the Store API request and the order gets scored. Blocking is for stores still on the classic checkout, where that route is an open door nobody is using.

What counts as a rogue duplicate checkout?

Any page other than your active checkout that still renders a working checkout. Builder duplicates, an old page kept “just in case”, a campaign clone. They are usually unlinked, which is exactly why nobody notices when a bot finds one and starts testing cards through it.

Shoppers, outages and cost

Will my customers have to solve anything?

No. reCAPTCHA v3 is invisible: no puzzles, no image grids, no extra click. It scores behaviour in the background. By default the script loads sitewide, because v3 judges a visitor on whole-site behaviour and that is what Google recommends. You can narrow it to checkout screens only if you prefer.

What happens if Google is unreachable?

That is your call. Fail-open is configurable. Leave it on and orders keep flowing when the verification call cannot complete; turn it off and nothing gets through unverified.

Is the scanner really free, or is it a trial?

Free. The WordPress.org version of Checkout Bouncer is fully functional, scanner included. A Pro tier is planned but not released yet, so there is nothing to buy today.

Scan before the next chargeback, not after it

It takes five minutes for the WooCommerce checkout scanner to find out how many ways an order can get into your store. The scan names every route it finds, not just the checkout page.

See which doors into your checkout are standing open