Checkout Bouncer

Checkout Bouncer support comes two ways, and both start here. Do it yourself: the docs are thorough and we answer email. Or hand the whole thing to us and we lock it down for you, usually within two days.

Done for you

Have us lock your checkout down for you

Getting carded means a run of tiny failed orders while a bot tests stolen cards against your gateway. If that is happening to your store, every attempt is a real authorisation, a real fee, and a step closer to your payment account being flagged. That is not a slow problem, and this is the fast way to close it.

We do the whole job: find every route an order can enter your store through, install and tune Checkout Bouncer so each one is scored, verify the block with real traffic rather than assuming it, and hand you a one-page report of what was open and what is now shut. Most stores only ever guard the one checkout form. We close the doors you cannot see.

One-time

Checkout Lockdown Audit

$300 – $500

Delivered within 48 hours.

  • Every route found: classic, block, Store API, pay-for-order, add-payment, duplicate pages
  • reCAPTCHA v3 installed and the score threshold tuned to your real traffic
  • The block verified against live requests, not assumed
  • A one-page report: what was exposed, what is now closed, what to watch
  • A short walkthrough so your team can run it after we hand it back

Optional, monthly

Ongoing Monitoring

$50 – $100 / month

Cancel any time.

  • We watch your block rate and logs for spikes and new attack patterns
  • Threshold and throttle re-tuned as your traffic and the threats change
  • A monthly check that every route is still covered after plugin and theme updates
  • An email the day something shifts, not a report at month end
  • Same business-day response when something is wrong

Where a store lands in each range depends on how many routes it exposes and which checkout it runs. Tell us your setup below and we will send an exact quote the same day; if the free plugin already covers you, we will say so plainly rather than sell you a job you do not need.

Tell us what your checkout is doing

No obligation. We reply by email, usually the same business day.

Prefer to do it yourself?

Checkout Bouncer support has no ticket portal and no chatbot. Pick whichever of these fits the question.

Email us directly

Use email for anything that touches your store: orders that were blocked, orders that got through, scanner findings, throttle settings, or a site where the block checkout is not being scored. Attach screenshots of the Checkout Scan and the Logs tab if you can.

support@checkoutbouncer.com

Never send Checkout Bouncer support your reCAPTCHA secret key, admin passwords or customer payment details. We do not need them, and we will ask you to rotate the key if you do.

The WordPress.org support forum

Every plugin listed on WordPress.org gets a free public support forum on its plugin page. That forum is the place for public questions: setup, compatibility with another plugin, “is this behaviour normal”, feature requests. We read and answer the threads there.

The forum is public and permanent, so other shop owners find the answer later. Keep order numbers, email addresses and IPs out of it and send those by email instead.

The forum is at wordpress.org/support/plugin/checkout-bouncer.

What to include so Checkout Bouncer support can actually answer

Checkout problems are almost always environment problems: a version mismatch, a checkout page that is not the one you think it is, or a score threshold set too high. Six lines of detail turn a three-email thread into one reply.

Send thisWhy it matters
WordPress versionCheckout Bouncer needs WordPress 6.2 or newer. Older cores lack the block and Store API behaviour we hook into.
WooCommerce versionWooCommerce 7.0 or newer. The Store API checkout route and HPOS order tables changed a lot across releases.
PHP versionPHP 7.4 or newer. Some reported “nothing happens” reports are a fatal error on an old PHP build.
Which checkout you useClassic shortcode, block checkout, or a page builder rendering it. These are protected by completely different code paths, so this single line decides where we look.
What the Checkout Scan saysThe scanner names your active checkout page, how it is rendered, any duplicate or rogue checkout pages, and whether the Store API route is exposed. Copy the findings or screenshot them.
Relevant lines from the Logs tabThe events table records passes, failures and blocks with the reason. Paste the rows around the time of the problem order.
Copy-paste template for your first email

Site URL:
WordPress version:
WooCommerce version:
PHP version:
Checkout type: classic shortcode / block checkout / page builder (which one)
Payment gateways in use:
Checkout Scan findings:
Score threshold setting:
Fail-open on or off:
Throttle limits and whether monitor mode is on:
What you expected to happen:
What actually happened, with the order number or time:
Log lines from the Logs tab around that time:

The Logs tab also has a CSV export. For anything involving more than a handful of orders, export the CSV and attach it rather than pasting rows.

Check these first. Most tickets end here.

Three questions account for most of what Checkout Bouncer support is asked. Each one has a documented answer you can act on right now.

“Orders are still getting through”

Nine times out of ten the store is on the block checkout, which submits through the WooCommerce Store API and never fires the classic checkout hooks. Run the Checkout Scan: it tells you exactly what renders your checkout and whether the Store API route is exposed, then offers a one-click Protect or Block on each finding.

How the Checkout Scanner works

“Real customers are being blocked”

Drop the score threshold. Google recommends 0.5 and anything above that will start catching cautious shoppers on shared connections. Check the throttle limits too: max orders per hour, failed payments per 15 minutes and distinct billing emails per hour all block independently of the score. Monitor mode logs those rules without enforcing them.

Thresholds, throttles and allowlists

“Nothing is being scored at all”

Check your keys. Checkout Bouncer needs free Google reCAPTCHA v3 keys, and v3 keys only. Then check whether you are logged in as staff: staff roles bypass by design, and your own IP may be on the allowlist. The scanner also flags configuration that silently verifies nothing, which is the case people miss.

Getting your reCAPTCHA v3 keys

Still stuck? That is what we are here for. Email us with the six details above.

How fast we reply

We answer email on business days. Most messages get a reply within one to two business days, and messages sent over a weekend or a public holiday are picked up on the next working day. Support on the free plugin is best effort, not a contracted service level, and we would rather say that plainly than print a guarantee we cannot hold to. A priority support tier is on the Pro roadmap.

We can help with

  • Setting up reCAPTCHA v3 keys and choosing a threshold
  • Block checkout and Store API orders not being scored
  • Reading and acting on Checkout Scan findings
  • Duplicate or rogue checkout pages, and when to block them
  • Pay-for-order and add-payment-method coverage
  • Order-rate throttle tuning and monitor mode
  • Per-gateway targeting, staff bypass and IP allowlists including CIDR
  • HPOS and page builder checkouts: Elementor, Divi, WPBakery, Beaver, Bricks, Oxygen
  • Making sense of the events table, block reasons and the CSV export

Outside what this plugin does

  • Spam on login, registration, comments or contact forms. Checkout Bouncer protects the checkout only.
  • reCAPTCHA v2 checkboxes, hCaptcha or Turnstile. This is reCAPTCHA v3 only.
  • Firewall rules, malware cleanup or server hardening. That is not what this is.
  • Chargeback disputes and payment gateway account issues. Your gateway handles those.
  • General theme or site development work unrelated to checkout protection.

If your question lands outside that list we will say so quickly rather than leave you waiting.

Pro waitlist

Want to hear when Pro lands?

Pro is not released and there is nothing to buy today. The WordPress.org version is free and fully functional, and it stays that way. If you want an email when Pro is ready, add your address to the launch list. We write once, when Pro lands, and nothing else.

What we are working towards, in no fixed order:

  • A shared threat intelligence blocklist across sites running the plugin
  • An agency dashboard for managing many stores in one place
  • Extra fraud rules beyond score and rate
  • Edge blocking through Cloudflare, before the request reaches WordPress
  • Alerts and digests when your block rate spikes
  • Longer log retention and priority support

Tell us which of those matters most to your store. Waitlist replies shape what gets built first. We use your address for the launch email and nothing else, and you can ask us to remove it at any time. See the privacy notice.

Reporting a bug or a security issue

Bugs go to the same address. Include the steps to reproduce, what you expected, what happened, and the plugin version from the changelog so we know which build you are on. If you have found a security problem, email us privately first and give us a chance to ship a fix before you post about it publicly. We will credit you in the changelog if you would like.


Not using the plugin yet and want to know whether it covers your setup? Ask. Send us your checkout type and gateway list and we will tell you straight, including if the answer is no. See what it does or get the free plugin (on WordPress.org).

See which doors into your checkout are standing open