Google runs two products under the reCAPTCHA name, in two consoles, with two different verification APIs. Here is how to tell which one your keys belong to, and what follows from that.
A velocity check counts repeated events and reacts when a threshold trips. The interesting part is not the counting, it is choosing what counts as the same thing.
WooCommerce records where each order came from, but the browser collects that data and submits it with the order. What the fields are, and what an odd profile is actually worth.
Order notes need an order to exist. The attempts that never became one live in logs or nowhere, and logs only record what was running at the time.
A BIN attack fixes one bank’s card range and varies everything else. Here is what that leaves behind in your own order data, and what it does not.
The form is on the checkout page. The request that places the order is not, and anything wired to the page template never sees it.
Failed orders are declines, not abandoned baskets. And the row count is not the attempt count, because WooCommerce reuses an order when the basket has not changed.
Google says the score is a risk signal, not a verdict. Here is how to read reCAPTCHA v3 scores on your own traffic and pick a threshold that does not cost you real orders.
Bursts of small failed authorisations, repeated addresses and throwaway emails look nothing like ordinary declines. Here is how to tell them apart with evidence you already have.