A velocity check counts repeated events and reacts when a threshold trips. The interesting part is not the counting, it is choosing what counts as the same thing.
WooCommerce records where each order came from, but the browser collects that data and submits it with the order. What the fields are, and what an odd profile is actually worth.
Order notes need an order to exist. The attempts that never became one live in logs or nowhere, and logs only record what was running at the time.
A BIN attack fixes one bank’s card range and varies everything else. Here is what that leaves behind in your own order data, and what it does not.
Eight labels, and most shops use three. Failed is a decline rather than an abandonment, and draft exists only because of the block checkout.
The decline reason your gateway gave is rarely on the order screen. It is in the notes panel beside it, written by machinery rather than by a person.
WooCommerce reads the shopper’s address from a forwarded header. Behind a proxy that is either the proxy itself or a value the client chose, and both break rules.
Failed orders are declines, not abandoned baskets. And the row count is not the attempt count, because WooCommerce reuses an order when the basket has not changed.
WooCommerce treats one page as the checkout. Any other page carrying the form can still place orders, and a captcha wired to the assigned page never sees them.
Bursts of small failed authorisations, repeated addresses and throwaway emails look nothing like ordinary declines. Here is how to tell them apart with evidence you already have.