Classic checkout and Checkout Blocks
Use configurable attempt limits and optional human checks for both native checkout experiences. Independent account abuse checks run on supported checkout submissions, including attempts that create an account.
Loading…
Gate House · WooCommerce security plugin
Repeated checkout attempts and unwanted customer accounts take time away from running your store. Gate House adds local attempt limits, independent account abuse checks and optional human verification to supported WooCommerce customer journeys.
Where Gate House helps
Choose controls for the checkout and account forms your store actually uses. Gate House checks supported submissions before native account creation or payment processing, with a local activity history to help explain its decisions.
Use configurable attempt limits and optional human checks for both native checkout experiences. Independent account abuse checks run on supported checkout submissions, including attempts that create an account.
Apply checks on supported native order-payment paths, including classic order-pay and the Store API checkout-order route. Test these separately from placing a new order.
Add checks to WooCommerce sign-in, registration and password-reset forms. Account abuse protection can block matching registration patterns independently of a successful CAPTCHA.
Human checks cover native product reviews through the WordPress comments integration. Contact Form 7 submissions can use the same selected provider when that plugin is active.
Account abuse protection
Some unwanted activity appears as a pattern across accounts. Gate House adds a separate check for supported registration and payment routes.
The account guard checks combinations of generated profile fields and repeated identities. A shared business address, unusual name or incomplete profile alone does not trigger a match. A matching pattern is a reason to investigate, rather than proof of payment fraud.
Use Observe — record matches to review account signals, or choose Block matching attempts when you are ready. Account abuse protection works independently of your CAPTCHA provider and attempt limits, so a passed challenge cannot override its block.
Review Activity when a customer reports a problem. Coverage distinguishes recognized adapters and configured rules from successful-use evidence. Relevant setup or rule changes require a new successful observation. Read how account protection is configured.
WooCommerce security checklist
A provider connection test verifies a challenge. A sandbox purchase verifies the buying path your customer will use.
Open the complete setup guide →Identify classic checkout or Checkout Blocks, My Account forms and existing-order payment links. Note express wallets, subscriptions, saved-card flows and any custom forms for separate review.
Start in Observe and review local activity. Choose attempt limits and the account abuse mode. If adding human checks, register your staging hostname with the provider and pass its connection test before enabling selected forms.
Use each payment method you offer. Exercise guest and signed-in checkout where enabled, checkout account creation and the order-payment links your store uses. Check successful submissions and rejected attempts.
Inspect the order result, customer-facing messages, Activity and Coverage. Confirm the tested rules allow legitimate buyers to finish. Review any unexpected block before applying the settings to production.
Repeat affected journeys after gateway, theme, checkout-extension or protection-rule changes. Keep your payment processor’s fraud controls and wider WordPress security practices in place.
Existing customer accounts
Account cleanup helps an authorized administrator investigate suspicious customers on a single-site installation while preserving order history.
Choose a registration date range of up to 31 days. The preview reviews up to 2,000 customer accounts and shows matching reasons, order history and available actions. Inspect individual candidates before selecting a batch of up to 25 accounts.
Quarantine revokes sessions and blocks supported sign-in and checkout paths while keeping the account and all orders. Build a fresh preview to restore an account if your review finds a legitimate customer.
Permanent deletion requires at least 24 hours in quarantine, a fresh preview and no linked orders in any status or authored content. Privileged accounts and uncertain histories are protected. Gate House never deletes orders through cleanup. Read the account cleanup steps and limits.
Before you install
Understand the checks, the limits and what to test on your own site.
Get help with your setupYes. Gate House has adapters for native Checkout Blocks and its Store API submission routes, as well as classic checkout. Check Coverage for your detected setup, configured rules, successful-use observations and available release evidence. Test your actual checkout and payment methods before enabling blocking.
Gate House can limit repeated attempts and check suspicious account patterns before payment processing on supported native routes. It does not determine whether a payment card is legitimate, guarantee fraud prevention or replace your payment processor’s controls. Failed orders still need review in the context of your store and gateway.
No. Human verification and account abuse protection make separate decisions. The account guard looks for combinations of generated-profile fields and repeated identities on supported routes. A passed human check or local-rate exception cannot override an account abuse block.
No universal gateway compatibility is claimed. Native checkout adapters do not cover every express-wallet initiation, saved-card setup, subscription renewal or external gateway path. Test each payment method and any custom flow separately; the provider connection test alone does not verify checkout compatibility.
Yes. The account cleanup workflow lets you preview candidates, inspect their order history and select eligible accounts for reversible quarantine. Quarantine retains the account and all orders. Permanent deletion is separate and unavailable for accounts with linked orders in any status.
No. Account abuse protection checks new attempts. Cleanup is a separate administrator-reviewed workflow. Permanent account deletion requires a fresh preview, at least 24 hours in quarantine and eligibility checks including no order history or authored content. Cleanup never deletes orders.
Yes. Attempt limits and account abuse protection work without provider keys. You can enable local checks first and decide separately whether checkout needs a human check. Fresh installations start in Observe; enabling local protection does not enable human checks or change existing accounts or orders.
Review the plans, check your forms and get help from the people who build Gate House.