Configure Anti-Bot Checkout Protection
Configure Blacklist Manager anti-bot checkout protection with Balanced, Strict, or Custom mode and test safely before going live.
Anti-Bot Protection helps stop automated checkout abuse before it becomes a fake order, card testing attempt, repeated failed order, or spam order. It uses internal checkout signals; CAPTCHA is optional and can be used separately when needed.

Before You Enable Anti-Bot Protection
Anti-bot checks can affect checkout, so start with a safe configuration and test before relying on it for live traffic.
- Make sure WooCommerce checkout is working normally.
- Place one normal test order before changing anti-bot settings.
- Open Blacklist Manager → Settings → Anti-bots.
- Enable the unified internal risk engine for checkout protection.
- Start with Balanced mode.
Protection Modes
| Mode | Best for | How to use it |
|---|---|---|
| Balanced | Most stores. | Use this as the default starting point. It reduces obvious automated abuse without being too strict too early. |
| Strict | Stores under active attack. | Use temporarily during card testing, repeated fake orders, or obvious bot traffic. Monitor customer complaints closely. |
| Custom | Stores that want precise tuning. | Use only after you understand which signals are causing blocks or false positives. |
Recommended First Setup
- Go to Blacklist Manager → Settings → Anti-bots.
- Enable Use the unified internal risk engine for checkout protection.
- Set Protection mode to Balanced.
- Save settings.
- Place a normal test order from desktop.
- Place another normal test order from mobile if your customers commonly order from mobile devices.
- If checkout works normally, keep Balanced mode active and monitor real orders.
When to Use Strict Mode
Use Strict mode when the store is actively under attack, such as many failed orders, repeated card testing, or obvious automated checkout attempts.
- Switch to Strict.
- Save settings.
- Monitor checkout complaints and activity logs closely.
- Return to Balanced after the attack slows down.
Do not leave Strict mode enabled permanently unless you have tested it with normal customers and your checkout flow.
When to Use Custom Mode
Use Custom mode only when you know which signal should be stricter or softer. Custom mode is useful when Balanced is too soft but Strict creates too much friction.
Custom mode can involve these signal groups:
- Frontend JS and interaction proof: checks whether checkout behaved like a real browser.
- Session continuity: checks whether the customer followed a normal cart-to-checkout journey.
- Browser and fingerprint anomalies: uses browser, header, automation, interaction, and device signals.
- Core device intelligence: uses device identity and linked history.
- Store API rate limiting: helps during Store API abuse or WooCommerce Blocks checkout attacks.
- Checkout velocity intelligence: watches repeated checkout bursts.
- Payment abuse intelligence: watches repeated payment failures or card testing patterns.
JavaScript Proof
JavaScript proof checks whether checkout was loaded and interacted with like a real browser. Bots that call checkout endpoints directly may fail this signal.
Session Continuity
Session continuity checks whether the checkout journey is consistent. Missing or broken session flow can indicate scripted abuse, direct Store API calls, or broken checkout behavior.
Fingerprint Anomalies
Fingerprint anomaly checks look for unusual browser or device signals. Higher sensitivity can catch more bots, but it can also create more false positives. Change this gradually.
Store API Rate Limit
WooCommerce Blocks checkout uses Store API endpoints. Rate limiting helps stop repeated checkout attempts through those endpoints.
Checkout Velocity
Checkout velocity detects repeated checkout behavior in a short period. This is useful for fake orders, spam attempts, and card testing patterns.
Payment Abuse Intelligence
Payment abuse intelligence looks for suspicious payment-related behavior during checkout. It is most useful when payment attempts happen repeatedly or too quickly.
Diagnostics
Use diagnostics when you need to understand why the anti-bot engine is blocking or challenging checkout. Diagnostics are useful for support and tuning, but they should not be treated as everyday store content.
If legitimate customers are blocked, switch back to Balanced mode or disable the Custom signal you changed most recently.
How to Test Without Blocking Real Customers
- Use Balanced mode first.
- Place a normal test order as a guest.
- Place a normal test order as a logged-in customer if your store uses accounts.
- If available, check Activity logs for anti-bot entries.
- If customers report blocked checkout, reduce strictness before changing several settings at once.
Expected Result
Balanced mode should reduce obvious automated checkout abuse while keeping normal checkout usable. Strict mode should be treated as a temporary response to active attacks. Custom mode should be used only after you know which signal needs adjustment.
Continue from Blacklist Manager Premium documentation to the complete product workflow.
Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.
Did this guide answer your question?
Still stuck?
Open a support request and include this article title, your plugin version, and what you already tried.
Open Support