Title: KossLabs Anti-Carding &amp; Bot Shield
Author: theaikoss
Published: <strong>October 5, 2026</strong>
Last modified: October 5, 2026

---

Search plugins

![](https://ps.w.org/kosslabs-anti-carding-shield/assets/banner-772x250.png?rev=
3729071)

![](https://ps.w.org/kosslabs-anti-carding-shield/assets/icon-256x256.png?rev=3729071)

# KossLabs Anti-Carding & Bot Shield

 By [theaikoss](https://profiles.wordpress.org/theaikoss/)

[Download](https://downloads.wordpress.org/plugin/kosslabs-anti-carding-shield.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/kosslabs-anti-carding-shield/#description)
 * [Reviews](https://wordpress.org/plugins/kosslabs-anti-carding-shield/#reviews)
 *  [Installation](https://wordpress.org/plugins/kosslabs-anti-carding-shield/#installation)
 * [Development](https://wordpress.org/plugins/kosslabs-anti-carding-shield/#developers)

 [Support](https://wordpress.org/support/plugin/kosslabs-anti-carding-shield/)

## Description

**KossLabs Anti-Carding & Bot Shield** protects online merchants from card testing
fraud (carding attacks) by intercepting automated bot submissions before they reach
payment gateways such as Stripe, PayPal, Square, or local payment providers.

When carding fraudsters target a WooCommerce store, they automate thousands of micro-
authorization attempts using stolen credit card dumps. Even when transactions fail,
merchants incur expensive authorization fees ($0.15 – $0.50 per attempt) and risk
payment account suspension.

This plugin delivers a **4-layer zero-bloat defense** that halts card testing attacks
at the gateway threshold without adding custom database tables:

 * **Layer 1: Invisible Honeypot Trap:** Traps naive automated bots that blindly
   fill all form inputs.
 * **Layer 2: Cryptographic Timestamp Token:** Blocks headless scripts that submit
   forms faster than humanly possible (< 1.5 seconds) using HMAC-signed tokens.
 * **Layer 3: Cloudflare Turnstile (Bring Your Own Key – BYOK):** Frictionless, 
   privacy-friendly bot challenge. Store owners use their own free Cloudflare credentials—
   no third-party proxy or developer API quota shared.
 * **Layer 4: Transient IP Rate Limiter:** Enforces strict attempt thresholds per
   IP (e.g., 3 failed attempts in 10 minutes) stored entirely in RAM (Transients
   API / Redis / Memcached).
 * **Dual-Shield Architecture:** Full compatibility with Classic Checkout and modern
   WooCommerce Blocks Store API (`/wp-json/wc/store/v1/checkout`).

### Privacy Policy & External Services

This plugin integrates with Cloudflare Turnstile to protect your checkout against
card testing and automated bot abuse.

 * **Service:** Cloudflare Turnstile
 * **Provider:** Cloudflare, Inc.
 * **Service Description:** Frictionless, privacy-preserving bot detection challenge.
 * **Terms of Service:** https://www.cloudflare.com/website-terms/
 * **Privacy Policy:** https://www.cloudflare.com/privacypolicy/
 * **Data Transmitted:** During checkout, the customer’s IP address and Turnstile
   response token are transmitted to Cloudflare’s validation endpoint (`https://
   challenges.cloudflare.com/turnstile/v0/siteverify`) to verify whether the submission
   is from a legitimate human. Store owners use their own Cloudflare account credentials(
   BYOK).

## Installation

 1. Upload the `kosslabs-anti-carding-shield` folder to your `/wp-content/plugins/`
    directory, or install directly via the WordPress Plugins menu.
 2. Activate the plugin through the ‘Plugins’ menu in WordPress.
 3. Ensure WooCommerce is installed and activated.
 4. Navigate to **WooCommerce > Anti-Carding Shield** in your WordPress admin menu.
 5. Enter your Cloudflare Turnstile **Site Key** and **Secret Key** (obtained free 
    from your Cloudflare dashboard).
 6. Adjust rate limiting thresholds if desired, then click **Save Configuration**.

## FAQ

### Does this plugin add tables to my database?

No. It strictly adheres to a “Zero-Bloat” philosophy. All rate limiting and temporary
blocks utilize the native WordPress Transients API, which operates in RAM when object
caching (Redis or Memcached) is enabled.

### Do I need a paid Cloudflare account?

No. Cloudflare Turnstile is completely free for up to 10 visible/managed sites per
account with unlimited challenge responses.

### Does this work with WooCommerce Blocks / Modern Checkout?

Yes. The plugin intercepts both traditional classic checkout (`woocommerce_checkout_process`)
and modern Store API REST checkout endpoints (`/wc/store/v1/checkout`).

### Will legitimate customers be interrupted by difficult CAPTCHAs?

No. Cloudflare Turnstile is designed to run non-interactively in the background 
without frustrating puzzles or image selections for genuine shoppers.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“KossLabs Anti-Carding & Bot Shield” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ theaikoss ](https://profiles.wordpress.org/theaikoss/)

[Translate “KossLabs Anti-Carding & Bot Shield” into your language.](https://translate.wordpress.org/projects/wp-plugins/kosslabs-anti-carding-shield)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/kosslabs-anti-carding-shield/),
check out the [SVN repository](https://plugins.svn.wordpress.org/kosslabs-anti-carding-shield/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/kosslabs-anti-carding-shield/)
by [RSS](https://plugins.trac.wordpress.org/log/kosslabs-anti-carding-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial public release.
 * 4-layer defense: Honeypot, 1.5s cryptographic timestamp, Cloudflare Turnstile,
   and Transient IP rate limiting.
 * Full support for WooCommerce Classic Checkout and Gutenberg Store API.
 * Real-time attack mitigation counter.

## Meta

 *  Version **1.0.0**
 *  Last updated **13 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [anti-fraud](https://wordpress.org/plugins/tags/anti-fraud/)[bot protection](https://wordpress.org/plugins/tags/bot-protection/)
   [card-testing](https://wordpress.org/plugins/tags/card-testing/)[turnstile](https://wordpress.org/plugins/tags/turnstile/)
 *  [Advanced View](https://wordpress.org/plugins/kosslabs-anti-carding-shield/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/kosslabs-anti-carding-shield/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/kosslabs-anti-carding-shield/reviews/)

## Contributors

 *   [ theaikoss ](https://profiles.wordpress.org/theaikoss/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/kosslabs-anti-carding-shield/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://profiles.wordpress.org/theaikoss)