You’re scrolling through your news feed when a headline catches your attention: The North Face has suffered a customer account breach.
You move on and continue with your day, but the story lingers in your head. There was no dramatic website outage or ransom demand. Attackers simply used stolen credentials to gain access to customer accounts.
If something similar happened to your store, how would you find out? Would one of your security tools alert you? Would you notice any unusual activity? Or would your first warning come from a customer?
Support keeps an eye on the tickets, ops keeps an eye on the orders, your agency keeps an eye on the uptime. A card test looks like background noise in any of these views – a few strange cards, an increase in failed payments, nothing on the uptime graph – and only looks like an attack when someone sees all three at once. On most teams, no one is in a position to see all three at once.
The most important first step is to understand exactly what is normal for your store so you know when something is wrong. This week, sit down with your team and document your average daily order volume, typical refund rate, failed orders, and average order value. Take note of the plugins and admin-level user accounts that already exist on your site.
Even for large stores, the WordPress dashboard provides clues to potential problems. You just need to know what to look for.
Most of these signals do not in themselves indicate a security problem. It’s important to consider them in the context of everything else happening on your site.

WooCommerce Analytics
WooCommerce Analytics gives you a baseline for what normal shopping activity looks like. Go to Analyzes → Orders in your WordPress dashboard and note:
- Unexplained order spikes or clusters of small orders in a short period of time, which may indicate card testing fraud.
- Sudden drops in the number of completed orders, which could indicate malicious code, a DDoS attack, or unauthorized changes to the checkout process.
- Unusual refund activity, which may indicate compromised accounts.

Order history
Your order history is often the first sign that something is wrong. NB:
- Unpaid orders marked as completed. This could be a compromised account or malicious code that manipulates orders.
- A sudden increase in failed or low-value orders, often associated with card testing or automated attacks.
- Unexpected refund spikes, a possible sign of illicit activity.
Pro tip: Payment gateways like WooPayments and Stripe have built-in fraud protection. If you use a different provider, see how they handle fraud protection and see if your development team needs to tighten the rules for your account.
User accounts
In the Users section of your WordPress dashboard, see who has access to your store and what actions they can take. NB:
- Unexpected admin accounts not created by your team.
- Rapid spikes in user registrations, which may indicate automated spam activity.
- Accounts with similar names or email addresses, these are patterns that bots use to automatically create accounts.
There are a few additional areas in your WordPress dashboard where unusual activity may appear:
- Plugins and themes: Look for anything that shouldn’t be there, such as an unexpected tool or a tool with a suspicious name.
- Pages and Posts: Check for changes or new content that your team didn’t create.
- Notes: Comment spam often appears next to automated account registration.
The WordPress dashboard provides valuable clues, but does not directly identify a hacking attempt or a security breach.
To get the full picture, add tools that connect the dots and help you determine whether things like order spikes are the result of a hack or something else. You also want immediate alerts about malware, vulnerabilities, and downtime so your team can respond before small issues snowball.

Start with Jetpack Security, which sends real-time security alerts and includes an activity log with actionable insight into everything happening on your site.

Anti-Fraud Shield for WooCommerce should be your next priority. This tool highlights high-risk orders and alerts your team based on the risk factors you set. It goes a step further than your payment gateway’s built-in fraud protection.

Datadog is a great option for multi-channel stores, monitoring security everywhere you sell and collecting data in one central dashboard. This expands your team’s view beyond just WooCommerce.
Many hosts also warn you about malware and other security issues. For example, some track site vulnerabilities and security issues directly in the hosting dashboard and send alerts about everything that’s going on.
When these systems are connected, you can detect unusual patterns earlier, understand their root cause, and address problems before they escalate.
While everything above will help you create a security strategy for the future, it can take some time to plan. In the meantime, here are a few ways you can reduce unnecessary risks today:
- Monitor your users. Scroll through your list of users and remove any users who don’t belong, such as former employees or contractors. Review existing roles and confirm that each role has the lowest level of permissions necessary to complete its task. Take it a step further by requiring two-factor authentication for administrators.
- Check REST API keys connected to WooCommerce. In your WordPress dashboard, go to WooCommerce → Settings → Advanced → REST API Keys. Delete any unused keys and check the keys with read/write access.
- Check your WooCommerce logs. The information can be found below WooCommerce → Status → Logs looks for sources that pull data from your site. Check to see if there are any services you no longer use or anything else that seems out of place. These logs can get technical, so it’s always a good idea to have your developer take a look at them.
- View the site traffic logs. Ask your developer to look for unwanted traffic through hosting logs or your analytics tool. Consider blocking unwanted traffic at the hosting level to avoid draining site resources.
Security warnings are important, but they don’t always appear first. Early signs often appear as small shifts in orders, accounts, or site activity. The key is to notice these changes and respond quickly.

Christopher is a Solutions Architect at Woo and works with growing sellers to solve the tough technical issues that hinder their next phase of growth. When he’s not working, he’s somewhere on the Carolina coast with his family and their golden doodle, or he’s holding a dessert that he has no intention of putting down.
