Ongoing carding / fake checkout attempts from PH & TW — best way to block at Kinsta level? Body:

Hi all,

We’re running a WooCommerce + Stripe store (lepure.com) on Kinsta and for the past several days we’ve been hit with a continuous wave of failed checkout attempts / manual card testing. Traffic is overwhelmingly from Philippines and Taiwan IPs — no legitimate customers in those regions, so blanket blocking is fine for us.

What we’ve tried so far:

  • Opened a chat with Kinsta support asking to block those ranges — either wasn’t applied or didn’t stick.

  • Manually added offending IPs to the IP Deny list in MyKinsta — attempts keep coming from fresh IPs in the same countries, so it’s a whack-a-mole.

What I’d like to hear from the community:

  1. Has anyone managed to set up country-level geoblocking (PH / TW) cleanly on Kinsta? Is the Kinsta firewall the right layer, or is everyone doing this via Cloudflare in front?

  2. For carding specifically on /checkout and /?wc-ajax=checkout, what’s working best — Cloudflare WAF managed rules, rate limiting, bot fight mode, a WooCommerce plugin, or a combination?

  3. Anyone blocking VPN / datacenter ASNs as well? Which ASN list / approach has been low-false-positive for you?

Goal is to stop this at the edge so it never hits PHP/Woo/Stripe. Any concrete rules, screenshots, or setups you’re happy with would be hugely appreciated.

Thanks!

Hello @Edouard_Rozan :waving_hand:

I’m sorry to hear that you’ve had a recurring issue with failed checkout attempts.

Those are usually the fault of a plugin vulnerability (for example like Woocommerce PayPal Payments)

Woocommerce advises Captcha: Fraud prevention Documentation - WooCommerce

Also, I advise you to come back to a chat and our engineers will take a look.

Kind regards!