SilentShield
← Back to Blog
WooCommerceSetupSpamWordPress

Protect the WooCommerce checkout from bots with a captcha

Marc Wagner·October 7, 2026·5 min read

WooCommerce has two kinds of checkout, and SilentShield has one switch for each. This guide shows both with screenshots. It was tested on 7 October 2026 with WooCommerce 11.1.2, SilentShield 2.15.14 and WordPress 7.1.2, with cash on delivery as the payment method. Other payment gateways were not part of this test. The captcha method and the other protection layers are covered in the general setup guide. The test used the plugin’s own captcha layers without an API key; the compatibility list for the SilentShield API is in the WordPress guide.

Step 1: Find out which checkout you use

A page that contains the shortcode [woocommerce_checkout] is the classic checkout. The checkout page that WooCommerce 11.1.2 created for our new store uses the Checkout block instead. Open your checkout page in the editor to see which one you have, or use both switches below if you are not sure.

Step 2: Switch on the checkout in SilentShield

Excerpt of the SilentShield Forms list: WooCommerce Block Checkout is off, WooCommerce Checkout is switched on with the badges “Detected” and “Fields detected”, WooCommerce Account Details and WooCommerce Login are off
Screenshot of the English admin interface and test site (SilentShield 2.15.14, WordPress 7.1.2, tested 7 October 2026).

Open SilentShield → Forms. WooCommerce appears as several entries; for the checkout there are WooCommerce Checkout (classic) and WooCommerce Block Checkout. Login, registration and account details have their own switches in the same list. The switch saves immediately, there is no Save button to press.

Step 3: Classic checkout: where the captcha appears

Order review of the classic WooCommerce checkout: the product “Website review × 2” with subtotal and total of 38.00 euros, the payment method “Cash on delivery”, the privacy notice, the captcha “Captcha 10 + 1 = ?” with reload button and answer field, and a black Place order button
Screenshot of the English admin interface and test site (SilentShield 2.15.14, WordPress 7.1.2, tested 7 October 2026).

Add a product to the cart as a visitor in a private browser window and open the checkout. Administrators and logged-in users skip all checks by default, so a test while you are logged in shows nothing. In the classic checkout the captcha sits in the order review, above the Place order button.

Step 4: Classic checkout: test a wrong answer

Classic checkout page with a coupon notice and, below it, a red error notice “Captcha not correct: Captcha check” above the billing details, whose fields keep the entered values
Screenshot of the English admin interface and test site (SilentShield 2.15.14, WordPress 7.1.2, tested 7 October 2026).

Fill in the billing details, enter a wrong answer and click Place order. The order is not placed, and a red notice appears at the top of the form: “Captcha not correct: Captcha check”. With the correct answer, the order went through in our test and WooCommerce showed the order received page.

Step 5: Block checkout: where the captcha appears

WooCommerce block checkout with contact information, billing address, payment option “Cash on delivery” and a black Place Order button; in the order summary on the right, below the total of 38.00 euros, the captcha “Captcha 7 + 5 = ?” with a reload button and an answer field
Screenshot of the English admin interface and test site (SilentShield 2.15.14, WordPress 7.1.2, tested 7 October 2026).

In the block checkout the captcha sits in the order summary on the right, below the total, not above the Place Order button.

Step 6: Block checkout: test a wrong answer

Block checkout after a wrong answer: a red banner “Captcha not correct: Captcha check” above the form, the entered address values still in place, and in the order summary the captcha “5 * 1 = ?” with the answer 99
Screenshot of the English admin interface and test site (SilentShield 2.15.14, WordPress 7.1.2, tested 7 October 2026).

Enter a wrong answer and click Place Order. A red banner appears above the form: “Captcha not correct: Captcha check”. Behind it, the checkout request is answered with an error (HTTP 400, code f12_cf7_captcha_spam_detected), and no order is created. With the correct answer, the order went through in our test.

What to know

  • If your store is still in WooCommerce’s “Coming soon” mode, a visitor window shows the coming-soon page instead of the checkout. We saw this on the block checkout page. Switch the store live before you test.
  • The captcha method, the timer, the gibberish detection and the rules apply to the checkout like to every other form. See the general setup guide.
  • If a caching or optimisation plugin delays JavaScript until the first interaction, exclude SilentShield’s scripts from that; the WordPress guide lists the file names.

Form protection guide

Ready to ditch CAPTCHA?

Start protecting your forms — invisibly. No credit card required.