Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareWooCommerce Credit Card Skimmer: Find and Remove Malware

WooCommerce Credit Card Skimmer: Find and Remove Malware

A WooCommerce credit card skimmer is malicious code designed to capture payment or customer information during checkout. Because the legitimate transaction can still complete normally, the compromise may not be obvious to the customer or store owner.

Signs you might see

  • Customers report card fraud after buying
  • Extra fields or scripts on checkout
  • Unknown scripts loading on checkout pages

Not sure? Run our free WordPress security scanner for a quick outside check.

How WooCommerce card skimming malware works

Web skimming, sometimes described as Magecart-style activity, targets ecommerce checkout processes. Malicious JavaScript can read information entered into a compromised payment page and transmit selected data to infrastructure controlled by the attacker.

The malicious code may be inserted into WordPress files, a theme, a plugin, the database or a third-party script loaded by checkout. An attacker can also alter the payment flow or inject convincing additional fields. This means an order appearing successfully in WooCommerce does not prove the browser was shown only legitimate code.

Payment-page security requires particular care because scripts executing in the customer's browser can affect sensitive information. PCI Security Standards Council guidance places specific emphasis on authorising payment-page scripts, checking their integrity and detecting unauthorised changes.

How to check WooCommerce for a credit card skimmer

If customers report suspicious card activity after purchasing, treat the report seriously without assuming the website is automatically the cause. Preserve evidence and inspect the checkout before making changes that could destroy useful information.

Review the browser developer tools and page source for scripts, domains or checkout fields that should not be present. Compare the current checkout with a known clean version and inspect recently modified theme, plugin and JavaScript files. Check database content for injected scripts and review third-party resources loaded by checkout.

Test from both desktop and mobile because malicious behaviour can be conditional. Where relevant, compare what ordinary visitors receive with the response available to Google's crawlers through Search Console inspection. Also check Search Console Security Issues and Pages reports and run a site:yourdomain.co.uk search for signs of a wider compromise.

The free WordPress security scanner provides another external check, but checkout skimming requires close inspection of the code and resources that actually execute in the browser.

How to clean a WooCommerce skimmer safely

  1. Preserve the evidence. Take a complete backup of the files and database before cleaning and retain an untouched copy of the compromised store. Preserve relevant server and security logs where available.
  2. Protect customers while investigating. If checkout may be compromised, stop exposing customers to the affected payment flow until it has been examined and secured.
  3. Identify both the skimmer and its entry point. Review changed files, database injections, plugins, themes, administrator accounts, hosting access and third-party scripts. Removing the visible JavaScript without closing the route used to install it leaves the store vulnerable to reinfection.
  4. Restore trusted code. Remove confirmed malicious injections, replace altered WordPress core files and reinstall affected plugins or themes from trusted sources. Verify every script expected on the checkout page.
  5. Rotate access credentials. Change WordPress passwords, hosting access, database passwords, FTP or SFTP credentials, relevant service keys and the WordPress salts in wp-config.php.
  6. Escalate the payment incident appropriately. If payment-card data may have been exposed, contact your payment service provider or acquirer promptly and follow the incident and PCI DSS requirements applicable to your payment setup.
  7. Retest before reopening checkout. Inspect the rendered payment page, network requests, files and database again and confirm the original access route has been closed.

Hacked Site Rescue is £349 fixed price for investigation and malware removal.

Reducing the risk of WooCommerce skimmer reinfection

Keep WooCommerce, WordPress, themes and plugins updated, and completely remove unused extensions. Restrict administrator access, require strong unique passwords and two-factor sign-in, and use lower-privilege accounts for people who do not need control of plugins or site code.

For checkout security, maintain an inventory of scripts that are supposed to run on payment-related pages and investigate unexpected additions or changes. Payment implementations differ, so merchants should follow current guidance from their payment provider and the PCI Security Standards Council for their environment.

File integrity checks and reliable off-server backups give you additional evidence and recovery options. Because WooCommerce is an ecommerce platform, ongoing support requires Premium Care, while Web Support Services care plans as a range start from £59 a month.

Common questions

Answers to the questions we hear most about this.

What is a WooCommerce credit card skimmer?

It is malicious code that interferes with the ecommerce payment flow, commonly by capturing information entered in the customer's browser and transmitting it to an attacker.

Can a checkout skimmer work even when payments still succeed?

Yes. Some skimming code copies data while allowing the legitimate checkout process to continue, so successful orders do not rule out a compromised payment page.

What should I do if customer card information may have been exposed?

Preserve evidence, stop using a payment flow that may still be compromised, investigate and remove the malicious code, and contact your payment service provider or acquirer promptly for the incident and PCI DSS steps applicable to your setup.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support