The honest answer on WooCommerce security plugins is that none of them stop the attack most likely to cost you money. A malware scanner and a firewall protect your files and your login page; the thing hitting stores hardest right now is card testing against your checkout, and that is a WooCommerce setting plus your payment gateway’s fraud rules, not a plugin you buy.
So this page does two jobs. It compares what the four main options actually cost in October 2026 and where each one is weak, and then it covers the checkout-specific hole all four leave open — including the exact WooCommerce filter that closes part of it, which is off by default on every store. Prices come from each vendor’s own pricing page; versions and install counts from WordPress.org.
A store is a different security problem from a blog
Every generic WordPress security roundup optimises for one scenario: somebody defaces your site or injects spam links. That matters, and it is roughly the whole threat model for a content site. A store adds three things that change the calculation.
First, your database holds names, addresses, order histories and partial card data, so a compromise is a disclosure event with legal consequences rather than an afternoon of cleanup. Second, your checkout is a free oracle for anyone holding a list of stolen card numbers — it will tell them, for the price of a $1 order, which cards are live. Third, your store has a revenue number attached to every hour of downtime, which changes what a six-hour malware-removal SLA is worth compared with a thirty-hour one.
Card testing is the attack to understand first
That is not an argument against buying a security plugin. It is an argument for knowing which of your problems the purchase solves, because the marketing on all four products below implies it solves all of them.
How I judged these WooCommerce security plugins
Stated up front so you can reweight them for a store shaped differently from the one I assumed: a US store, 100 to 2,000 orders a month, one or two people running it, no security specialist, and a host that gives you cPanel or a dashboard rather than root.
- What the free tier genuinely does. Not whether one exists. The useful question is which of detection, protection and cleanup you get for nothing, because those three are priced very differently and vendors blur them.
- Where the firewall runs. A plugin firewall runs inside PHP, so a request has already loaded WordPress before it is blocked. A DNS-level firewall blocks it before it reaches your server. That difference decides whether an attack costs you PHP workers.
- Whether cleanup is included or sold separately. The gap between “we will tell you that you are infected” and “we will fix it” is the single largest price jump in this category.
- Response time, in writing. For a store, an SLA measured in hours is a product feature. Compare it against your own revenue per hour rather than against the next vendor’s number.
- Licence shape at one site. Several of these are priced for agencies. A single store can end up paying 25-site rates, which is the most common way this budget gets wasted.
- What it does about checkout. Judged honestly, and the answer is mostly “nothing”, which is why the second half of this article exists.
What I deliberately did not judge: detection rates. Every vendor publishes its own and none of them are reproducible on your store. I would rather tell you what each product costs and what it structurally cannot do.
WooCommerce security plugins compared
Prices read from each vendor’s own pricing page in October 2026. On a narrow screen this table stacks into one card per option rather than scrolling sideways.
| Option | Firewall runs | What you get free | Paid price | Cleanup included | Where it falls short |
|---|---|---|---|---|---|
| Wordfence 9.0.2 | In PHP, on your server | A lot. 5+ million active installs, 4.7/5 from 5,021 reviews, tested to WordPress 7.1.3, last updated 30 September 2026. Firewall, malware scanner and login security, with rules that arrive later than paying customers get them | Premium $149/yr. Care $590/yr. Response $1,250/yr | Only at Care and above | The firewall loads WordPress before it blocks, so a sustained attack still burns PHP workers. Rule and signature updates are real-time only on Premium. Cleanup needs the $590 tier |
| Patchstack | Virtual patching at the plugin layer | Personal plan: 3 site slots, vulnerability detection and real-time email alerts, central dashboard. Detection only — no attack protection | $5/mo per site on Personal (up to 3 sites). Developer $69/mo billed annually for 25 sites, or $79/mo monthly, plus $12.50/mo per extra 5 sites | No | Priced for agencies. One store pays $5/mo for protection, or jumps to a 25-site plan it cannot use. No malware removal at any tier |
| Sucuri Platform | DNS level, before your server | A free scanner plugin, which checks and reports but does not block | Basic $229/yr, Pro $339/yr, Business $549/yr | Yes, on every paid tier | Scan frequency and response time are what you are buying: 12 hours and a 30-hour SLA on Basic against 30 minutes and 6 hours on Business. The DNS firewall means pointing your domain at them, which is a real operational commitment |
| MalCare | In PHP, scanning offloaded to their servers | Free plan: weekly scanning and a basic firewall. No cleanup | Protect $99/yr (1 site) / $299 (5). Repair $299/yr (1) / $899 (5). Fortify $499/yr (1) / $1,499 (5) | From Repair up — one-click removal | One-click cleanup, the reason most people look at it, starts at $299/yr. The $99 tier is protection without repair. Its pricing page lists no backups, so budget for those separately |
| Hardening by hand + a CDN firewall | At the CDN edge | Everything, at $0, if you do the work | $0, or a few dollars a month for a paid CDN tier | No — you restore from backup instead | No scanner, no alerting, nobody to call at 2am. You will not notice a subtle infection. Fine as a floor, not as a plan, and it costs you evenings rather than dollars |
Wordfence: the default, and what the free tier really costs you
Version 9.0.2, more than 5 million active installs, 4.7 out of 5 across 5,021 reviews, tested to WordPress 7.1.3 and updated at the end of September 2026. That install base is the strongest argument for it: whatever breaks on your stack, somebody has already hit it and written it up.
Premium is $149 a year. Read Wordfence’s own description of what that buys and the free tier’s limitation is explicit — Premium lists real-time firewall rule and malware signature updates as a paid feature, alongside a 30-day audit log, the IP blocklist, country blocking and priority support. Free installs get the same rules, later. For a blog, later is usually fine. For a store, the window between a WooCommerce extension vulnerability going public and your firewall knowing about it is exactly when stores get hit, because attackers scan for new disclosures within hours.
Above Premium, Care at $590/yr adds a dedicated analyst, a yearly security audit, incident response and a 6-month audit log. Response at $1,250/yr adds 24/7/365 incident response with a one-hour response time and a one-year log. Those are the tiers where somebody else cleans up an infection.
Weakness worth naming: the firewall is a WordPress plugin, which means a blocked request has still booted PHP, loaded WordPress and queried your database before Wordfence rejects it. Under a real flood that is the problem — your store does not go down because the attack succeeded, it goes down because every PHP worker is busy rejecting it. If your host gives you a fixed worker count, read WooCommerce hosting requirements for PHP workers and RAM and work out how many concurrent requests you can absorb before anything queues; and if your admin has started crawling for no obvious reason, diagnosing a slow WordPress admin dashboard covers how to tell attack traffic from a plugin problem.
Patchstack: a different idea, priced for agencies
Patchstack does not try to be a scanner. It watches the vulnerability disclosure feed, works out which of your plugins are affected, and applies a virtual patch — a rule that neutralises the specific exploit — so you are covered in the gap between disclosure and the plugin author shipping a fix. On a store running fifteen WooCommerce extensions, that gap is your actual risk, and this is the most direct answer to it.
The free Personal plan gives you 3 site slots with vulnerability detection and real-time email alerts, and is clear that it only detects: protection is paid, from $5 a month per site, up to 3 sites on that plan. Above that it is the Developer plan at $69/mo billed annually (or $79 monthly) for 25 sites, with extra slots at $12.50/mo per 5.
Weaknesses worth naming: the licence shape is wrong for a single store. Protection for one site is $5/mo, which is good value, but there is nothing between that and a 25-site agency plan — so a two-store owner wanting room to grow is looking at $828 a year for 25 slots. And Patchstack will not remove malware. If something already got in, this is not the product that gets it out.
Virtual patching also does not excuse you from updating. It buys time, and the WordPress 7.1.x cycle has shown how fast that time runs out — see the 7.1.2 release that fixed CVE-2026-87902 for the shape of a disclosure you want to be ahead of.
Sucuri: the only one that blocks before your server
Sucuri’s platform is $229/yr Basic, $339/yr Pro, $549/yr Business, and what separates the tiers is time. Basic scans every 12 hours with a 30-hour malware-removal response estimate; Pro every 6 hours with 12; Business every 30 minutes with 6. Cleanup is included on all three, which is the structural difference from Wordfence, where it starts at $590.
The firewall is the real draw. It runs at DNS level, so you point your domain at Sucuri and malicious traffic never reaches your origin — which is the one thing a PHP-based firewall cannot do. Their Anycast CDN sits in the same path; Sucuri’s claim of a 60% average reduction in server load is a vendor figure, not something I measured, and the page does not tie it to a tier.
Weaknesses worth naming: putting a third party in front of your DNS is a commitment, not a setting. Their edge becomes a dependency for your checkout, you need to get origin IP allowlisting right or attackers simply bypass the firewall by hitting your server directly, and it interacts with whatever page caching you already run. Work through WooCommerce caching plugins and what breaks before you add another caching layer in front of cart and checkout, because two caches disagreeing about those pages produces bugs that look like fraud. The 30-hour response on the $229 tier is also slow for a store — if you are buying Sucuri for the cleanup SLA rather than the firewall, Basic is probably not the tier you want.
MalCare: cleanup is the product, and it is not the cheap tier
MalCare’s pitch is one-click malware removal without a support ticket, and its scanning runs on its own servers rather than yours, so a deep scan does not compete with your store for CPU. There is a genuine free plan: weekly scanning and a basic firewall, no cleanup.
Paid is where you have to read carefully, because the tier names do the opposite of what you would guess. Protect is $99/yr for one site ($299 for five) and gives you 24-hour scanning and an advanced firewall — but no cleanup. Repair at $299/yr for one site ($899 for five) is the first tier with one-click removal, plus 12-hour scanning and a real-time firewall. Fortify at $499/yr ($1,499 for five) scans hourly and adds unlimited manual fixes.
Weaknesses worth naming: the headline feature is in the $299 tier, not the $99 one, which makes MalCare more expensive than it first looks and more expensive than Sucuri Basic for a comparable outcome. Its pricing page does not mention backups, so do not assume this replaces one — and do not let the word “Repair” convince you it does.
What $0 actually covers, and what it leaves open
Worth being specific about, because the free baseline is better than most roundups admit and there is no commercial reason for anyone to tell you so. A store with these five things done is harder to compromise than a store running Wordfence Premium with none of them:
- Update on a schedule you actually keep. Nearly every compromise traced to a vulnerability is a known one with a patch already shipped. This is free and it outperforms everything you can buy.
- Disable file editing. Put
define( 'DISALLOW_FILE_EDIT', true );inwp-config.phpso a stolen admin session cannot rewrite your theme from the dashboard. - Two-factor on every administrator and shop manager. WordPress has shipped application passwords and there are free 2FA plugins; the attack this stops is credential stuffing, which is the most common way stores actually lose an admin account.
- A CDN firewall in front of the site. Cloudflare’s free tier will absorb volumetric nonsense before it reaches your PHP workers. This is the capability the paid plugin firewalls cannot give you.
- Turn on your gateway’s fraud screening. If you take cards through Stripe, Radar Lite is included at no additional charge on standard payments pricing and explicitly covers card testing. The paid Radar tier starts at $10 a month. Enabling what you already pay for is the highest-value fifteen minutes in this entire article.
What $0 does not give you is detection. Nothing above will notice a web shell quietly sitting in your uploads directory, or a modified payment template skimming card numbers at checkout. That is what you are buying with a scanner, and for a store handling customer payment data it is a reasonable thing to buy.
The checkout hole none of these plugins close
Here is the part worth the price of admission, and it is free. WooCommerce’s Store API has built-in rate limiting, and it is disabled by default. Card-testing attacks now hit that API directly, including on stores that never adopted the Checkout block, because the endpoint is there either way.
Turn it on with a filter. Drop this in wp-content/mu-plugins/ so a theme switch cannot take your protection with it:
<?php
// wp-content/mu-plugins/store-api-rate-limit.php
add_filter( 'woocommerce_store_api_rate_limit_options', function () {
return [
'enabled' => true, // default: false
'proxy_support' => false, // true if you sit behind a CDN or proxy
'limit' => 25, // default: 25 requests
'seconds' => 10, // default: per 10 seconds
];
} );
Three things to know before you ship it. If your store is behind Cloudflare, Sucuri or any proxy, set proxy_support to true — otherwise every request appears to come from the proxy’s IP and you will rate-limit your own customers into a single bucket. WooCommerce 9.6 added much stricter rules specifically for the place-order endpoint, POST /wc/store/v1/checkout, which can be switched on from the admin UI rather than in code. And WooCommerce 9.8 added a woocommerce_store_api_rate_limit_id filter so you can identify clients by something other than IP — a hash of user agent and Accept-Language, for instance — which matters because a competent attacker rotates IPs.
Two different rate limiters, two different screens
One more trap, and it is a nasty one. If you added a CAPTCHA to checkout and assumed that settled it, check the plugin’s version. Several popular CAPTCHA plugins did not validate against the Checkout block or the Store API at all, so the check could be bypassed entirely while the settings screen showed it enabled. Patched releases landed in December 2024 — Google reCAPTCHA by Koala Apps 1.4.1, reCAPTCHA by I13 Solutions 2.57, reCAPTCHA by RelyWP 1.4.0 and Cloudflare Turnstile by RelyWP 1.28.0. If yours predates that, your CAPTCHA has been decorative.
Rate limiting slows card testing; it does not prevent it. The layer that actually declines the transactions is your gateway’s fraud screening, which is why the Radar point above sits where it does. And watch what the noise does to your reporting: a card-testing run fills your store with half-finished checkouts, which inflates every abandonment number you have, so if your recovery metrics suddenly look strange, read them against WooCommerce abandoned cart plugins compared before you conclude your checkout has a usability problem. The per-transaction consequences are in WooCommerce payment gateway fees explained for US stores — dispute fees are the line item that turns this from a nuisance into a real number.
A security plugin is not a backup, and the reverse
These get bought as substitutes and they are not related. A scanner tells you something is wrong. A backup is how you get back to a state where it was not. Wordfence Premium at $149 does neither of those last two things, and MalCare’s pricing page lists no backups at any tier.
There is a wrinkle specific to stores, and it is the reason restoring a hacked store is harder than restoring a hacked blog: rolling back to last night’s snapshot also deletes every order that arrived this morning. You need a restore plan that reconciles orders rather than discarding them — WooCommerce backup plugins compared for store owners covers which tools let you do that, and whether a plugin, a host snapshot or a service fits your store is the decision underneath it.
Two practical notes for the bad day. If a security plugin locks you out of your own dashboard — which happens, usually at the worst moment — disabling a WordPress plugin without dashboard access is the way back in. And before you conclude you have been compromised, turn on logging and look: enabling WordPress debugging and safely reading error logs will often show a plugin conflict rather than an intrusion.
What to pick at your store’s size
- Under 100 orders a month, tight budget. Wordfence free, plus the five hardening steps, plus Cloudflare’s free tier, plus Store API rate limiting and your gateway’s fraud screening. Spend nothing. This configuration beats a paid plugin on an unhardened store, and it costs you one evening.
- A real store, one site, you want cleanup covered. Sucuri Pro at $339/yr. Cleanup on every tier, a firewall that blocks before your server, and a 12-hour response rather than Basic’s 30. The DNS change is the cost of entry.
- Many WooCommerce extensions and a slow update habit. Patchstack protection at $5/mo per site, which is the cheapest meaningful spend in this article. Add a scanner separately, because Patchstack will not find an existing infection.
- You have already been hacked once and want a button. MalCare Repair at $299/yr. One-click removal without waiting on a ticket is worth the premium over the $99 tier, which does not include it.
- Revenue where an hour of downtime hurts. Wordfence Care at $590/yr or Response at $1,250/yr buys a human and a response time. Compare those numbers against your revenue per hour, not against the other plugins.
- Agency or 20+ sites. Patchstack Developer at $69/mo annually for 25 sites is dramatically cheaper per site than anything else here.
Whichever you choose, do the free checkout work first. It takes fifteen minutes, it costs nothing, and it addresses the attack your security plugin is not looking at.
Frequently asked questions
Do I need a security plugin if my host says it handles security?
Ask what specifically they do, because “we handle security” usually means network-level filtering and nightly backups. That is real and useful, and it is not a malware scanner looking at your WordPress files, and it is almost never anything about your checkout. Get three answers in writing: do they scan the filesystem for malware, will they clean an infection or just restore a backup over it, and do they do anything about application-layer attacks like card testing. Most managed hosts answer no to the third, which is the one this article is about.
Is the free version of Wordfence enough for a WooCommerce store?
For a small store with a disciplined update habit, yes, as a starting point. The limitation is timing: Wordfence lists real-time firewall rule and malware signature updates as a Premium feature, so free installs get new rules later than paying ones. Attackers scan for newly disclosed vulnerabilities within hours of publication, and that delay is the window. If your store carries real revenue, $149 a year to close it is not a hard decision — but hardening and checkout rate limiting should come first, because they are free and they matter more.
Will a security plugin slow down my WooCommerce store?
A PHP-based firewall adds work to every request, and a filesystem scan is heavy I/O, so yes, measurably. Two things reduce it: schedule scans for your quietest hour rather than leaving the default, and prefer a product that scans off your server — MalCare runs scanning on its own infrastructure, and Sucuri’s firewall filters traffic before it reaches you at all. The bigger performance risk is not steady-state overhead but an attack: a plugin firewall blocks requests only after WordPress has loaded, so a flood can exhaust your PHP workers even though every request is being refused.
How do I stop card testing attacks on WooCommerce checkout?
Three layers, and no security plugin is one of them. Enable Store API rate limiting with the woocommerce_store_api_rate_limit_options filter, since it is off by default, and set proxy support if you sit behind a CDN. Turn on your gateway’s fraud screening — Stripe’s Radar Lite is included at no extra charge on standard payments pricing and specifically covers card testing. Then verify your CAPTCHA actually validates against the Store API, because several popular CAPTCHA plugins did not until patches shipped in December 2024. Rate limiting slows the attack; the gateway is what declines the transactions.
Can I run two security plugins at once?
Two scanners is wasteful but survivable. Two firewalls is asking for trouble — they fight over login handling, IP blocking and the same hooks, and the failure mode is you locked out of your own store with no clear reason. One sensible combination is a detection-only product alongside a protection product, for instance Patchstack watching your plugin vulnerabilities while Wordfence scans your files. If you are moving from one security plugin to another, deactivate and delete the first, and check that it removed its firewall rules from .htaccess or wp-config.php, since several leave them behind.
Does a security plugin make my store PCI compliant?
No, and treat any vendor implying otherwise with suspicion. PCI DSS applies to your whole business, and your obligations depend mostly on how card data reaches your processor. A store using a hosted or tokenised field, where card numbers go straight to Stripe or PayPal and never touch your server, sits in a much narrower scope than one posting card data through its own PHP. A firewall and a scanner support your case; they do not establish it. If compliance is a contractual requirement for you, ask your processor which self-assessment questionnaire applies to your integration before buying anything.
The short version
Do the free work before you spend: update on a schedule, two-factor every admin, a CDN in front of the site, Store API rate limiting on, and your gateway’s fraud screening enabled. That configuration stops more of what actually happens to stores than any licence on this page.
Then buy detection, because that is the thing hardening cannot give you. Sucuri Pro at $339/yr if you want cleanup included and a firewall that blocks before your server. Wordfence Premium at $149/yr if you want the option with five million installs behind it. Patchstack at $5/mo per site if your risk is unpatched extensions. And keep a backup you have actually test-restored, because none of these are one.
Sources
- Wordfence on WordPress.org and Wordfence pricing
- Patchstack pricing plans
- Sucuri Website Security Platform plans
- MalCare pricing
- Rate limiting for Store API endpoints and Card testing attacks and the Store API
- Configuring rate limiting for customer accounts
- Stripe Radar pricing and Stripe pricing for dispute fees

Leave a Reply to This Post