Securantis

WordPress & WooCommerce

WooCommerce Monitoring: Events, Alerts, Compatibilities and Checkout Exclusions

Understand the WooCommerce events monitored by Securantis, configure alerts, check compatibility and exclude the checkout from unreliable blocks to preserve payments.

← Back to help center

Securantis how-to guide

Purpose of this article

This guide explains what Securantis monitors in a WooCommerce store, how to enable and configure alerts, which compatibilities to verify (WooCommerce version / themes / block-based checkout) and how Securantis avoids interrupting the payment flow by applying cautious exclusions to the checkout.

Who this article is for

  • Administrators and technical managers of WooCommerce stores.
  • Users of the Securantis plugin for WordPress & WooCommerce who want to understand the events visible in the client area.

Prerequisites

  1. Securantis plugin installed and activated on WordPress.
  2. WooCommerce installed and activated on the same WordPress instance.
  3. Active Securantis account and linked agent (valid license, working cloud connection if synchronization is desired).
  4. WordPress administrator access to change settings and test.

Monitored WooCommerce events (overview)

Securantis collects and records sensitive events related to WooCommerce in order to alert, keep history and assist diagnosis. Common event types include:

  • WooCommerce configuration changes (e.g. modification of payment gateways or banking details).
  • Order status transitions (including transitions considered unusual).
  • Creation of refunds.
  • Creation and update of coupons.
  • Creation, modification and deletion of webhooks.
  • Creation of customer accounts.

These events are sent to your Securantis client area without transmitting secret keys, passwords or full banking details.

Enable and configure WooCommerce monitoring

Steps:

  1. Open the Securantis administration interface on your site (WooCommerce dedicated area in the plugin).
  2. Verify that the connection with the cloud service is active if you want to synchronize events to the client area.
  3. In the plugin’s WooCommerce settings, enable the types of events to monitor: order status, refunds, coupons, customers, webhooks, etc.
  4. Save the settings then, if necessary, force a synchronization of pending events.

Expected result:

  • Selected events appear in the plugin’s local history and are marked for synchronization to the cloud if the connection is active.
  • The Securantis dashboard displays the number of events over 24 h and events pending synchronization.

Compatibility and practical checks

  1. WooCommerce version: Securantis detects if WooCommerce is active and its version number. Ensure you use a current version supported by WooCommerce and WordPress. If WooCommerce is absent or inactive, the Securantis WooCommerce module will remain inactive.
  2. Block-based checkout: Securantis detects if the checkout page uses the official WooCommerce block. This information is used to determine whether certain protections (such as injecting a CAPTCHA widget) are compatible.
  3. Themes and page builders: some themes or modules that deeply modify the checkout may require manual testing; enable protections progressively and verify the purchase flow.

Exclusions and security principles for the checkout

  • Prudent fail-open principle: Securantis applies a cautious policy to avoid blocking payments. Ambiguous signals do not trigger automatic blocking of payment flows or critical webhooks.
  • Explicit exclusions: The order flow, payment webhooks, REST requests related to payments and certain business AJAX routes are excluded from uncertain blocks. These exclusions are intended to preserve commercial availability.
  • CAPTCHA at checkout: Securantis can display a CAPTCHA on the order confirmation form if the option is enabled and compatible with the current checkout page. Enabling CAPTCHA at checkout is a separate option — enable it only after testing the flow in a pre-production environment if possible.

Recommended cautious settings

  1. Enable monitoring in production but keep automatic blocking for the checkout initially disabled; observe alerts for 48–72 hours.
  2. Enable email notifications for critical events (gateway change, webhook deletion, significant refund).
  3. For CAPTCHAs, start with detection and reporting before applying a visible CAPTCHA at checkout.
  4. If you use a heavily customized theme, perform a complete order test (product, cart, checkout, payment) after each settings change.

Common errors and their causes

  • No WooCommerce events recorded: WooCommerce may be inactive or the Securantis plugin may not have the necessary permissions. Verify that WooCommerce is activated and that the Securantis extension has been updated.
  • Events stuck in synchronization: the connection between the agent and the cloud may be interrupted. Check license status and outbound connectivity (HTTPS to Securantis services).
  • CAPTCHA not displayed at checkout: either the CAPTCHA option for checkout is not enabled, or the checkout page uses a block not detected as compatible. Verify whether the checkout is based on the official WooCommerce block and test on a bare page.

Step-by-step troubleshooting

  1. Check the state of the WooCommerce module in Securantis: confirm the module is active and the WooCommerce version is detected.
  2. Reproduce a test event (e.g. create a coupon, modify a gateway, create a refund) and check its appearance in the local history.
  3. If the event does not appear: flush caches, check for conflicts with other plugins that intercept the same hooks, enable the plugin debug mode if available.
  4. If cloud synchronization remains pending: check PHP and network error logs, ensure outbound HTTPS requests are not blocked by the server or a hosted WAF.
  5. For CAPTCHA at checkout that legitimately blocks customers: temporarily disable the checkout protection, collect details (time, IP, user agent), then adjust the sensitivity.

Important precautions

  • Never configure a global automatic block without a progressive observation phase; false positives can interrupt sales.
  • Never send passwords or secret keys by email. Sensitive information is not sent to the cloud by Securantis.
  • Quarantine, deletion or restoration actions on files must always be validated by a person: Securantis does not perform these deletions automatically.

When to contact Securantis support

Contact support if:

  • You observe checkout blocks despite exclusions being enabled.
  • Critical events (gateway change, webhook deletion) do not appear or are not synchronized to the client area.
  • You need an in-depth check (logs, event traces, fraud case analysis) and require a technical intervention.

Information to provide when contacting support:

  • WordPress and WooCommerce versions.
  • Precise description of the observed behavior (reproducible steps).
  • Timestamps of events and identifiers of affected orders.
  • Indicate whether you have a test environment to reproduce the issue.

Conclusion

Securantis provides dedicated monitoring of sensitive WooCommerce elements (gateways, refunds, coupons, webhooks, customer accounts, order statuses) while applying cautious protections at checkout to avoid interrupting payments. Enable and observe first, then harden progressively: this is the best approach to reconcile security and commercial availability.

If you are unsure about a setting or encounter abnormal behavior, contact Securantis support with the items listed above; we will guide you step by step.

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active