---
title: "\"Checkout's being weird\" · Woodshack"
description: "A store's customer said checkout was being weird. It was a credit card skimmer that only some visitors ever saw, and that more than one security plugin had missed. How we found it, and why we stopped trusting WordPress to watch WordPress."
url: https://woodshack.net/work/the-skimmer/
site: Woodshack (https://woodshack.net/)
about_this_site: https://woodshack.net/for-ai/
---
Work · Security · Ongoing care

# "Checkout's being weird."

That was the whole report, passed along from one of the store's own customers. It turned out to be a credit card skimmer that only some visitors ever saw.

Tim did this work at the web agency where he's director of operations. Walter Sentry, the tool that came out of it, is his own.

## The report

A customer of an online store told the owner that the site was being weird on checkout. The owner passed it on to us. There was no error message and nothing obviously broken. Just one customer who had noticed something.

We weren't sure what we were looking for. Attackers have gotten good and sneaky, and with AI tools in the mix they're getting better at it fast, so "nothing looks broken" no longer means nothing is wrong. We took the report seriously and started digging.

## What we found

Hidden in the checkout was a credit card skimmer: code that quietly copies customers' card details as they pay. It only showed itself to certain visitors, on certain browsers, under certain conditions. Everyone else got a normal checkout.

That's how it had gone unnoticed. More than one industry-standard WordPress security plugin was running on the site, and none of them had caught it.

## How it worked

We cleaned it out, then spent a lot of time taking it apart, because a skimmer that careful doesn't get there by accident.

One of its tricks: nobody's account had been promoted to administrator, which is the thing a security plugin looks for. Instead, an ordinary user role had quietly been given administrator permissions. Every account on the site still showed its usual role, and the users list looked normal. The role itself was the back door. There were other tricks, and they shared one idea: look normal to anything that checks for the usual things.

## Don't ask WordPress to watch WordPress

We moved the store to clean, safe hosting and cleaned out the malicious code. That fixed the day. It didn't fix the next day.

The bigger lesson was about the plugins. A security plugin lives inside the site it protects, and it sees the site the way WordPress shows it. Whoever gets deep enough to plant a skimmer can get deep enough to shape what the plugin sees. So we stopped trusting WordPress to watch WordPress, and built a way to keep watching from outside: a monitor that checks the site over the same access a developer would use, with nothing installed on the site itself, looking for the kinds of changes skimmers and backdoors leave behind, like a role that gained permissions it never had.

That tool became [Walter Sentry](https://woodshack.net/sentry/).

## Since then

The store is still clean. Sentry has been watching the whole time, and it's mostly been quiet, which is exactly what you want from a security tool.

When it has spoken up, it was right to:

- **It flagged someone installing a file manager plugin** of the kind attackers love, and that we never allow on a site we look after.

- **It flagged one user logging into several sites.** That one turned out to be us, but it's exactly the pattern it should notice.

## Every site makes every site safer

Sentry doesn't just learn from one store. Every lesson from every site we watch goes back into the tool. So when we find a problem in one place, we check everywhere.

That's how we caught a vendor's compromised password on about half a dozen sites, before it turned into a skimmer of its own.

## Why it matters for you

The best early warning system is a customer who says "checkout's being weird," an owner who passes it on, and someone who takes it seriously enough to look past "nothing's obviously broken."

Cleanup fixes today. Watching is how you find out if that changes, and the watching has to happen from outside the thing being watched. Security is boring when it's working, and boring is the goal. That's the whole idea behind ongoing care, and it's why we built Walter Sentry in the first place.

[How ongoing care works →](https://woodshack.net/care/) [About Walter Sentry →](https://woodshack.net/sentry/)

- security

- incident response

- WooCommerce

- ongoing care

[← All work](https://woodshack.net/work/)
