NewMaxio Metering is now available — usage-based billing for Advanced Billing.Learn more
/

Manage Card Testing Exposure

··

Last updated on Sep 1, 2026

Card testing occurs when fraudsters use automated scripts to validate stolen or algorithmically generated card numbers, typically through small-value or zero-dollar transactions on publicly accessible payment forms. Public Signup Pages, designed to reduce friction for new Customers, can also give automated testing scripts an easy entry point.

Recognize card testing activity

Watch for these signs that your account may be experiencing a card testing attack:

  • A sudden spike in failed payments or authorization-only transactions
  • A high volume of small-value charges ($0.01-$5.00) with no associated order or sale
  • Multiple failed payment attempts from the same IP address or device
  • Frequent use of international or high-risk card BINs
  • Reversals or voids immediately following authorizations
  • Unusual activity concentrated in off-hours or across time zones

Configure Maxio protections against card testing

Maxio provides several protections against automated card testing that you can enable or keep up to date on your own account.

Consider these options to reduce card testing exposure on Public Signup Pages:

  • Enable CVV verification as a required field for your account. This affects Public Signup Pages and other payment forms, and can eliminate a significant portion of card testing attempts that use basic stolen card data.
  • Upgrade to the latest version of Maxio.js (formerly Chargify.js). Maxio.js applies Google reCAPTCHA Enterprise protection automatically to help block automated bot traffic while remaining invisible to legitimate Customers. Sites on an outdated Maxio.js version don't receive this protection.
  • If you have a custom checkout implementation, keep Maxio.js updated to the latest version to receive ongoing bot-detection and security token improvements.

Respond to a card testing attack

If you're using Maxio Payments, contact the support team immediately when you detect suspicious activity. The Maxio team can implement temporary protective measures while you work together on a longer-term solution.

If you're using an external payment gateway, contact your gateway provider immediately. Gateway providers offer their own tools for combating card testing that aren't available through the standard Maxio merchant interface.

If you collect card details through your own pages rather than a Maxio-hosted page, see Prevent Card Testing Abuse with Maxio.js for the protections available at the form itself.

Get help

If you need help reviewing your current payment setup or strengthening your card testing defenses, contact us:

Still need help?
Reach out and our support team will take it from here.

Contact support