WooCommerce high-risk payment gateways after a Stripe shutdown

WooCommerce runs on your hosting, so switching gateway is a plugin change. What breaks, what to migrate, and which gateways support restricted categories.

Why WooPayments and Stripe says no

  • WooPayments is built on Stripe, so Stripe’s restricted business list applies to it in full. A category Stripe will not accept is not made acceptable by using the WooCommerce-branded version of it.

  • Stripe operates category-level policy rather than case-by-case underwriting. Its risk systems match on product names, MCC and site content, which is why a shutdown often arrives with no warning and no route of appeal.

  • The same applies to PayPal’s WooCommerce integration. Merchants who move from Stripe to PayPal after a shutdown frequently repeat the experience within a few months.

  • Because WooCommerce itself is not a payment company, nothing about the platform prevents you from using a different gateway. This is the single biggest structural advantage WooCommerce has over hosted platforms in restricted categories.

What switching actually involves

  1. 01

    Get the acquiring relationship first

    The gateway is the easy part. Until an acquirer has underwritten and approved your business, no plugin will help. Pre-qualify, get placed, and only then choose the gateway that provider supports.

  2. 02

    Install the provider’s WooCommerce plugin

    Most high-risk gateways ship a maintained WooCommerce extension. Install on staging, not production. Check the plugin’s last-updated date and its compatibility with your WooCommerce and PHP versions before you commit.

  3. 03

    Migrate stored payment tokens, or accept that you cannot

    If you take subscriptions, this is the decisive question. Card tokens held by your old gateway are usually not portable, which means existing subscribers must re-enter their cards. Ask about token migration before you sign, because after you sign it is not negotiable.

  4. 04

    Rebuild the subscription plumbing

    WooCommerce Subscriptions binds to the gateway that created each subscription. Changing gateway on live subscriptions is the most common source of silent revenue loss during a migration. Plan a re-authorisation campaign and expect to lose some customers to it.

  5. 05

    Test the whole path on staging

    Authorisation, capture, partial refund, full refund, failed renewal and dispute notification. Refunds and disputes are where poorly maintained plugins break, and you will discover it during your first chargeback if you do not test it first.

  6. 06

    Switch, then watch the decline reasons

    Go live at a quiet hour and monitor authorisation rates for a week. A new gateway with untuned risk rules or misconfigured 3-D Secure can quietly decline good customers, and the drop is easy to mistake for seasonality.

WooCommerce is the easy platform to fix

If you are going to be terminated by a mainstream processor, it is better to be on WooCommerce than almost anywhere else. That sounds glib after a shutdown, but it is structurally true and it changes what your recovery looks like.

WooCommerce is a plugin running on hosting you control. It has no opinion about what you sell, no acceptable use policy of its own, and a documented API that any gateway can build against. When Stripe or WooPayments closes your account, you have lost a payment provider, not a store.

Compare that to a hosted platform where the payments layer is owned by the platform itself and switching means working around the product rather than reconfiguring it.

What actually broke

WooPayments is Stripe underneath. The branding is WooCommerce; the underwriting, the restricted business list and the risk decisions are Stripe’s. Merchants regularly discover this at the worst possible moment, having assumed that the WooCommerce-branded product was a separate relationship.

Which means: if your category is on Stripe’s restricted list, WooPayments was never a durable option. Moving to PayPal’s WooCommerce integration usually reruns the same experience a few months later, because PayPal maintains comparable category restrictions.

The route out is a gateway backed by an acquirer that underwrites your category deliberately, rather than one that will discover it during a periodic review.

The subscription trap

This is the part that costs merchants real money, and it is worth reading twice if you bill on renewal.

WooCommerce Subscriptions ties each subscription to the gateway that created it. Card tokens held by your old gateway are, in most cases, not portable to a new one — the tokens are the old provider’s asset, held under their PCI scope.

The practical consequence: on the day you switch, your existing subscribers stop renewing unless they re-enter their card details.

What to do about it:

  • Ask about token migration before signing. Some gateways can receive a token export from specific providers. Most cannot. Establish which before you commit, not after.
  • Plan a re-authorisation campaign. Email subscribers ahead of the switch, explain plainly why they need to re-enter a card, and make the link one click.
  • Expect losses and budget for them. Some percentage will simply not re-authorise. A realistic assumption is better than an optimistic one.
  • Do not run both gateways in parallel indefinitely. It is tempting, and it makes reconciliation and dispute handling steadily worse.

Test the boring paths

New gateway plugins are usually fine on the happy path and unreliable on the paths nobody tests. Before you go live on production, run all of these on staging:

  1. Authorisation and capture, including a 3-D Secure challenge
  2. A partial refund, then a second partial refund against the same order
  3. A full refund on an order that was already partially refunded
  4. A failed renewal, and whatever dunning you have configured
  5. A dispute notification arriving and appearing where you expect it

Refunds and disputes are where poorly maintained extensions break. Finding out during your first chargeback, when the clock is running, is a bad way to find out.

After you switch

Watch authorisation rates for a week. A new gateway with untuned risk rules or badly configured 3-D Secure can quietly decline good customers, and a five point drop in approval rate is easy to mistake for a slow week.

Ask your provider for decline reason codes rather than a headline rate. The distinction between issuer declines, risk-rule declines and authentication failures tells you what to fix, and only one of those three is anything to do with your customers.

Last reviewed

23 August 2026. Regulation in this area moves. Check the primary sources below before acting on anything here, and treat this page as orientation rather than legal advice.

WooCommerce: questions merchants ask

Can I use WooCommerce for a high-risk business?

Yes, and it is usually the better platform for one. WooCommerce is software running on your own hosting rather than a payments company, so it imposes no restrictions on what you sell. You need an acquirer and a gateway that support your category, but the platform itself is not the obstacle.

Why did WooPayments shut down my store?

WooPayments is built on Stripe, so Stripe’s restricted business list applies to it in full. If your category is on that list, WooPayments was never going to be a durable option regardless of how the account performed. The same is true of the PayPal integration.

Will I lose my subscribers if I change gateway?

Possibly, and this is the question to resolve before signing anything. Stored card tokens are usually not portable between gateways, which means existing subscribers have to re-enter their card details. Ask any prospective provider directly about token migration, and plan a re-authorisation campaign if the answer is no.

How long does the switch take?

The technical work is usually a day or two on staging plus a short go-live window. The acquiring approval that has to precede it typically takes 3 to 10 business days from a complete file, and a category needing scheme registration adds one to three weeks after approval. Almost all of the elapsed time is underwriting and registration, not integration.

Do I need a separate merchant account, or just a gateway?

Both. The gateway is the software that talks to the card networks; the merchant account, provided by an acquirer, is what accepts the risk and settles money to your bank. In high-risk categories the acquirer is the hard part, and a gateway on its own will not get you processing.

Find out what is realistic for your store

Five questions, no documents, and an honest answer about whether we can place you — including when the answer is no.