The short answer
Use a gateway with hosted fields or an iframe so card data never touches your server — this keeps you in SAQ-A scope instead of a full audit. Enable AVS and CVV checks, configure 3D Secure 2, and test the full refund path before launch.
PCI scope is the big decision
Direct post or self-hosted card forms drag a WordPress site into a far heavier compliance regime. Hosted fields keep the site out of scope while still looking native.
Test the unhappy paths
Declined card, partial refund, full refund, subscription card update. These are the flows that break silently and cost support hours later.
Key takeaways
- Hosted fields keep PCI scope minimal
- Enable AVS, CVV and 3D Secure 2
- Test declines and refunds before launch
Want this checked against your own statement?
We are an independent agent — we shop every processor we work with and bring you the best deal for your profile. Free analysis, every fee named, back within 4 hours. Or call now and we will quote you on the phone.