Sample report. Northwind Notes is a fictional company and every number below comes from Stripe Leak Check's synthetic demo fixture (stripe-leak-check demo leaky). No real Stripe data. Back to Stripe Leak Check
Stripe Leak Check: Northwind Notes
Summary
| Severity | Check | What we found | Est. at risk |
|---|---|---|---|
| HIGH | Involuntary churn (cancelled for failed payment) | 14 subscriptions ($256.49/mo) were cancelled because payment failed, 70% of all cancellations in the window. | $3,078 |
| HIGH | Payouts, holds and account requirements | Verification requirements due by 2026-10-10: individual.verification.document; plus 2 more. | $2,260 |
| HIGH | Failed invoice payments and retries | 11 invoice(s) with $1,406 outstanding are failed or overdue, and automatic retries appear to be off. | $1,976 |
| HIGH | Dispute rate vs card-network thresholds | Dispute activity is 0.68% over 90 days. At least one recent month crossed a threshold that card networks or Stripe act on. | $1,132 |
| HIGH | Webhook deliveries that haven't landed | 23 events from the last 30 days still haven't been delivered to at least one endpoint, including 16 payment events worth $544.00. | $544.00 |
| HIGH | Early fraud warnings you can still refund | 4 payments have an actionable early fraud warning and are not refunded or disputed yet. | $387.00 |
| HIGH | Card-testing signals | Found 1 burst(s) of failed charges (220 failures) consistent with card testing; 1 customer(s) cycling through cards. | $112.00 |
| HIGH | Disputes waiting for your response | 4 open disputes have no evidence submitted. If the deadline passes, you lose them automatically. | $76.00 |
| HIGH | Webhook endpoint setup | we_a68j9zBlMVFFkJ005125 (http://old.northwind-notes.example/hooks/stripe) is DISABLED. Stripe stops sending to it, so nothing it handled is happening; plus 2 more. | – |
| MEDIUM | Refund rate | Refunds are 9.98% of gross volume over 90 days. | $15,928 |
| MEDIUM | Customers without an email address | 47 subscribed customers ($854.96/mo) can't receive receipts, failed-payment or card-expiring emails. | $854.96 |
| MEDIUM | Past-due and unpaid subscriptions | 9 subscriptions ($171.00/mo, 3.1% of MRR) are behind on payment. | $513.00 |
| MEDIUM | Cards expiring in the next 60 days | 12 subscriptions ($228.00/mo) are on cards that expire within 60 days. | $228.00 |
| MEDIUM | Radar rules and lists | No evidence of custom Radar rules. You're relying on Stripe's default rules only, while this report found fraud or dispute signals. | – |
| LOW | Statement descriptor and support details | Public details that help customers recognise your charges are incomplete. | – |
Findings
HIGH Involuntary churn (cancelled for failed payment) INVOLUNTARY_CHURN
14 subscriptions ($256.49/mo) were cancelled because payment failed, 70% of all cancellations in the window.
- 20 cancellations in the last 180 days; 14 with cancellation_details.reason = payment_failed.
- Lost MRR from these: $256.49/mo.
- These customers didn't choose to leave. Email them a reactivation link.
- Turn on Smart Retries and failed-payment emails, and consider a longer retry window before cancelling.
- Enable card-expiring reminders so cards get updated before the renewal fails.
Stripe docs: Automate payment retries (Smart Retries) · Automate customer emails · Revenue recovery
HIGH Payouts, holds and account requirements PAYOUTS
Verification requirements due by 2026-10-10: individual.verification.document; plus 2 more.
- Payout schedule: daily, delay 14 days.
- Balance: $2,412 available, $10,854 pending.
- 26 payouts in the window.
- Verification requirements due by 2026-10-10: individual.verification.document
- Payout delay is 14 days, longer than usual. Stripe sometimes extends it when it sees risk. Ask Stripe support if you didn't choose it.
- 1 payout(s) failed or were canceled ($2,260): po_girAhHK0BfDqFw005174 account_closed
- Clear any requirements in Settings > Business > Account status before the deadline.
- For failed payouts, check the bank account details in Settings > Payouts.
- If payouts are delayed and you didn't change the schedule, contact Stripe support and ask whether a reserve or review applies.
- Reserves aren't fully visible to a restricted key; check Balances in the Dashboard.
Stripe docs: Payouts
HIGH Failed invoice payments and retries FAILED_INVOICES
11 invoice(s) with $1,406 outstanding are failed or overdue, and automatic retries appear to be off.
- 11 open auto-charge invoices with a failed payment: $1,406 outstanding.
- 0 have a retry scheduled; 11 have no next_payment_attempt (retries finished or off).
- attempt_count distribution: 1×11
- 11 of 11 failed after a single attempt and were never retried. That pattern usually means automatic retries are off.
- 3 invoices marked uncollectible in the window: $570.00 written off.
- Turn on Smart Retries: Billing > Revenue recovery > Retries (https://dashboard.stripe.com/revenue_recovery/retries). Stripe's recommended default is 8 tries within 2 weeks.
- Turn on failed-payment emails with a link to update the card (Billing > Revenue recovery > Emails: https://dashboard.stripe.com/revenue_recovery/emails).
- Decide what happens after the last retry (cancel, mark unpaid, or leave past_due) on purpose, not by default.
- Retry settings aren't readable through the API; confirm them in the Dashboard.
Stripe docs: Automate payment retries (Smart Retries) · Automate customer emails · Revenue recovery
HIGH Dispute rate vs card-network thresholds DISPUTE_RATE
Dispute activity is 0.68% over 90 days. At least one recent month crossed a threshold that card networks or Stripe act on.
- Last 90 days: 9 disputes on 1330 captured payments (0.68%).
- Monthly (captured / disputes / dispute activity / Visa VAMP events & ratio / Mastercard chargebacks & rate vs prior month):
- 2026-05: 451 / 1 / 0.22% / 1 (0.41%) / 0 (0.00%)
- 2026-06: 443 / 1 / 0.23% / 1 (0.46%) / 0 (0.00%)
- 2026-07: 442 / 2 / 0.45% / 2 (0.88%) / 0 (0.00%)
- 2026-08: 473 / 1 / 0.21% / 1 (0.38%) / 0 (0.00%)
- 2026-09: 447 / 7 / 1.57% / 11 (5.00%) / 0 (0.00%)
- 2026-10 (month to date): 9 / 0 / 0.00% / 0 (0.00%) / 0 (0.00%)
- Rising: last full month 1.57% vs 0.30% average of the prior three.
- Top reasons: fraudulent (5), product_not_received (2), subscription_canceled (2)
- 2026-09: dispute activity 1.57% ≥ Stripe's 0.75% line.
- Network 'excessive' programs also need minimum counts (Visa 1,500 events; Mastercard 100 chargebacks), so small accounts rarely enter them formally. Stripe can still act on high rates or spikes.
- Check your standing on the VAMP dashboard (Radar > Card network monitoring): https://dashboard.stripe.com/radar/cbmp/vamp
- Make the charge recognisable: a clear statement descriptor and a support URL/email on your public details.
- Refund actionable early fraud warnings before they become disputes (see the EFW finding).
- Turn on Stripe's dispute prevention (Visa Order Insights / RDR, Mastercard Ethoca alerts) if your volume justifies the per-alert fee.
- For 'fraudulent' disputes, add Radar rules (block CVC failures, 3DS for high-risk payments).
- For 'product_not_received' / 'subscription_canceled', send renewal reminders and make cancelling easy.
Stripe docs: Dispute and fraud monitoring programs · Measuring disputes · Preventing disputes and fraud
HIGH Webhook deliveries that haven't landed WEBHOOK_DELIVERY
23 events from the last 30 days still haven't been delivered to at least one endpoint, including 16 payment events worth $544.00.
- Oldest undelivered event: 2026-09-07 12:00 UTC.
- By type: checkout.session.completed (8), invoice.paid (8), customer.updated (7)
- Stripe retries live-mode deliveries for up to three days, then stops.
- Open Developers > Webhooks > your endpoint > Event deliveries and read the error.
- Fix the handler (return 2xx quickly, do work async), then resend or process the missed events.
- Reconcile: check that every paid Checkout Session or invoice in this list got fulfilled.
Stripe docs: Process undelivered webhook events · Webhooks
HIGH Early fraud warnings you can still refund EFW_UNREFUNDED
4 payments have an actionable early fraud warning and are not refunded or disputed yet.
- 4 actionable warnings, $327.00 in payments.
- Visa counts these warnings toward the VAMP ratio whether or not a dispute follows.
- issfr_06NaU3OUEZ3cM8004865 on ch_xmALVdXq1bLs5C003916: made_with_stolen_card, 2026-09-03
- issfr_JDgbG4U1uFF7p4004866 on ch_q5SUZOurS4tZd5003921: made_with_stolen_card, 2026-09-03
- issfr_WM9OMC8MyYio3s004867 on ch_5gnVSxqFDqXOpa003941: made_with_stolen_card, 2026-09-04
- issfr_2gaKlzQk8JQ1ol004868 on ch_IOyLyXV1AbCJXs003936: made_with_stolen_card, 2026-09-05
- Review each payment. If it looks fraudulent, refund it now (Payments > select payment > Refund).
- Consider a Radar rule or list entry for the card fingerprint or email involved.
Stripe docs: Early fraud warnings · Radar lists
HIGH Card-testing signals CARD_TESTING
Found 1 burst(s) of failed charges (220 failures) consistent with card testing; 1 customer(s) cycling through cards.
- 2026-09-14 03:00 UTC for 2h: 220 failed vs 8 succeeded, 120 distinct cards, 100% of attempts ≤ $5.00; top decline reasons: generic_decline (110), do_not_honor (55), incorrect_cvc (55)
- 1 customers/emails tried 5+ different cards that failed (max 6). Customer IDs: cus_F3n6w4QhfCKK4l004839
- Overall: 314 failed of 2977 charge attempts (10.55%) in the window.
- IP addresses aren't available through the API; check Radar's payment details for IP and device data.
- Refund the small successful charges from the burst windows before they turn into disputes.
- Use Checkout or the Payment Element (Stripe's built-in card-testing defences apply there).
- Add a CAPTCHA and rate limiting to any endpoint that creates PaymentIntents or SetupIntents.
- Add Radar rules, for example block if :card_count_for_customer_daily: > 3, or require 3DS on small amounts.
- Make sure your secret key hasn't leaked; roll it if in doubt.
Stripe docs: Card testing · Radar rules
HIGH Disputes waiting for your response DISPUTES_UNANSWERED
4 open disputes have no evidence submitted. If the deadline passes, you lose them automatically.
- 4 disputes need a response, totalling $76.00.
- dp_F75jCRgnJemIAK004859: $19.00, reason fraudulent, evidence due 2026-10-03
- dp_jdFwmqm3uoZUtb004860: $19.00, reason product_not_received, evidence due 2026-10-04
- dp_SVQb5IxlnMphmP004861: $19.00, reason subscription_canceled, evidence due 2026-10-05
- dp_feAWEsnpso2n7Y004862: $19.00, reason product_not_received, evidence due 2026-10-06
- Open each dispute in the Dashboard (Payments > Disputes) and submit evidence before the due date.
- Include proof of delivery or usage, your refund policy, and customer communication.
- If the claim is valid, accept it to close it quickly.
Stripe docs: Responding to disputes
HIGH Webhook endpoint setup WEBHOOK_CONFIG
we_a68j9zBlMVFFkJ005125 (http://old.northwind-notes.example/hooks/stripe) is DISABLED. Stripe stops sending to it, so nothing it handled is happening; plus 2 more.
Evidence- 2 endpoints (1 enabled).
- we_ujeF93V9NHLPgG005124: enabled, https://app.northwind-notes.example/api/stripe, 2 event types
- we_a68j9zBlMVFFkJ005125: disabled, http://old.northwind-notes.example/hooks/stripe, 1 event types
- we_a68j9zBlMVFFkJ005125 (http://old.northwind-notes.example/hooks/stripe) is DISABLED. Stripe stops sending to it, so nothing it handled is happening.
- we_a68j9zBlMVFFkJ005125 uses plain http:// (http://old.northwind-notes.example/hooks/stripe).
- No enabled endpoint listens for: charge.dispute.created, invoice.payment_failed, customer.subscription.updated, customer.subscription.deleted.
- Re-enable or delete disabled endpoints (Developers > Webhooks). Fix the handler first, or it will be disabled again.
- Use HTTPS endpoints only.
- Subscribe to invoice.payment_failed, invoice.paid, customer.subscription.updated/deleted and charge.dispute.created.
- Verify signatures on every event.
Stripe docs: Webhooks · Using webhooks with subscriptions
MEDIUM Refund rate REFUND_RATE
Refunds are 9.98% of gross volume over 90 days.
- Last 90 days: $7,365 refunded on $73,765 gross (9.98%), 124 refunds.
- Reasons: requested_by_customer (56), duplicate (36), none given (32)
- Stripe does not return the original processing fee when you refund.
- Read the refund reasons and the products involved; fix the top cause (expectations, onboarding, billing surprise).
- Send renewal reminders before annual charges.
- Keep refunding instead of letting disputes happen; just make refunds rarer.
Stripe docs: Refunds
MEDIUM Customers without an email address MISSING_EMAILS
47 subscribed customers ($854.96/mo) can't receive receipts, failed-payment or card-expiring emails.
- 47 of 300 active subscriptions belong to customers with no email.
- 0 payments in the last 90 days have no customer, receipt email or billing email, so no receipt can be sent.
- Whether Stripe emails receipts automatically is a Dashboard setting (https://dashboard.stripe.com/settings/emails) that a key can't read.
- Collect email at checkout (Checkout does this by default) and backfill it on existing customers.
- Turn on successful-payment and refund receipts in Settings > Customer emails (https://dashboard.stripe.com/settings/emails).
- Unrecognised charges become disputes; a receipt is a cheap way to be recognised.
Stripe docs: Receipts and paid invoices · Automate customer emails
MEDIUM Past-due and unpaid subscriptions PAST_DUE_SUBS
9 subscriptions ($171.00/mo, 3.1% of MRR) are behind on payment.
- past_due: 9
- Total MRR $5,526.
- Email these customers a link to update their payment method (the Customer portal works).
- Make sure retries and failed-payment emails are on (see the failed-invoice finding).
- For 'unpaid' subscriptions, decide whether to cancel or keep providing service.
Stripe docs: Subscription statuses · Automate customer emails
MEDIUM Cards expiring in the next 60 days EXPIRING_CARDS
12 subscriptions ($228.00/mo) are on cards that expire within 60 days.
- 12 of 300 active subscriptions pay with a card that expires before 2026-11-30.
- 3 of these cards have already expired.
- sub_XQ8agOMTNwncxv000104: mastercard expiring 09/2026, $19.00/mo
- sub_Uzn8aB5kBh0fzK000109: mastercard expiring 09/2026, $19.00/mo
- sub_N2m1ElKncz8Hky000114: visa expiring 09/2026, $19.00/mo
- sub_ZCGGQccOif7UuX000119: mastercard expiring 10/2026, $19.00/mo
- sub_zkO7rRu5ykYYqh000124: mastercard expiring 10/2026, $19.00/mo
- sub_Gx5diFoNPcbdaK000129: visa expiring 10/2026, $19.00/mo
- sub_kd6XgaNJQ8mjAm000134: amex expiring 10/2026, $19.00/mo
- sub_95nf4Gakq5p1Vm000139: mastercard expiring 10/2026, $19.00/mo
- sub_eVce2LWxm090I5000144: mastercard expiring 10/2026, $19.00/mo
- sub_XgwETdIKnT30fK000149: visa expiring 10/2026, $19.00/mo
- Turn on expiring-card emails in Billing > Revenue recovery > Emails (https://dashboard.stripe.com/revenue_recovery/emails). It's Dashboard-only, so we can't read it.
- Link customers to the Customer portal to update their card.
- Listen for payment_method.automatically_updated to see which cards the networks refreshed.
Stripe docs: Automatic card updates · Automate customer emails
MEDIUM Radar rules and lists RADAR_RULES
No evidence of custom Radar rules. You're relying on Stripe's default rules only, while this report found fraud or dispute signals.
Evidence- 2977 of 2977 card charges carry a Radar risk score.
- 0 charges were allowed, blocked or reviewed by a custom rule (outcome.reason = 'rule').
- Value lists with entries: 0 of 1.
- Stripe has no API for listing Radar rules, so this is inferred from charge outcomes.
- Review https://dashboard.stripe.com/radar/rules and add rules that match your fraud pattern.
- Common starters: block if :cvc_check: = 'fail'; review if :risk_score: > 65; request 3DS if :risk_level: = 'elevated'.
- Use block lists for card fingerprints and emails from confirmed fraud.
Stripe docs: Radar rules · Radar lists
LOW Statement descriptor and support details DESCRIPTOR
Public details that help customers recognise your charges are incomplete.
Evidence- Statement descriptor is 'NWN'. Customers who don't recognise a charge dispute it.
- No public support email or phone. Customers who can't reach you ask their bank instead.
- Set a recognisable statement descriptor and support details in Settings > Business > Public details.
Stripe docs: Statement descriptors
Thresholds we compare against
| Program | Measures | Ratio | Minimum | Consequence |
|---|---|---|---|---|
| Stripe guidance | Dispute activity | 0.75% | No minimum | Stripe says activity above 0.75% is excessive and may reach out sooner on spikes. |
| Visa VAMP: non-compliant | (Disputes + fraud warnings) / captured payments, monthly | 0.5% | 5 events | Visa may assess fees. |
| Visa VAMP: excessive | Same | 1.5% (2.2% CEMEA) | 1,500 events (150 + USD 75k in CEMEA) | Visa assesses fees. |
| Mastercard ECM | Chargebacks this month / captured payments last month | 1.5% | 100 chargebacks | Fines from month 2 (USD 1,000 and rising). |
| Mastercard HECM | Same | 3.0% | 300 chargebacks | Higher fines. |
Coverage
Things a restricted key can't read (check by hand):
- Radar rules: There is no API to list Radar rules. We infer custom rules from charge outcomes (outcome.rule) and check value lists. Review https://dashboard.stripe.com/radar/rules.
- Smart Retries / retry schedule: Billing retry settings are Dashboard-only. We infer whether retries are running from invoice attempt_count and next_payment_attempt. Check https://dashboard.stripe.com/revenue_recovery/retries.
- Customer email settings (receipts, failed-payment emails): Dashboard-only. Check https://dashboard.stripe.com/settings/emails (receipts) and https://dashboard.stripe.com/revenue_recovery/emails (dunning).
- Webhook delivery attempt logs: Per-attempt logs are Dashboard-only. We use the Events API's pending_webhooks counter (last 30 days) instead.
- IP addresses of payment attempts: Not exposed on Charge objects. Card-testing detection uses timing, amounts, card fingerprints and decline codes instead.
- Reserves: Rolling or fixed reserves aren't fully visible to a restricted key. We flag the signals we can see (payout schedule delay, pending balance, verification requirements).
Stripe Leak Check by Zephos. Stripe is a trademark of Stripe, Inc.; this tool is not affiliated with or endorsed by Stripe.