Sample report. Northwind Notes is a fictional company and every number below comes from Stripe Leak Check's synthetic demo fixture (stripe-leak-check demo leaky). No real Stripe data. Back to Stripe Leak Check

Stripe Leak Check: Northwind Notes

Generated 2026-10-01 12:00 UTC · 180-day window · mode DEMO (leaky synthetic fixture, not real data) · USD · v0.1.0
9 high-severity leak(s) worth fixing this week.
Disclaimer. Not financial, legal or tax advice. Dollar amounts are estimates built from your own Stripe data plus the assumptions stated next to each one; they overlap and are not a forecast. Card-network thresholds were checked against Stripe's public docs on 2026-10-02 and can change. Confirm anything important with Stripe or your advisor.
0CRITICAL
9HIGH
5MEDIUM
1LOW
0PASS
$27,089est. at risk*

* Sum of per-finding estimates. They overlap and mix one-off and annualised figures; read each basis below.

Summary

SeverityCheckWhat we foundEst. at risk
HIGHInvoluntary churn (cancelled for failed payment)14 subscriptions ($256.49/mo) were cancelled because payment failed, 70% of all cancellations in the window.$3,078
HIGHPayouts, holds and account requirementsVerification requirements due by 2026-10-10: individual.verification.document; plus 2 more.$2,260
HIGHFailed invoice payments and retries11 invoice(s) with $1,406 outstanding are failed or overdue, and automatic retries appear to be off.$1,976
HIGHDispute rate vs card-network thresholdsDispute activity is 0.68% over 90 days. At least one recent month crossed a threshold that card networks or Stripe act on.$1,132
HIGHWebhook deliveries that haven't landed23 events from the last 30 days still haven't been delivered to at least one endpoint, including 16 payment events worth $544.00.$544.00
HIGHEarly fraud warnings you can still refund4 payments have an actionable early fraud warning and are not refunded or disputed yet.$387.00
HIGHCard-testing signalsFound 1 burst(s) of failed charges (220 failures) consistent with card testing; 1 customer(s) cycling through cards.$112.00
HIGHDisputes waiting for your response4 open disputes have no evidence submitted. If the deadline passes, you lose them automatically.$76.00
HIGHWebhook endpoint setupwe_a68j9zBlMVFFkJ005125 (http://old.northwind-notes.example/hooks/stripe) is DISABLED. Stripe stops sending to it, so nothing it handled is happening; plus 2 more.–
MEDIUMRefund rateRefunds are 9.98% of gross volume over 90 days.$15,928
MEDIUMCustomers without an email address47 subscribed customers ($854.96/mo) can't receive receipts, failed-payment or card-expiring emails.$854.96
MEDIUMPast-due and unpaid subscriptions9 subscriptions ($171.00/mo, 3.1% of MRR) are behind on payment.$513.00
MEDIUMCards expiring in the next 60 days12 subscriptions ($228.00/mo) are on cards that expire within 60 days.$228.00
MEDIUMRadar rules and listsNo evidence of custom Radar rules. You're relying on Stripe's default rules only, while this report found fraud or dispute signals.–
LOWStatement descriptor and support detailsPublic details that help customers recognise your charges are incomplete.–

Findings

HIGH Involuntary churn (cancelled for failed payment) INVOLUNTARY_CHURN

14 subscriptions ($256.49/mo) were cancelled because payment failed, 70% of all cancellations in the window.

Estimated at risk: $3,078. Estimate: lost MRR × 12, assuming these customers would otherwise have stayed a year. Treat it as an upper bound.
Evidence How to fix
  1. These customers didn't choose to leave. Email them a reactivation link.
  2. Turn on Smart Retries and failed-payment emails, and consider a longer retry window before cancelling.
  3. Enable card-expiring reminders so cards get updated before the renewal fails.

Stripe docs: Automate payment retries (Smart Retries) · Automate customer emails · Revenue recovery

Object IDs to look at: sub_GolAGMm4KL6r6U001504, sub_CQiLoAZPdtlnON001509, sub_i16KZBHxUd1bQ1001514, sub_rKU0UP4aNGH05m001519, sub_1bQ3pt5l2F5UmM001524, sub_aqdLmWJAsSxvPu001529, sub_0Mk5oQo1uKpoky001534, sub_Yhgl9PKDO3nsbu001539, sub_fcAuJISnmb0hMY001544, sub_UHfz2a6fDol3Vm001549

HIGH Payouts, holds and account requirements PAYOUTS

Verification requirements due by 2026-10-10: individual.verification.document; plus 2 more.

Estimated at risk: $2,260. Money delayed rather than lost: failed/canceled payouts plus pending balance if it looks held.
Evidence How to fix
  1. Clear any requirements in Settings > Business > Account status before the deadline.
  2. For failed payouts, check the bank account details in Settings > Payouts.
  3. If payouts are delayed and you didn't change the schedule, contact Stripe support and ask whether a reserve or review applies.
  4. Reserves aren't fully visible to a restricted key; check Balances in the Dashboard.

Stripe docs: Payouts

Object IDs to look at: po_girAhHK0BfDqFw005174

HIGH Failed invoice payments and retries FAILED_INVOICES

11 invoice(s) with $1,406 outstanding are failed or overdue, and automatic retries appear to be off.

Estimated at risk: $1,976. Amounts outstanding on open failed/overdue invoices plus those written off as uncollectible in the window. Not all of it is recoverable.
Evidence How to fix
  1. Turn on Smart Retries: Billing > Revenue recovery > Retries (https://dashboard.stripe.com/revenue_recovery/retries). Stripe's recommended default is 8 tries within 2 weeks.
  2. Turn on failed-payment emails with a link to update the card (Billing > Revenue recovery > Emails: https://dashboard.stripe.com/revenue_recovery/emails).
  3. Decide what happens after the last retry (cancel, mark unpaid, or leave past_due) on purpose, not by default.
  4. Retry settings aren't readable through the API; confirm them in the Dashboard.

Stripe docs: Automate payment retries (Smart Retries) · Automate customer emails · Revenue recovery

Object IDs to look at: in_Uy6WZDYop0A4TI005110, in_gQcnHe5Rp4wQzA005111, in_ziZiDzBZXNCzqX005112, in_ffmoBuDsssnLwt005113, in_CAzYOjPVtblAjm005114, in_JSRKib2LCoOlBJ005115, in_OxI6Pv9JOQ2GrJ005116, in_XBc65yWTAeCqAK005117, in_iKOHpgWyH5lgnj005118, in_RvBDiuvu6aWdfX005119

HIGH Dispute rate vs card-network thresholds DISPUTE_RATE

Dispute activity is 0.68% over 90 days. At least one recent month crossed a threshold that card networks or Stripe act on.

Estimated at risk: $1,132. Estimate: last 90 days' disputed amounts not won ($144.00) plus $15.00 fee per dispute, annualised at the current pace.
Evidence How to fix
  1. Check your standing on the VAMP dashboard (Radar > Card network monitoring): https://dashboard.stripe.com/radar/cbmp/vamp
  2. Make the charge recognisable: a clear statement descriptor and a support URL/email on your public details.
  3. Refund actionable early fraud warnings before they become disputes (see the EFW finding).
  4. Turn on Stripe's dispute prevention (Visa Order Insights / RDR, Mastercard Ethoca alerts) if your volume justifies the per-alert fee.
  5. For 'fraudulent' disputes, add Radar rules (block CVC failures, 3DS for high-risk payments).
  6. For 'product_not_received' / 'subscription_canceled', send renewal reminders and make cancelling easy.

Stripe docs: Dispute and fraud monitoring programs · Measuring disputes · Preventing disputes and fraud

Object IDs to look at: dp_ZRTet5Fr6o1KuO004856, dp_vc62sKrxAbIvZ2004857, dp_0AQhjxZzQaIitF004858, dp_F75jCRgnJemIAK004859, dp_jdFwmqm3uoZUtb004860, dp_SVQb5IxlnMphmP004861, dp_feAWEsnpso2n7Y004862, dp_zP7WGWmV4xsKoS004863, dp_6EHFOorbJRv1Dr004864

HIGH Webhook deliveries that haven't landed WEBHOOK_DELIVERY

23 events from the last 30 days still haven't been delivered to at least one endpoint, including 16 payment events worth $544.00.

Estimated at risk: $544.00. Payment amounts on events your app may never have processed (orders not fulfilled, upgrades not granted, cancellations not applied). Some may have been handled another way.
Evidence How to fix
  1. Open Developers > Webhooks > your endpoint > Event deliveries and read the error.
  2. Fix the handler (return 2xx quickly, do work async), then resend or process the missed events.
  3. Reconcile: check that every paid Checkout Session or invoice in this list got fulfilled.

Stripe docs: Process undelivered webhook events · Webhooks

Object IDs to look at: evt_BbBlVKCRzMX9E5005126, evt_Sj3F9jjt9lMrTM005127, evt_kkMWxcbOdvYEBI005128, evt_XgoSp6lDlyc2wv005129, evt_rchN0HtjSsDVEM005130, evt_NGMfuFNqd1yxYX005131, evt_DUkr2FFHLeFviy005132, evt_e65bVqZWL56LPy005133, evt_Um124XGzZr3h5Y005134, evt_N9xHJH7c0YjT4O005135

HIGH Early fraud warnings you can still refund EFW_UNREFUNDED

4 payments have an actionable early fraud warning and are not refunded or disputed yet.

Estimated at risk: $387.00. Estimate: if each becomes a dispute you lose the payment plus the dispute fee. Refunding now loses the payment but avoids the fee and the dispute count.
Evidence How to fix
  1. Review each payment. If it looks fraudulent, refund it now (Payments > select payment > Refund).
  2. Consider a Radar rule or list entry for the card fingerprint or email involved.

Stripe docs: Early fraud warnings · Radar lists

Object IDs to look at: issfr_06NaU3OUEZ3cM8004865, issfr_JDgbG4U1uFF7p4004866, issfr_WM9OMC8MyYio3s004867, issfr_2gaKlzQk8JQ1ol004868

HIGH Card-testing signals CARD_TESTING

Found 1 burst(s) of failed charges (220 failures) consistent with card testing; 1 customer(s) cycling through cards.

Estimated at risk: $112.00. Estimate: 7 small charges that succeeded during bursts (likely stolen cards that will be disputed) plus a dispute fee each. Not counted: higher decline rates for your real customers, which card testing can cause.
Evidence How to fix
  1. Refund the small successful charges from the burst windows before they turn into disputes.
  2. Use Checkout or the Payment Element (Stripe's built-in card-testing defences apply there).
  3. Add a CAPTCHA and rate limiting to any endpoint that creates PaymentIntents or SetupIntents.
  4. Add Radar rules, for example block if :card_count_for_customer_daily: > 3, or require 3DS on small amounts.
  5. Make sure your secret key hasn't leaked; roll it if in doubt.

Stripe docs: Card testing · Radar rules

Object IDs to look at: ch_9dMvVoFfFh643P004819, ch_hYzWZJ19V3fyPa004797, ch_i2sg3XqwltbpOR004633

HIGH Disputes waiting for your response DISPUTES_UNANSWERED

4 open disputes have no evidence submitted. If the deadline passes, you lose them automatically.

Estimated at risk: $76.00. The disputed amounts, which you lose by default if you don't respond (the dispute fee is charged either way).
Evidence How to fix
  1. Open each dispute in the Dashboard (Payments > Disputes) and submit evidence before the due date.
  2. Include proof of delivery or usage, your refund policy, and customer communication.
  3. If the claim is valid, accept it to close it quickly.

Stripe docs: Responding to disputes

Object IDs to look at: dp_F75jCRgnJemIAK004859, dp_jdFwmqm3uoZUtb004860, dp_SVQb5IxlnMphmP004861, dp_feAWEsnpso2n7Y004862

HIGH Webhook endpoint setup WEBHOOK_CONFIG

we_a68j9zBlMVFFkJ005125 (http://old.northwind-notes.example/hooks/stripe) is DISABLED. Stripe stops sending to it, so nothing it handled is happening; plus 2 more.

Evidence How to fix
  1. Re-enable or delete disabled endpoints (Developers > Webhooks). Fix the handler first, or it will be disabled again.
  2. Use HTTPS endpoints only.
  3. Subscribe to invoice.payment_failed, invoice.paid, customer.subscription.updated/deleted and charge.dispute.created.
  4. Verify signatures on every event.

Stripe docs: Webhooks · Using webhooks with subscriptions

Object IDs to look at: we_a68j9zBlMVFFkJ005125

MEDIUM Refund rate REFUND_RATE

Refunds are 9.98% of gross volume over 90 days.

Estimated at risk: $15,928. Estimate: refunds above 5% of gross ($3,677) plus unreturned processing fees on all refunds (assumed 2.9% + 30¢, US standard pricing; about $250.78), annualised. Some refunds are healthy; they're cheaper than disputes.
Evidence How to fix
  1. Read the refund reasons and the products involved; fix the top cause (expectations, onboarding, billing surprise).
  2. Send renewal reminders before annual charges.
  3. Keep refunding instead of letting disputes happen; just make refunds rarer.

Stripe docs: Refunds

Object IDs to look at: re_ubAY8z3710CE5a004982, re_4UhHWH7pPWJmFs004985, re_Z5j2rEPFbJGg1I004987, re_OVQ3sJMV0928Qg004989, re_u5iOTVuOhJKKi0004990, re_hiqoRpQyxCT1dp004991, re_AIb2T2ADIM4TIu004992, re_jtfqe8AC7Xo0zz004993, re_pEeDhjv7HgO5RK004994, re_36rblq35tTn4G3004995

MEDIUM Customers without an email address MISSING_EMAILS

47 subscribed customers ($854.96/mo) can't receive receipts, failed-payment or card-expiring emails.

Estimated at risk: $854.96. MRR on subscriptions where dunning emails can't reach anyone. It's at risk only if their payment fails.
Evidence How to fix
  1. Collect email at checkout (Checkout does this by default) and backfill it on existing customers.
  2. Turn on successful-payment and refund receipts in Settings > Customer emails (https://dashboard.stripe.com/settings/emails).
  3. Unrecognised charges become disputes; a receipt is a cheap way to be recognised.

Stripe docs: Receipts and paid invoices · Automate customer emails

Object IDs to look at: sub_xNKu8iS2G8NPRV000014, sub_1SkHbn88HxjSI6000019, sub_GMGmSrCGIZEG8p000034, sub_xvCkgafrfwA94h000089, sub_Gx5diFoNPcbdaK000129, sub_ZZdPaRXLujTpwr000264, sub_YunX6wV6fASVzV000284, sub_z9MNfZZdURvMQt000304, sub_celN0PRMz1E9kS000319, sub_ewn294oUerTlaq000354

MEDIUM Past-due and unpaid subscriptions PAST_DUE_SUBS

9 subscriptions ($171.00/mo, 3.1% of MRR) are behind on payment.

Estimated at risk: $513.00. Estimate: three months of their MRR, a rough value of keeping them versus losing them.
Evidence How to fix
  1. Email these customers a link to update their payment method (the Customer portal works).
  2. Make sure retries and failed-payment emails are on (see the failed-invoice finding).
  3. For 'unpaid' subscriptions, decide whether to cancel or keep providing service.

Stripe docs: Subscription statuses · Automate customer emails

Object IDs to look at: sub_n7qLWaYyDIfIZw000204, sub_g8CXL0M9iq1cvm000209, sub_EdgjuWa8mRVtLL000214, sub_J4jC3jrAApjbrK000219, sub_c6AnrKli1lHXoT000224, sub_7C9HehwTp0136u000229, sub_rhhhz4iILo3ojQ000234, sub_7DOcZ44cc3PNr6000239, sub_xD5JtNEE0tbpvo000244

MEDIUM Cards expiring in the next 60 days EXPIRING_CARDS

12 subscriptions ($228.00/mo) are on cards that expire within 60 days.

Estimated at risk: $228.00. Upper bound: one month of MRR on these subscriptions. Stripe's automatic card updates refresh many US cards on their own, so the real loss is usually lower.
Evidence How to fix
  1. Turn on expiring-card emails in Billing > Revenue recovery > Emails (https://dashboard.stripe.com/revenue_recovery/emails). It's Dashboard-only, so we can't read it.
  2. Link customers to the Customer portal to update their card.
  3. Listen for payment_method.automatically_updated to see which cards the networks refreshed.

Stripe docs: Automatic card updates · Automate customer emails

Object IDs to look at: sub_XQ8agOMTNwncxv000104, sub_Uzn8aB5kBh0fzK000109, sub_N2m1ElKncz8Hky000114, sub_ZCGGQccOif7UuX000119, sub_zkO7rRu5ykYYqh000124, sub_Gx5diFoNPcbdaK000129, sub_kd6XgaNJQ8mjAm000134, sub_95nf4Gakq5p1Vm000139, sub_eVce2LWxm090I5000144, sub_XgwETdIKnT30fK000149

MEDIUM Radar rules and lists RADAR_RULES

No evidence of custom Radar rules. You're relying on Stripe's default rules only, while this report found fraud or dispute signals.

Evidence How to fix
  1. Review https://dashboard.stripe.com/radar/rules and add rules that match your fraud pattern.
  2. Common starters: block if :cvc_check: = 'fail'; review if :risk_score: > 65; request 3DS if :risk_level: = 'elevated'.
  3. Use block lists for card fingerprints and emails from confirmed fraud.

Stripe docs: Radar rules · Radar lists

LOW Statement descriptor and support details DESCRIPTOR

Public details that help customers recognise your charges are incomplete.

Evidence How to fix
  1. Set a recognisable statement descriptor and support details in Settings > Business > Public details.

Stripe docs: Statement descriptors

Thresholds we compare against

ProgramMeasuresRatioMinimumConsequence
Stripe guidanceDispute activity0.75%No minimumStripe says activity above 0.75% is excessive and may reach out sooner on spikes.
Visa VAMP: non-compliant(Disputes + fraud warnings) / captured payments, monthly0.5%5 eventsVisa may assess fees.
Visa VAMP: excessiveSame1.5% (2.2% CEMEA)1,500 events (150 + USD 75k in CEMEA)Visa assesses fees.
Mastercard ECMChargebacks this month / captured payments last month1.5%100 chargebacksFines from month 2 (USD 1,000 and rising).
Mastercard HECMSame3.0%300 chargebacksHigher fines.

Sources: Stripe: Dispute and fraud monitoring programs · Stripe: Measuring disputes (checked 2026-10-02). The 0.9% Visa figure often quoted is from Visa's Dispute Monitoring Program (VDMP), retired in March 2025 and replaced by VAMP, which also counts fraud warnings. Some 2025 bulletins said VAMP's excessive ratio would fall to 0.9% in 2026; Stripe's current docs show 1.5%. Either way, Stripe's own 0.75% line comes first.

Coverage

Things a restricted key can't read (check by hand):

API requests made: 13, all GET: /v1/account ×1, /v1/balance ×1, /v1/charges ×1, /v1/disputes ×1, /v1/radar/early_fraud_warnings ×1, /v1/radar/value_lists ×1, /v1/refunds ×1, /v1/payouts ×1, /v1/subscriptions ×1, /v1/invoices ×2, /v1/webhook_endpoints ×1, /v1/events ×1

Your key was held in memory for this run only: not written to disk, not logged, and sent only to api.stripe.com. This report contains Stripe object IDs and aggregates, not card numbers or customer emails.

Stripe Leak Check by Zephos. Stripe is a trademark of Stripe, Inc.; this tool is not affiliated with or endorsed by Stripe.