Choosing a WooCommerce Payment Gateway: A Category-by-Category Decision Guide
Every WooCommerce payment gateway decision starts in the same place, and it is not a feature comparison. It starts with what the store sells. A gateway that approves a candle maker in an afternoon can decline a supplement brand at underwriting, and a gateway built for supplement brands charges the candle maker fees she never needed to pay. Merchants who match the gateway to the product category first tend to build once. Merchants who pick the gateway from a plugin directory and hope tend to build twice.
Category First, Gateway Second, Everything Else After
WooCommerce itself imposes no acceptable-use list. The software runs the catalog, the cart, and the checkout page, and it does not care what is in the cart. The rules live one layer down, in the payment gateway’s terms, because the gateway carries the fraud exposure, the chargeback liability, and the card-network relationships that a product category can put at risk.
That is why the decision order matters. The product category determines which gateways will accept the store at all. The surviving gateways can then be compared on fees, contracts, and integration quality. Merchants who run the comparison in the other order often discover, after the build, that the gateway they designed around will not take them. On a hosted platform like Shopify, the platform bundles this decision into its own payments terms; on WooCommerce the merchant makes it deliberately, which is more work and more control in the same motion.
When WooPayments or Stripe Is Fine
For most catalogs, the mainstream tier is the right answer and the search ends early. WooPayments (the gateway WooCommerce’s own maker publishes) and Stripe both offer fast onboarding, flat published pricing, no monthly minimums, and mature WooCommerce plugins maintained by the companies themselves.
The fit test is straightforward: an unrestricted catalog and standard risk. That typically means physical or digital goods with no age gate, no regulatory overlay, and a chargeback history in the normal range. Apparel, home goods, books, most food, most services, and most digital products all live comfortably here. One caveat deserves attention: WooPayments runs on Stripe’s infrastructure, so both carry substantially the same restricted-business list. Switching between them does not move a merchant across a category line. Merchants near a gray area (certain supplements, certain financial services, anything age-restricted) can be approved at signup and terminated later when a manual review catches up, because these platforms underwrite lightly at the start and continuously afterward.
Authorize.net and NMI: The Middle Tier
Between the instant-approval processors and the high-risk specialists sits an older architecture: a dedicated merchant account paired with a gateway. Authorize.net and NMI are the common names here, and pairing Authorize.net with WooCommerce is a well-worn path with official and third-party plugins to choose from.
The structural difference matters more than the brand names. Stripe and WooPayments are aggregators: thousands of merchants share one master account, which is why onboarding is instant and termination can be abrupt. A dedicated merchant account is underwritten for one business by an acquiring bank that reads the application, looks at the website, and prices the actual risk. That underwriting takes days or weeks instead of minutes, and it usually adds a monthly gateway fee to the per-transaction cost.
What the merchant gets for the friction is tolerance. A category that makes an aggregator’s automated systems nervous (higher ticket sizes, longer fulfillment windows, mild regulatory color) can be perfectly acceptable to an acquirer who has reviewed it and priced it. The middle tier is where merchants land when they are too complicated for Stripe but not restricted enough to need a specialist. NMI adds a further advantage for stores thinking ahead: it is processor-agnostic, so the merchant account behind it can change without rebuilding the checkout.
Specialist High-Risk Gateways: What Changes
Some categories are named on nearly every mainstream restricted list: tobacco and vape, CBD, firearms accessories, adult products, and others with heavy chargeback or regulatory profiles. For these, a high risk payment gateway paired with a high-risk merchant account is not a fallback, it is the plan.
Three things change at this tier. Fees rise, because the acquirer is pricing real category risk; rates run meaningfully above mainstream published pricing, and quotes vary by category and history rather than following a public rate card. Contracts lengthen, often with terms measured in years, early-termination clauses, and rolling reserves that hold back a slice of revenue against future chargebacks. Integration narrows: instead of a polished first-party plugin, the store may rely on a third-party WooCommerce plugin, an NMI-style gateway sitting in front of the high-risk account, or a developer wiring an API directly.
None of that makes the tier a bad deal. It makes it a deal to enter with eyes open, with the contract read closely and the reserve terms understood before signing, because the alternative for these categories is usually no card processing at all.
Integration Realities on WooCommerce
Once the category narrows the field, plugin quality separates the finalists. Three things are worth checking before committing.
Hosted fields matter for compliance. When the card form is served by the gateway inside the checkout page, the card number never touches the store’s server, which keeps the merchant in the lightest PCI self-assessment tier. Gateways whose WooCommerce plugins post card data through the site raise the compliance burden considerably.
Tokenization matters for the long term. A gateway that stores cards in a portable customer vault (NMI’s is a known example) lets subscriptions and repeat customers survive a future processor change. Tokens locked to one processor become an exit cost that is invisible until the day the store needs to leave.
Plugin maintenance matters every week. A gateway plugin that lags WooCommerce core releases, or that was last updated a year ago, becomes the fragile piece of an otherwise healthy store. First-party plugins from Stripe and WooPayments set the standard here; for middle-tier and high-risk gateways, the update history and support responsiveness of the specific plugin deserve a look before the contract is signed.
A Decision Table by Category Type
| Category type | Typical fit | What to expect | | — | — | — | | Unrestricted goods, standard risk | WooPayments or Stripe | Instant onboarding, flat pricing, first-party plugins | | Higher tickets, long fulfillment, mild gray areas | Authorize.net or NMI with a dedicated merchant account | Real underwriting, monthly gateway fee, more tolerance | | Named restricted categories (vape, CBD, firearms accessories, adult) | Specialist high-risk gateway and merchant account | Higher rates, longer contracts, rolling reserves, narrower plugins | | Subscription-heavy, any category | A gateway with a portable customer vault | Tokens that move with you if the processor relationship ends |
The table compresses the guide, but the first column is the one that does the work: the category decides the tier, the tier decides the shortlist, and the shortlist is where fees and plugins finally get their say.
Boston Web Group builds and maintains WooCommerce stores for New England businesses, including stores in categories the mainstream processors decline. We can shortlist gateways for your category, check the terms that matter before you sign, and wire the winner into your store.


