logo

WordPress Design Agency

020 3355 8747

Message Us
  • Home
  • About Impact®
    Learn More About Impact Media®
    • Meet The Team
       
    • Why WordPress
       
    • Careers
       
    • Giving Back
       
    • 100K Tree Challenge
       
    James Coates
    Schedule a discovery call with UX Specialist James
    Book A Call
  • WordPress Services
    Learn More About Our Services
    • WordPress Web Design
       
    • UX Design
       
    • WordPress Development
       
    • WordPress Support & Maintenance
       
    • WordPress Evolve Retainer
       
    • WordPress Multisite Development
       
    • WooCommerce
       
    • Replatform To WordPress
       
    • WordPress Consultancy
       
    • Integrations & Plugins
       
    • WordPress Managed Hosting
       
    • WordPress Health Check
       
    James Coates
    Schedule a discovery call with UX Specialist James
    Book A Call
  • Our Process
  • Case Studies
  • Insights
  • Contact Us
WordPress Design Agency
020 3355 8747
logo logo
Book A Call
Back
Menu
  • Home
     
  •  
    About Impact Media
    Learn More About The Impacters
    • Meet The Team
       
    • Why WordPress
       
    • Careers
       
    • Giving Back
       
    • 100K Tree Challenge
       
  •  
    Our Services
    Discover How We Can Help
    • WordPress Web Design
       
    • UX Design
       
    • WordPress Development
       
    • WordPress Support & Maintenance
       
    • WordPress Evolve Retainer
       
    • WordPress Multisite Development
       
    • WooCommerce
       
    • Replatform To WordPress
       
    • WordPress Consultancy
       
    • Integrations & Plugins
       
    • WordPress Managed Hosting
       
    • WordPress Health Check
       
  • Our Process
     
  • Case Studies
     
  • Insights
     
  • Contact Us
     
020 3355 8747
Mon - Fri • 9am - 5pm
Close

Oops! We could not locate your form.

Home / Insights / Bot Traffic And Fake Orders, The Hidden Cost To Your eCommerce Store
Home / Insights / Bot Traffic And Fake Orders, The Hidden Cost To Your eCommerce Store
Back

Bot Traffic And Fake Orders, The Hidden Cost To Your eCommerce Store

Published 04.08.26
4th August 2026
Newer
8 Min Read
Martin Coates
Martin Coates
Support & Maintenance
Older
8 Min Read
 
Martin Coates
Martin Coates
 
Support & Maintenance

Learn how we overcame an issue which an eCommerce client was experiencing with fake orders and account sign-ups.

If you run a WooCommerce store, you’ve probably noticed the odd failed order or a customer sign-up that never quite completes. Most of the time it’s nothing, just that a customer changed their mind, a card was declined, someone got distracted mid-checkout.

But recently, on one of our clients’ sites, this turned out to be something else entirely. The way we identified this and the fix we put in place overnight is one every eCommerce site owner should know about.

Flooded With Failed Orders

While reviewing routine monitoring data on a client’s WooCommerce site this week, after a reported uptick in transactional email bounces, we spotted two related patterns that had been quietly building for some time:

  1. A wave of failed orders. Several of these were going through with the same delivery address (10 Downing Street was one of these!), repeatedly. These were all from PayPal, and all failing at the payment stage.
  2. A mass of fake account registrations, using invalid or disposable email addresses.

Both were coming from constantly rotating IP addresses, which is exactly why a simple IP block doesn’t solve the problem. You block one address and the next attempt just comes from somewhere else. This is bot traffic, and automated scripts probing checkout and registration forms at scale, and it’s becoming more and more common.

The volume kept climbing, so we deployed our solution overnight and by the time we checked in the morning, over 5,000 attempts had been detected and blocked in a matter of hours.

Why This Matters Beyond The Annoyance Factor

It’s tempting to write this off as background noise, but it has real, practical costs:

Server Resources

Every one of those bot requests still has to be processed by your server, your database, your CPU. At scale, that’s wasted hosting resources you’re paying for and, in the worst cases, it can slow the site down for genuine customers.

Email Deliverability

Fake sign-ups generate a high rate of invalid email addresses. Every bounce from those addresses damages your sender reputation with your transactional email provider (the service that sends your order confirmations, shipping updates, and password resets) and your email marketing provider. Push that reputation too far and you risk being blacklisted, meaning real customers stop receiving real order emails, or your marketing communications. This is actually what first flagged the issue to us, as the email provider got in touch about bounce rates.

Operational Risk

For stores that handle fulfilment manually, exporting orders to send to a courier or warehouse, a bot-generated fake order slipping through can mean postage and packing time wasted on an address that was never a genuine customer.

Failed Orders Skewing Your Data

A spike in failed payments can look like a checkout problem or a payment gateway issue, when actually it’s bots hammering the payment form. That’s a frustrating rabbit hole to go down if you don’t know what you’re looking for.

The Solution Is Cloudflare Turnstile

Rather than adding a reCAPTCHA that forces every customer to prove they’re human on every visit, we implemented Cloudflare Turnstile across registration, login, and the checkout.

Cloudflare Turnstile is a modern alternative to traditional CAPTCHA. Rather than making customers solve puzzles or select images, Turnstile runs invisible checks in the background to confirm a real person is submitting the form. Genuine shoppers pass through without noticing a thing, while bot traffic gets blocked before it can place a fake order or create a fake account, keeping order data clean and cutting down on wasted time processing orders that were never going to convert.

We also configured it to fail open, meaning if the Turnstile service itself ever goes down, checkout still works rather than blocking every customer.

Within hours of switching it on, the fake registrations and failed orders dropped off a cliff, with Turnstile challenging and blocking over 5,000 by the following morning, and more than 27,000 at the time of writing.

Turnstile analytics dashboard showing blocked bots

Turnstile Is One Layer, Not The Whole Picture

This kind of incident is also a good reminder that bot protection works best as part of a wider, ongoing security routine rather than a one-off fix. Turnstile solved the immediate problem, but it’s worth being honest about what it didn’t do. It didn’t scan for malware already on the site, it didn’t patch the plugin vulnerability a bot might have been probing for next, and it won’t stop an attack that doesn’t come through a form at all.

That’s why, on every site we manage, solutions like Turnstile sit alongside an established security routine rather than replacing it That routine includes:

  • Active malware scanning of both files and the database, run on a regular schedule rather than a one-time check.
  • WordPress core, themes, and plugins kept updated on an ongoing basis, rather than left to drift.
  • Known vulnerability patches actioned promptly as soon as they’re disclosed, not left in a queue.
  • All traffic routed through a Web Application Firewall (WAF), filtering out malicious requests before they ever reach the site.
  • Brute-force protection and rate limiting on login and admin pages.
  • Automated offsite backups with a tested restore process.
  • SSL/TLS enforced sitewide.
  • Real-time security monitoring and alerting.
  • A staging environment to test updates before they go live.

What We’re Watching Next

A week of monitoring will confirm the drop holds, but we’re also looking further upstream at email validation services (similar in concept to how Akismet filters spam blog comments, but for sign-up forms) that sit between your site and your transactional email provider, checking an address is genuinely deliverable before it ever triggers a welcome email or account creation. These typically run from around £40 to £50 a month depending on volume, and are worth it for any store seeing this kind of activity regularly.

The Takeaway For eCommerce Store Owners

Bot traffic and fake orders aren’t rare, they’re a normal part of running an online store today, and we’ve seen more of it this year than in previous years. The warning signs are usually there before it becomes a real problem – a run of failed payments to the same address, a spike in account sign-ups that don’t match your usual traffic, or a sudden bounce-rate warning from
your email provider.

This example was caught early for our client because the monitoring and maintenance routine flagged it, not because anyone was watching for this specific attack. If any of the warning signs above sound familiar on your site, this is the moment to check, not after the bounce rate becomes a blacklisting, and the failed orders spiral.

Experiencing a similar issue? Get in touch and we can take a look at what is happening on your site.

A picture of James Coates.

If you’d like to learn more about our WordPress & WooCommerce Support & Maintenance plans, drop us an email or give James a call.

Our plans provide a holistic solution to your website’s performance, reliability and security, and are inclusive of premium tools and services.

button to visit contact page

Share Socially
Martin Coates
Martin Coates
Technical Director, Golf Enthusiast & Ex-Superstar DJ
Martin is Mr Technical. His background is in PHP & WordPress development, however, the thing that keeps him up at night now is how to make websites load faster. Insights on performance optimisation and security are what you'll mostly find Martin sharing.
View Team Profile
See More Articles
Martin Coates
Martin Coates
Technical Director, Golf Enthusiast & Ex-Superstar DJ
Martin is Mr Technical. His background is in PHP & WordPress development, however, the thing that keeps him up at night now is how to make websites load faster. Insights on performance optimisation and security are what you'll mostly find Martin sharing.
See More Articles
View Team Profile
Looking For Support For
Your WordPress Website?
Let Us Take The Stress Of Website Maintenance & Support Off Your Plate
Let's Talk
studio@impactmedia.co.uk
020 3355 8747
Impact Media's LinkedIn
Impact Media's Twitter
Impact Media's Facebook
Impact Media's Instagram
Impact Media's Youtube
wordpress.org

About Impact

  • About Impact Media®
  • Meet The Impact Team
  • Why WordPress?
  • Our Web Development Process
  • Careers
  • Awards
  • Partners
  • Giving Back
  • 100K Tree Challenge

WordPress Services

  • WordPress Web Design
  • UX Design
  • WordPress Development
  • WordPress Evolve Retainers
  • WooCommerce Development
  • Multisite WordPress
  • Migrate To WordPress
  • Custom Integrations & Plugins
  • WordPress Consultancy

WordPress Support

  • WordPress Support & Maintenance
  • WordPress Managed Hosting
  • Case Studies
  • Insights
  • Contact Us

Addresses

London Address:

50 Liverpool Street,

London, EC2M 7PY, UK

+44 (0) 20 3355 8747

 

Registered Address:

Woodland Place, Hurricane Way

Wickford, SS11 8YB, UK

  • Privacy Policy
  • Cookie Policy
Impact Media logo
© Impact Media® 2003 - 2026
Impact Media is a trading name of IMDMS LTD. Company Reg. 05970261
Impact® & Impact Media®
are registered trademarks of IMDMS LTD