Over the last 12 months we have noticed an increase in the number of spam orders being attempted on our clients’ websites and have had to implement solutions to prevent this.
Safeguarding your ecommerce website can require a combination of preventive measures and tools to mitigate bot activity aimed at generating spam orders. Here are some options to consider as part of your strategy.
1. Enable Captchas
Captchas can be effective in blocking bots from submitting fake orders. There are various plugins for WooCommerce and these can be added to checkout, registration, and login pages.
2. Use Anti-Spam Plugins
There are also specialised plugins designed to prevent spam in WooCommerce which can be adapted for forms and some of these are free and simple to set up.
3. Enable Account Registration Verification
This is a built-in setting in WooCommerce that requires users to verify their accounts before placing orders. If this is used, the customer will need to verify their email address before placing an order.
This is an effective tool but does add an extra step to the ordering process that may be off-putting to some.
4. Restrict Checkout by Location
You can try limiting who can place orders by certain countries using the ‘Sell to countries, except for…’ feature in the WooCommerce general settings. This is useful if selling, say nationally and not internationally or if you are aware of attacks from particular countries.
5. Honeypot Fields
Honeypot fields trick bots into revealing themselves by interacting with hidden fields that human users won’t see. There are a number of plugins available for WordPress and WooCommerce that automatically add these ‘honeypot’ fields to your forms.
6. Keep WooCommerce and Plugins Updated
Always keep your WooCommerce and plugins updated to the latest versions to patch security vulnerabilities and ensure that any Captchas or anti-spam plugins are up to date.
7. Use Firewall and Security Plugins
You can enhance your website security with well-known WordPress plugins such as Wordfence that enable login security, spam filtering, and IP blocking (see next point).
8. Block Suspicious IPs
You can manually block known ‘problem’ IPs using specific plugins or configure IP blocking via your hosting service.
If you want to find out more about how Realnet could help you with WooCommerce, including safeguarding against spam orders, get in touch!
