Video transcript: How To Stop Fake Spam Orders in WooCommerce
0:00The Problem of Fake Orders in WooCommerce
Hey, it's Brendan from WP Speed Fix. I have a really short video here, and I'm going to try and keep it short. We've been getting this problem a lot in the last month, so I thought I'd make a video for it. We're getting clients with fake orders in WooCommerce. We see this come in waves. We just had a ticket in the system this morning for a customer that had this, three pages of fake orders in his WooCommerce site.
You can see here that the orders are coming in quite frequently. This is overnight for an Australian store that does, I think, five orders a day on average. You can see they're all for $1.7. Typically these malicious orders come from bad actors testing fraudulent or stolen credit card details to see if they work. That's why they're such a low amount: they're testing a dollar to see if it works.
This is obviously a huge problem for a lot of different reasons, but particularly if you've got a 3PL, a third party shipping provider, because if any of these orders are successful, they'll probably be shipped. If this happens over a weekend, those orders will go into the shipping queue and may get shipped before you even see them, so it can be a massive problem. It's a nuisance anyway, and it can also be a problem for your merchant facility. If you're getting a lot of this stuff, they might be unhappy with it and shut you down.
1:11Turn On Rate Limiting in WooCommerce
So, some simple steps to fix it. Let me talk these through. Actually, I'll add another one here, Stripe Radar. I didn't have that in the original list I made, but we'll talk about it. The first step is to turn on rate limiting in WooCommerce. WooCommerce does have a feature for some rate limiting, but it probably won't do much in this kind of scenario, because the orders are not coming through frequently enough. You can see here there's a handful per hour.
There's a doc here that I'll link you up to, but you can access it in the WooCommerce backend. Go to WooCommerce settings, Advanced, Features, and enable rate limit checkout and Store API. This will only work if they're really rapidly and aggressively hitting the cart and checkout, and they're probably not. It will lock the cart so that it only accepts three requests per 60 seconds. In this instance, as you can see, orders are not coming through frequently enough for that to even work. But if you don't have heavy API or cart action on your site, it's worth turning that on anyway, just in case. It doesn't hurt, and it's an extra security feature. Like I said, it's not going to do much for this scenario most of the time, but it doesn't hurt to turn it on.
2:20Use Cloudflare to Filter Traffic Outside Your Target Country
The next one is implementing Cloudflare and filtering traffic from outside your home country or target country. This is very effective, and it will also generally boost the security of the site and make you less of a soft target. There is some messing around to get this to work, and it is not going to work if you are shipping worldwide. If you're shipping worldwide it may not work, but you should use Cloudflare anyway, because it will add a layer of security to block the garbage scrapers and crawlers. If you're only shipping to certain countries, just filter outside those countries or continents. For example, you can filter outside Europe. You can do the filtering on country or continent or lots of different variables.
If you go to our website, there is already a blog post on Cloudflare firewall rules for WordPress, and you'll see there is one to filter traffic outside your target country. You basically add this rule in. I'll see if I can enlarge this, it doesn't get any bigger. Okay, so this is "block foreign traffic". In this example we're filtering outside North America, so Canada and the US. We want to let known bots in, because we don't want to block Google crawlers or AI crawlers or anything like that. If they are a known bot, we let them through.
We also want to add exclusions. This folder or path is typically required for SSL certificates, especially on WordPress, so this says "does not contain". It's cut off a little bit there. We also don't want to block uptime monitoring. Just keep in mind that if you add this rule, it's going to need some adjusting, as it may block genuine stuff that is interacting with your site. In this example we don't want to block uptime monitors, so again this says "does not contain" uptime in the user agent. If you're using third party tools for things like order management or shipping, you may need to add more to this rule.
My suggestion, if you're DIYing it, is to add it and be mindful that it might break stuff. Then go into Cloudflare, look at the log to see what it's blocking, and you can expand this rule. Usually the user agent is the way to unblock stuff. If you have a particular piece of software that's accessing the site, or APIs or something like that, adding it into this rule will let it through and stop blocking it. So just be mindful if you do add this. It may need some fiddling, but it's usually very effective. It'll also make the site more robust against other types of attacks as well: negative SEO attacks, and other crawlers, scrapers and types of garbage that typically seek out WooCommerce sites to do all sorts of malicious stuff on them.
5:01Install a WooCommerce Fraud Protection Plugin
Okay, so that's that. Use Cloudflare, and then use a fraud plugin. There are a couple of options here. This one is free for 500 orders a month. FraudLabs Pro is very good for a small business website. This site would be under that 500 orders a month, with 5 to 10 orders a day. It will do a whole bunch of stuff to block fraud orders and repeat orders, and block things like multiple orders per IP address. Generally a lot of these fraud plugins are doing the same thing in slightly different ways, so they're all much the same. Some of them have big databases of malicious IPs that they filter on. This would be a good starting point if you have a little site or you're not making much money from your site.
Then there's a paid plugin on the WooCommerce site, Anti-Fraud for WooCommerce, that's a bit more advanced. You can see all the different options if you click through. There are things like whether the location of the order matches the order details or shipping details, all sorts of stuff like that. These plugins even do things like this: if you are shipping to western countries, and the order comes in and all the order information is in lower case, that could also be a flag that the order is malicious. Those would be the two options. This one is slightly more advanced, but they're essentially the same thing. I'd say try the free one first. If you have a low amount of orders, see how that goes. If it's not doing what it needs to do, then look at some of the paid options.
6:34Stripe Radar and Where to Get Help
The last one is Stripe Radar. If you're using Stripe for payment, which you may not be, you may be using the WooCommerce payment integration, but Stripe does have an add-on called Radar that will block fraudulent orders as well. There is some cost involved there, so you probably want to try the fraud plugin first before going with Stripe Radar.
So that's it. I said I'd keep this video short, and I think it's only 5 minutes long. If you need help with your site, head over to our website, wpspeedfix.com. We specialize in site speed and technical SEO. On our website you'll see there's a free audit, and you can request help. There's also a bunch of free tools: a free SEO audit, a free Core Web Vitals report for site speed, and a free WordPress site speed test that uses AI to give you all sorts of recommendations telling you how to improve your site speed. All those are no opt-in required. They take 60 to 90 seconds and they're completely free, so give them a go.
Then we have our mailing list, Simple, Not Obvious, which has a lot of good stuff like this. You can see the past newsletters there. There's a lot of really useful stuff for making your site perform better and faster, better SEO, all that sort of jazz. So anyway, if there's anything else you need, if you get stuck or have any questions, just post in the comments below. Cheers.
We’ve been seeing a rise in customers with spam WooCommerce orders coming through their site. These aren’t just a nuisance, they can be a huge issue especially if you using a 3PL for order fulfillment because if some portion of the fake orders get through, they may end up actually being shipped. Ultimately this means you lose twice, once on the fraud order that gets shipped and then again with the chargeback.
In this post we’ll show you how to stop these spam WooCommerce orders permanently. This general approach and the same principles apply for other CMSes so if you’re running Magento or Opencart, this will also solve your problem.
To get started, head over to our QuickFix service, order 1 x QuickFix service and our team will get cracking. Generally we can get this implemented within 1 business day or less of getting the access we need. We’ll need admin access to your hosting account, or more specifically, your DNS hosting and an email address you want to use to setup the Cloudflare account under.

Spam, fraud and fake orders are typically low dollar amounts. Malicious actors are essentially testing their list of credit card numbers to see which work or are genuine.
Orders will typically come through something like the screenshot below where there are several orders per hour all for the same product. Notice also that these orders more often than not will have the customer details all in lowercase as they orders typically originate from non-Western countries where the language doesn’t have uppercase character.

Table of Contents
Why Fake Orders Are a Serious Risk
Leaving fake orders unchecked can cause huge headaches for your business:
- If you use a 3PL or fulfillment partner, fake orders might actually get shipped.
- Your merchant account or payment processor could flag or suspend you due to suspicious activity.
- It clutters your order system, wastes your time, and damages trust with legitimate customers.
5 Steps to Stop Fake WooCommerce Orders
Here’s three simple steps to stop fake orders in your WooCommerce site (or any ecommerce site).
1. Enable Rate Limiting in WooCommerce
WooCommerce has some inbuilt rate limiting security features for the API and checkout. Typically this feature won’t be enough to stop most fake and spam order attacks because the rate of fake orders is too low but it’s worth turning on this feature anyway.
Do this in the WordPress backend under WooCommerce -> Settings -> Advanced -> Features and enabling “Rate limiting Checkout block and Store API”.
Learn more about this on the WooCommerce site here: https://developer.woocommerce.com/docs/apis/store-api/rate-limiting/
2. Use Cloudflare and Enable Country Filtering
Ideally you should be using Cloudflare for your WordPress site as even the free plan offers a whole bunch of features and benefits to improve site speed and your SEO.
With the Cloudflare firewall rules you can filter traffic outside your target country, countries or continents.
Using this technique will stop automated bots and tools that are typically using automation to place these orders.
Click here for a blog post on filtering traffic outside your target country using Cloudflare.
NOTE – you NEVER want to block countries outright as its inevitable real users will at some point be caught by the filter. Instead use the managed challenge or interactive challenge which will allow genuine users to get past the filtering through a captcha style mechanism.
3. Install a WooCommerce Fraud Plugin
There’s a whole bunch of these plugins and they all do similar things and will filter checkouts based on predetermined rules, IP blocklists and various other behaviours known to be fraudulent.
Here’s two options for you to try:
Fraudlabs Pro which is free for up to 500 orders per month: https://wordpress.org/plugins/fraudlabs-pro-for-woocommerce/
AntiFraud for Woocommerce which is a paid plugin but has a whole range of settings you can use to dial in filtering: https://woocommerce.com/products/woocommerce-anti-fraud/
4. For Stripe Users, Enable Stripe Radar
If you’re using Stripe, their Radar product will help identify and flag spam and fraud orders. There is a fee to using this service but it’s well worth it.
Learn more at https://stripe.com/radar
5. Review the server log and block based on activity (advanced)
We published this post in September 2025 because we had a bunch of customers over a weekend report fake orders. Some of these customers are selling digital products internationally so we can’t use the Cloudflare country blocking rules. Interestingly, because these were digital products, no shipping address was required but orders were showing up with shipping info – this is very strange given the checkout doesn’t have shipping details.
We did some server log analysis, looking at the IP addresses the orders came from (this should show on the individual order in Woocommerce) and filtering the server log based on these IP addresses and looked at the user behaviour.
What was happening in this particular case was that the malicious orders were being submitted by the WordPress REST API that was public facing. This was how orders were appearing with shipping info when there was no option to add this via the cart.
We traced the IP addresses back to a single hosting company too.
Using this info we were able to create a new rule in Cloudflare to block this activity. A screenshot of the rule is below – you’ll see we’re blocking two different API calls being used to add items to the cart and update the customer details. There’s another line in there to block a call that was being used to list all the products out and then a fourth line to block the network these attacks were coming from. We used the Cloudflare event log to determine the AS number which is the network ID these attacks were coming from.
Your server log is accessible via your hosting control panel. It’ll be called “Apache Access Log” or “Nginx Access Log” or just “Access Log”. Typically there will be an access log and an error log. You can usually filter these by IP in the web interface but if not you’ll be able to download these logs and search through them using Notepad or some other basic text editor.

What Doesn’t Work
Two common pieces of advice you’ll see around the web in relation to this problem are to “turn off guest checkouts” and “enable recaptcha or Cloudfalre turnstile on the checkout”
Don’t do this.
These are at best completely ineffective and will likely hurt your conversion rates.
Guest checkouts are better for your conversion rate in 99.9% of cases and won’t block the more complex attacks. All you’re doing is annoying real customers.
I’m sure you’ll agree, catpcha’s are horrible and with the advent of AI, are easily bypassed by malicious actors anyway. You’re better off using Cloudflare’s network level firewall rules as per above, which are massively more effective and won’t interfere with conversion rates or regular users in the same way a recaptcha does.
Need More Help or Want It Done For You?
We’re specialists in WordPress and Woocommerce and can help you to fix your spam and fraud order problem.
If you’re looking for help with your site, click here for a FREE Site Audit and one of the team will come back to you usually within a day or so and advise how we can help.