WooCommerce spam orders: protection and order recovery

Spam bots place orders in WooCommerce stores automatically. A fake order looks like a real one - a name, an email, a product in the cart - but nobody is waiting for the parcel. CleanTalk Anti-Spam stops these orders at the checkout, keeps every blocked order in a separate list, and lets you restore any of them in one click if a real customer was stopped by mistake.

Installing the CleanTalk Anti-Spam plugin takes about 2 minutes and does not require any special configuration. After installation it protects every form on your website, including the WooCommerce checkout. All installation instructions are here https://cleantalk.org/help/install.

How CleanTalk handles a WooCommerce order

 

Why fake orders appear in WooCommerce

What bots do

  • scan the web for stores and submit the checkout form automatically
  • test stolen cards with small orders
  • place orders with disposable or non-existent emails
  • use the order notes field to send links and advertising
  • create an account during checkout to get inside your site

What it costs you

  • staff time spent on orders nobody placed
  • stock reserved for orders that will never be paid
  • payment gateway declines and extra fees
  • order numbering and sales reports that no longer match reality
  • notification emails and SMS sent for nothing

 

How CleanTalk protects the WooCommerce checkout

When an order is submitted, the plugin sends the sender data - email, IP address, name and behaviour signals - to the CleanTalk cloud and receives a verdict in about 0.1 second. Real customers see nothing: no CAPTCHA, no puzzles, no extra step. Only automated submissions are stopped.

What is covered

  • the classic WooCommerce checkout
  • the block checkout built on the WooCommerce Store API
  • account registration during checkout
  • product reviews and the "add to cart" requests of anonymous visitors

What the cloud checks

  • the sender email against a database of addresses used by spam bots
  • the IP address against a database of more than 8,600,000 spam-bot IPs
  • how the form was filled in - speed, order of fields, behaviour on the page
  • whether the same sender has already been blocked on other websites

Spam order blocked at the WooCommerce checkout by CleanTalk Anti-Spam

This is what a spam bot gets at the checkout: the order is refused, and nothing is created in your store.

 

Keep every blocked order instead of losing it

Store blocked orders option in the CleanTalk Anti-Spam settings

A blocked order does not have to disappear. With the Store blocked orders option enabled, the plugin saves the whole order - the cart, the customer data and the reason for the verdict - in a separate list, where you can review it and restore it later.

Stored orders do not touch your stock, your order numbering or your WooCommerce reports.

How to switch it on:

WordPress Dashboard → Settings → Anti-Spam by CleanTalk → Advanced settings → WooCommerce → Store blocked orders → On → Save Changes

 

Where blocked orders are stored

WordPress Dashboard → WooCommerce → WooCommerce spam orders

WooCommerce spam orders page with blocked orders

What each column shows

  • ID - the internal number of the blocked order
  • Order details - the products and the amount of the order that was stopped
  • Customer details - name, email, IP address and the rest of the submitted fields
  • Order date - when the order was submitted, sortable

What you can do with a row

  • See details - opens the full request in a window
  • Restore - returns the order to your store
  • Delete - removes it, one by one or in bulk with the checkboxes

 

How to restore an order in one click

No filter is perfect, and a real customer can occasionally be stopped - for example when the order is placed from an IP address that a spam bot used before.

  1. Open WordPress Dashboard → WooCommerce → WooCommerce spam orders.
  2. Find the order by date, customer email or amount.
  3. Press See details and check what exactly was submitted.
  4. Press Restore.

Restore link on a blocked order

The order returns to your normal WooCommerce orders list with all of its data and continues the usual workflow. The customer does not have to place it again, and you do not have to ask them to.

Restored order in the WooCommerce Orders list

 

How to see why an order was blocked

WooCommerce spam order details window

Press See details on the order and take the CleanTalk request id. The same request is available in your CleanTalk Dashboard, with the verdict, the reason - block list, behaviour, disposable email and so on - and the full body of the request.

If you disagree with a verdict, send it to us from the same screen. We review such requests and correct the filter.

 

FAQ

Do real customers see a CAPTCHA?
No. The check runs in the background and a real customer completes the checkout as usual.

Do blocked orders clutter my store?
No. They are kept in a separate list and do not affect stock, order numbering or reports.

Is this included in my license?
Yes. WooCommerce protection and blocked order storage are part of the Anti-Spam license, there is nothing extra to buy.

Which checkouts are supported?
The classic checkout, the block checkout and registration during checkout.

Can I delete stored orders?
Yes, one by one or in bulk with the checkboxes.

What if I turn the option off?
Blocked orders are simply not stored. Protection keeps working, but you will not be able to review or restore anything.

 

Related guides

Была ли эта информация полезной?

Copied to clipboard