• Hello!

    I would appreciate any help or advice please!!

    I had a WooCommerce site created for me Dec 2025 and it is truly very disappointing! I upgraded (so I was told!) from an out of date Zen Cart! Never had any issues with that but this WooCommerce site is so far very disappointing.

    In the last 3 days I have had 60 spam draft orders – they are relentless… (100 in total now) I have recapture and security added via PayPal so thankfully no payments made also not one real order yet (except from a previously banned competitor wanting to buy all my best stock to re-sell!) but I am concerned to promote the site as it obviously has a security issue to allow these draft orders – some have emails (which I block) some have no info or use 10 Downing Street as address and mobile number 07123456789 or 07987654321 etc and some may have name usually Harry Potter or equally obvious faux spam details! The draft orders are creating order numbers and affecting the sales reports etc.

    My webhost/site creator added a plugin to add blocked emails but these draft orders are unacceptable, the site obviously has flaws as I have read some reviews.

    I will not be happy if I have to abandon this platform as it cost quite a lot to build and customise the website. I do not not want to be spending more money on ‘premium’ plugins until I know the site is secure and functionable or suitable for an ecommerce shop with 2000+ items.

    Could anyone please offer me any advice please that can save the day of these relentless spam draft orders. Maybe there is a task/adaption I need to do to stop them but I am not that technical!

    Thank you in advance!

Viewing 3 replies - 1 through 3 (of 3 total)
  • Hello @funkyflower ,

    What you describe is usually caused by bots hitting the WooCommerce checkout endpoint directly. WooCommerce creates the order before the payment step, so even if the payment fails or is never completed, the order can still appear as draft/pending.

    reCAPTCHA plugins also often protect login or forms but not always the checkout, which allows bots to create these orders.

    A few things that would help diagnose this:

    • What status do these orders have exactly (Draft, Pending payment, Failed)?
    • Is guest checkout enabled?
    • Which captcha/security plugins are currently active?

    If you don’t mind sharing the URL of the site, I’d be happy to take a look from the outside and see if anything obvious stands out.

    Moderator threadi

    (@threadi)

    I recommend getting in touch with WooCommerce’s support about this via https://woocommerce.com/my-account/create-a-ticket/ if you have any of their paid WooCommerce products or https://wordpress.org/support/plugin/woocommerce/ if you do not.

    Thread Starter happy sunflower

    (@funkyflower)

    thank you @marferblanco and @threadi for your advice

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.