Security

How to Stop Spam User Registrations in WordPress and WooCommerce

Stop fake sign-ups on WordPress and WooCommerce: when to turn off registration, CAPTCHA and honeypots, email checks, and how to clean up spam accounts safely.

How to Stop Spam User Registrations in WordPress and WooCommerce
On this page
  1. Why bots register on your site
  2. Does "Anyone can register" need to be on?
  3. Add bot protection to every registration form
  4. Verify email addresses
  5. Block disposable and suspicious email domains
  6. Clean up existing spam accounts safely
  7. When spam registrations signal a bigger problem
Key takeaways
  • Most business sites can untick "Anyone can register", and the default role should always be Subscriber or Customer.
  • Protect every registration form with honeypots, low-friction challenges, rate limiting and, where it fits, email verification.
  • Back up before deleting spam accounts, keep customers with orders, and investigate any spam account with a higher role.

You open the Users screen and find hundreds of accounts with random names and strange email addresses, all created in the last few weeks. Fake sign-ups are one of the most common nuisances on WordPress and WooCommerce sites. Usually they're just bots, but they clutter your database, can trigger emails from your site to fake addresses, and occasionally point to a more serious problem. Here's how to stop them and clean up safely.

Why bots register on your site

  • To post spam comments, reviews or forum posts that need a logged-in account
  • To create profile pages with links, on sites running membership, forum or directory plugins
  • To probe for vulnerable plugins that might give a new account more access than it should have
  • Simply because an open registration form exists, and spam bots fill in every form they find

Most of these accounts never do anything. But they show that bots can reach a form you may not even know is open.

Does "Anyone can register" need to be on?

Go to Settings > General and find Membership. If "Anyone can register" is ticked, anyone can create an account through the standard WordPress registration page.

Most business websites, such as service businesses, clinics, B2B companies and brochure sites, don't need this. Staff accounts are created by an administrator, so you can untick it. Leave it on only if visitors genuinely need accounts, for example on a membership, course or community site.

While you're there, check New User Default Role. It should be Subscriber (or Customer on a store). If it shows Administrator, Editor or another role with editing rights and nobody on your team set it, treat that as a likely sign of a hack, not a setting to quietly fix.

WooCommerce account settings

WooCommerce has its own account options under WooCommerce > Settings > Accounts & Privacy, separate from the WordPress setting. You can choose whether customers can create an account on the My Account page, during checkout, or both, and whether guest checkout is allowed. Much store registration spam comes through the My Account form, so allowing accounts only at checkout, with guest checkout enabled, can cut fake sign-ups considerably without affecting real customers. Option names change between versions, so check what yours shows.

Add bot protection to every registration form

If registration has to stay open, protect it the same way you would a contact form. The methods in how to stop contact form spam apply here too:

  • Honeypot fields: hidden fields that bots fill in and people never see. They're invisible to customers and stop many simple bots.
  • Invisible or low-friction challenges such as Cloudflare Turnstile, Google reCAPTCHA or hCaptcha, added through a plugin that supports both the WordPress and WooCommerce registration forms
  • Rate limiting: a firewall or security plugin that limits how many registrations can come from one IP address in a short time

Make sure the protection covers every registration form on the site. It's common to protect the standard WordPress registration page but miss the WooCommerce My Account form, or a membership plugin's own sign-up page. Avoid hard puzzles that frustrate real customers, especially on mobile.

Verify email addresses

By default, WordPress creates the account straight away and emails a link to set a password. A bot using a fake address never sets one, but the account still sits in your database. Email verification goes further: the account isn't activated until the person clicks a confirmation link.

Many membership, registration and security plugins offer email confirmation or manual approval of new accounts. Manual approval suits small communities and B2B dealer portals where you know who should be signing up. On a busy shop, extra verification steps add friction, so weigh them against how much spam you actually get.

Block disposable and suspicious email domains

Many fake sign-ups use throwaway email services that create temporary inboxes. Some plugins can block registrations from known disposable domains, or from domains and patterns you add yourself.

  • Disposable domain lists go out of date, so choose an actively maintained plugin
  • Don't block big free providers like Gmail; many genuine Indian customers and small businesses use them
  • Review what gets blocked now and then, so real customers aren't turned away silently

Clean up existing spam accounts safely

  1. Take a full backup of the database before deleting anything
  2. Close the door first: switch off or protect registration, or new spam keeps arriving while you clean
  3. Identify the spam: Subscriber or Customer role, no orders, no comments, random-looking usernames, unusual email domains and sign-ups in short bursts
  4. Don't delete accounts with orders without checking; real customers sometimes have odd-looking emails, and their order history is a business record
  5. Delete in small batches from the Users screen, or have a developer use WP-CLI for thousands of accounts, tested on a staging copy first
  6. Check for higher roles: a "spam" account with Editor, Shop Manager or Administrator rights is not ordinary spam

When spam registrations signal a bigger problem

Usually fake sign-ups are just noise. Look more closely if you see any of these:

  • New accounts with Administrator, Editor or Shop Manager roles that nobody created
  • The default role or "Anyone can register" changed without anyone on your team doing it
  • Accounts still appearing after you've switched registration off everywhere, which can point to a vulnerable plugin or another way in
  • Your host warning about outgoing email, or people receiving odd emails from your site; see website sending spam emails
  • Strange pages, redirects or unfamiliar files appearing around the same time

Any of these deserves a proper security check, not just a bulk delete. If you run a store, the WooCommerce security checklist is a good place to start.

Need fake sign-ups stopped without blocking real customers? I set this up as part of WooCommerce development, and if something looks more serious, I can investigate through WordPress malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now