Small Businesses Battling Bot Traffic
Small business owners are experiencing significant spikes in website traffic, overwhelmingly attributed to bot activity. These bots inflate session counts, skew analytics, and require constant mitigation efforts, often proving ineffective despite attempts at solutions like Cloudflare. The problem is causing frustration and a need for more robust bot detection and prevention strategies.
SOURCES (60)
“Put Cloudflare, even the free version, in front of the site. Then also make sure nobody can hit the site via IP address and only via the actually URL (it will bypass Cloudflare)”
“Thanks for that info. All my filters were tightened up by my web master. Authorize.net has been helping me also. Thanks again!”
“Thanks, the bots are getting by Captcha easily, and I have the Advanced Fraud Detection really tight. Thanks for all of the info!”
“You need to enable Advanced Fraud Detection Suite in Authorize.net and configure rules for velocity per IP. I can provision NMI or Authorize.net. Bots are finding it very easy to challenge and solve captcha. Also setting higher rate limits on My Account / Add payment Method or rate limiting the Store API if you’re using blocks checkout also should help. Some of this information you can’t learn without the server logs to check.”
Put ReCaptcha on your site, that all but ended it for me on Woo
“The checkbox on the page doesn't cover the payment API, which is why it comes back the minute the gateway is on. Pull the auth log for a few minutes of the attack and look for lots of cards from one IP, tiny amounts, and AVS failures. Country blocks chase the same pattern around the map.”
Your "webmaster" is incompetent. Disable the wp json api.
“Hey guys, Im running a clothing brand in india . Recently experienced a sudden drop in the traffic quality , all COD orders having a high rto risk , absolutely no engagement on ads , like i used to get followers from ads too but that stopped too in these 7 days. Anyone experiencing the same thing? If yes, would appreciate some help for the same submitted by /u/Actual-Message-905 [link] [comments]”
“also seeing this on shopify plus first I tried blacklisting the countries it was coming from initially, but that turned in a game of whack-a-mole with traffic originating from ever more random places (e.g., Lahore, Pakistan). tried whitelisting then with even less effect =/”
“They got redirected to my home page, My site is designed as a one pager when everything is easy to follow and crawl by bots to make it as easy to index as possible”
“Countries that show normal proportions of visits:wishlists:sales from organic Steam traffic, but show infinity:0:0 proportions of clicks:wishlists:sales on Reddit Ads and consume clicks suspiciously rapidly? Like Philippines Furthermore, is there a list of countries that show high wishlist bot activity after Reddit Ads (tons of wishlists, suspiciously low purchases compared to the US/Belgium)? Like Germany/Sweden/Norway Thanks in advance! submitted by /u/Anodaxia_Games [link] [”
“Like others have said, first set up Cloudflare DNS, then install a geo blocking app like Shieldleaf (both have free options). You won’t stop it all and still get visits signal from some bots but the app will stop any other signal on your site, like stuff that can effect ads analytics and pixels. Anything more advanced is overkill and too heavy handed for now. Shopify need to plug the whole to fix the rest.”
“you can use microsoft clarity. it filters them out and it tells you how many sessions with bot your site had”
“After posting a Show HN on this platform, a veritable bot onslaught occurred within minutes. 175 bots were involved, generating over 1300 hits. Unfortunately, not a single real person was among the "visitors"—apparently not even out of pure curiosity. However, here is a list shortened to 50 entries (the input field doesn't allow more). The rest of the list, which has since been expanded to include another 90 bots, can be found via the link below. This list can be freely used for bot blocking, an”
“Ive been noticing alot of junk traffic more than usual lately. Few seconds and bounce. Atcs way down. It almost seems like users on meta are way down lately, not sure why. What are you seeing? submitted by /u/Huge_Kaleidoscope_40 [link] [comments]”
“you classifying by UA, bot ASNs, or tagging why the request happened?? blocking crawlers feels wrong when some of those agents send the actual user later”
“There are almost certainly more of these than you can see. A visit that comes out of a chat usually arrives with no referrer, so most analytics file it under direct, and the ones you can identify are only the minority that happened to keep a link intact. Worth pulling that direct bucket apart before you size this channel. Founder here, I sell done-for-you product sites, so that is my bias stated up front. On our own site ChatGPT has passed Google as the largest source of visits, and that changed”
“An app does not do anything to protect your analytics. The page renders before they can be blocked.”
“Cloudflare and some fraud filters can help, but Shopify exposes json pages that cannot be protected because they are accessibly via my Shopify domain lookups that have all your content. Myshopify domains are unprotected. Want to try it? Pull up any page on your myshopify domain with “.json” at the end. (So like mystore.myshopify.com/products/produxt-url.json) So basically nothing. We’re doing nothing until Shopify fixes this gap.”
“My site is purely hobby and fascinating for me to witness bot traffic, hacking attempts etc. I don't make any money off my posts. I am in the software industry and see how we spend at least 35% of a budget on security. ANd I'm talking about development teams responsible for feature development. Regular developers also have to constantly upgrade 3rd party libraries. It was not like this 20 years ago. I am on a quest to see if choosing the right architecture, or tech stack, including langu”
“https://preview.redd.it/ovuz70t6wymh1.png?width=2173&format=png&auto=webp&s=9a261d7696439320bc6b4b684947385606d5d872 I got this “Suspicious activity detected” warning last night and it’s still there. I already changed my password, but nothing has changed yet. I’ve seen people saying that you sometimes just have to wait 24 hours, but I have no idea if that’s actually true. Has anyone had this recently? Did it go away by itself, and how long did it take? submitted by /u/Mon”
“We have a part of our app that we have open to the public for SEO. It’s a business directory, of sorts. It helps get traffic and eyeballs on our paid features, but it also sometimes gets the attention of bots and other m…”
“Yeah, we’ve noticed this too. Bot traffic can definitely skew the numbers, especially direct traffic. Looking at behavior and engagement alongside GA4 seems more useful than relying on traffic numbers alone.”
“Cross-referencing against send times is the cheap version of this and almost nobody does it. A newsletter lands as a direct spike an hour or two after the send, and held on its own it reads as brand. Same story for anything dropped into a private community that day.”
“In-app browser handoffs are the worst of the set, because they land in direct right when you are deciding budget. Wrong number, worst possible moment. One check that usually settles it before anyone pauses a campaign: look at the geo split of direct. If it lines up with the countries the campaign was targeting, that is not brand recall.”
“For Shopify Analytics I filter out bots and just use North America in my dashboard reports. We occasionally sell to folks outside of North America, but I don’t need to know my conversion rate for Sweden on a daily basis.”
“You can actually proxy a storefront through it. We are doing it today and its cut down on a ton of bot traffic. See their [documentation].( https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/saas-customers/provider-guides/shopify/ )”
“honeypots are a good first line of defense, especially for preventing automated form submissions. beyond that, looking at behavioral patterns like mouse movements or typing speed can often differentiate bots from human users more effectively than simple CAPTCHAs, which are becoming easier for AI to solve. rate limiting requests from a single IP is also crucial to prevent scraping or brute-force attacks.”
“Nothing being sold here. Just curious how people are dealing with the growing amount of bot traffic in their analytics.”
“With AI crawlers and agents hitting websites constantly, how much of what analytics calls “direct traffic” is even human anymore? If bots are getting counted as visits, conversion rates automatically look worse. And then decisions about landing pages, content, ad spend etc. are being made from numbers with a messed up denominator. Blocking bots doesn't really solve it either. Some are obviously junk, but others are search crawlers, monitoring tools or AI agents that might actually send users”
“160k users! It’s unlikely anyone is focusing on anything but malware events in an environment that large, as an administrator, if we cared about these things, I wouldn’t be concerned unless there were repeat offences.”
“Hey, someone is bruteforcing my login since 2 days. Seems to be a bot and I cannot be the only one. I am not even subscribed nor have I payment information connected in my account Any things I can do despite changing Mail? submitted by /u/AdInternational1230 [link] [comments]”
“I'm mostly venting too but hoping someone sees this post that can do something about it. I've seen people from Shopify reply before, not officially but giving advice. I'm glad you posted”
“this is mostly just to vent, i dont have any solutions. its crazy bots even found my site, its so small”
Thank you for posting, this is driving me nuts for the last few weeks. Mostly China but some Singapore. Geoblocking apps do nothing because they only fire after the page loads and…
“If it's actually bot traffic and it's starting to pollute your store and email analytics, I'd handle it at the edge rather than just filtering it in reports. Before blocking the whole country though, I'd check the IPs, user agents and request patterns first, because legitimate customers can obviously come from Singapore too. A country-level rule is pretty blunt, so I'd rather start with a challenge/block rule for suspicious traffic and tighten it if the same pattern keeps sho”
“Cloudflare breaking Merchant Center + Google Ads undeliverable is brutal. I’ve had Cloudflare misconfig turn half my feed and ads into a total mess until the site responses were clean again. It’s almost always the crawl/reachability side causing the whole cascade.”
“But what if Google tries crawling outside of the US? Worried my ad account might get hit with this setup”
“Cloudflare isn't an option here, you can't proxy a Shopify storefront through it, Shopify serves from its own edge. GoDaddy is just DNS so it won't do anything either. There's no network layer for you to block at, which is the thing most people waste a weekend discovering. What actually works, roughly in order of effort: A country or IP blocking app runs in your theme and stops those sessions before your analytics and Klaviyo scripts fire. That cleans the numbers, but it's wh”
Cloudflares geo-blocking, I only allow my market + US for the crawlers.
“are we using an app? setting up a filter on cloudflare or godaddy"? not sure what to do, i usually just filter this in GA4 and GSC but now its inflating my Klaviyo and Shopify Analytics submitted by /u/trailmix17 [link] [comments]”
Use an vpn and set it japan or somewhere else, it has worked for me
“Bot traffic is up and it's only going to get worse, mainly it's from AI bots scraping the web. Not sure why it says Alibaba, maybe their Qwen AI models?”
“Good point yes, I've been considering how to prevent it in the future but the region packs are static files, on a CDN for the web app and bundled inside the APK for the native one, so anyone with a browser's network tab or ten minutes has them. I don't have accounts currently - not that that would make it impossible. What fits is exactly your last point: the traversal shape. A real trip planner opens one region, maybe three if they're comparing valleys. Nobody planning a hike pul”
“I don't think they're copying the content and leaving, since the content is generated every day. Thanks, I'll check my logs. I hadn't thought of that.”
“I’m seeing a strange traffic pattern on my site in Umami and I’m trying to figure out what could be generating it. Throughout the day I’m getting sessions that all have essentially the same fingerprint: Browser: Edge OS: iOS Usually exactly 1 page view 0 events A new session roughly every half an hour Location changes every time Today I’ve seen sessions from Madrid, Marseille, Paris, Prague, Frankfurt, Zurich, Santa Clara, Los Angeles. All of them are Edge + iOS + 1 view + 0 events. My normal tr”
“tbh thats what I was thinking too, tying it to cpu load feels like it'd have a lot of false positives”
“I dealt with the same situation recently on a site of similar size. My fix was to switch on Precursor for all requests at the low setting and then add a rule for the search URL path at the high setting. Real user traffic generally doesn't hit the search URL directly so should already have the cf_clearance cookie in the request and generally won't even see an interstitial managed challenge page. Any real user hitting a search page directly might see a managed challenge but is likely to pa”
“the ip cycling thing is what breaks every conventional approach here -- rate limit by ip, block ips, iptables rules, all the same dead end when you're dealing with a botnet rotating through hundreds of addresses. using cpu as the trigger sidesteps the classification problem entirely. you're not asking "is this a bot" you're just asking "is something hammering us right now" and responding”
“We support a client site with ~20,000 pages. It has an SSR search page that uses the url querystring to execute the search/sort/filter. We have of course disallowed bots on that page because the 20k pages are meaningful and should be scraped/indexed, but the billions of possible query combinations on a search page are not. Most of the bots just ignore the robots rule and this results in waves of traffic hammering every possible query combination on the search page. These waves are 10x-50x the hu”
“Report them as spam and block their messages. I find it helpful to set up filters to send emails with specific phrases to a separate email folder that is likely spam (so you can review them at a glance 1x daily).”
“That's a scraper, not traffic. Alibaba Cloud Singapore is one of the most common sources of it, usually price monitoring or someone cloning your product data. Confirm it in your analytics first. If those 51K sessions show near-zero session duration, close to 100% bounce and zero add to carts, that's your answer. The uncomfortable bit about Blockify and apps like it is that they run as theme JavaScript in the visitor's browser. A scraper that never executes JS never sees them. They wo”
