Massive spam on registration and contact forms
The forms work perfectly, that’s the actual problem: hundreds of fake accounts, contact messages or reviews generated by bots arrive without any human filling anything in. It’s the opposite of a form that fails to send, and it’s handled differently.
How I go about it
-
Identifying the entry point
I check which form is being targeted: registration on /my-account/, contact, product reviews, or attempts on xmlrpc.php, since each calls for a different response.
-
Measuring volume and origin
I check in the logs whether submissions come from a handful of IP addresses, targeted, or thousands of different ones, a distributed bot network, which changes the response needed.
-
Setting up an invisible filter
I add a honeypot field, invisible to a human visitor but automatically filled in by most bots, which silently rejects their submission without a visible CAPTCHA.
-
Adding reCAPTCHA v3 if needed
For heavier volume, I add Google reCAPTCHA v3, based on a behaviour score, with no visible challenge for a legitimate visitor.
-
Closing off unnecessary entry points
I limit or disable xmlrpc.php if it isn’t in use, and disable public registration on the WooCommerce side if guest checkout already covers the real need.
What I handle regularly
- Dozens of fake accounts created every day on /my-account/
- The contact inbox receives hundreds of spam messages
- Product reviews with suspicious links show up awaiting moderation
- Repeated login attempts on wp-login.php or xmlrpc.php visible in the logs
- The form works fine for a real customer, the problem isn’t technical but volume
Why a WordPress form attracts bots
WordPress’s default entry points — registration, comments, the contact form — have no built-in bot protection. A bot only needs to find the form’s URL and send a POST request to it directly, bypassing any visual CAPTCHA that isn’t actually verified server-side.
On a WooCommerce store, the "Allow customers to create an account during checkout" setting combined with a public /my-account/ registration page is a common target for bots specialised in mass account creation. Another entry point that’s often overlooked is xmlrpc.php, an older WordPress API regularly abused for brute-force login attempts or pingback spam, separate from the visible forms but just as exposed.
The real mitigations, roughly in order of effort: an invisible honeypot field that only bots fill in, Google reCAPTCHA v3 which scores behaviour with no visible challenge for a human, rate-limiting requests by IP address, and finally outright disabling public registration if guest checkout already covers customers’ real needs.
Related pages
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.