Forms · Checkout · Analytics WordPress & WooCommerce

Filter the noise. Keep the customers.

Anyone can block spam by making the form hostile. The work is filtering out the bots while the customer who was ready to buy still gets through first time, on a phone, without being asked to prove anything.

No puzzlesevery check is invisible
2–3 daysforms and comments
$240fixed, one site

Borderline messages are quarantined, never deleted.

For customers
No puzzles. Every check is invisible.
Price
Fixed $240 for forms, comments and registrations.
Stores
$690 including card-testing protection on checkout.
Timeline
2–3 working days, 4–5 for a store.
Search engines
Verified crawlers are allowed through, checked by reverse DNS.
False positives
Borderline messages are quarantined, never deleted.

Why it is worth fixing

Spam is annoying. Bots are expensive.

Nobody buys spam protection because the inbox is untidy. They buy it after they add up one of these four, usually the second one.

The expensive part of spam is not the spam

Enquiries nobody opens

A form that mostly delivers junk gets read less and less. The message that mattered was in the middle of it, and by the time anyone noticed, the prospect had gone elsewhere.

The one that arrives as an invoice

Card testing fees

Bots push stolen cards through checkout in tiny amounts to see which ones work. Every attempt costs a gateway fee, and a high decline ratio gets accounts reviewed or suspended.

The one nobody notices

Decisions from fake numbers

Automated sessions inflate traffic and flatten conversion rate. Then the budget moves toward the channel with the most bots, because on the dashboard it looked like growth.

The one you keep paying

Hosting you did not need

Scrapers and login attempts hit PHP directly and ignore your cache. Plenty of “we need a bigger plan” conversations are really “we have never filtered anything” conversations.

Runs in your browser · nothing is sent anywhere

Paste a message you received

This is the content-scoring layer, working exactly as it does on a client site. It reads the text, shows every signal that fired and explains what each one means.

Or try one:

The scoring runs on each keystroke, on your machine. There is no request behind it.

    Being straight about what this is: content scoring is the cheapest of the five layers and the easiest to fool — a careful human writing a pitch sails through it, and so they should. The layers that do the heavy lifting sit in front of it and never let the request reach your form at all.

    How we stop it

    Five layers. The cheap ones run first.

    No single check is clever enough on its own. The point of the stack is that the expensive decisions only ever run on what is left — and that each layer is honest about what walks past it.

    At the edge

    Blocked before WordPress wakes up

    Stops

    • Known bad networks, hosting ranges and headless browsers
    • Volumetric floods on login, XML-RPC and search
    • Request rates no human produces
    • Regions your own order history says you do not sell to — never a country you actually ship to

    Gets past it

    A patient attacker on a residential IP, going slowly.

    Costs you nothing per request — PHP never runs.

    WooCommerce

    On a store, this is a money problem

    On a content site the cost is the enquiry nobody opened. On a store it arrives as a line on the gateway invoice — fees per attempt, held stock, and a processor asking about your decline ratio.

    01Card testing

    Hundreds of small authorisations against stolen cards. You pay a fee per attempt, and a decline ratio above your processor’s threshold gets the account reviewed.

    02Fake accounts and coupons

    Automated registrations farm first-order discounts, exhaust limited coupons and leave you with a customer table you cannot email.

    03Checkout and cart floods

    Cart and checkout cannot be cached, so every bot request runs PHP and queries the database. This is what falls over first on a busy day.

    04Price and catalogue scraping

    Competitors pull your whole catalogue on a schedule and undercut you automatically. It also pins your server at a steady load you are paying for.

    05Review and question spam

    Product reviews with links, or questions that are really adverts. Both damage the page for customers and for search.

    06Inventory holding

    Automated carts hold stock that real buyers then cannot get, especially on limited runs and launches.

    Card testing is the one to check today. Open your gateway dashboard and look at the ratio of declined to successful payments over the last month. If declines are climbing and the amounts are small and round, that is not your customers having a bad week.

    Pricing

    Fixed prices, defined scope

    One site per package, and 30 days of tuning included in each — the first two weeks always find a rule that was too strict or too loose against your real traffic.

    Forms & comments

    The inbox is unusable and comments are a link farm.

    $240one site, fixed price

    • Existing spam cleaned out of comments and the database
    • Honeypot, timing and token checks on every form
    • Invisible challenge, no puzzles for customers
    • Content scoring tuned to your real messages
    • Quarantine instead of deletion, so nothing is lost
    • Registration and login protection
    • 30 days of tuning after launch
    Most chosen

    Store & checkout

    WooCommerce: card testing, fake accounts, coupon farming.

    $690one store, fixed price

    • Everything in Forms & comments
    • Card-testing protection on checkout
    • Rate limits on cart, checkout and account endpoints
    • Coupon and first-order abuse rules
    • Review and product-question filtering
    • Scraper rules that leave Google alone
    • Gateway decline ratio watched for 30 days

    Traffic & analytics

    The numbers are wrong and the ad budget follows them.

    $290one site, fixed price

    • Edge rules: bad networks, hosting ranges, headless browsers
    • Verified crawlers pass — checked by reverse DNS, not by the user agent they claim
    • Bot traffic filtered out of GA4 and Search Console reporting
    • Referral and ghost spam removed from your reports
    • Ad-click fraud rules where the platform allows them
    • Before-and-after report so you can see the difference
    • Server load compared on the same two weeks

    Several sites, or a multisite network? Say how many in the form — the rules are largely shared, so the price per site drops quickly.

    FAQ

    What people ask first

    Something not here? Ask it in the form — the reply comes from the engineer who would do the work.

    Will customers have to solve puzzles?

    No. Everything we install runs invisibly — a challenge the browser answers on its own, a hidden field a human never sees, and a timing check. Nobody is asked to identify traffic lights. Visible challenges cost real conversions, often more than the spam does.

    How much does spam protection cost?

    Forms, comments and registrations on one site is a fixed $240. A WooCommerce store, including card-testing protection on checkout, is $690. Cleaning bot traffic out of your analytics and edge is $290. Prices are fixed before we start.

    Is a plugin like Akismet not enough?

    Akismet is good at comments and we often leave it running. It does not protect checkout from card testing, does not rate-limit your login page, does not stop scrapers, and does not filter bots out of your analytics. Those are four different doors, and Akismet watches one of them.

    Will you block Google?

    No. Verified search crawlers are allowed through explicitly, and we check them by reverse DNS rather than by the user agent they claim — which is exactly how the impersonators get caught. Blocking Google by accident is the classic way a bot rule costs more than the bots did.

    What if a real customer gets blocked?

    That is what the quarantine layer is for. Borderline messages are quarantined, not deleted, and someone looks at them. In the first two weeks we tune against your real traffic, because a rule that is right for one site is wrong for the next. If a false positive happens later, you will see it in the quarantine rather than hear about it from the customer.

    How long does it take?

    Two to three working days for forms, comments and registrations. Four to five for a store, because checkout rules are tested against real orders before they go live. Then 30 days of tuning, which is included — the first two weeks always find something the initial rules were too strict or too loose about.

    Can you tell how much of my traffic is bots?

    Yes, from server logs rather than from analytics — analytics only sees what executed JavaScript, which is precisely what most bad bots do not do. The gap between your server log and your analytics is usually larger than anyone expects.

    Do you need access to my site?

    SFTP or SSH, a WordPress administrator account, and access to your CDN or DNS if the edge layer is in scope. For a store we also want read access to the payment gateway dashboard, to watch the decline ratio before and after. Create the credentials fresh and remove them when we are done.

    Tell us what is getting through

    One minute, and an engineer reads it.

    You get a reply with what we would do first, in what order, and what it would take. If you can, keep a few of the spam messages — they tell us more in two minutes than a description does in ten.

    Reply within one business day
    Fixed price before anything starts
    No puzzles for your customers, ever
    30 days of tuning included
    [email protected]Telegram · WhatsApp

    Your site

    What is the main problem?

    Where is it coming through?

    Pick any optional

    Where should we reply?

    This form runs the same honeypot and timing checks we would install on yours. That is why you did not have to prove anything.