WordPress Spam User Registrations: Stopping Fake Users Signing Up

Your WordPress site is getting spam user registrations — fake users signing up with gibberish names and odd email addresses, sometimes dozens a day — and you want them stopped without locking out real customers.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

Spam registrations are almost always automated. Bots scan the web for WordPress sites with registration switched on, then sign up in bulk. Many site owners never switched it on deliberately — it was ticked during setup, turned on by a plugin, or left over from an old feature. WooCommerce and membership plugins add further sign-up forms that bots find just as easily.

The motives vary. Some bots simply want an account that can post comments or forum spam. Some stuff links and promotional text into the name fields so your site's welcome email carries their spam to whatever address they entered, using your domain's reputation. Others collect low-level accounts on thousands of sites, waiting for a plugin flaw that lets a Subscriber raise their own privileges. A pile of Subscribers is not a hack in itself, but it gives attackers a head start when the next vulnerable plugin appears.

The fix follows from whether you actually need public registration. If you do not, turn it off everywhere and clean up the fakes. If you do — a shop, a members' area, a course site — keep it on, but put a bot check and email verification in front of it, keep the default role at the lowest level, and keep plugins updated. The same bots often go after your contact forms too; see spam contact form submissions. Aggressive challenges can block real people, which is covered in reCAPTCHA blocking visitors.

What not to do

When to get help

Bring in help if the sign-ups continue after registration is switched off (that means another form or plugin is open, or something worse), if any spam account has more than Subscriber access, if there are tens of thousands of users to sort through, or if your shop's real customers are tangled up with the fakes. At that scale a careful database-level cleanup is faster and safer than clicking through screens, and it is worth confirming no plugin flaw has already been used to escalate one of those accounts.

Glenn at WebsiteSelfHelp cleans up spam registrations and locks down WordPress and WooCommerce sign-up forms for small businesses without breaking checkout. Describe what you are seeing — how many users, which forms, and whether you sell online — and he will give you a clear picture of what it takes to stop it.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

Why are fake users signing up on my WordPress site?

Bots look for WordPress sites with registration open and sign up automatically, to post spam, push links through your welcome emails, or hold accounts in case a plugin flaw lets them gain more access later.

How do I stop WordPress spam user registrations?

If you do not need public accounts, untick Anyone can register under Settings, General, and turn off extra sign-up forms from plugins. If you do need registration, add a honeypot, Turnstile, or reCAPTCHA and require email confirmation.

Are spam registrations a sign my site was hacked?

Not on their own. Low-level spam accounts are nuisance traffic. It becomes a security concern if any of them have Editor or Administrator access, or if the default role has been changed to something higher than Subscriber.

Is it safe to delete spam users in WordPress?

Yes, once you have a backup and have checked that no real customers or members are included. Attribute any content to your own account when asked, and delete in manageable batches.

Why does WooCommerce create so many fake customer accounts?

WooCommerce can let visitors create accounts on the My Account page and at checkout, and bots target those forms. Turning off account creation on My Account, if you do not need it, and adding bot protection usually cuts it sharply.

Can spam registrations hurt my email deliverability?

They can. If bots put links in their names, your site sends welcome emails containing that spam to whatever address they supplied, and complaints about those emails can damage your domain's sending reputation.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible