WordPress Spam User Registrations: Stopping Fake Users Signing Up
Your WordPress site is getting spam user registrations — fake users signing up with gibberish names and odd email addresses, sometimes dozens a day — and you want them stopped without locking out real customers.
Common signs of this issue
- WordPress spam user registrations keep arriving — new users with random names, gibberish usernames, or strange email addresses.
- Your inbox fills with "New User Registration" notifications from your own site.
- The Users screen shows hundreds or thousands of Subscribers or Customers you never expected.
- On a WooCommerce shop, new customer accounts appear that never place an order.
- Some usernames or names contain links, phone numbers, or promotional text.
- Your site has no membership area, forum, or shop — yet people are still signing up.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Go to Settings, then General and look at Membership: Anyone can register. If your site does not need public sign-ups — most brochure-style business sites do not — this box should be unticked. That alone stops most WordPress spam registrations.
- On the same screen, check New User Default Role. It should be Subscriber (or Customer for a shop). If it says Editor, Author, or Administrator, fix it and read unknown admin user in WordPress — that setting is a known sign of tampering.
- Open Users, then All Users, filter by role, and look for anyone with more than Subscriber access you do not recognize. Spam sign-ups should only ever be low-level accounts.
- If you run WooCommerce, open WooCommerce, then Settings, then Accounts & Privacy. Check whether customers can create an account on the My Account page or during checkout. If you do not need accounts on the My Account page, turning that off closes a common bot target while still allowing checkout.
- Check other plugins that add their own sign-up forms — membership, course, forum, event, or form-builder plugins. Each one can be a separate registration door even if the main WordPress setting is off.
- If you do need public registration, add bot protection to every registration form: a honeypot field, Cloudflare Turnstile, or reCAPTCHA, plus email confirmation before an account is activated where your plugins allow it. Test the form yourself on your phone afterwards.
- Before bulk-deleting anything, take a backup and sort genuine accounts from fake ones. On a shop, check for order history; elsewhere look at comments, course progress, or membership records. Filter by registration date if the spam started on a known day.
- Delete in small batches rather than thousands at once, which can time out on shared hosting. When WordPress asks what to do with the user's content, attribute it to your own account rather than deleting it, until you are sure.
What this usually means
Spam registrations are almost always automated. Bots scan the web for WordPress sites with registration switched on, then sign up in bulk. Many site owners never switched it on deliberately — it was ticked during setup, turned on by a plugin, or left over from an old feature. WooCommerce and membership plugins add further sign-up forms that bots find just as easily.
The motives vary. Some bots simply want an account that can post comments or forum spam. Some stuff links and promotional text into the name fields so your site's welcome email carries their spam to whatever address they entered, using your domain's reputation. Others collect low-level accounts on thousands of sites, waiting for a plugin flaw that lets a Subscriber raise their own privileges. A pile of Subscribers is not a hack in itself, but it gives attackers a head start when the next vulnerable plugin appears.
The fix follows from whether you actually need public registration. If you do not, turn it off everywhere and clean up the fakes. If you do — a shop, a members' area, a course site — keep it on, but put a bot check and email verification in front of it, keep the default role at the lowest level, and keep plugins updated. The same bots often go after your contact forms too; see spam contact form submissions. Aggressive challenges can block real people, which is covered in reCAPTCHA blocking visitors.
What not to do
- Don't bulk-delete every Subscriber or Customer without checking. On a shop, real buyers and their order history can be mixed in with the fakes.
- Don't leave Anyone can register switched on if your site has no reason for visitors to have accounts.
- Don't raise the default role above Subscriber or Customer for convenience. Giving new sign-ups more power is how spam accounts become a security problem.
- Don't stack several captcha plugins on the same form. They conflict, and genuine visitors end up unable to register or check out.
- Don't ignore registrations with links in their names. Your site may be sending those links to strangers inside its own welcome emails, which can hurt your email reputation.
- Don't delete thousands of users in one go on shared hosting. Big batches can time out mid-way and leave the database in a messy state.
When to get help
Bring in help if the sign-ups continue after registration is switched off (that means another form or plugin is open, or something worse), if any spam account has more than Subscriber access, if there are tens of thousands of users to sort through, or if your shop's real customers are tangled up with the fakes. At that scale a careful database-level cleanup is faster and safer than clicking through screens, and it is worth confirming no plugin flaw has already been used to escalate one of those accounts.
Glenn at WebsiteSelfHelp cleans up spam registrations and locks down WordPress and WooCommerce sign-up forms for small businesses without breaking checkout. Describe what you are seeing — how many users, which forms, and whether you sell online — and he will give you a clear picture of what it takes to stop it.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
Why are fake users signing up on my WordPress site?
Bots look for WordPress sites with registration open and sign up automatically, to post spam, push links through your welcome emails, or hold accounts in case a plugin flaw lets them gain more access later.
How do I stop WordPress spam user registrations?
If you do not need public accounts, untick Anyone can register under Settings, General, and turn off extra sign-up forms from plugins. If you do need registration, add a honeypot, Turnstile, or reCAPTCHA and require email confirmation.
Are spam registrations a sign my site was hacked?
Not on their own. Low-level spam accounts are nuisance traffic. It becomes a security concern if any of them have Editor or Administrator access, or if the default role has been changed to something higher than Subscriber.
Is it safe to delete spam users in WordPress?
Yes, once you have a backup and have checked that no real customers or members are included. Attribute any content to your own account when asked, and delete in manageable batches.
Why does WooCommerce create so many fake customer accounts?
WooCommerce can let visitors create accounts on the My Account page and at checkout, and bots target those forms. Turning off account creation on My Account, if you do not need it, and adding bot protection usually cuts it sharply.
Can spam registrations hurt my email deliverability?
They can. If bots put links in their names, your site sends welcome emails containing that spam to whatever address they supplied, and complaints about those emails can damage your domain's sending reputation.