SHOPIFY BOT DETECTION

Shopify bot traffic: an investigation checklist

Investigate unusual Shopify traffic with a practical checklist for event coverage, repeated activity, consent gaps and merchant review.

By Blokk · Published

1. Name the action that needs investigation

A rise in sessions is a reason to investigate Shopify bot traffic. It does not tell you which visits were automated, whether they were unwanted, or whether a control would help. Start with a concrete question: are repeated cart visits creating review work, are checkout starts unusually repetitive, or is one expensive action being repeated? Give the question a time window and an owner.

Write down the business impact separately from the traffic count. A useful initial note might say that the team spent an hour reviewing repeated checkout starts. It should not say that every unfinished checkout was fraud. Keeping those statements separate makes the later review easier to defend and easier to correct.

2. Check what the integration can observe

Shopify documents distinct customer events for product views, cart activity and checkout progression. An integration receives the events it subscribes to and can collect in that environment. Make a coverage list before interpreting a timeline. Record the source, relevant consent state, installation date and known gaps. A browser event is an observation supplied through the browser; its presence does not establish purchaser identity.

Check the actual journey on an authorised test store. An event family supported in code may never have been received in your particular test. Keep the list of observed events separate from the list of implemented subscriptions.

3. Explain missing data before interpreting it

No recent events can mean no activity, disabled collection, an inactive extension, a consent restriction or a delivery problem. Check those possibilities in that order using the setup view and an authorised, ordinary journey. Shopify's customerPrivacy interface exposes consent state and changes. Do not turn a gap caused by a visitor's choice into an automation label.

Record when collection was enabled and when the test occurred. Comparing events from before an installation change with events after it can create a misleading impression that the current setup is working.

4. Review sequences without inventing identity

Read the order and timing of relevant actions. Repeated cart-to-checkout movement can be a review lead, but repetition alone cannot establish harmful intent. A shopper may retry after an error, compare options or use an assistive tool. Keep competing explanations beside the observation until another source resolves them.

Source session groups are correlation labels. They are not a count of people, and separate theme and pixel groups should not silently become one identified shopper. Avoid joining records simply because their times look close.

5. Leave a review note someone else can check

Use the same small review record for every selected case. This prevents an alarming chart from becoming the sole basis for a decision. Keep personal or payment details out of shared notes; use the approved reference for the relevant record instead.

  • Observed action and time window, with the source of each observation.
  • Available evidence, missing evidence and any collection interruption.
  • Merchant judgement: legitimate, confirmed unwanted or unresolved, with its basis.
  • Next action, reviewer and review date; preserve later corrections.

What our 25 September observation established

Blokk's development-store exercise received theme and pixel observations, including an ordinary checkout start, through a local development API. Collection stopped after consent withdrawal and resumed after analytics consent was regranted. A reviewer marked one checkout-start action legitimate. No order was submitted and no checkout block was demonstrated.

That evidence supports a practical setup and review checklist. It does not establish detection performance on merchant traffic. On 26 September, hosted monitoring was also exercised on development stores, with page and product observations, consent withdrawal and resumption, and collection stop/resume. Those checks did not demonstrate checkout protection. Blokk remains a research alpha offering guided Shopify monitor-mode pilots. Keep existing protections in place and agree the exact workflow before considering a pilot.

Sources and further reading

Continue with a practical next step.

Discuss a pilot

All articles