Platform Guide

Bot Traffic in Shopify Analytics: Why Sessions Are Inflated

Your Shopify sessions jumped but orders didn't. Tell bot inflation from attribution gaps and broken tracking — and what Shopify's bot filter can't fix.

Bot FilteringGA4 vs ShopifyWhat's AutomaticReal CR Math
July 29, 2026·24 min read·
Listen to a short brief of this article
Hands-free while you multitask

Key Insights in 60 Seconds

Skim the highlights, then jump to the section that matches what your own reports are doing.

You can split human sessions from bot sessions in your own reports today — the Human or bot session dimension costs nothing extra, and Shopify names no plan requirement for it.
It only covers data from October 7, 2025 onward — older sessions are never reclassified.
Nothing is filtered automatically — you add the dimension per report, and it labels bots rather than blocking them.
Headless and Hydrogen storefronts don't get the filter at all — those stores measure differently.
Cloudflare and hCaptcha already run on your store — putting your own proxy in front weakens Shopify's bot detection.
Orders and revenue stay honest — anything with sessions in the denominator is what's under suspicion.

What You'll Learn

1Which of four problems is yours
2Why the two counters differ
3What the native filter can't do
4Bot patterns in your admin
5Your real conversion rate
6Which moves backfire

Your sessions are up forty percent this month and your orders are flat. Or Shopify says nine thousand sessions while GA4 insists on three thousand for the same week. Or you woke up to a wave of new customer accounts with names that look like keyboard mash, and an abandoned-cart report that reads like a server log.

Whichever one you are looking at, the damage is the same: the conversion rate you judge everything by divides by the one number now under suspicion. You cannot tell whether the store got worse, the ads got worse, or nobody real showed up at all — and until you can, every weekly decision is a guess wearing a percentage sign.

Four Problems, One Symptom: Which One Is Yours?

Key takeaway

Shopify's own definition is the plain one: bot traffic is any visit to your website generated by software rather than a human. That covers search crawlers doing their job, price scrapers, load tests, and outright fraud alike — which is exactly why “are these bots?” is the wrong first question. The useful first question is narrower: which of four things is making my numbers move?

Find your row before you fix anything

What you're seeingWhat it usually isThe 15-minute checkWhere it's covered
Sessions jumped, orders stayed flatBot inflationSplit the sessions report by Human or bot session and re-read the rateThis guide, from here down
Two tools disagree about which channel sent the same orderAn attribution gapCompare order counts rather than sessions, and see how each tool credits one orderShopify Analytics guide
Numbers changed right after a theme, tag or consent-banner changeA broken or duplicated tracking setupConfirm the tag fires once per page and once per purchaseGoogle Tag Manager on Shopify
Sessions steady, rate down, nothing else movedA genuine conversion changeLook at the funnel and the pages, not the counterStore patterns that convert

The scale question is worth settling early, because it decides how seriously to take the possibility. automated traffic passed human activity for the first time in a decade, reaching 51% of all web traffic in 2024, with bad bots at 37%. That is a measurement of the whole internet by a security vendor, not of Shopify storefronts and certainly not of yours — treat it as evidence the phenomenon is ordinary, never as an estimate of your own share.

A fifth pattern that runs the other way
If another analytics tool reports far more sessions than Shopify does, you are looking at the opposite problem. One merchant documented 713 sessions in GA4 and Microsoft Clarity against 13 in Shopify for the same window, with purchases recording correctly. That is under-counting, it has a different cause, and mixing it in with bot inflation is the single most common mistake in articles on this topic. Your next step is not in the table above: orders keep recording correctly in this pattern, so make them your reference point, and read what nobody can fix for you before you invest time in chasing the session count.

Why Shopify and GA4 Were Never Going to Agree

Key takeaway

Before you accuse anything of being a bot, you have to know how much disagreement is structural. Two tools watching the same shoppers will produce different session counts even on a perfectly clean day, because they do not agree on what a session is, when it ends, or whose visits are worth counting.

If your two counters roughly agree and it is the rate that fell, this section is not your problem — skip to what bot inflation looks like in your admin and come back here only if you later need to explain a gap between tools.

Two Different Definitions of a Session

Key takeaway

The midnight rule alone guarantees divergence: a shopper browsing from 11:40pm to 12:20am UTC is one session in GA4 and two in Shopify. Multiply that by every late-night browser in a global catalog and the counts drift apart without a single bot involved.

Differences in how sessions are defined. For example, some analytics software counts search bots as visitors, but other software doesn't.
Shopify — Analytics discrepancies — Shopify Help Center · View source (help.shopify.com)
BehaviorShopifyGA4
What starts a sessionA visit tied to a cookieA page or screen view when no session is active
What ends it30 minutes of no activity30 minutes of user inactivity
Hard cut-offMidnight UTC, every dayNone — there is no limit to how long a session can last
Traffic source changing mid-visitNot documented as a session boundaryDoes not start a new session; one campaign or source per session
Known bots and spidersClassifiable in sessions reports from October 7, 2025, and only where you add the dimensionExcluded automatically, with no opt-out and no view of the volume
Page reloadsA browser doesn't count reloads of cached pagesGoogle counts every page reload
What can stop the countShopify calls its own recording mechanism proprietary and never sharedJavaScript, cookies, ad blockers, denied consent, seven-day Safari cookie expiry

Sources: Shopify Help Center on visitor and session counting and Google's GA4 session documentation, both read July 2026.

What Each Side Silently Drops

Key takeaway

The asymmetry matters more than the definitions. GA4 quietly removes traffic it recognizes as automated before you ever see a report, and it publishes neither the volume removed nor a way to turn the exclusion off — so the cleaner-looking number is cleaner partly because it is smaller by an amount nobody will tell you.

In Google Analytics properties, traffic from known bots and spiders is automatically excluded. This ensures that your Analytics data, to the extent possible, does not include events from known bots.
Google — [GA4] Known bot-traffic exclusion — Google Analytics Help · View source (support.google.com)
GA4 drops known bots for you
Identified from Google's own research plus the IAB's International Spiders and Bots List. There is no opt-out and no report of how much was removed. Shopify has no equivalent silent exclusion — it labels, and only where you ask.
Ad blockers cut the tag off at the domain
EasyPrivacy — the filter list behind most consumer blockers — blocks Google's tag-serving domain outright. For those visitors GA4 never fires at all, while Shopify still records the visit.
Safari expires the identifier in seven days
WebKit's tracking prevention caps JavaScript-set persistent cookies at a seven-day expiry, so a returning iPhone shopper can look like a brand-new visitor to GA4 and like a familiar one to Shopify.
Denied consent changes the shape, not the traffic
With analytics storage denied, GA4 writes no cookie; under advanced consent mode it falls back to cookieless pings and modeling, while a basic setup blocks the tag and drops the visit entirely. The visitor is real, the session is real, and the two systems still end up describing them differently.

Is There a Normal Shopify-vs-GA4 Gap?

Key takeaway

This is the gap most articles fill with a confident number. We checked three official Shopify pages on discrepancies and reporting: not one carries a percentage. The rule of thumb you have probably read — that 5–10% is within normal range and above 10–15% suggests a configuration issue — was published in March 2026 by Ruler Analytics, a marketing-attribution vendor with an interest in you investigating further. It is a reasonable orientation and it is not Shopify's position, because Shopify does not have one.

Use the trend, not the threshold
Since no official number exists, the honest substitute is your own history: record the gap between the two tools every week for a month while nothing is changing. A gap that stays roughly constant is structural — the definitions, the blockers, the consent rates. A gap that suddenly widens is an event with a date, and a date is something you can investigate.

What Bot Inflation Looks Like in Your Admin

Key takeaway

Shopify documents what bot activity looks like from inside the admin — and, on the same page, a second list of entirely innocent scenarios that produce the same spikes and drops. Competing articles quote the first list and stop. Reading both together is what turns a scary chart into a diagnosis.

What Shopify lists as a bot signWhat it looks like in the adminWhat else can cause the same thing
A high volume of free ($0.00) ordersBursts of orders with no revenue attachedA free product accidentally exposed to buyers
Checkout or payment attempts using repeated or suspicious customer detailsThe same details reused across many attemptsA genuine customer retrying a declined card
Many customer profiles with unexpected, strangely-formatted namesA wave of new accounts nobody recognizesA migration or import bug
A session or device-type spike in your sessions reportsA step change overnight in one device typeAn unexpected flash sale, or a promotion you did not schedule
Landing-page URL volume from marketing or search integrationsOne landing page taking an implausible shareQA or load testing run by a partner
Sessions from known data center locations (Google Cloud, AWS)Traffic from places no customer of yours livesA niche crawler you have never heard of
A sudden spike or drop in conversion rateThe rate breaks while the funnel looks untouchedAccelerated checkout, a password page, or new checkout requirements
A high volume of search terms that resemble request IDsLong machine-shaped strings in store searchA tool probing your search syntax

Both columns come from Shopify's identifying-bot-activity page — the signs it publishes for bot activity, and its separate list of non-bot scenarios that can look the same. Pairing one against the other is our editorial arrangement, not Shopify's.

The drop side of the same list
Shopify also names causes for a sudden drop that resemble bot damage but are not: accelerated checkout, a password page still up, changed checkout requirements, tracking changes, cookie-consent issues including VPN blocking, and sales channels nobody is tracking. If your rate fell rather than your sessions rose, start here.

What Shopify's Own Bot Filter Does

Key takeaway

This is the part most competing coverage misses entirely. Shopify ships a Human or bot session dimension for sessions-related metrics — sessions, conversion rates and visitor counts — and it applies to data recorded from October 7, 2025 onward. Shopify's changelog announcement followed a few weeks later, which is part of why so many merchants never heard about it.

It is a manual, per-report action: you open the report, add the dimension in the configuration panel, and optionally add a filter set to Human. Nothing is pre-filtered anywhere, so a report you have not touched is still showing you the blended number.

The Four Things It Doesn't Do

Key takeaway

The first question every merchant asks is whether this cleans up the mess already in the reports. It does not, and Shopify says so in one sentence.

Bot filtering applies only to new incoming data as of October 7, 2025, and can't retroactively classify older sessions.
Shopify — Bot filtering in Shopify Analytics — Shopify Help Center · View source (help.shopify.com)
It is not retroactive
What this means for you: sessions recorded before the cutover carry no classification and never will. A polluted quarter stays polluted, so year-on-year comparisons that reach back that far have to be made on orders, not rates.
It is not available on Headless or Hydrogen
What this means for you: if your storefront is headless, the dimension is not an option at all. The published symptom list below is still your checklist, every session-denominator metric stays unverified today, and whatever bot handling you do lives in the layer you run in front of your own front end. Shopify publishes no headless equivalent of this filter as of July 2026 — its changelog announcement lists support for headless and Hydrogen stores under “coming soon,” with no date attached.
It is not applied for you
What this means for you: you add the dimension per report, and some reports cannot take it at all — whole categories (Finance apart from US sales tax, Fraud, Orders apart from shipping labels, and Web Performance) accept no filters or edits.
It is not protection
What this means for you: the dimension classifies traffic that already arrived. Not a single bot is turned away by switching it on, and no fake account or empty cart disappears from your admin because a report now labels it.
One claim you will see that Shopify does not make
A widely repeated line says Shopify takes 24 to 48 hours to classify a session. That sentence does not appear on Shopify's bot-filtering page; the only timing Shopify documents is the October 7, 2025 cutover. If a delay matters to your reporting, treat it as unpublished rather than as a known figure.

What It Does Change: The Conversion-Rate Math

Key takeaway

Shopify publishes a worked example of what the split does to the number you actually report. It is the article's reference case from here on.

SegmentSessionsOrdersConversion rate
Summary (what your report shows)1,000353.5%
Human sessions750304.0%
Bot sessions25052.0%

Shopify's own worked example, published on the bot-filtering page quoted above. Shopify presents it as an illustration of the arithmetic, not as a benchmark or a target for your store.

Two details in that table are easy to miss. The blended rate is lower than the human rate, which is the whole point: bot sessions drag the average down and make a healthy store look broken. And the bot row is not empty — Shopify's illustration puts five of the thirty-five orders inside bot-classified sessions, a reminder that classification is a judgment about traffic, not a guarantee about intent.

One more boundary worth knowing before you compare screens: Live View runs its own, simpler bot filtering, separate from the Human or bot session system. Your real-time map and your reports are not obliged to agree, and Live View has never exposed a visitor's IP address as a field you can act on.

Find Your Problem in Five Questions

Key takeaway

You now have the vocabulary the questions need: how the two counters differ, what Shopify itself lists as a bot sign, and what its filter can and cannot do. Answer from your own admin rather than from what you suspect — the route you get depends on the direction of your gap, what your orders did, and what is actually on the screen.

Bots, attribution, or a broken pixel?5 questions → the diagnosis your numbers actually support
Question 1 of 5
Which way does the gap between your tools run?

Your Levers: What's Automatic, What You Switch On, What Backfires

Key takeaway

Merchants usually arrive at this topic assuming they need to build something. In practice most of the defensive stack is already running, the configurable surface is unusually small, and several of the moves that feel productive are actively harmful.

What Shopify Already Runs for You

Key takeaway

The most useful thing to know before you buy anything is how much is already switched on. Shopify is unusually blunt about the first layer.

Cloudflare is always active on your store and requires no action from you.
Shopify — Protecting your store from bots — Shopify Help Center · View source (help.shopify.com)
LayerWhat it doesYour actionAvailability
CloudflareAlways active on your store, in Shopify's own wordsNoneAll stores
hCaptcha, invisible checkRuns a non-interactive challenge on every form submission and escalates suspicious ones to a puzzleNone — activated by defaultAll stores
hCaptcha on contact and comment formsSpam protection on those formsOne checkbox in online store preferencesAll stores
hCaptcha on login, create account and password recoverySpam protection on legacy customer account flows — Shopify states the current customer accounts verification process doesn't require hCaptchaOne checkbox in online store preferencesAll stores (effect on legacy customer accounts only)
Automated-traffic throttlingShopify rate-limits bots and crawlers hitting the Storefront API and Shopify-hosted pages, and limits checkout creation separatelyNoneAll stores
Checkout bot protectionExtra protection for the checkout during sales and product launchesActivate it in checkout settingsShopify Plus only

hCaptcha behavior and the two checkboxes are documented in online store preferences; the throttling of automated traffic is documented in Shopify's API rate limits. Both read July 2026.

Only the last row is plan-gated. Checkout bot protection is a Shopify Plus feature aimed at flash sales and product launches, where the risk is bots buying limited inventory rather than bots polluting a report — a different job from the analytics dimension, and one worth weighing against everything else in the plan comparison rather than on its own.

The Clean-Read Workflow

Key takeaway

Every route from the quiz uses the same seven steps, in a different order. If you landed on bot inflation, work them straight through. If you landed on a tracking change, do step 5 before step 3. If your storefront is headless, step 1 is unavailable to you — start at step 3 and lean harder on step 6. And if Shopify is under-counting rather than over-counting, steps 2 and 6 are the ones that matter.

The seven-step clean-read workflow (about 20 minutes)

Work down the list once. Most stores get their answer by step 3 — and the last step is deliberately last, because everything above it is free.

0 of 7 done
  1. In your Shopify admin open Analytics, then Reports, click the report you want, and add Human or bot session as a dimension in the configuration panel; filtering down to human visits only is an explicitly optional extra step.

  2. Read the blended conversion rate and the human-only conversion rate for exactly the same window, and write both down before you interpret anything.

  3. Check your admin against the signs Shopify publishes: free $0.00 orders, repeated or suspicious checkout details, strangely-formatted customer profiles, session spikes, data center locations, and search terms that resemble request IDs.

  4. Open your online store preferences and confirm both hCaptcha checkboxes are set the way you intend — the second one applies to legacy customer account pages, and Shopify states the current customer accounts verification process doesn't require hCaptcha — then confirm you have a fraud-prevention routine for the orders that do come through.

  5. Work through Shopify's own list of non-bot causes for the same window: an exposed free product, a migration bug, deactivated hCaptcha, a niche crawler, an unexpected flash sale, partner load testing, accelerated checkout, a password page, changed checkout requirements, tracking changes, cookie-consent issues, or untracked sales channels.

  6. While the denominator is in doubt, report orders and revenue rather than conversion rate, and annotate the window so future comparisons are not made against a polluted baseline.

  7. Only after the free steps have run their course, weigh a bot-management app against what it actually does: it acts on live traffic, and it never repairs sessions Shopify has already recorded.

When Does a Bot-Management App Earn Its Price?

Key takeaway

There is a clean line between the two reasons people shop for these apps. If your goal is a report you can trust, you do not need one: the native dimension already separates the traffic, and nothing on the market rewrites history. If your goal is to stop the same operation hitting your store week after week — the carts, the accounts, the checkout attempts — that is live traffic, and live traffic is what these tools act on.

AppWhat it actually doesPricing (July 2026)RatingWhat it does not do
Blockify Fraud Filter, BlockerBlocks visitors by IP, country, bot signature, VPN, proxy or Tor before they browseFree; $9.99, $19.99 and $39.99 a month, each with a 3-day trial4.9 from 1,501 reviewsMakes no claim to clean sessions Shopify has already recorded
Negate — Bot ProtectionFilters bot traffic out of analytics data and stops bot events firing marketing pixels, by the vendor's own description$19, $49 and $299 a month, each with a 7-day trial4.6 from 47 reviewsVendor claim, not an independently verified result — and no retroactive repair either

Ratings, review counts and pricing read live on the Shopify App Store, July 2026. No app we could find claims to reclassify historical Shopify session data, which matches Shopify's own statement that its filtering is not retroactive. Listed by class of job, not as a ranking.

Five Moves That Make It Worse

Key takeaway

Each of these is standard advice somewhere else on the web, and each one costs you something on Shopify. The first is the one that circulates most.

Putting your own Cloudflare in front
Why it is tempting: it is the standard answer everywhere else on the web. What actually happens: on a storefront Shopify hosts, its own troubleshooting page warns a proxy can block the HTTP challenges used to issue SSL certificates, removes Shopify's failover, and alters request attributes so bot detection works less well.
Hunting individual IP addresses
Why it is tempting: the offending addresses feel findable. What actually happens: one merchant reported an operation rotating more than 18,000 addresses, which makes IP blocking pointless — and Live View never exposes a visitor's IP as a merchant-visible field anyway.
Blocking whole countries
Why it is tempting: the spike came from somewhere you do not sell to. What actually happens: you pay for it with real customers who travel, use a VPN, or live in a diaspora market — and the bots move to the next range. Geography is a symptom here, not a cause.
Deleting fake accounts by hand every day
Why it is tempting: the admin looks clean afterwards. What actually happens: one merchant described 20 to 50 fake-account abandoned carts a day, with captcha already on and the volume worse than the year before. Manual cleanup is a treadmill, not a fix.
Blocking crawlers to tidy the report
Why it is tempting: robots.txt looks like a switch. What actually happens: those rules are advisory, they change nothing about sessions already recorded, and Shopify's own bot taxonomy names beneficial bots you want — search indexers and accessibility tools among them. The crawler side belongs to technical SEO, and sanctioned shopping agents are their own separate question.
Scope note on the proxy warning
Shopify's warning is about putting a proxy in front of a storefront Shopify hosts — that is where the certificate challenges, the failover and the request attributes belong to Shopify. It does not describe a headless front end you host yourself, and it is not an argument for or against anything you run there; Shopify publishes no guidance on that case.

Which Numbers Still Tell the Truth While Traffic Is Dirty?

Key takeaway

The single most useful habit during a dirty window is to sort your metrics by whether sessions appear in the denominator. Orders, revenue, average order value and refunds do not care how many visits were counted. Conversion rate, sessions by channel, cost per session and every “traffic quality” dashboard do, and they will move whether or not anything about your store changed.

The calculator below runs the same arithmetic as that 1,000-session example, on your numbers. It is worth your time in three specific situations: when the window you care about predates the filter and can never be classified, when your storefront is headless and the split is unavailable, and — most usefully — when you want to know whether any plausible share of bots could explain the drop you are chasing, before you spend a week acting on it.

Session Inflation Calculator

It opens on Shopify's own worked example — 1,000 sessions, 35 orders, a quarter of the sessions classified as bots, five of the orders placed inside them. Swap in your window. The bot share is your assumption, not a measurement: Shopify reports the human/bot split inside a report, but publishes no percentage and never reclassifies sessions recorded before October 7, 2025.

You only know this once the dimension is applied. Don't know it yet? Leave it at 0 — then the human-session rate reads as a ceiling rather than an estimate.
Reported (blended) rate
3.50%
What your report shows today, across all 1,000 sessions
Human-session rate
4.00%
Across 750 human sessions — the number worth acting on
Bot-session rate
2.00%
Across 250 bot-classified sessions
About 25.0% of your sessions would have to be bots for your human conversion rate to be back at 4.00%. Apply the Human or bot session dimension and check that against the split Shopify actually reports.

* Arithmetic only, on numbers you supply. The defaults reproduce the illustrative table Shopify publishes on its bot-filtering page — Shopify presents it as an example, not a benchmark, and it is not a target for your store. The bot-share slider stops at 60% as an editorial bound, not a sourced one: Shopify publishes no “normal” bot-share figure for storefronts. Nothing here cleans a report — the split only exists in Shopify's own reports for sessions recorded from October 7, 2025 onward.

For a sanity check on the output: one measurement of Shopify stores specifically, Littledata's 2023 study of 2,800 sites, put the average session-to-order rate at 1.4%. That is a Shopify-specific benchmark from a single analytics vendor, not a global ecommerce average and not a target — it is here only so a wildly different human-session rate prompts you to check the inputs rather than the store.

While the window is under suspicion, report these instead:

  • Orders and revenue for the period, compared with the same period last month.
  • Orders by channel rather than sessions by channel.
  • Conversion rate on human sessions only, clearly labeled as filtered.
  • A written note on the window itself, so next year's comparison is not silently made against polluted data.

When It Stops Being a Reporting Problem

Key takeaway

Everything above is about numbers. Two things turn bot traffic into money leaving your account, and both are documented by the platforms themselves rather than by vendors.

The first is card testing — automated scripts running stolen card details through your checkout to see which ones work. Each chargeback counts toward your chargeback rate regardless of whether you win or lose the dispute, and Shopify adds that a surge of declined transactions can raise your decline rate for legitimate customers even after the attack stops. That is the clearest case where a “traffic” problem stops being about traffic.

The second is paid media. Google states plainly that you will not receive refunds for invalid traffic — clicks are credited only when its systems detect them. For scale, Lunio — a vendor that sells invalid-traffic prevention, surveying 131 senior marketers in May 2026 — reports that 75.6% believe they lose more than 5% of monthly performance budget to invalid traffic, while 5.3% use a dedicated tool for it. Read that as a vendor's survey of opinion, not as a measurement of your account.

If you suspect paid clicks: the window is 60 days
Google lets advertisers request an invalid-traffic investigation covering the past 60 days of traffic. That is the only deadline in this whole article, and it runs while you are still deciding whether the problem is real — so if a campaign window is part of what you are questioning, file the request first and finish the diagnosis afterwards.

One knock-on effect deserves naming even though no one publishes a defensible number for it: labeling a session as a bot inside Shopify's reports does nothing about the client-side pixels that already fired during that visit. Negate, one of the apps above, sells specifically on preventing bot events from reaching marketing pixels — a vendor claim, not an independent finding, but the mechanism is real and it means retargeting audiences and ad-platform signals can absorb traffic your Shopify reports have since reclassified.

The Ceiling: What Nobody Can Fix for You

Key takeaway

Honest guides end where the platform ends. Three limits here are structural, and no app, setting or support ticket moves them.

The history is the first: sessions recorded before the cutover are never classified, so a year of comparisons has a seam in it that nothing will close. The second is escalation. There is no published route to report sustained add-to-cart abuse or mass fake-account creation — not in Shopify's bot documentation, its legal fraud-reporting material, its changelog or its developer docs, all of which we checked. The closest official instruction is to implement a fraud protection strategy to limit fraudulent order activity, which is advice about orders rather than a channel for abuse. Plan your response on the assumption that nobody is coming to switch it off for you.

The third is what merchants are living with in the meantime. These are reports, not data — they show what individual merchants say they experienced, with no way to know how common it is.

What the merchant reportedPostedWhere it stands
Add-to-cart abuse at scale, using more than 18,000 rotating IPsMay 2025No Shopify staff reply on the thread, and not marked solved as of July 2026
20 to 50 fake-account abandoned carts a day, captcha already on, worse than last yearAugust 2025Still active and unresolved — last reply July 2026, and no accepted answer
713 sessions in two external tools against 13 in Shopify, purchases recording correctlySeptember 2025Poster reports support closed it as normal — and this is under-counting, not bot inflation

Threads on Shopify's community, re-read July 2026. Merchant reports are illustrative only: they record what one merchant experienced, never an incidence rate.

“A new, highly persistent bot is exploiting a loophole in Shopify's backend architecture to generate massive volumes of add-to-cart activity.”

— JanVeroti, merchant report on the Shopify Community, May 2025

Read that as the ceiling, not as a verdict on the platform. The practical consequence for you is narrow and specific: build your reporting so it survives a dirty window, because you cannot rely on anyone cleaning one up for you.

The Bottom Line

Key takeaway

Inflated sessions are not a mystery, they are a triage problem. Four things produce the same symptom, one of them is bots, and Shopify gives you a free way to test that hypothesis in about fifteen minutes — as long as you know the test is manual, forward-looking, and unavailable on headless storefronts.

Split the denominator before you spend anything. Almost every expensive reaction to this problem — an app, a proxy, a country block, a week of manual cleanup — is triggered by a blended number nobody has separated yet. Separate it first; the answer is free, and it decides whether the rest is even worth doing.
Your Next Step by Stage
Confirm it yourselfRun the clean-read workflow: apply the filter, compare the two conversion rates, and rule out the innocent causes before you touch anything.The clean-read workflow
Report numbers that holdRecompute conversion on human sessions only, and switch this month's reporting to orders and revenue.Numbers you can still trust
Hand it to a developerHeadless storefront, a tangled pixel setup, or abuse that keeps coming back? Get a developer who can see what your store is actually counting.Get a Shopify developer

Numbers You Can't Trust Before a Big Decision?

We audit what your storefront and tracking actually count — sessions, pixels and the bot noise in between — so the report you plan next quarter on is the real one.

Get a measurement audit

Frequently Asked Questions

Yes. Shopify records sessions from automated visitors alongside human ones, then lets you separate them: since October 7, 2025 a Human or bot session dimension is available in sessions-related reports. Nothing is filtered out for you by default — you add the dimension to a report yourself, and the raw session count still includes bots.
Because the two count different things. GA4 automatically excludes known bots and spiders, and it never sees visitors whose ad blockers block Google's tag domain. Denied analytics consent behaves differently by setup: with advanced consent mode GA4 falls back to cookieless pings and modeling, while the more common basic setup blocks the tag entirely and the visit is invisible. Safari's seven-day cookie expiry makes a returning shopper look new rather than invisible. Shopify's own page adds that both recording methods are proprietary and never fully shared, so a gap is expected, not diagnostic.
Open Analytics then Reports in your admin, click the report you want, and in the configuration panel add Human or bot session from the Dimensions menu. To see human visits only, add the same field under Filters, choose Human, and apply. The dimension step is required; the human-only filter is explicitly optional.
No. Shopify states that bot filtering applies only to new incoming data as of October 7, 2025 and cannot retroactively classify older sessions. Anything recorded before that date stays as it is, and no app we found claims to repair it. For older windows, compare orders and revenue instead of rates.
Shopify's bot-filtering page names no plan requirement at all — no mention of Basic, Advanced or Plus anywhere on it. The feature that is explicitly Plus-only is a different one: activating extra bot protection for your checkout during sales and product launches. Do not confuse the analytics dimension with checkout protection.
No. Shopify says bot detection is not available for Headless and Hydrogen storefronts, so the Human or bot session dimension is not an option there. The published symptom list still works as a manual checklist, but every session-based metric on those storefronts stays unverified — report orders and revenue instead.
Both, in different places. The analytics dimension only labels sessions so your reports can separate them. Blocking happens elsewhere and automatically: Cloudflare is always active on your store, hCaptcha runs an invisible check on form submissions, and Shopify rate-limits automated traffic hitting your storefront and checkout creation.
No, not in front of a Shopify-hosted storefront. Shopify's own troubleshooting page says a Cloudflare proxy can interfere with the HTTP challenges used to issue SSL certificates, removes Shopify's failover, and alters request attributes so its bot detection works less well. Cloudflare already protects your store without any action from you.
Shopify publishes no number. Its discrepancy documentation lists causes without a single percentage, so any threshold you have read is somebody else's. Ruler Analytics, an attribution vendor, calls 5–10% normal and above 10–15% worth investigating, published in March 2026 — useful as orientation, but not a Shopify-endorsed rule.
Both are possible. Card testing uses automated scripts to test stolen cards on your checkout, and every resulting chargeback counts toward your chargeback rate whether you win the dispute or lose it. A wave of declines can also depress approval rates for genuine customers afterwards. Paid campaigns pay for undetected invalid clicks.
Only if abuse keeps returning after the free steps. App Store blockers act on live traffic — Blockify blocks by IP, country, bot signature, VPN or proxy from a free tier up to $39.99 a month; Negate starts at $19. Both prices were read on the Shopify App Store in July 2026. Neither repairs sessions Shopify already recorded, so nothing here cleans a report.
There is no published escalation path. Across Shopify's bot documentation the closest official advice is to implement order risk assessment, and merchants report threads on add-to-cart abuse and daily fake accounts going without a staff reply. Plan on managing it yourself: the toggles, the filter, and orders-based reporting.
About This Article
Shopify Developer & E-Commerce Writer
9+ years with Shopify since 2017

Front-end developer specializing in Shopify since 2017. Experienced in building custom Liquid themes, optimizing storefront performance, and integrating third-party apps. Writes in-depth, data-driven e-commerce guides based on hands-on experience with real merchant stores.

Continue Learning

What to Read Next

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.