Key Insights in 60 Seconds
Skim the highlights, then jump to the section that matches what your own reports are doing.
What You'll Learn
Your sessions are up forty percent this month and your orders are flat. Or Shopify says nine thousand sessions while GA4 insists on three thousand for the same week. Or you woke up to a wave of new customer accounts with names that look like keyboard mash, and an abandoned-cart report that reads like a server log.
Whichever one you are looking at, the damage is the same: the conversion rate you judge everything by divides by the one number now under suspicion. You cannot tell whether the store got worse, the ads got worse, or nobody real showed up at all — and until you can, every weekly decision is a guess wearing a percentage sign.
Four Problems, One Symptom: Which One Is Yours?
Key takeaway
Shopify's own definition is the plain one: bot traffic is any visit to your website generated by software rather than a human. That covers search crawlers doing their job, price scrapers, load tests, and outright fraud alike — which is exactly why “are these bots?” is the wrong first question. The useful first question is narrower: which of four things is making my numbers move?
Find your row before you fix anything
| What you're seeing | What it usually is | The 15-minute check | Where it's covered |
|---|---|---|---|
| Sessions jumped, orders stayed flat | Bot inflation | Split the sessions report by Human or bot session and re-read the rate | This guide, from here down |
| Two tools disagree about which channel sent the same order | An attribution gap | Compare order counts rather than sessions, and see how each tool credits one order | Shopify Analytics guide |
| Numbers changed right after a theme, tag or consent-banner change | A broken or duplicated tracking setup | Confirm the tag fires once per page and once per purchase | Google Tag Manager on Shopify |
| Sessions steady, rate down, nothing else moved | A genuine conversion change | Look at the funnel and the pages, not the counter | Store patterns that convert |
The scale question is worth settling early, because it decides how seriously to take the possibility. automated traffic passed human activity for the first time in a decade, reaching 51% of all web traffic in 2024, with bad bots at 37%. That is a measurement of the whole internet by a security vendor, not of Shopify storefronts and certainly not of yours — treat it as evidence the phenomenon is ordinary, never as an estimate of your own share.
Why Shopify and GA4 Were Never Going to Agree
Key takeaway
Before you accuse anything of being a bot, you have to know how much disagreement is structural. Two tools watching the same shoppers will produce different session counts even on a perfectly clean day, because they do not agree on what a session is, when it ends, or whose visits are worth counting.
If your two counters roughly agree and it is the rate that fell, this section is not your problem — skip to what bot inflation looks like in your admin and come back here only if you later need to explain a gap between tools.
Two Different Definitions of a Session
Key takeaway
The midnight rule alone guarantees divergence: a shopper browsing from 11:40pm to 12:20am UTC is one session in GA4 and two in Shopify. Multiply that by every late-night browser in a global catalog and the counts drift apart without a single bot involved.
Differences in how sessions are defined. For example, some analytics software counts search bots as visitors, but other software doesn't.
| Behavior | Shopify | GA4 |
|---|---|---|
| What starts a session | A visit tied to a cookie | A page or screen view when no session is active |
| What ends it | 30 minutes of no activity | 30 minutes of user inactivity |
| Hard cut-off | Midnight UTC, every day | None — there is no limit to how long a session can last |
| Traffic source changing mid-visit | Not documented as a session boundary | Does not start a new session; one campaign or source per session |
| Known bots and spiders | Classifiable in sessions reports from October 7, 2025, and only where you add the dimension | Excluded automatically, with no opt-out and no view of the volume |
| Page reloads | A browser doesn't count reloads of cached pages | Google counts every page reload |
| What can stop the count | Shopify calls its own recording mechanism proprietary and never shared | JavaScript, cookies, ad blockers, denied consent, seven-day Safari cookie expiry |
Sources: Shopify Help Center on visitor and session counting and Google's GA4 session documentation, both read July 2026.
What Each Side Silently Drops
Key takeaway
The asymmetry matters more than the definitions. GA4 quietly removes traffic it recognizes as automated before you ever see a report, and it publishes neither the volume removed nor a way to turn the exclusion off — so the cleaner-looking number is cleaner partly because it is smaller by an amount nobody will tell you.
In Google Analytics properties, traffic from known bots and spiders is automatically excluded. This ensures that your Analytics data, to the extent possible, does not include events from known bots.
Is There a Normal Shopify-vs-GA4 Gap?
Key takeaway
This is the gap most articles fill with a confident number. We checked three official Shopify pages on discrepancies and reporting: not one carries a percentage. The rule of thumb you have probably read — that 5–10% is within normal range and above 10–15% suggests a configuration issue — was published in March 2026 by Ruler Analytics, a marketing-attribution vendor with an interest in you investigating further. It is a reasonable orientation and it is not Shopify's position, because Shopify does not have one.
What Bot Inflation Looks Like in Your Admin
Key takeaway
Shopify documents what bot activity looks like from inside the admin — and, on the same page, a second list of entirely innocent scenarios that produce the same spikes and drops. Competing articles quote the first list and stop. Reading both together is what turns a scary chart into a diagnosis.
| What Shopify lists as a bot sign | What it looks like in the admin | What else can cause the same thing |
|---|---|---|
| A high volume of free ($0.00) orders | Bursts of orders with no revenue attached | A free product accidentally exposed to buyers |
| Checkout or payment attempts using repeated or suspicious customer details | The same details reused across many attempts | A genuine customer retrying a declined card |
| Many customer profiles with unexpected, strangely-formatted names | A wave of new accounts nobody recognizes | A migration or import bug |
| A session or device-type spike in your sessions reports | A step change overnight in one device type | An unexpected flash sale, or a promotion you did not schedule |
| Landing-page URL volume from marketing or search integrations | One landing page taking an implausible share | QA or load testing run by a partner |
| Sessions from known data center locations (Google Cloud, AWS) | Traffic from places no customer of yours lives | A niche crawler you have never heard of |
| A sudden spike or drop in conversion rate | The rate breaks while the funnel looks untouched | Accelerated checkout, a password page, or new checkout requirements |
| A high volume of search terms that resemble request IDs | Long machine-shaped strings in store search | A tool probing your search syntax |
Both columns come from Shopify's identifying-bot-activity page — the signs it publishes for bot activity, and its separate list of non-bot scenarios that can look the same. Pairing one against the other is our editorial arrangement, not Shopify's.
What Shopify's Own Bot Filter Does
Key takeaway
This is the part most competing coverage misses entirely. Shopify ships a Human or bot session dimension for sessions-related metrics — sessions, conversion rates and visitor counts — and it applies to data recorded from October 7, 2025 onward. Shopify's changelog announcement followed a few weeks later, which is part of why so many merchants never heard about it.
It is a manual, per-report action: you open the report, add the dimension in the configuration panel, and optionally add a filter set to Human. Nothing is pre-filtered anywhere, so a report you have not touched is still showing you the blended number.
The Four Things It Doesn't Do
Key takeaway
The first question every merchant asks is whether this cleans up the mess already in the reports. It does not, and Shopify says so in one sentence.
Bot filtering applies only to new incoming data as of October 7, 2025, and can't retroactively classify older sessions.
What It Does Change: The Conversion-Rate Math
Key takeaway
Shopify publishes a worked example of what the split does to the number you actually report. It is the article's reference case from here on.
| Segment | Sessions | Orders | Conversion rate |
|---|---|---|---|
| Summary (what your report shows) | 1,000 | 35 | 3.5% |
| Human sessions | 750 | 30 | 4.0% |
| Bot sessions | 250 | 5 | 2.0% |
Shopify's own worked example, published on the bot-filtering page quoted above. Shopify presents it as an illustration of the arithmetic, not as a benchmark or a target for your store.
Two details in that table are easy to miss. The blended rate is lower than the human rate, which is the whole point: bot sessions drag the average down and make a healthy store look broken. And the bot row is not empty — Shopify's illustration puts five of the thirty-five orders inside bot-classified sessions, a reminder that classification is a judgment about traffic, not a guarantee about intent.
One more boundary worth knowing before you compare screens: Live View runs its own, simpler bot filtering, separate from the Human or bot session system. Your real-time map and your reports are not obliged to agree, and Live View has never exposed a visitor's IP address as a field you can act on.
Find Your Problem in Five Questions
Key takeaway
You now have the vocabulary the questions need: how the two counters differ, what Shopify itself lists as a bot sign, and what its filter can and cannot do. Answer from your own admin rather than from what you suspect — the route you get depends on the direction of your gap, what your orders did, and what is actually on the screen.
Your Levers: What's Automatic, What You Switch On, What Backfires
Key takeaway
Merchants usually arrive at this topic assuming they need to build something. In practice most of the defensive stack is already running, the configurable surface is unusually small, and several of the moves that feel productive are actively harmful.
What Shopify Already Runs for You
Key takeaway
The most useful thing to know before you buy anything is how much is already switched on. Shopify is unusually blunt about the first layer.
Cloudflare is always active on your store and requires no action from you.
| Layer | What it does | Your action | Availability |
|---|---|---|---|
| Cloudflare | Always active on your store, in Shopify's own words | None | All stores |
| hCaptcha, invisible check | Runs a non-interactive challenge on every form submission and escalates suspicious ones to a puzzle | None — activated by default | All stores |
| hCaptcha on contact and comment forms | Spam protection on those forms | One checkbox in online store preferences | All stores |
| hCaptcha on login, create account and password recovery | Spam protection on legacy customer account flows — Shopify states the current customer accounts verification process doesn't require hCaptcha | One checkbox in online store preferences | All stores (effect on legacy customer accounts only) |
| Automated-traffic throttling | Shopify rate-limits bots and crawlers hitting the Storefront API and Shopify-hosted pages, and limits checkout creation separately | None | All stores |
| Checkout bot protection | Extra protection for the checkout during sales and product launches | Activate it in checkout settings | Shopify Plus only |
hCaptcha behavior and the two checkboxes are documented in online store preferences; the throttling of automated traffic is documented in Shopify's API rate limits. Both read July 2026.
Only the last row is plan-gated. Checkout bot protection is a Shopify Plus feature aimed at flash sales and product launches, where the risk is bots buying limited inventory rather than bots polluting a report — a different job from the analytics dimension, and one worth weighing against everything else in the plan comparison rather than on its own.
The Clean-Read Workflow
Key takeaway
Every route from the quiz uses the same seven steps, in a different order. If you landed on bot inflation, work them straight through. If you landed on a tracking change, do step 5 before step 3. If your storefront is headless, step 1 is unavailable to you — start at step 3 and lean harder on step 6. And if Shopify is under-counting rather than over-counting, steps 2 and 6 are the ones that matter.
The seven-step clean-read workflow (about 20 minutes)
Work down the list once. Most stores get their answer by step 3 — and the last step is deliberately last, because everything above it is free.
In your Shopify admin open Analytics, then Reports, click the report you want, and add Human or bot session as a dimension in the configuration panel; filtering down to human visits only is an explicitly optional extra step.
Before you tick this off
- Opened the sessions report for the window you are questioning
- Added Human or bot session from the Dimensions menu
- Optionally added the same field under Filters and set it to is Human
Read the blended conversion rate and the human-only conversion rate for exactly the same window, and write both down before you interpret anything.
Before you tick this off
- Recorded the blended rate and the human-only rate
- Used an identical date range for both
- Noted how much of the gap the split actually explains
Check your admin against the signs Shopify publishes: free $0.00 orders, repeated or suspicious checkout details, strangely-formatted customer profiles, session spikes, data center locations, and search terms that resemble request IDs.
Before you tick this off
- Reviewed orders for $0.00 totals and repeated checkout details
- Reviewed customer profiles created during the window
- Reviewed sessions by location and by landing page
Open your online store preferences and confirm both hCaptcha checkboxes are set the way you intend — the second one applies to legacy customer account pages, and Shopify states the current customer accounts verification process doesn't require hCaptcha — then confirm you have a fraud-prevention routine for the orders that do come through.
Before you tick this off
- Confirmed hCaptcha on contact and comment forms
- Confirmed hCaptcha on login, create account and password recovery (legacy customer accounts)
- Confirmed an order risk assessment routine exists
Work through Shopify's own list of non-bot causes for the same window: an exposed free product, a migration bug, deactivated hCaptcha, a niche crawler, an unexpected flash sale, partner load testing, accelerated checkout, a password page, changed checkout requirements, tracking changes, cookie-consent issues, or untracked sales channels.
Before you tick this off
- Checked whether the theme, apps or tags changed during the window
- Checked whether a promotion, feed or partner test ran during the window
- Checked the consent banner and password page state
While the denominator is in doubt, report orders and revenue rather than conversion rate, and annotate the window so future comparisons are not made against a polluted baseline.
Before you tick this off
- Reported orders and revenue for the window
- Annotated the window wherever your team reads the numbers
- Stopped quoting conversion rate for this period
Only after the free steps have run their course, weigh a bot-management app against what it actually does: it acts on live traffic, and it never repairs sessions Shopify has already recorded.
Before you tick this off
- Confirmed the abuse is persistent and repeating, not a one-off spike
- Compared app tiers against what the native dimension already gives you
- Confirmed the app's claims stop at live traffic, not historical reports
When Does a Bot-Management App Earn Its Price?
Key takeaway
There is a clean line between the two reasons people shop for these apps. If your goal is a report you can trust, you do not need one: the native dimension already separates the traffic, and nothing on the market rewrites history. If your goal is to stop the same operation hitting your store week after week — the carts, the accounts, the checkout attempts — that is live traffic, and live traffic is what these tools act on.
| App | What it actually does | Pricing (July 2026) | Rating | What it does not do |
|---|---|---|---|---|
| Blockify Fraud Filter, Blocker | Blocks visitors by IP, country, bot signature, VPN, proxy or Tor before they browse | Free; $9.99, $19.99 and $39.99 a month, each with a 3-day trial | 4.9 from 1,501 reviews | Makes no claim to clean sessions Shopify has already recorded |
| Negate — Bot Protection | Filters bot traffic out of analytics data and stops bot events firing marketing pixels, by the vendor's own description | $19, $49 and $299 a month, each with a 7-day trial | 4.6 from 47 reviews | Vendor claim, not an independently verified result — and no retroactive repair either |
Ratings, review counts and pricing read live on the Shopify App Store, July 2026. No app we could find claims to reclassify historical Shopify session data, which matches Shopify's own statement that its filtering is not retroactive. Listed by class of job, not as a ranking.
Five Moves That Make It Worse
Key takeaway
Each of these is standard advice somewhere else on the web, and each one costs you something on Shopify. The first is the one that circulates most.
Which Numbers Still Tell the Truth While Traffic Is Dirty?
Key takeaway
The single most useful habit during a dirty window is to sort your metrics by whether sessions appear in the denominator. Orders, revenue, average order value and refunds do not care how many visits were counted. Conversion rate, sessions by channel, cost per session and every “traffic quality” dashboard do, and they will move whether or not anything about your store changed.
The calculator below runs the same arithmetic as that 1,000-session example, on your numbers. It is worth your time in three specific situations: when the window you care about predates the filter and can never be classified, when your storefront is headless and the split is unavailable, and — most usefully — when you want to know whether any plausible share of bots could explain the drop you are chasing, before you spend a week acting on it.
Session Inflation Calculator
It opens on Shopify's own worked example — 1,000 sessions, 35 orders, a quarter of the sessions classified as bots, five of the orders placed inside them. Swap in your window. The bot share is your assumption, not a measurement: Shopify reports the human/bot split inside a report, but publishes no percentage and never reclassifies sessions recorded before October 7, 2025.
* Arithmetic only, on numbers you supply. The defaults reproduce the illustrative table Shopify publishes on its bot-filtering page — Shopify presents it as an example, not a benchmark, and it is not a target for your store. The bot-share slider stops at 60% as an editorial bound, not a sourced one: Shopify publishes no “normal” bot-share figure for storefronts. Nothing here cleans a report — the split only exists in Shopify's own reports for sessions recorded from October 7, 2025 onward.
For a sanity check on the output: one measurement of Shopify stores specifically, Littledata's 2023 study of 2,800 sites, put the average session-to-order rate at 1.4%. That is a Shopify-specific benchmark from a single analytics vendor, not a global ecommerce average and not a target — it is here only so a wildly different human-session rate prompts you to check the inputs rather than the store.
While the window is under suspicion, report these instead:
- Orders and revenue for the period, compared with the same period last month.
- Orders by channel rather than sessions by channel.
- Conversion rate on human sessions only, clearly labeled as filtered.
- A written note on the window itself, so next year's comparison is not silently made against polluted data.
When It Stops Being a Reporting Problem
Key takeaway
Everything above is about numbers. Two things turn bot traffic into money leaving your account, and both are documented by the platforms themselves rather than by vendors.
The first is card testing — automated scripts running stolen card details through your checkout to see which ones work. Each chargeback counts toward your chargeback rate regardless of whether you win or lose the dispute, and Shopify adds that a surge of declined transactions can raise your decline rate for legitimate customers even after the attack stops. That is the clearest case where a “traffic” problem stops being about traffic.
The second is paid media. Google states plainly that you will not receive refunds for invalid traffic — clicks are credited only when its systems detect them. For scale, Lunio — a vendor that sells invalid-traffic prevention, surveying 131 senior marketers in May 2026 — reports that 75.6% believe they lose more than 5% of monthly performance budget to invalid traffic, while 5.3% use a dedicated tool for it. Read that as a vendor's survey of opinion, not as a measurement of your account.
One knock-on effect deserves naming even though no one publishes a defensible number for it: labeling a session as a bot inside Shopify's reports does nothing about the client-side pixels that already fired during that visit. Negate, one of the apps above, sells specifically on preventing bot events from reaching marketing pixels — a vendor claim, not an independent finding, but the mechanism is real and it means retargeting audiences and ad-platform signals can absorb traffic your Shopify reports have since reclassified.
The Ceiling: What Nobody Can Fix for You
Key takeaway
Honest guides end where the platform ends. Three limits here are structural, and no app, setting or support ticket moves them.
The history is the first: sessions recorded before the cutover are never classified, so a year of comparisons has a seam in it that nothing will close. The second is escalation. There is no published route to report sustained add-to-cart abuse or mass fake-account creation — not in Shopify's bot documentation, its legal fraud-reporting material, its changelog or its developer docs, all of which we checked. The closest official instruction is to implement a fraud protection strategy to limit fraudulent order activity, which is advice about orders rather than a channel for abuse. Plan your response on the assumption that nobody is coming to switch it off for you.
The third is what merchants are living with in the meantime. These are reports, not data — they show what individual merchants say they experienced, with no way to know how common it is.
| What the merchant reported | Posted | Where it stands |
|---|---|---|
| Add-to-cart abuse at scale, using more than 18,000 rotating IPs | May 2025 | No Shopify staff reply on the thread, and not marked solved as of July 2026 |
| 20 to 50 fake-account abandoned carts a day, captcha already on, worse than last year | August 2025 | Still active and unresolved — last reply July 2026, and no accepted answer |
| 713 sessions in two external tools against 13 in Shopify, purchases recording correctly | September 2025 | Poster reports support closed it as normal — and this is under-counting, not bot inflation |
Threads on Shopify's community, re-read July 2026. Merchant reports are illustrative only: they record what one merchant experienced, never an incidence rate.
“A new, highly persistent bot is exploiting a loophole in Shopify's backend architecture to generate massive volumes of add-to-cart activity.”
— JanVeroti, merchant report on the Shopify Community, May 2025
Read that as the ceiling, not as a verdict on the platform. The practical consequence for you is narrow and specific: build your reporting so it survives a dirty window, because you cannot rely on anyone cleaning one up for you.
The Bottom Line
Key takeaway
Inflated sessions are not a mystery, they are a triage problem. Four things produce the same symptom, one of them is bots, and Shopify gives you a free way to test that hypothesis in about fifteen minutes — as long as you know the test is manual, forward-looking, and unavailable on headless storefronts.
Frequently Asked Questions
Front-end developer specializing in Shopify since 2017. Experienced in building custom Liquid themes, optimizing storefront performance, and integrating third-party apps. Writes in-depth, data-driven e-commerce guides based on hands-on experience with real merchant stores.
What to Read Next
Shopify Analytics: What's Built In, What's Missing & How to Read It
B2B guide to Shopify Analytics — what's built in by plan, the four metrics that drive decisions, attribution gaps, ShopifyQL, and when to add third-party tools.
Read articleShopify Statistics: Verified Numbers for Merchants
Shopify plan prices, card rates, account limits, GMV and App Store size — every figure with its official source, its own date, and the date we last checked it.
Read articleShopify Store Code Audit: Before You Fix or Rebuild
Inherited a messy Shopify store? Audit the theme code, ghost code, ScriptTags and access yourself — then decide fix vs rebuild, and what an audit costs.
Read article