Client work

Bots Crashing a Store Through Its Product Filter

A store kept going down under load. The traffic was real, but it was not customers — bots were hammering the product filter, and every combination generated another expensive query.

Australian-based team Senior developers only Fixed quote before we start
100k+
Bot requests hitting the filter
10%
CPU use after mitigation
Hours
To restore stability
Client
WooCommerce store on SiteGround (anonymised)
Industry
Ecommerce
Scope
Bot mitigation & Cloudflare configuration
WooCommerce SiteGround Cloudflare

Australian team

Based here, working your hours — not a timezone away

144+ projects delivered

Over 10+ years building and maintaining sites for Australian businesses

One developer, start to finish

The same person every time — no re-explaining your site

Straight answers, on your terms

We only take work we can finish. Ask us anything first — no obligation

The challenge

  • The site was crashing repeatedly and the hosting CPU allowance was exhausted.
  • Traffic looked high, which made it easy to mistake an attack for success.
  • The target was the product filter — faceted URLs generate near-infinite combinations, each one an uncached database query.
  • Any fix had to keep genuine shoppers and search engine crawlers getting through.

What we did

  • Read the SiteGround and site logs together to separate customer traffic from automated traffic, and confirmed the filter endpoints were the target.
  • Moved the site behind Cloudflare so requests could be judged before they reached the origin at all.
  • Wrote rules aimed specifically at the filter parameters rather than the site as a whole — blunt site-wide blocking would have caught real shoppers.
  • Tuned the rules against live traffic so legitimate browsing and search crawlers continued through untouched.

The outcome

  • Site stable within hours.
  • CPU use fell to around 10%, from exhausting the plan’s allowance.
  • Memory use dropped correspondingly — the load had been almost entirely automated.
  • Same hosting plan, no upgrade required. The capacity was always there; it was being spent on bots.

Got something similar?

Tell us what is happening and we will come back with a fixed quote and a timeline, usually within one business day.

Get a fixed quote

Why CloudyWP

We build websites that earn their keep — fast, custom, and yours outright — then automate the work around them, so your business spends its hours on customers instead of admin.

Get a fixed quote

02 — How we work

From first call to live — four steps, no surprises.

Every CloudyWP project runs the same way, whether it is a one-page site or a store with a thousand SKUs. Here is exactly what happens.

01

We map what you actually need.

A single scoping call, then a written plan: what gets built, what it costs, and when it ships. No discovery-phase invoices, no moving targets.

Typically 48 hours

02

We design and build it properly.

Custom WordPress or Shopify on clean code you own outright. Every build ships fast, passes Core Web Vitals, and is handed over documented.

2–6 weeks typical

03

We automate the busywork.

Your site talks to the tools you already run — CRM, invoicing, email, stock. The repetitive admin stops being someone's job and starts running itself.

Average 15 hrs saved weekly

Scope A fixed quote, in writing

Deliverables, price and dates agreed before a line of code is written.

  • Free scoping call
  • Written scope document
  • Fixed price, no hourly creep

48 hrs to your quote

Get a quote