• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / How Does WordPress.com Prevent Fake Signups and Orders Without CAPTCHA or 2FA?

How Does WordPress.com Prevent Fake Signups and Orders Without CAPTCHA or 2FA?

  • Unknown's avatar
    karthiks16 · Member · Nov 18, 2024 at 12:57 pm
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    Hello,

    I’ve noticed that WordPress.com does not seem to use CAPTCHA or 2FA during the signup or order process. While the security page mentions Two-Step Authentication, it seems to be an optional feature.

    For example, if I create an account on WooCommerce.com without enabling Two-Step Authentication, I am still able to place orders. This raises the question of how WordPress.com and WooCommerce.com effectively prevent fake signups and fraudulent orders without mandatory CAPTCHA or 2FA during the account creation and order processes.

    Are there specific techniques, plugins, or workflows used to handle this? Any insights or best practices would be greatly appreciated.

    Thank you!

    WP.com: Yes
    Jetpack: No
    Correct account: Yes

    The blog I need help with is: (visible only to moderators and staff)

  • Unknown's avatar
    benjamingabriell288 · Member · Nov 18, 2024 at 1:06 pm
    • Copy link Copy link

    WordPress.com and WooCommerce.com prevent fake signups and fraudulent orders using invisible CAPTCHA, behavioral analysis, rate limiting, IP blacklists, email verification, and machine learning-based fraud detection. Payment gateways like Stripe and PayPal add extra security with AVS and 3D Secure checks. Optional 2FA enhances security for willing users, while honeypots and security plugins are also used to block bots and suspicious activity without disrupting user experience.

  • The topic ‘How Does WordPress.com Prevent Fake Signups and Orders Without CAPTCHA or 2FA?’ is closed to new replies.

Tags

  • account
  • payment
  • WooCommerce
  • wpcomhelp

About this topic

  • In: Support
  • 2 participants
  • 1 reply
  • Last activity 1 year
  • Latest reply from karthiks16

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions