Home › Docs › Failed & Spam Order Cleaner user guide

Failed & Spam Order Cleaner user guide

Updated October 7, 2026

On this page What do I need? How do I install it? How do I choose which orders to clean up? What does the preview show? How do I clean up? What happens while it runs? How do I read the attack report? Does it remove the data in Stripe or PayPal too? Can I undo a cleanup? Which orders does it leave alone? Where do I see past cleanups? What can I change in Settings? How does the licence work? Something isn't working. What should I check? What doesn't it do?

Failed & Spam Order Cleaner clears the failed, unpaid and abandoned orders a card-testing or spam attack leaves in WooCommerce. It works through them in the background, however many there are, and writes a report on the attack when it’s done. The screenshots below come from our test store, where we seeded 541 failed and pending orders from a made-up attack.

What do I need?

  • WordPress 6.0 or newer, PHP 8.0 or newer and WooCommerce 8.2 or newer.
  • Either WooCommerce order storage: High-Performance Order Storage or the older posts storage. The Clean Up tab shows which one your store uses.
  • A store manager or administrator account. The License and Data tabs are for administrators only.

How do I install it?

  1. Download the ZIP from My Licences, then go to Plugins → Add New → Upload Plugin and upload it.
  2. Click Activate. The tool appears under WooCommerce → Spam Order Cleaner, with five tabs: Clean Up, Activity Log, Settings, License and Data.
  3. Paste your licence key on the License tab so the site receives updates. Every feature works without a key; the key only keeps updates coming.

How do I choose which orders to clean up?

On the Clean Up tab, tick the statuses and set a date range, then click Preview matching orders. Previewing changes nothing.

The Clean Up tab: order statuses, a date range, quick ranges and the last-hour safety option
The Clean Up tab order statuses a date range quick ranges and the last hour safety option
  • Order status. Failed, Pending payment, On hold and Draft (abandoned checkout). Failed is ticked by default. Be careful with On hold: many shops use it for real bank-transfer and cheque orders that haven’t been paid yet.
  • Created from and Created to. Dates in your store’s timezone. Leave one empty for no limit on that side. The quick ranges fill them in: Last 24 hours, Last 7 days, Last 30 days, Older than 30 days or All time.
  • Skip orders created in the last hour. On by default, because a real customer may still be paying.

What does the preview show?

The number of orders the cleanup will act on, split by status, and the newest matching orders with their date, email, IP address and total. Click an order number to open it. If anything in the list looks like a real customer, narrow the filters before you go on.

The preview: 480 failed and 60 pending orders, and the newest matches
The preview 480 failed and 60 pending orders and the newest matches

The count already leaves out the orders the plugin never touches (see what it leaves alone). On our test store we seeded 541 orders, one of them a failed order that had once been paid. The preview said 540.

How do I clean up?

Choose what happens to the orders, then click Clean Up with the number of orders on the button.

Move to trash is the default. Delete permanently needs a ticked box and the word DELETE
Move to trash is the default Delete permanently needs a ticked box and the word DELETE
  • Move to trash (recommended). The orders go to WooCommerce’s trash. You can restore the whole run in one click from its report, or single orders from the Orders screen’s trash.
  • Delete permanently. The orders, their notes and line items are removed from the database. A red box asks you to tick I understand these orders will be permanently deleted and cannot be restored and to type DELETE. The server checks this again, so it can’t be skipped.
  • Generate report only (change nothing). The same attack report, without touching any order.

If your site has the trash switched off (EMPTY_TRASH_DAYS set to 0), WordPress would delete trashed orders straight away, so the screen only offers permanent deletion. Take a backup first.

What happens while it runs?

The cleanup runs in the background through Action Scheduler, which comes with WooCommerce. Each batch stops after a few seconds, so it doesn’t hit the timeouts the Orders screen runs into. You can leave the page and come back through the Activity Log tab.

  • Progress updates on the page while you watch, and the page turns into the report when the job ends.
  • Only one job runs at a time. Starting a second one tells you to wait for the first or cancel it.
  • Orders placed after you clicked Clean Up are never included.
  • If the server ends a batch part-way, the job is queued again after a few minutes and carries on.

Our 540 test orders took about a minute. A large cleanup on shared hosting takes longer, but it moves steadily and doesn’t lock up the admin.

How do I read the attack report?

The four numbers at the top are the orders handled and the distinct email addresses, IP addresses and countries behind them. A handful of emails and IPs behind thousands of orders usually means one bot. Thousands of each usually means a spread-out attack.

The report for our test run: 540 orders from 201 emails, 151 IP addresses and 12 countries
The report for our test run 540 orders from 201 emails 151 IP addresses and 12 countries

The table below the numbers lists how many orders were examined, moved, left alone and failed, the time span the orders were placed in, and how many had no email or IP address. Emails are compared without case, so Bot@Example.com and bot@example.com count once.

Top email addresses, IP addresses and countries for the run
Top email addresses IP addresses and countries for the run

Export attack report (CSV) downloads the whole report with every email, IP address and country and the number of orders each one placed. It opens in Excel or Google Sheets.

Does it remove the data in Stripe or PayPal too?

No. Deleting an order only removes it from your store. Data already sent to a payment gateway, a shipping or fulfilment service or an email tool stays there, and you manage it in that service. The plugin shows this reminder on every result screen and in every export.

The reminder shown with every cleanup
The reminder shown with every cleanup

Can I undo a cleanup?

Yes, if you moved the orders to the trash. The report’s Undo or finish this cleanup panel has two buttons.

Restore the whole run, or delete the trashed orders for good
Restore the whole run or delete the trashed orders for good
  • Restore these orders from the trash puts every order from the run back in the status it had. Large restores run in the background in batches too.
  • Delete these trashed orders permanently asks for the same tick box and DELETE before it runs.

WordPress empties the trash after its usual period, so don’t leave it too long if you may want the orders back. Permanently deleted orders can’t be restored.

Which orders does it leave alone?

Even when they match your filters, these orders are never touched:

OrderWhy
Orders in a status you didn’t tickOnly the chosen statuses are considered. An order whose status changes between the preview and the run, for example when the customer finally pays, is skipped.
Orders with a recorded payment dateAn order with a payment date took real money at some point. This protection is on by default on the Settings tab.
Orders linked to a WooCommerce Subscriptions subscriptionParent and renewal orders keep their history.
Orders from the last hourA customer may still be paying. On by default on the Clean Up tab.
Orders created after the job startedThe job works from the orders that existed when you clicked Clean Up.

Where do I see past cleanups?

The Activity Log tab lists every cleanup, report, restore and permanent delete: when it ran, what happened, how many orders, the date range, distinct emails and IP addresses, and who started it. View reopens a report and Export CSV downloads it again.

The Activity Log after our test cleanup
The Activity Log after our test cleanup

What can I change in Settings?

Settings: batch size, the paid-order protection and how long breakdowns are kept
Settings batch size the paid order protection and how long breakdowns are kept
  • Batch size (default 50, from 10 to 500). How many orders each step of a batch loads. Lower it only if your host is very slow or short on memory.
  • Never touch orders that have a recorded payment (on). Leave this on.
  • Keep email / IP breakdowns for (days) (default 90). After this many days a report’s lists of emails, IP addresses and countries are deleted. The summary numbers stay in the Activity Log. Set 0 to keep them until you delete them yourself.

The Data tab decides what happens when you delete the plugin. By default its records are kept, so reinstalling brings the log back. Deleting the plugin never deletes your orders, and deactivating it never deletes anything.

How does the licence work?

Paste the key from your purchase receipt on the License tab and click Activate. The site checks in once a day to keep receiving updates. Licences cover 1, 5 or unlimited sites. On a multisite network one licence covers the network, each subsite running the plugin counts as one site, and only a network administrator can activate it.

The License tab
The License tab

Something isn’t working. What should I check?

What you seeWhat to do
No orders match these filtersWiden the dates, tick more statuses or untick the last-hour option. With the default settings, paid, subscription and very recent orders are left out.
Another job is already runningWait for it to finish, or open it from the Activity Log and cancel it.
Only Delete permanently is offeredThe trash is switched off on your site. Turn it on for a reversible cleanup, or back up and delete permanently.
The progress bar isn’t movingBackground tasks are slow or blocked. Keep the cleanup screen open, which moves a stalled job along, and check WooCommerce → Status → Scheduled Actions for wc_spam_cleaner_process_run.
The number on the button is lower than expectedPaid, subscription and last-hour orders are left out on purpose. See what it leaves alone.

What doesn’t it do?

It cleans up after an attack. It doesn’t stop the next one: there’s no real-time blocking, rate limiting, CAPTCHA or fraud scoring, and it never blocks an email or IP address on its own, because attackers change both. For prevention, use an anti-fraud or bot-blocking tool alongside it.

A good habit: start with a narrow date range and Move to trash, check the report and the trash, then widen the range for the next run.

Still stuck? Email support@pluginsprout.com We reply within 24 hours, Monday to Friday.