Shopify now lets you filter bot traffic in Analytics. The feature is called Human or bot session. Merchants hear “Shopify filters bots” and expect the abandoned checkout list to clear. Those are two different problems that happen to share a word.
A bot session is a storefront visit Shopify labeled Bot — a crawler, a scraper, a script that loaded your theme. A bot abandoned checkout is a checkout a script created. One can exist without the other. Shopify’s filter is built for the first. It does not score, tag, or stop the second.
What Shopify’s bot-filtering article actually shipped
Shopify classifies each online-store session as Human or Bot. Every event in that session — a product click, a cart add, a checkout start — inherits the label. You add Human or bot session as a dimension on a sessions-related report, or filter the report to Human when you want conversion rate and visitor counts that ignore automated traffic.
Shopify is explicit that this is optional on purpose. Search crawlers and other “helpful” bots still visit, and that traffic still helps discovery. The raw session count still includes them. The filter is a reporting lens, not a block. The October 2025 changelog put it in those terms: clearer conversion rates and a way to see which referrers bring real customers.
The limits in the help article matter as much as the feature:
- It applies only to sessions-related metrics. Abandoned checkouts, customers, and email profiles are outside it.
- Classification started with new sessions on October 7, 2025. Older traffic is not re-labeled.
- It is not available on Headless or Hydrogen storefronts.
- Some sophisticated automated traffic stays unclassified while the system learns.
None of those limits are bugs. They describe a session classifier. They are the reason a cleaner Analytics report can sit next to an Abandoned checkouts list that still looks broken.
A bot session is not a bot abandoned checkout
Treat them as separate events. A bot can create one without the other.
Bot session, no checkout. SEO crawlers, price scrapers, and uptime monitors load your storefront and leave. They pad sessions, flatten conversion rate, and make a referral source look busier than it is. They never open a checkout, never create a customer, never land in Klaviyo or Omnisend. Shopify’s Human filter is the right tool here. Filter to Human and those visits drop out of the report.
Bot checkout, no useful bot session. Scripts hit /cart/add.js or a cart URL, jump into checkout, and submit a name and email. Many never render your theme, so there is no storefront session for Shopify to classify — or the session looks Human because the client was a real browser on a residential IP. You still get a row in Orders → Abandoned checkouts, a customer record, and a Started Checkout in your ESP. Shopify’s session filter has nothing to hide, because the damage is not a session.
Both. A browser-shaped bot browses like a person, then fabricates a checkout. Shopify can clean the session numbers. The checkout, the customer, and the email profile still land unless something else scores that checkout.
That third case is why “I filtered Analytics to Human and I still have junk checkouts” is not a contradiction. You cleaned the wrong list.
Why merchants still see fake abandoned checkouts
The abandoned checkout list answers a different question than a sessions report. It asks whether a checkout was created, not whether a storefront visit looked automated.
Most of the fake abandoned checkouts merchants complain about never needed a bot session at all:
- Fabricated names and placeholder addresses (
123 Main Stshows up constantly) - Sequential or disposable emails, often with the marketing box ticked
- Direct cart or checkout hits that skip product pages
- Bursts against the cheapest variant, with no matching campaign
Shopify’s June 2026 abandoned-checkout bot-noise update hides one narrow pattern: card-testing bots that probe stolen numbers and never complete payment. That is a checkout-side change, and it is still only that pattern. Scripts that create a checkout and leave — no payment attempt — still become abandoned checkouts.
So you can have three native Shopify pieces at once and still have a dirty recovery list: Human or bot session on reports, the card-testing filter on some failed payments, and a pile of fabricated checkouts neither one covers.
What to use for which question
Use Shopify’s Human or bot session filter when the question is “how many real people visited?” Open a sessions-related report, add the dimension, and optionally filter to Human. Compare both when you want to see how much crawler and scraper traffic is in the raw numbers. That is the job the help article describes.
Do not use it as proof that checkout spam is gone. Filtering Human does not delete abandoned checkouts, does not tag customers, and does not keep a junk email out of a recovery flow. Those objects were created by a checkout, not by a session label.
Score the checkout when the question is “is this checkout a person?” That is a different signal set: email format and disposability, address patterns, missing visitor context a real browser session leaves behind, velocity no human matches. A checkout that scores as a bot should be tagged on the customer record and kept out of Klaviyo, Omnisend, Mailchimp, and Drip before a send fires. On plans that include it, payment can be refused at Pay now so the order is never completed.
That checkout-side work is what CartWatch does. It listens to checkout webhooks, scores each one as it happens, auto-tags likely bots, and suppresses them from connected email platforms. It does not replace Shopify’s session filter. The filter is still the right way to read storefront traffic. CartWatch is what you run on the checkouts that filter never sees.
If Analytics looks cleaner and Abandoned checkouts does not, that split is the explanation. Install CartWatch from the Shopify App Store and score the checkout side — the session filter will keep doing its job.