We've been running a small e-commerce site selling industrial kitchen equipment for about eight months. We normally average around 12,000 unique visitors a week, but over the last two weeks, daily request counts suddenly tripled. With no increase in orders or contact form inquiries, we got suspicious and checked the server access logs. We found hundreds of IPs from various countries constantly crawling our product detail and cart pages.
We ran about forty of these suspicious IP addresses randomly through a public honeypot checker online. The tool flagged almost every single one of them as a high-risk bot, crawler, or known attack source.
Now we're not quite sure what to do with these results. Is it safe to trust third-party tools like this and block the IPs outright? Do we risk blocking genuine customers visiting the site? As a small business, how can we protect ourselves without putting too much strain on the server?