No campaign = attack shortcut
A burst of people following the same social link is not automatically systematic enumeration.
Puur.gr relies heavily on social campaigns to bring shoppers directly into the store. During severe pressure windows, catalogue filters and commerce actions were competing for the same WordPress, PHP and database resources customers needed to browse and buy.
The security problem was not only stopping abuse. It was keeping the buying journey usable.The five-to-six-minute add-to-cart delay and customer purchasing difficulty were reported by the site operator from production experience. The screenshots below independently show real Nexus pressure, traffic separation, correlation and topology states captured on Puur.gr; they do not by themselves measure checkout conversion or page-response time.
Puur.gr is not a quiet brochure website. Campaigns—especially through Instagram—can send real shoppers into product and filtered catalogue URLs in concentrated bursts. That makes “high traffic” a poor security verdict on its own.
According to the site operator, the serious production problem was usability: pages could become extremely slow and add-to-cart could take roughly five to six minutes to complete. Real customers were trying to buy while automated catalogue and commerce activity was adding expensive work to the same application stack.
For a WooCommerce store, availability of the buying path is part of security.
A social campaign can produce thousands of visitors doing the same legitimate thing: opening the same product, following the same filtered URL, or arriving through the same mobile carrier. Shared 5G and CGNAT networks can also place many unrelated customers behind a small number of public IP addresses.
That means an aggressive “many requests = attacker” rule can protect the server by hurting the business. The objective for Nexus was different: preserve legitimate shopper access while building confidence around repeated automated pressure, systematic catalogue exploration and state-changing commerce actions.
Popularity is not enumeration. An IP address is evidence—not a customer identity.
The Causality Engine linked repeated WooCommerce abuse observations into one coordinated sequence. In the captured timeline it reported 53% correlation confidence, 41/100 threat severity and evidence grade B.
Just as important, the same screen said No impact detected. The engine did not reinterpret pressure as proof of file, account, session or persistence compromise.
Confidence is not severity, and suspicious behavior is not automatically compromise.
The Threat Constellation placed recent evidence around the protected site instead of forcing the operator to reason from disconnected counters. The production capture showed thousands of events in the 24-hour window, blocked and suspicious activity, active Early WAF evidence and the WooCommerce path under watch.
The objective was not to make the screen look dramatic. It was to answer practical questions: which surface is involved, which layer saw the behavior, whether containment is active and whether normal application paths remain reachable.
This case mattered because the safest-looking response could also have been commercially destructive. Nexus had to preserve the distinction between load, suspicious automation and real shoppers.
A burst of people following the same social link is not automatically systematic enumeration.
Shared mobile networks and CGNAT are treated as network context, not perfect identity.
The defensive goal is to keep legitimate commerce paths available while qualifying abuse is contained.
Continuum keeps “no impact detected” visible when the evidence does not support a stronger claim.
The production evidence shows Nexus separating allowed visitors from watched and blocked activity while representing WooCommerce pressure explicitly. The site operator's business concern was severe purchase-path latency; the protection strategy therefore focused on reducing qualifying automated work without treating social campaign traffic itself as hostile.
No synthetic conversion uplift or speed percentage is claimed here. The case study documents the security problem, the operator-reported commercial impact and the real Nexus evidence used to understand and contain the pressure.
The screenshots are genuine Nexus PRO production captures from Puur.gr. The screenshots support the presence of high WooCommerce-related pressure, allowed/watched/blocked traffic separation, a correlated commerce sequence with no measured compromise impact, and the Constellation topology shown. The five-to-six-minute add-to-cart latency and customer purchasing difficulty are operator-reported production observations. No claim is made here about a quantified increase in sales, a measured percentage reduction in server load or a successful compromise.
Explore Nexus PRO and the protection layers built specifically around WordPress and WooCommerce behavior.