That's if you aren't a target at all, which is only applicable for very few services. Any inexperienced attacker could use burp suite or inspect element to see and imitate this hidden field.
Sure, but that's often the case. You might only be a target, for example, because you're running WordPress. Nobody is deliberately going after your site specifically.
There's plenty of sites that don't need a full-on captcha.
Oooo, I like this, thanks for the tip :)
Do try something more obscure than just display:none or similar. The bots seem wise to that.
Also call the field “website” or any variation of standard Wordpress field names.