Automated traffic follows a pattern. Real visitors never do.
Bot Shield: Catching Automated Traffic Plain IP Blocking Misses
Not every attacker announces themselves with a known-bad IP. Scrapers rotate addresses, scanners mimic real browsers, and some traffic never triggers a single geography or blocklist rule at all. Bot Shield catches what IP-based blocking structurally can’t, behaviour, patterns, and deliberate traps that only ever get triggered by something automated.
Key Features
AI Crawler Blocking
Blocks known AI-training crawlers, separately from search crawlers, entirely under your control. Search visibility stays untouched while training bots get shut out, your choice on which ones and whether at all.
Rate Limiting
A configurable limit on how many requests a single source can make in a given window, slowing scripted traffic down to the point it stops being worth running, without affecting a normal visitor browsing the site.
Honeypot Trap
An invisible link, present in the page but never visible or clickable to a real person. A human never finds it. A scraper crawling every link on the page does, and gets caught the moment it does.
Behavioral Detection
Flags patterns no real browser produces, unnaturally fast consecutive requests, or requests missing headers every genuine browser sends automatically. Off by default, built specifically to catch traffic that evades IP-based checks entirely.
Canary Trap
Fake versions of paths attackers commonly probe for directly, wp-config.php.bak, .env, backup.zip, files that don't exist and never should. A single request for one is proof of intent. One hit auto-blocks the IP and emails you immediately.
Admin-Area Honeytoken
An invisible trap link inside the admin area itself, only ever visible to someone already logged in. If it's ever triggered, that's a human being alerted directly, not an automatic ban, since a false positive here matters more than one out on the public site.
Country blocking, threat intel, and bot detection, working together
