TechDex Search Scrape Guard
TechDex Search Scrape Guard is a focused database backstop for public WordPress search.
It rejects malformed or abusive public searches during WordPress request parsing, before the main search query is built. Administration, REST, AJAX, cron, and WP-CLI requests are excluded.
Current protections include:
- Empty and whitespace-only search rejection
- Search character and word limits
- Separate search pagination limits for anonymous and logged-in users
- Chrome 30 automation-signature blocking
- Fixed-slot rate limiting with a bounded 256-row table
- Optional Cloudflare Turnstile verification and a short-lived signed cookie
- Lightweight rejection responses with no theme rendering
- Search noindex enforcement and virtual robots.txt guidance
- A searchable, paginated 250-signature browser log with automatic refresh
- A TechDex dashboard with settings, event-log, changelog, and donation access
Robots directives are guidance for compliant crawlers. They are not a security control.
External Services
Cloudflare Turnstile is optional and no data is sent unless a site administrator configures Turnstile keys. Once configured, Turnstile may be used when required verification is enabled or after a search rate limit is reached. The verification page loads Cloudflare’s Turnstile JavaScript and submits the visitor’s verification token and connection IP address to Cloudflare for validation. This data is sent only when Turnstile is configured and a search request requires verification.
Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/
Cloudflare terms: https://www.cloudflare.com/website-terms/
The plugin does not otherwise send search queries, log records, usage statistics, or site data to TechDex or any other external service.
Privacy
Search Scrape Guard stores bounded operational security data locally in the WordPress database. Raw IP addresses are not retained. Search samples and reported user-agent strings may contain information supplied by a requester, so administrators should treat the log as security data and limit dashboard access accordingly.
