plugin-icon

BotBlocker Security – Firewall & Bot Protection

Stop bots, brute force, spam, and fake crawlers before they reach WordPress. Three-layer firewall, 9 CAPTCHAs, FCrDNS, 2FA. Setup in 60 seconds.
Votações
5
Versão
1.6.21
Instalações ativas
3K
Última atualização
Jun 17, 2026
BotBlocker Security – Firewall & Bot Protection

BotBlocker Security blocks 99% of automated attacks before WordPress even loads. No bloat, no slowdowns, no monthly fees for core protection.

If your site is hit by login brute force, spam comments, fake Googlebots, content scrapers, or XML-RPC floods, you are not alone: bots generate over 47% of all web traffic. Most security plugins react after WordPress boots, wasting CPU and memory on every bad request. BotBlocker stops them at the door.

Why site owners switch to BotBlocker

  • Faster than the competition. Runs on early init through three interception layers, before themes and plugins load. Server load drops during attacks instead of spiking.
  • Smarter CAPTCHA. 9 modes including Silent Auto-Verify – zero clicks for humans, hard wall for bots. Proprietary CAPTCHAs defeat AI-based solvers that crack reCAPTCHA for $2-3 per 1 000.
  • Honest free version. Full firewall, all 9 CAPTCHA modes, full 2FA, full logging, full Multisite support. No nag screens, no crippled features.
  • Privacy-first. No visitor data leaves your server. GDPR and CCPA compliant out of the box.
  • Works with everything. Cloudflare, WP Rocket, LiteSpeed, WooCommerce, Elementor, multisite, IPv6, PHP 7.4 to 8.5.

🛡️ Core Firewall (Free)

  • Three-Layer Architecture – intercepts traffic at wp-config.php (before WordPress), MU-plugin phase, and main shield. The first layer blocks known threats without loading WordPress at all, saving 30-100ms and 5-20MB RAM per blocked request.
  • Web Application Firewall (WAF) with real-time rule updates via the BotBlocker Threat Defense Feed
  • 2 899 User-Agent signatures – largest blacklist among WordPress plugins – covering Scrapy, Selenium, Puppeteer, PhantomJS, curl, wget, Python, Java, Perl, and SQL injection tools
  • Brute force protection with progressive lockouts – 5 attempts per 15 minutes, escalating bans for repeat offenders
  • Anti-spam for comments, registration, contact forms – spammers blocked before they connect
  • XML-RPC and REST API locked down by default with allowlist for trusted services
  • Fake crawler detection via FCrDNS (dual-direction DNS verification), ASN tokens, and published IP ranges – 95% effective, impossible to spoof without controlling the provider’s DNS zone
  • LLM / AI crawler management – allow or block GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Bytespider via CIDR-verified IP ranges. Trusted crawlers verified, impersonators blocked.
  • Country, ASN, IP range, User-Agent, Referer blocking rules with instant enforcement
  • Cloudflare-aware real-IP resolution and origin bypass protection
  • Full IPv6 support – separate tables and logic for IPv4 and IPv6, every feature works with both
  • Live traffic monitor with attack map, country, ASN, device, browser, and exact block reason for every request
  • Built-in caching via Redis and Memcached – free, auto-disable on connection failure

🔒 Login Security & 2FA (Free)

  • Two-Factor Authentication compatible with Google Authenticator, Authy, 1Password, Bitwarden – TOTP standard with 10 backup codes
  • 9 CAPTCHA modes: Silent Auto-Verify, Single Button, Color CAPTCHA, Images CAPTCHA, Shapes CAPTCHA (60fps Canvas), Digits CAPTCHA, Hold Button CAPTCHA, plus Google reCAPTCHA v2 and v3
  • Hybrid Mode – combine any internal CAPTCHA with reCAPTCHA v3 for two-layer invisible defense
  • Hide login URL (PRO)
  • Configurable lockout durations with escalation for repeat offenders – failed CAPTCHA triggers short ban, repeated failure triggers 24-hour ban

💳 Payment Gateway Bypass (Free)

Auto-detects 25+ e-commerce platforms (WooCommerce, Easy Digital Downloads, SureCart, MemberPress, Paid Memberships Pro, Give, Dokan, CartFlows, FunnelKit, and more) and 150+ payment providers (Stripe, PayPal, Mollie, Adyen, Braintree, Square, Razorpay, Klarna, Paddle, Authorize.Net, 2Checkout, YooKassa, LiqPay, and more). Webhooks, IPN callbacks, and payment notifications never get blocked. Four detection layers ensure zero false positives on payment traffic.

📊 Visibility & Control (Free)

  • Visual dashboard with attack map, top offenders, blocked-vs-allowed ratio, world traffic map
  • Detailed event log with IP, country, ASN, User-Agent, and exact block reason – 54 unique event codes
  • Health Score gauge – 42 parameters across 3 categories, 5 security levels from Critical to Secure
  • 3 security presets – Light, Strong, Full – one-click configuration
  • Setup Wizard – 8 steps from welcome to test attack, setup in under 5 minutes
  • 8 interface languages – English, Deutsch, Español, Français, Polski, Русский, Українська + POT template
  • Configurable retention with timezone and DST awareness
  • Clean uninstall – drops all 16 tables, removes 40+ options, clears cron hooks. Zero leftover data.

🚀 PRO Adds (Premium / Pro / Ultimate)

  • Real-time cloud threat intelligence cross-checked against global databases – 5M+ attack IPs, hundreds of thousands of bot signatures, updated daily
  • Zero-day behavioral and heuristic detection – catches unknown attack patterns before signatures exist
  • VPN, Tor, proxy, ASN, and hosting reputation checks
  • Early Init Mode – filtering before WordPress Core loads, maximum resource savings during attacks
  • Hide Login URL addon – custom admin URL, hardened wp-login.php protection
  • Security Headers addon – HSTS, CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy, X-Content-Type-Options
  • Speed Up WordPress addon – 14 frontend and server optimizations
  • Malware Scanner addon – 25 patterns scanning files + 7 database tables, detects webshells, eval injections, base64-obfuscated code hidden in wp_options and post_content
  • Priority support – 24-hour response time

Four plans to match your traffic: Premium ($12/month, 25k cloud checks), Pro ($50/month, 100k cloud checks), Ultimate ($100/month, 250k cloud checks + emergency 24h support). Annual billing includes 1 month free. 30-day refund policy. Licensed per domain, billed securely via Freemius.

Compare plans

⚡ Performance & Compatibility

  • Zero database queries for returning visitors – 9 runtime PHP files with SHA-256 integrity signatures, loaded via include
  • Measured overhead: +3-15ms TTFB for cached visitors, +50-200ms for first-time PTR lookups, +2-4MB memory
  • Redis and Memcached support – free, auto-disables gracefully on connection failure
  • Cache plugin compatibility – automatic DONOTCACHEPAGE and Cache-Control: no-store on verification pages. Works with WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, Hummingbird, WP Fastest Cache, Cache Enabler
  • CDN and WAF compatibility – Cloudflare, Sucuri, Incapsula, AWS CloudFront, Fastly, KeyCDN, StackPath. Multi-header real-IP resolution (CF-Connecting-IP, X-Forwarded-For, X-Real-IP)
  • DDoS Protection Compatibility – automatic detection of JS-challenges from DDoS-Guard, Stormwall, Qrator. HMAC-signed AJAX responses, Circuit Breaker with automatic retry and backoff. BotBlocker is the only WordPress plugin that works correctly behind aggressive DDoS protection without manual configuration.
  • Multisite Support – network activation, per-site data, per-site cleanup. Free on all plans.
  • PHP 7.4 – 8.5 – tested across 7 PHP versions. WordPress 5.0 – 7.0+. Linux and Windows.
  • GDPR and CCPA compliant – no PII collected, technical parameters only, Legitimate Interest basis (Art. 6(1)(f))

🤝 Trusted by

  • 3 000+ active installations
  • Translated into 8 languages
  • Tested up to WordPress 7.0 and PHP 8.5
  • Developed and maintained by GLOBUS.studio

“Replaced two security plugins and a CAPTCHA plugin with one. Site is faster and the spam stopped overnight.” – WordPress.org user

Privacy

BotBlocker Security does not collect or process personal data of your visitors. All cloud analysis is performed on technical parameters only (IP, headers, User-Agent). No personally identifiable information is collected, stored, or transmitted to any external service.

Support and Documentation

License

This plugin is licensed under the GPLv2 or later. See LICENSE.txt for details.

Credits & Authors

BotBlocker Security is developed and maintained by GLOBUS.studio.

  • Concept, architecture & code – Yevhen Leonidov: https://leonidov.dev/
  • Code, code review – Andrii Lukashevych
  • Code, translations – Aleksandr Kinakh

BotBlocker Security – The first line of defense for your WordPress site.

Gratuitoem planos pagos
Ao instalar, você concorda com os Termos de Serviço do WordPress.com e com os Termos do plugin de terceiros.
Testado até
WordPress 7.0
Esse plugin está disponível para download para o seu .