plugin-icon

WebDecoy Bot Detection

作者 Web Decoy·
Zero-config bot, spam, and carding protection. Works instantly on activation, with no account, API key, or external connections.
版本
2.3.0
最近更新:
Jul 23, 2026
WebDecoy Bot Detection

WebDecoy is a free, fully-functional bot detection and protection plugin that works 100% locally. Unlike CAPTCHA solutions that frustrate visitors, WebDecoy uses invisible multi-layer detection — legitimate users never see challenges or interruptions.

Works immediately on activation. No account needed. No API key required. No external connections at all until you optionally connect a WebDecoy Cloud account.

Why WebDecoy?

  • Zero friction — Humans never see CAPTCHAs or challenges
  • Zero configuration — Install, activate, done
  • Zero dependencies — Everything runs locally on your server
  • Multi-layer detection — Server-side + client-side + proof-of-work challenges
  • Free forever — Full protection at no cost. Premium cloud features are optional.

Free Features (No API Key Needed)

Server-Side Detection * User-Agent analysis and HTTP header inspection * Good bot verification (reverse DNS for Googlebot, Bingbot, etc.) * MITRE ATT&CK path analysis (admin probing, config file access) * Rate limiting with automatic blocking * IP blocking (individual + CIDR, IPv4/IPv6, expiration)

Client-Side Detection * WebDriver detection (Selenium, Puppeteer, Playwright) * Headless browser detection (Chrome headless, PhantomJS) * Automation framework detection * Behavioral analysis (mouse movement, click patterns, scroll behavior) * Canvas/WebGL fingerprinting * AI crawler detection (GPTBot, ClaudeBot, PerplexityBot)

Invisible Proof-of-Work Challenges * SHA-256 challenges solved in background (no user interaction) * Challenge mode for suspicious requests (checkbox widget, auto-solves) * Difficulty scales based on threat signals * No external CAPTCHA service needed

Form Protection * Comment spam protection * Login brute force protection * Registration spam prevention * Invisible honeypot fields on comment, login, and registration forms

WooCommerce Protection * Checkout carding attack prevention * Velocity limiting (configurable attempts per time window) * Card testing pattern detection * WooCommerce Blocks compatible

Local Dashboard & Analytics * Detection log with threat scores and MITRE tactic mapping * Statistics page with 30-day trend charts * Blocked IPs management * Dashboard widget with threat overview * CSV export * Automatic data cleanup (30 days)

Smart Bot Recognition * 60+ known good bots automatically allowed * Search engines, social media, monitoring services, SEO tools * Optional AI crawler blocking * Custom allowlist support

Premium Features (Optional WebDecoy Cloud)

Connect an API key to unlock cloud-powered intelligence:

  • WAF Integrations — Arm your existing edge: push confirmed attackers to Cloudflare or AWS WAF so they’re blocked before a request ever reaches WordPress, plus webhooks for any other firewall
  • IP Reputation — AbuseIPDB integration, threat scoring
  • VPN/Proxy Detection — Identify visitors hiding behind VPNs, proxies, and Tor
  • GeoIP Enrichment — Geographic data from MaxMind
  • Cloud Sync — Forward detections to centralized dashboard
  • Cross-Site Intelligence — Aggregate threat data from all WebDecoy customers
  • Advanced Analytics — Cloud dashboard at app.webdecoy.com with indefinite history
  • Webhooks & Alerts — Automated response chains, email notifications

Explore Plans | Start Free Trial

Threat Scoring

WebDecoy uses an intelligent scoring system (0-100):

  • 0-19: MINIMAL — Allow (likely human)
  • 20-39: LOW — Log only
  • 40-59: MEDIUM — Optional challenge
  • 60-74: HIGH — Challenge or block
  • 75-100: CRITICAL — Automatic block

The threshold is fully configurable to match your site’s needs.

External Services

This plugin can optionally connect to the following external services when you connect a WebDecoy Cloud account — either with the one-click Connect button or by entering an API key manually:

WebDecoy Cloud — app.webdecoy.com, api.webdecoy.com and ingest.webdecoy.com

This plugin only contacts WebDecoy Cloud after you explicitly start a connection on the WebDecoy Cloud settings tab. With no connection made and no API key configured, no data is ever sent to these services.

What is sent, and when: * When you click “Connect to WebDecoy Cloud”: your browser is redirected to app.webdecoy.com to approve the connection (carrying your site URL, site name, a one-time nonce, and your monthly-report preference). After you approve, the plugin exchanges a one-time token with api.webdecoy.com (sending the token, your site URL and the nonce) to receive the site’s API keys. Cancelling sends nothing further. * After connecting: the plugin fetches your plan entitlements from ingest.webdecoy.com (authenticated with your API key) twice daily. * When a detection or rule violation occurs: the visitor’s IP address, user agent, request path, threat score and detection flags are sent to ingest.webdecoy.com so the event appears in your cloud dashboard. * When you use an IP-reputation filter rule (e.g. ip.abuse_score, ip.tor): the visitor’s IP address is sent to ingest.webdecoy.com to look up reputation/geo data. * When validating your key or forwarding a WooCommerce checkout detection: your API key, organization ID and the detection data above are sent to api.webdecoy.com / ingest.webdecoy.com.

All requests are made server-side over HTTPS. This is an optional cloud service provided by WebDecoy. Terms of Service: https://webdecoy.com/terms Privacy Policy: https://webdecoy.com/privacy

Without an API key, the plugin operates 100% locally — no external connections on the front end or back end. Chart.js (used for the admin Statistics charts) is bundled with the plugin, not loaded from a CDN.

Bundled third-party libraries

Chart.js v4.5.1 (MIT license) is included at admin/js/vendor/chart.umd.min.js for the admin Statistics charts. It is the official distribution build; the human-readable source is available at https://github.com/chartjs/Chart.js/releases/tag/v4.5.1 . No other third-party libraries are bundled.

Reference URLs in the good-bot database

The bundled good-bot list (sdk/src/GoodBotList.php) stores a documentation URL for each known bot (e.g. developer.amazon.com/amazonbot, api.slack.com/robots) purely as reference metadata shown alongside detections. These URLs are never requested by the plugin — no connection of any kind is made to them.

Privacy Policy

WebDecoy collects the following data locally for bot detection purposes:

  • IP addresses
  • User agent strings
  • HTTP headers
  • Browser fingerprint signals
  • Request patterns

This data is stored in your WordPress database and automatically cleaned up after 30 days. No data is sent externally unless you configure a WebDecoy Cloud API key.

For more information, see our Privacy Policy.

目前已測試版本
WordPress 7.0.2
此外掛程式已可供下載,並可用於你 系統。