Blackhole for Bad Bots
✨ Trap bad bots in a virtual black hole Important: Do NOT use this plugin on sites with caching. Learn more » 👾 Bye bye bad bots.. Bad bots are the worst. They do all sorts of nasty stuff and waste server resources. The Blackhole plugin helps to stop bad bots and save precious resources for legit visitors. 👾 How does it work? First the plugin adds a hidden trigger link to the footer of your pages. You then add a line to your robots.txt file that forbids all bots from following the hidden link. Bots that then ignore or disobey your robots rules will crawl the link and fall into the trap. Once trapped, bad bots are denied further access to your WordPress site. I call it the “one-strike” rule: bots have one chance to obey your site’s robots.txt rule. Failure to comply results in immediate banishment. The best part is that the Blackhole only affects bad bots: human users never see the hidden link, and good bots obey the robots rules in the first place. Win-win! 🙂 ✨ Add a blackhole trap to help stop bad bots Important: Do NOT use this plugin on sites with caching. Learn more » 👾 Features Easy to set up Squeaky clean code Focused and modular Lightweight, fast and flexible Built with the WordPress API Works with other security plugins Easy to reset the list of bad bots Easy to delete any bot from the list Regularly updated and “future proof” Blackhole link includes “nofollow” attribute Plugin options configurable via settings screen Works silently behind the scenes to protect your site Whitelists all major search engines to never block Focused on flexibility, performance, and security Email alerts with WHOIS lookup for blocked bots Complete inline documentation via the Help tab Provides setting to whitelist any IP addresses Customize the message displayed to bad bots 😉 One-click restore the plugin default options Does NOT use or require any .htaccess rules Blackhole for Bad Bots protects your site against bad bots, spammers, scrapers, scanners, and other automated threats. ✨ Not using WordPress? Check out the standalone PHP version of Blackhole! 👾 Whitelist By default, this plugin does NOT block any of the major search engines (user agents): AOL.com Baidu Bingbot/MSN DuckDuckGo Googlebot Teoma Yahoo! Yandex These search engines (and all of their myriad variations) are whitelisted via user agent. So are a bunch of other “useful” bots. They always are allowed full access to your site, even if they disobey your robots.txt rules. This list can be customized in the plugin settings. For a complete list of whitelisted bots, visit the Help tab in the plugin settings (under “Whitelist Settings”). ✨ Check out Blackhole Pro and level up with advanced features! 👾 Exclusive Pro Features Option to disable for logged-in users Threshold control (number of allowed hits) Custom email alerts Custom messages for blocked bots Custom redirect for blocked bots Custom blackhole trigger links Complete inline documentation Block bots based on user agent Block bots based on IP address Whitelist/allow bots by user agent Whitelist/allow bots by IP address Redirect whitelisted bots Set custom HTTP Status Code Full-featured Bad Bot Log with paging, sorting, and field search Manually add bad bots to the Bad Bot Log Geo/IP location lookups for each bad bot Logs number of blocked hits for each bot ..plus everything the free version can do and more. ✨ Learn more and get Blackhole Pro » 👾 Privacy User Data: This plugin automatically blocks bad bots. When bad bots fall into the trap, their IP address, user agent, and other request data are stored in the WP database. No other user data is collected by this plugin. At any time, the administrator may delete all saved data via the plugin settings. Services: This plugin does not connect to any third-party locations or services. Cookies: This plugin does not set any cookies. Credit: Header Image Courtesy NASA/JPL-Caltech. Blackhole for Bad Bots is developed and maintained by Jeff Starr, 15-year WordPress developer and book author. 👾 Support development I develop and maintain this free plugin with love for the WordPress community. To show support, you can make a donation or purchase one of my books: The Tao of WordPress Digging into WordPress .htaccess made easy WordPress Themes In Depth Wizard’s SQL Recipes for WordPress And/or purchase one of my premium WordPress plugins: BBQ Pro – Blazing fast WordPress firewall Blackhole Pro – Automatically block bad bots Banhammer Pro – Monitor traffic and ban the bad guys GA Google Analytics Pro – Connect WordPress to Google Analytics Head Meta Pro – Ultimate Meta Tags for WordPress REST Pro Tools – Awesome tools for managing the WP REST API Simple Ajax Chat Pro – Unlimited chat rooms USP Pro – Unlimited front-end forms Links, tweets and likes also appreciated. Thank you! 🙂
Top keywords
- bots30×3.77%
- bad20×2.52%
- bad bots16×2.01%
- wordpress13×1.64%
- blackhole11×1.38%
- pro11×1.38%
- user7×0.88%
- block5×0.63%
- bot5×0.63%
- custom5×0.63%
- ip5×0.63%
- link5×0.63%
SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
SilentShield is a unified captcha and anti-spam plugin for WordPress. It works with the most popular form builders and protects login, registration, and comment forms – without slowing your site. Why choose SilentShield? – Invisible defense – Captcha, honeypot, and blacklists working silently. – Instant results – Install, activate, and stop spam. – Universal support – Works with Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms, Forminator, Kadence, WooCommerce, and more. – Privacy-first – No cookies, no tracking, fully GDPR / DSGVO compliant. SilentShield doesn’t just protect forms. It protects your time, your customers, your business. Core Features Invisible Captcha (Arithmetic, Honeypot, Image) Smart IP Blocking & Blacklists Spam filters for links, code & keywords Whitelisting for admins & customers GDPR-ready, no cookies, no tracking Supported Form Plugins & Integrations SilentShield protects forms from all major WordPress form builders and core features: Form Builders: – Contact Form 7 (CF7) – WPForms / WPForms Lite – Elementor Pro Forms (classic widget and v4 “atomic” forms) – Gravity Forms – Fluent Forms – Formidable Forms – Ninja Forms – Forminator – JetFormBuilder – Kadence Blocks (Advanced Form) – Jetpack Forms (contact form block and shortcode) – Avada (Fusion Builder) Forms Newsletter: – MC4WP – Mailchimp for WordPress (signup forms) WooCommerce: – Checkout – block (the default for new shops since WooCommerce 8.3) – Checkout – classic (incl. PayPal Payments) – Login – Registration – Lost password – Account details WordPress Core: – Login form (wp-login.php) – Registration form – Lost password form – Comment forms (including WooCommerce product reviews) Communities & Forums: – bbPress (new topics and replies) – BuddyPress (member registration) Donations: – GiveWP (classic donation form; the visual-builder form is not yet covered) Other: – Ultimate Member (Login & Registration) – WP Job Manager (Job Applications) Each integration can be enabled or disabled individually under Settings > Extended. Protection Layers SilentShield uses 10+ protection mechanisms working together: Captcha – Arithmetic math, honeypot, or image-based captcha JavaScript Protection – Detects submissions from bots without JS support Browser Detection – Validates User-Agent strings Timer Protection – Blocks submissions faster than a human can type Multiple Submission Protection – Prevents rapid duplicate submissions IP Rate Limiting – Limits requests per IP and time window IP Blacklist – Block known bad IPs Content Rules – Limit URLs, block BBCode, keyword blacklist Gibberish Detection – Recognises submissions filled with random characters, the kind a bot writes when it only needs the form to go through. Unlike every other check it does not depend on the sender’s browser, so a bot driving a real browser cannot pass it by playing along. Starts in observation mode and blocks nothing until you switch it on. Whitelist – Skip validation for admins, logged-in users, or specific emails/IPs SilentShield API – Cloud-based spam detection (silentshield.io) The Promise SilentShield is not “just another plugin.” It’s an invisible wall against the background noise of the internet. Activate once – and your forms are human again. Want more? SilentShield API Everything above is free and stays free. No feature is held back, no submission limit, no account needed. What the free plugin cannot do is recognise a bot that behaves like a person — one driving a real browser, solving the captcha, typing at human speed. Rules can only catch what looks wrong, and those do not. The SilentShield API answers that with behaviour analysis and browser fingerprinting, scored in the cloud, and it usually decides without showing anyone a captcha at all. Switch it on and the local protections stay exactly where they are as a fallback — if the API is ever unreachable, your forms are still protected. There is a free plan and a trial, and you can see what it would have caught before you pay for anything: turn on Comparison Mode and the plugin logs what the API would have decided, alongside what your local rules actually did. 👉 Plans and free trial at silentshield.io Privacy & Telemetry No cookies, no user tracking. Encrypted IP storage (max. 2 months, only for spam defense). Every transmission described below is optional and can be switched off in the plugin settings. The plugin’s built-in Privacy page shows which of these are active on your site, what that means, and gives you ready-made privacy-policy snippets in 25 languages. 1. Plugin statistics (setting “Telemetry”) Anonymous, no personal data, sent at most once a day: – plugin_slug, plugin_version – snapshot_date – settings_json (anonymized config – only boolean/integer flags, no free-text) – features_json (enabled features) – created_at, first_seen, last_seen – counters_json (spam events) – wp_version, php_version, locale 2. AI-crawler observation (setting “Observe AI crawlers”, on by default; SILENTSHIELD_OBSERVER to force off) Sent only for requests identified as an AI crawler — never for your human visitors. Delivered after the page has already been sent to the visitor: – ua (the crawler’s User-Agent), ip, path (without query string), method – The IP address is pseudonymised on the server (daily keyed hash) and never stored in the clear. 3. Blocked-request reports (only with “Block AI crawlers (enforce)” on; follows the observation setting above) Same fields as (2), plus the outcome (deny / throttle), for every request enforcement turned away. Note that a block rule which is not restricted to a specific crawler can also catch a human visitor — that request is then reported in the same way. 4. Form assessment (only with the SilentShield API enabled) See the API snippet on the plugin’s Privacy page for the full description.