Bot Lockout
Bot Lockout is a security plugin that implements a lightweight cryptographic challenge system to distinguish between real browsers and automated bots. Unlike traditional CAPTCHA systems, it uses JavaScript-based cryptographic operations that are easy for humans but difficult for most bots to solve. Key Features Lightweight Protection: Uses minimal resources and doesn’t impact site performance Cryptographic Challenges: SHA-256 hashing with date and user agent binding Smart Whitelisting: Allow trusted bots (Google, Bing, etc.) and IP addresses Flexible Configuration: Exclude specific pages and customize block messages Comprehensive Logging: Track blocked attempts for analysis Custom Styling: Add custom CSS to match your site’s design Daily Token Expiration: Prevents long-term bypass attempts How It Works Initial Request: When a visitor accesses your site, the plugin checks for a valid challenge token JavaScript Challenge: If no token exists, a cryptographic challenge is presented Token Generation: The challenge combines the current date with the user agent string and creates a SHA-256 hash Secure Storage: The hash is base64 encoded, truncated, and stored as a secure cookie Validation: Subsequent requests are validated against the stored token Security Features Cryptographically Secure: Uses SHA-256 hashing algorithm Time-Bound: Tokens expire daily to prevent long-term bypass Browser-Specific: User agent binding prevents token sharing Secure Cookies: Implements proper cookie security settings Whitelist Support: Allow trusted services and IP addresses Multi-Site Support Bot Lockout supports WordPress Multi-Site installations with both network-wide and site-specific configurations: Network Activation: Apply settings to all sites in the network Site-Specific Activation: Independent settings for each site Mixed Configuration: Network-wide defaults with site-specific overrides Security Advisory Bot Lockout is one layer in a broader security strategy, not a silver bullet. While Bot Lockout is designed to deter automated bots and AI scrapers through cryptographic JavaScript challenges, no single solution can offer complete protection. Web scraping technologies continue to evolve, and determined actors may find ways to bypass front-end defenses. This plugin should be used as part of a multi-layered approach to website security. For best results, we recommend combining Bot Lockout with additional tools such as server-level firewalls, rate limiting, CAPTCHA systems, behavior-based threat detection, and CDN-level bot mitigation. Kognetiks makes no guarantee that this plugin will block all unwanted bot traffic. It is intended as a proactive, lightweight defense mechanism—not a comprehensive security system. Users are responsible for evaluating their own threat model and deploying appropriate complementary protections. Support For support, please visit the WordPress.org support forums or check the plugin documentation. Credits Developer: Kognetiks This plugin is licensed under the GPL v3 or later.
Top keywords
- bot7×1.66%
- security7×1.66%
- token6×1.43%
- bot lockout5×1.19%
- challenge5×1.19%
- cryptographic5×1.19%
- lockout5×1.19%
- support5×1.19%
- bots4×0.95%
- secure4×0.95%
- site4×0.95%
- agent3×0.71%
IPIntel AI Firewall
IPIntel AI Firewall (WAF) integrates AI-powered IP reputation analysis into WordPress to help site owners detect and mitigate automated abuse, scanners, and malicious traffic. Incoming requests are evaluated using external reputation signals and risk scoring. Based on the assessed risk level, traffic may be allowed, challenged for human verification, or blocked automatically. The plugin is designed to be easy to use and does not require custom code or infrastructure management. Project website: https://ipintel.ai Features AI-powered IP reputation and risk scoring Automatic allow, challenge, or block decisions Human verification challenge for suspicious traffic Compatible with aggressive caching environments (one-time manual configuration required) Optional visual security badge Simple configuration for non-technical users Free API key available with daily request limits Data Privacy This plugin connects to the IPIntel.ai API to analyze visitor IP addresses for security and threat detection purposes. Data transmitted to the external service: – Visitor IP address – API key (used solely for request authentication) No WordPress user account data, cookies, or User-Agent information are transmitted. The external service is used exclusively to determine whether a request should be allowed, challenged, or blocked. A free API key is available with a daily request limit. Get API key: https://ipintel.ai/dashboard Higher request limits require an upgrade. Terms of Service: https://ipintel.ai/terms Privacy Policy: https://ipintel.ai/privacy Page Cache Compatibility IPIntel AI Firewall relies on per-visitor verification. When full-page caching is enabled, the cache must vary by the verification cookie in order for challenges to work correctly. For LiteSpeed Cache: – Go to LiteSpeed Cache → Cache → Vary – Add the following cookie: ipintel_human_ok – Save changes and purge the cache This is a one-time configuration step. Without cache variation, it is technically impossible for any WordPress plugin to reliably challenge unverified visitors. Optional Footer Badge The plugin includes an optional footer badge that can be enabled from the settings page. When enabled, the badge displays a small visual indicator showing that the site is protected by IPIntel.ai. The badge does not collect data, perform tracking, or load external resources. The footer badge is disabled by default and can be turned on or off at any time.
Top keywords
- ipintel9×2.49%
- ai8×2.22%
- ipintel ai8×