Crawlantix AI Bot Tracker
Crawlantix AI Bot Tracker monitors visits from 30+ AI crawlers and gives you visibility into how bots interact with your site. See which bots visit, what pages they crawl, and catch misbehaving bots with a built-in logging-only honeypot. Lightweight, privacy-first, and fully functional out of the box. Free forever — no artificial limits on bot detection. Tracked Bots (30+): GPTBot / ChatGPT-User / OAI-SearchBot (OpenAI) ClaudeBot / Claude-Web / anthropic-ai (Anthropic) Googlebot / Google-Extended (Google / Gemini) bingbot (Microsoft / Copilot) PerplexityBot (Perplexity) DeepSeek, Qwen (Alibaba), Mistral AI Applebot-Extended (Apple Intelligence) Meta-ExternalAgent (Meta AI) Bytespider (ByteDance) CCBot (Common Crawl), Amazonbot, YouBot, DuckDuckBot AI2Bot, Diffbot, Timpibot, PetalBot SemrushBot, AhrefsBot, DataForSeoBot, MJ12bot, DotBot Features: Lightweight Bot Detection (30+ Bots) Hooks into WordPress init with a priority-1 action. Bails immediately on non-AI User-Agents — zero performance cost for human visitors. All 30+ bots tracked. Dashboard with Charts Clean dashboard with trend chart and provider breakdown pie chart (Chart.js, bundled locally). Summary cards show total visits, unique bots, pages crawled, and daily averages. No external dependencies. Bot Activity Table Dedicated tab showing all detected bots with visits, bytes transferred, 24h sparklines, verification status, and honeypot hit counts. Crawled Pages See which pages bots visit most, which bots crawl them, and when they were last seen. Honeypot Endpoint (Logging Only) A CSS-hidden, aria-hidden, rel=nofollow link is injected in the footer. Only raw link-extracting bots will follow it. Visits are logged for transparency. Active defense (blocking, tarpit, rate-limit, decoy, shadowban) is reserved for the paid build. Bot Verification Reverse DNS (FCrDNS) verification for major bots — confirms Googlebot, GPTBot, ClaudeBot, etc. are actually who they claim to be. Privacy First IP addresses are SHA-256 hashed with a per-install salt before storage. Raw IPs are never saved. Includes WordPress Privacy API exporter and eraser hooks so data-subject access and erasure requests can flow through the standard WordPress Tools → Personal Data workflow. AI Discovery Layer Serves ai-plugin.json (a discovery manifest that tells visiting AI agents the site is monitored) and llms.txt / llms-full.txt (text content authored by the admin via WordPress pages with slugs llms-txt and llms-full-txt) at the site root. Data Retention Bot visit data is retained for 30 days. Older records are automatically pruned via WP-Cron. External Services This plugin connects to the following external services: Reverse DNS Lookups The bot verification feature performs reverse DNS (FCrDNS) lookups using PHP’s gethostbyaddr() and gethostbyname() functions to verify that bots are who they claim to be (e.g., confirming a request claiming to be Googlebot actually originates from Google’s network). These lookups send the bot’s IP address to your server’s configured DNS resolver and the authoritative DNS servers for the IP address’s reverse DNS zone. Under some privacy regimes, IP addresses may be considered personal data. This feature runs automatically when a known AI bot visits your site and cannot currently be disabled via the admin UI (a filter hook crawlantix_enable_verification is available for developers). No other external services, third-party APIs, or remote requests are used by this plugin. All analytics data is stored locally in your WordPress database. Chart.js is bundled locally — no CDN requests are made. Privacy Policy Crawlantix AI Bot Tracker is designed with privacy as a core principle: Bot traffic only. The plugin only tracks automated bot traffic identified by User-Agent strings. Human visitors are not tracked and no cookies are set. No raw IP addresses stored. All IP addresses are SHA-256 hashed with a per-install random salt before storage (or AUTH_SALT when defined in wp-config.php). The original IP address cannot be recovered from the hash. Note: pseudonymous IP hashes may still be considered personal data under GDPR. Data stored per bot visit: IP hash, User-Agent string, requested URL, HTTP referrer URL, request method, timestamp, and derived fields (bytes transferred, bot verification status). Referrer URLs may contain personal data depending on the referring site. WordPress Privacy API integration. The plugin registers exporter and eraser callbacks with WordPress core, so data-subject access and erasure requests filed through Tools → Personal Data flow correctly. No external data transmission. All analytics data remains in your local WordPress database. No data is sent to Crawlantix or third-party services. The only external communication is DNS lookups for bot verification (see External Services above). Data retention controls. Bot visit data is automatically pruned after 30 days. Administrators can delete all collected data on uninstall via the “Delete Data on Uninstall” Settings toggle. For sites that require a formal privacy policy disclosure, you may note: “We use the Crawlantix AI Bot Tracker plugin to monitor automated AI bot traffic to our site. This plugin records bot User-Agent strings, pseudonymous IP hashes, pages visited, referrer URLs, and timestamps for detected bot traffic only. Raw IP addresses are cryptographically hashed before storage. No human visitor data is collected.” Premium Version Crawlantix also offers paid tiers at crawlantix.com for site owners who need active bot defense in addition to monitoring. The paid build adds the following features on top of everything in this free version: Protect tier Active honeypot responses: HTTP 403 block, tarpit (random 5–25s delay with worker-exhaustion safeguards), rate limit 429, decoy content, shadowban. Auto-block of repeat honeypot offenders, with configurable thresholds. Per-IP response rules — apply a chosen response strategy to specific IP hashes (up to 200 rules). Custom honeypot paths (up to 5) with a reserved-route safety list. Email alerts for honeypot hits and parameter explosion patterns. Robots.txt trap entries that catch non-compliant scrapers. Optional override that suppresses the WordPress core /wp/v2/users REST endpoints (username-enumeration hardening, off by default and easy to opt back in). Optimize tier Full REST API at /wp-json/ai-tracker/v1/ with API key authentication and 13 endpoints (status, stats, page, trends, bots, top-pages, report, export, alerts, honeypot, crawled-pages, etc.). GeoIP location tracking with MaxMind GeoLite2. Crawl Analytics tab with deeper traffic-quality metrics. Extended data retention up to 365 days. Scale tier Backup & restore — export all data as JSON; import with merge or replace modes. Unlimited retention. Priority support. The paid build is a drop-in upgrade: same plugin slug, same database tables, same option keys, so all your historical bot data carries over with no migration step on your part.
Top keywords
- bot22×2.14%
- data20×1.94%
- bots14×1.36%
- ip12×1.17%
- ai10×0.97%
- wordpress9×0.87%
- honeypot8×0.78%
- crawlantix7×0.68%
- dns7×0.68%
- external7×0.68%
- privacy7×0.68%
- site7×0.68%
Easy MCP AI – Connector for Claude, ChatGPT & SEO Data
Easy MCP AI is the most complete free WordPress MCP server — a remote MCP server built so AI assistants and autonomous AI agents can run your entire site workflow, from content and publishing to SEO research, traffic monitoring, and daily admin, through the Model Context Protocol. It works as an MCP adapter for any MCP-compatible AI client, making your site agent-ready out of the box. Ask your AI about Google Analytics, Google Search Console, and SEO data without leaving your chat. You bring the direction. Your AI handles the execution. No Node.js. No external proxy. No complicated setup. Just install, generate a token, and start building. At a glance: 243 tools — 96 core WordPress tools (posts, pages, media, users, comments, menus, taxonomies, change history, and more), 93 plugin-integration tools (WooCommerce, ACF, The Events Calendar, BuddyPress, and 6 SEO plugins), and 54 data-integration tools (Google Analytics 4, Google Search Console, Semrush, SE Ranking, DataforSEO, Ahrefs) 1-click OAuth 2.0/2.1 with per-scope consent (Claude Desktop, Cursor, etc.) Plugin integrations — WooCommerce, ACF, The Events Calendar, BuddyPress, and SEO plugins (Yoast, Rank Math, AIOSEO, SEOPress, Slim SEO, The SEO Framework) Google Analytics 4 & Google Search Console — ask your AI about traffic, top pages, conversions, search queries, clicks, impressions, and indexing status Semrush, SE Ranking, DataforSEO & Ahrefs — ask your AI for SEO and competitive research: keyword and backlink data, organic competitors, SERP results, rank tracking, and AI-search visibility (Ahrefs Domain Rating needs a free Ahrefs API key) Auto-discovers WordPress 6.9+ Abilities API Full audit trail — every AI action on your site is logged in a searchable user activity log Change History — every MCP-originated write (posts, meta, terms, users, options, comments, WooCommerce, BuddyPress) is recorded with before/after snapshots and queryable via 3 dedicated wp_history_* tools Works With Every Major AI Connect any of the following AI assistants or AI agents to your site through the WordPress MCP endpoint — full integration guides here: Manus — the autonomous AI agent that can run multi-step workflows start to finish Claude (Claude.ai, Claude Desktop, Claude Code) — connect Claude to WordPress in one click via OAuth ChatGPT (OpenAI) — connect ChatGPT to WordPress and manage your entire site by chat Gemini AI (Antigravity CLI / Google Antigravity) — Google’s AI tools with MCP support Cursor, Windsurf, Cline, Roo Code — AI-powered code editors that can also manage your content n8n — automation for content pipelines and publishing workflows Any MCP-compatible client — the protocol is open and supported by a growing ecosystem What Can Your AI Do On Your Site? Once connected, your AI agent can handle everything you’d normally do in the WordPress admin: AI Content Writing & Publishing — let your AI agent draft, rewrite, SEO-optimize, schedule, and publish WordPress posts and pages; update existing posts and pages AI Media Library & Alt Text — upload images from chat, browse the media library, and auto-generate AI alt text and captions for SEO and accessibility Taxonomy & Navigation — manage categories, tags, term meta, and WordPress navigation menus; assign terms from any taxonomy to posts User Management — create WordPress user accounts, assign roles, update profiles, and manage user meta Plugins & Themes — list installed plugins and themes; see which theme is currently active WordPress Settings — read and update site title, tagline, timezone, date format, time format, and posts-per-page WooCommerce AI Agent — manage WooCommerce products, variations, attributes, orders, customers, coupons, and webhooks; view order refunds, shipping zones, shipping methods, tax rates, and payment gateways; pull sales, top-seller, and revenue reports; bulk update products, variations, and orders SEO with Yoast, Rank Math, AIOSEO, SEOPress, Slim SEO & The SEO Framework — read and update post (and term) SEO metadata across all six major SEO plugins: SEO titles, meta descriptions, canonical URLs, robots and advanced-robots directives, Open Graph and Twitter card fields, focus / target keywords, primary term, breadcrumb titles, and schema / cornerstone / pillar settings Advanced Custom Fields (ACF) — read and write ACF custom field values on posts and users; read ACF fields on taxonomy terms; list ACF field groups Events Calendar & BuddyPress — create, edit, and delete events with The Events Calendar; create and view venues; create and list organizers; list BuddyPress members, groups, group members, and private message threads; create and delete activity stream posts Comment Moderation — let AI list, approve, hold, mark as spam, edit, or delete WordPress comments Change History & Rollback Awareness — every write your AI makes is recorded with structured before/after snapshots. Ask “what did the AI change on this post last week?”, diff any two revisions, or audit per-user activity through the wp_history_list, wp_history_get, and wp_history_diff tools — plus a full Change History admin page with retention and on/off controls Gutenberg & Full Site Editing — create, edit, and reuse Gutenberg blocks; update block templates and global styles for FSE themes Custom Post Types (CPT) — read and write any registered custom post type — portfolios, listings, courses, reviews, anything Google Analytics 4 — ask about traffic, top pages, conversions, custom dimensions/metrics, and realtime active users Google Search Console — ask about top search queries, clicks, impressions, sitemaps, and URL indexing status Semrush — pull domain overviews, keyword research, organic keywords, organic competitors, keyword difficulty and related keywords, question phrases, and backlink overview / referring domains / anchors for any target SE Ranking — pull domain overviews (regional and worldwide), keyword and backlink research, organic competitors, top pages, keyword comparisons, and AI-search visibility (how a domain appears in Google AI Overviews, ChatGPT, Perplexity, and Gemini) for any domain DataforSEO — run on-page SEO audits on any URL, check keyword search volumes and trends, pull live SERP results, analyse backlinks, and look up ranked and site keywords for any domain Ahrefs — look up the Domain Rating (backlink-profile strength, 0–100) for any domain or URL; needs a free Ahrefs APIv3 key, which costs nothing and uses no API units Any Plugin — automatically connects to plugins that support WordPress 6.9+ Abilities API, no custom code needed Ask your AI anything — for example: * “Write a 500-word blog post about healthy eating and publish it as a draft” * “Show me today’s WooCommerce orders and their total revenue” * “What keywords does my homepage rank for and what are the click counts?” Tools 243 Tools, Ready to Use 96 core tools cover every major WordPress content type — posts, pages, media, categories, tags, custom taxonomies, comments, users, menus, custom post types, post/term/user meta, revisions, Gutenberg blocks, templates, global styles, site settings, plugins, themes, and full-text search. Each type supports create, read, update, delete and more, plus conveniences like one-call full-post reads, find-and-replace in post content, and AI alt-text on media. 11 Google Analytics 4 Tools Account & Property — list account summaries, get property details, check compatibility, get metadata Reports — run standard reports, pivot reports, and realtime reports Configuration — list data streams, conversion events, custom dimensions, and custom metrics 6 Google Search Console Tools Sites — list verified properties Search Analytics — query top search terms, pages, countries, devices with clicks, impressions, CTR, and position Sitemaps — list and inspect submitted sitemaps URL Inspection — check indexing status and coverage for any URL on your site 13 Semrush Tools Domain — domain overview and organic competitor research Keywords — keyword research tools: domain organic keywords, URL organic keywords, keyword overview, related keywords, keyword difficulty, and phrase questions Backlinks — backlinks overview, backlinks list, referring domains, and anchors 15 SE Ranking Tools Domain — regional and worldwide domain overviews, organic keywords, organic competitors, top pages/subdomains, and keyword comparisons Keywords — keyword research (similar, related, questions, long-tail) and multi-keyword overview with volume, CPC, and difficulty Backlinks — backlink summary, detailed backlinks / anchors / referring domains, and domain authority (InLink Rank) AI Search — AI-search visibility across Google AI Overviews, ChatGPT, Perplexity, and Gemini, plus brand discovery and AI prompts 8 DataforSEO Tools SERP — fetch live search engine results pages for any keyword and location Keywords — look up monthly search volume and trend data for one or more keywords Labs — get ranked keywords for any domain, or find keywords a specific page ranks for Backlinks — get a backlink summary and list of referring domains for any target URL On-Page — run a full on-page SEO audit on any URL and get a list of actionable issues 1 Ahrefs Tool Domain Rating — look up the Ahrefs Domain Rating (0–100) for any domain or URL. Needs a free Ahrefs APIv3 key (no cost, no API units). Attribution “Domain Rating by Ahrefs” is required when displaying the value. 10 Plugin Integrations WooCommerce — 46 WooCommerce AI tools for products, orders, customers, coupons, shipping, reports, and more Advanced Custom Fields (ACF) — 6 tools to get and update ACF fields on posts, users, and terms; list ACF field groups The Events Calendar — 10 tools to create and manage events, venues, and organizers BuddyPress — 10 tools for members, activity stream, groups, group members, and private messages Yoast SEO — get and update post SEO metadata, plus rendered SEO head output Rank Math — get and update post SEO metadata, plus rendered SEO head output All in One SEO (AIOSEO) — get and update post SEO metadata, plus breadcrumb data SEOPress — get and update post and term SEO metadata, plus content analysis Slim SEO — get and update post SEO metadata The SEO Framework — get and update post SEO metadata Connect Any Plugin with Abilities API WordPress 6.9+ introduces Abilities API — a standard way for plugins to declare what they can do. Easy MCP AI acts as an MCP adapter for any plugin that registers Abilities — automatically discovering and exposing them as MCP tools with no custom code needed. If a plugin supports the Abilities API, your AI can use it out of the box. One-Click Connect with OAuth 2.0/2.1 Skip manual token copy-paste. Your WordPress MCP endpoint ships with a full OAuth 2.0/2.1 authorization server — PKCE, refresh-token rotation, and Dynamic Client Registration (RFC 7591) built in. Compatible MCP clients like Claude Desktop can connect with a single click: they register themselves, you approve the scopes on a consent screen, and you’re done. Bearer tokens still work for power users and automation. Built for Security Giving an AI access to your site is serious — so security is built into every layer: Bearer token authentication with SHA-256 hashing — the raw token is never stored Per-token permissions — create a read-only token for one AI, a full-access token for another WordPress capability checks on every single tool call Rate limiting per token (default 60 requests/min, configurable) Full audit trail — every tool call is logged in a searchable user activity log with the token used, arguments, result, and client IP IP whitelisting — optionally restrict which IPs can use the MCP endpoint Simple Admin Interface Dashboard — your MCP endpoint URL and one-click connection configs for every major AI client API Tokens — create and manage tokens with a checkbox-based tool permission tree Audit Log — a paginated, searchable user activity log of every AI action taken on your site Change History — a dedicated page with before/after snapshots of every MCP-originated write, inline diff expand, and user / object / date filtering Settings — tune rate limits, audit and change-history retention, IP whitelist, and more External services This plugin connects to the following third-party services only after a site administrator explicitly enables them in Easy MCP AI → External Data (by saving their own external account credentials). Nothing is contacted on a default install. Ahrefs Domain Rating API — api.ahrefs.com When: only after an administrator saves an Ahrefs APIv3 key and enables the tool under Easy MCP AI → External Data → Ahrefs (it is OFF by default — nothing is contacted on a default install). Thereafter: when an authorized MCP client calls the wp_ahrefs_domain_rating_free tool, and once each time an administrator saves the key or presses Test Connection on the External Data screen (both validate the key against Ahrefs). What is sent: your Ahrefs APIv3 key, as an Authorization: Bearer header, plus the target domain or URL supplied with the call. No WordPress credentials or personal data are transmitted. Terms: https://ahrefs.com/legal/domain-rating-license Privacy: https://ahrefs.com/legal/privacy-policy Semrush API — api.semrush.com, www.semrush.com When: only if an admin saves a Semrush API key. What is sent: the configured Semrush API key plus the parameters supplied per call (target domain, target URL, keyword/phrase, database/region code, display limits). Terms: https://www.semrush.com/company/legal/terms-of-service/ Privacy: https://www.semrush.com/company/legal/privacy-policy/ DataForSEO — api.dataforseo.com When: only if an admin saves a DataForSEO account login + API password. What is sent: the configured DataForSEO login + API password (HTTP Basic auth), plus the parameters supplied per call (keyword, target domain, target URL, location code, language code). Terms: https://dataforseo.com/terms-of-use Privacy: https://dataforseo.com/privacy-policy SE Ranking API — api.seranking.com When: only if an admin saves a SE Ranking API key. What is sent: the configured SE Ranking API key (sent as an Authorization token) plus the parameters supplied per call (target domain, target URL, keyword, region/source code, search engine, display limits). Terms: https://seranking.com/legal/terms-of-service.html Privacy: https://seranking.com/legal/privacy-statement.html Google Analytics 4 Data API & Google Search Console API — analyticsdata.googleapis.com, searchconsole.googleapis.com / www.googleapis.com/webmasters/v3 (token exchange via oauth2.googleapis.com) When: only if an admin uploads a Google service-account JSON. What is sent: a signed JWT minted from the service-account key, plus the chosen target and per-call parameters — for Analytics, the GA4 property id and report definition (dimensions, metrics, date range, filters); for Search Console, the site URL and query parameters (date range, dimensions, URL to inspect, sitemap URL). Terms: https://policies.google.com/terms Privacy: https://policies.google.com/privacy Easy MCP AI connection diagnostics (optional) — easymcpai.com When: only if you click the Diagnose Connection button on the Easy MCP AI dashboard. The plugin never contacts this service on its own — it simply opens the page in a new browser tab. What is sent: only your site’s address (its hostname), so the diagnostic page can check that your MCP endpoint is reachable. No credentials, content, or personal data are sent. Privacy: https://easymcpai.com/privacy Author Developed by EasyMCPAI.