AlmaWeb AI Visitor Analytics
Two sides of AI traffic, one powerful plugin. With the rise of AI platforms like ChatGPT, Claude, Gemini, and Perplexity, your website faces two new realities: 1. AI bots scraping your content for training and indexing 2. Real human visitors discovering your site through AI tools and clicking through to visit AlmaWeb AI Visitor Analytics is the only WordPress plugin that tracks BOTH: AI Bot Detection Identify bots from major AI companies (OpenAI, Google, Anthropic, Meta, Amazon), SEO crawlers (Ahrefs, Semrush), aggressive scrapers, and even “stealth” bots hiding behind standard User-Agents. Detect GPTBot, ClaudeBot, Google-Extended, Gemini, Bytespider, Perplexity and 200+ more. AI Referrer Tracking Track real human visitors coming FROM AI platforms! When someone asks ChatGPT a question and clicks a link to your site, you will see it. Understand which AI tools are sending you traffic, which pages they land on, and how diverse your AI traffic sources are. Why AlmaWeb AI Visitor Analytics? In a world where AIs massively consume AND distribute web content, it is crucial to know: Who’s scraping your content – Precisely identify each AI bot (GPTBot, ClaudeBot, Google-Extended, Gemini, etc.) Whether ChatGPT is training on your data – Detect OpenAI crawlers in real time and block them if needed Which pages are being targeted – Discover what content interests AI bots the most Hidden bots – Detect even bots that mask their identity with standard User-Agents (stealth detection) Which AI platforms send you traffic – Track human visitors referred by ChatGPT, Claude, Perplexity, etc. Key Features 🔍 Multi-Level Bot Detection Level 1 – User-Agent: Detects 200+ AI bot signatures (OpenAI, Anthropic, Google, Meta, Amazon, Apple, xAI, Mistral, Cohere, Perplexity, DeepSeek, and more) Level 2 – IP Range: Verifies official IP ranges from OpenAI, Anthropic, and Google to catch masked bots Level 3 – Stealth Detection: Detects invisible bots like ChatGPT Atlas that use standard browser User-Agents by cross-referencing IP addresses 📊 Comprehensive Dashboard Real-time statistics (human visits vs bots) Evolution charts with Chart.js Distribution by AI family (OpenAI, Google, Anthropic, etc.) Top 10 most active bots Top 10 most scraped pages Comparison with previous period Business KPIs: growth rate, peak hours, intent distribution 📋 Detailed Logs Advanced filtering by bot type, IP, date Real-time search Full CSV export Complete details: User-Agent, IP, URL, detection method, AI family, bot intent Special badge for “invisible” bots ⚙️ Flexible Configuration Enable/disable tracking Bad bot blocking option (disabled by default) Configurable data retention (90 days by default) Automatic daily cleanup of old data Exclude logged-in users (optional) 🔒 Privacy Respectful No data sent to third-party services All data stays in your WordPress database GDPR compliant No cookies or client-side tracking Only downloads public data (IP ranges) Detected Bots The plugin detects over 200 different bots in the following categories: AI Bots (AI Training & Inference): OpenAI (GPTBot, ChatGPT-User, OAI-SearchBot, Operator, ChatGPT Agent), Anthropic (ClaudeBot, Claude-Web, Claude-SearchBot), Google AI (Google-Extended, Gemini, NotebookLM, GoogleAgent-Mariner), Meta AI, Amazon (Amazonbot, Bedrock, Nova Act), Apple Intelligence, Perplexity, Mistral, xAI (Grok), Cohere, DeepSeek, Character.AI, Kagi, Exa, Tavily, Apify, and 150+ others. Search Engines: Google, Bing, Yahoo, DuckDuckGo, Yandex, Baidu, etc. SEO Crawlers: Ahrefs, Semrush, Moz, Majestic, etc. Scrapers & Malicious Bots: Content scrapers, email collectors, attack bots, etc. Advanced Stealth Bot Detection Some AI bots like ChatGPT Atlas use standard browser User-Agents (Chrome, Safari) to go unnoticed. AlmaWeb AI Visitor Analytics detects them by cross-referencing IP addresses against official IP ranges from OpenAI, Anthropic, and Google — all stored locally, no external calls required. Example: A visitor with User-Agent “Mozilla/5.0 Chrome/…” from an IP in the OpenAI range will be identified as “ChatGPT Atlas” and marked with an “INVISIBLE” badge in the logs. Firewall — Block Unwanted Bots Since v1.2.0, the plugin includes a built-in Firewall to block bots before they access your content: Block by intention — Stop training crawlers (GPTBot, ClaudeBot), scrapers, or inference bots Block by family — Block all bots from a specific company (ByteDance, Meta, OpenAI, etc.) Blocked bots receive a 403 response and are still logged for analysis Performance Zero external calls: IP ranges for OpenAI, Anthropic and Google are stored locally Minimal impact: Optimized to not slow down your site Optimized queries: Indexes on all important columns Automatic cleanup: Daily deletion of old data Protect your content and understand your traffic like never before. Official Plugin Page Visit the official plugin page for additional resources and support: https://almaweb.fr/ai-visitor-analytics Privacy & Data Protection AlmaWeb AI Visitor Analytics takes your privacy seriously: Data Storage All data is stored locally in your WordPress database No external services receive any data from your site You have full control over data retention (configurable from 1 to 365 days) Automatic daily cleanup removes old data based on your settings What Data is Collected The plugin collects the following information for each visit: * User-Agent string * IP address * Requested URL * HTTP referrer * Request method (GET, POST, etc.) * HTTP headers (Accept, Accept-Language, Accept-Encoding) * Timestamp This data is used solely for bot detection and traffic analysis on your own site. GDPR Compliance No cookies are set by this plugin No client-side tracking or JavaScript-based analytics IP addresses are stored for bot identification purposes only You can configure data retention to comply with your privacy policy Users can request data deletion through standard WordPress data export/erasure tools What This Plugin Does NOT Do Does NOT send your data to external servers Does NOT track end-user behavior for advertising Does NOT use third-party analytics services Does NOT set cookies Does NOT require user consent (server-side logging only) Third-Party Services This plugin may connect to the following third-party services only to download publicly available bot IP ranges: OpenAI IP Ranges GPTBot: https://openai.com/gptbot.json ChatGPT-User: https://openai.com/chatgpt-user.json SearchBot: https://openai.com/searchbot.json Purpose: Verify IP addresses to detect OpenAI bots, including stealth bots like ChatGPT Atlas Data sent: None – the plugin only downloads public IP range information Caching: IP ranges are cached for 24 hours to minimize requests Privacy Policy: https://openai.com/privacy Important Notes No data from your site is ever sent to these services The plugin only downloads publicly available IP range lists These requests happen server-side (not from visitors’ browsers) IP ranges are cached locally for 24 hours If the external service is unavailable, the plugin continues to work using User-Agent detection Bundled Libraries Chart.js v4.5.1 (bundled locally) * Used for dashboard visualizations * No external connections required * Loaded only on admin pages * License: MIT All third-party code is included in the plugin and does not require external CDN connections. Support & Documentation Getting Help If you need help with the plugin, here are your options: Documentation: Check the plugin settings page for inline help and tooltips WordPress Support Forum: Post your questions on the WordPress.org support forum Official Page: Visit https://almaweb.fr/ai-visitor-analytics for contact and support Reporting Bugs If you find a bug, please report it on the WordPress.org support forum with: * WordPress version * PHP version * Steps to reproduce the issue * Any error messages you’re seeing You can also contact us directly through our official page at https://almaweb.fr/ai-visitor-analytics Feature Requests We welcome feature suggestions! Please submit them on the WordPress.org support forum or contact us through https://almaweb.fr/ai-visitor-analytics Contributing This plugin is open source and welcomes contributions! Translation The plugin is available in French and English. To add a new language: Copy languages/almaweb-ai-visitor-analytics.pot Translate using Poedit or similar tool Save as almaweb-ai-visitor-analytics-{locale}.po and compile to .mo Contact us through https://almaweb.fr/ai-visitor-analytics to submit your translation Credits Developed by: Yohan Ziri Company: AlmaWeb (https://almaweb.fr) License: GPLv3 or later Special Thanks: * Chart.js for beautiful visualizations * The WordPress community for feedback and support * All users who help improve the bot detection library
Top keywords
- ai26×2.01%
- bots24×1.86%
- data21×1.63%
- ip19×1.47%
- openai16×1.24%
- bot12×0.93%
- almaweb11×0.85%
- https10×0.77%
- wordpress10×0.77%
- chatgpt9×0.70%
- detection9×0.70%
- etc8×0.62%
IronPhantom Antifraud
IronPhantom Antifraud brings AI-assisted fraud monitoring and bot defense to WooCommerce. The plugin works in a non-intrusive way by analyzing checkout, order, login, behavioral, and technical risk signals in real time. It helps identify risky behavior, compromised account indicators, suspicious IP patterns, automated activity, and session anomalies before they become a serious operational problem. IronPhantom is designed for merchants who want more visibility, more control, and less noise. Automated Provisioning IronPhantom is built for fast activation. After the merchant accepts the Privacy Policy and enables the service, the plugin can automatically generate a unique API Key linked to the store domain and connect the WooCommerce installation to the MGFirewallAI SaaS environment. No risk analysis data is sent to MGFirewallAI until the merchant accepts the Privacy Policy and activates the service. Smart Correlation Engine Traditional fraud tools often generate too much noise. IronPhantom focuses on correlated risk signals instead of isolated events. The dashboard is designed to highlight the most relevant suspicious transactions, where multiple indicators suggest a concrete risk. Examples of correlated signals may include: Anonymous or high-risk IP address Email address associated with previous data breaches Password exposure indicator using privacy-preserving checks where applicable Repeated checkout attempts Suspicious user-agent or device behavior Behavioral patterns compatible with automation Unusual order or session activity Technical signals related to suspicious sessions or checkout abuse This helps merchants focus on the cases that actually require attention. Decision Support, Not Automatic Checkout Blocking IronPhantom is designed to support merchant decisions, not replace them blindly. By default, the plugin does not automatically block the WooCommerce checkout. This reduces the risk of false positives damaging legitimate sales. IronPhantom is intended to support the merchant before order fulfillment and shipping. When a suspicious transaction is detected, the plugin provides risk context and supporting signals so the merchant can make a more informed decision before dispatching the product. IronPhantom does not automatically block payments, cancel orders, refund orders, or stop shipments. Any decision to approve, review, verify, hold, cancel, refund, or ship an order remains under the merchant’s control and responsibility. Instead, IronPhantom provides clear risk signals, context, and decision-support information so the merchant can decide whether to approve, review, verify, hold, refund, cancel, or ship an order. Advanced mitigation features may be available in future paid or Pro plans, depending on the configuration enabled by the merchant. Merchant Decision Responsibility IronPhantom provides risk intelligence, alerts, and decision-support information. The plugin does not make final business decisions on behalf of the merchant. Decisions such as approving, holding, verifying, refunding, cancelling, or shipping an order remain entirely under the merchant’s control and responsibility. Risk scores, alerts, provider responses, and behavioral signals are intended to support review workflows and should not be considered a guarantee that an order is fraudulent or safe. Behavioral AI Sensor IronPhantom includes an optional behavioral sensor that can monitor interaction patterns such as mouse movement, scroll behavior, click timing, session duration, and technical browser signals. The sensor is designed to help detect patterns compatible with: Bot activity Card testing attempts Credential stuffing Automated checkout abuse Suspicious session behavior Abnormal interaction patterns The Behavioral AI Sensor is disabled by default and can be enabled manually from the IronPhantom dashboard after the merchant has reviewed the privacy information and service settings. The sensor is designed to analyze behavioral and technical patterns. It is not intended to record payment card numbers, CVV codes, plain-text passwords, or the content of private form fields. In the current testing phase, the sensor may operate in monitoring mode. Advanced mitigation and active response features may be introduced in future paid or Pro plans. Identity Verification Workflow For high-risk cases or high-value orders, IronPhantom can support an identity verification workflow through Didit. Identity verification is handled externally by Didit. IronPhantom does not process or store identity documents, facial recognition data, biometric data, or government document images. IronPhantom receives only the limited verification result/status required to support the merchant’s risk decision. Identity verification features may be limited, disabled, or reserved for future paid or Pro plans depending on the current service configuration. Testing Phase IronPhantom is currently available for testing and evaluation. During this phase, merchants may be able to test the plugin and its connected MGFirewallAI risk intelligence features without payment. Future paid plans may introduce additional features, extended limits, advanced mitigation, identity verification workflows, and enhanced dashboard capabilities. Key Features AI-Assisted Risk Intelligence – Detect suspicious order, login, checkout, behavioral, and technical risk signals. Behavioral AI Sensor – Optional sensor for interaction-based bot and automation detection, disabled by default. Smart Risk Dashboard – Shows priority transactions where multiple signals indicate a meaningful risk. Bot & Card Testing Detection – Helps detect patterns compatible with automated checkout abuse and repeated payment attempts. Credential Risk Signals – Supports checks related to compromised emails and password exposure indicators. External Risk Intelligence – Supports integrations with providers such as FraudLabs Pro, ProxyCheck, and Have I Been Pwned, where configured. Identity Verification Support – Optional workflow through Didit for high-risk cases, where available. Decision Support Mode – Helps merchants decide without automatically interrupting legitimate customers. Pre-Fulfillment Review Support – Helps merchants review suspicious orders before shipping products. GDPR-First Approach – Built with data minimization, pseudonymization where applicable, and privacy-aware processing. SaaS Architecture – Keeps heavy analysis outside the WordPress installation. Testing Mode Availability – Current testing access may be available without payment while the service is being evaluated. Privacy & Data Security IronPhantom follows a Privacy by Design approach. The system is designed to process only the data required for fraud prevention, bot detection, security monitoring, and risk intelligence. No risk analysis data is sent to MGFirewallAI until the merchant accepts the Privacy Policy and activates the service. The Behavioral AI Sensor is disabled by default and must be enabled manually by the merchant from the dashboard. Data Used for Risk Analysis Depending on the plugin configuration and WooCommerce event, IronPhantom may process limited technical, behavioral, and transactional metadata such as: Order ID or transaction reference Store domain or merchant identifier Email address or pseudonymized identifier where applicable IP address Order amount Timestamp Browser and user-agent information Session and technical metadata Behavioral sensor signals, if enabled Risk-related status returned by external providers Behavioral Sensor Data If enabled by the merchant, the Behavioral AI Sensor may process interaction and technical signals such as: Mouse movement patterns Scroll behavior Click timing Session duration Browser and user-agent signals Technical indicators related to automation or abnormal sessions The sensor is intended to analyze behavioral patterns and technical signals. It is not intended to record payment card numbers, CVV codes, plain-text passwords, or the content of private form fields. Payment Data IronPhantom does not process, collect, transmit, or store: Full payment card numbers CVV codes Full payment credentials Plain-text passwords Banking credentials Payment processing remains handled by the store’s payment gateway or WooCommerce payment provider. Didit Identity Verification For high-risk cases or high-value orders, IronPhantom can support an identity verification workflow through Didit, where available. Identity verification is handled externally by Didit. During the 5-day Pro trial period, the “Verify User” button and the identity verification workflow through Didit are available for testing. Identity verification is available during the 5-day Pro trial and with an active Pro subscription. IronPhantom does not store: Identity document images Facial recognition data Biometric data Government ID files Liveness check media IronPhantom receives only the limited verification result/status needed to support the merchant’s fraud review process. External Intelligence Providers IronPhantom may use external providers such as: FraudLabs Pro ProxyCheck Have I Been Pwned Didit These integrations are used only for security, fraud prevention, identity verification, and risk validation purposes, as described in the Privacy Policy. Availability of specific integrations may depend on the current configuration, testing phase, or future paid service plan. WordPress Database Impact IronPhantom is designed as a SaaS-based solution. Heavy analysis is handled outside the WordPress installation, helping keep the local WordPress environment lighter and focused on essential plugin settings, status information, and relevant risk summaries.