JTZL's Bot Maze
JTZL’s Bot Maze protects your WordPress site from unwanted AI crawlers and scrapers by planting invisible trap links that only bots will follow. When a bot enters the trap maze, it gets lost in an ever-expanding maze of realistic-looking fake pages while it quietly builds a suspicion score based on its behavior. How it works: Trap link injection — Invisible links are added to your real pages. Legitimate visitors never see them, but bots following every link on the page will enter the trap maze. Lazy maze generation — Trap pages link to more trap pages, generated on demand. The deeper a bot goes, the more time it wastes. Bot scoring — Each trap page visit adds suspicion points. Deeper traversal earns bonus points. Once a threshold is reached, the visitor is flagged as a bot. Blocking and tarpitting — Flagged bots can be blocked outright (403), served decoy pages (light tarpit), or slowed down with a deliberate delay (full tarpit). Crawler verification — Known search engine crawlers (Googlebot, Bingbot, etc.) are verified via reverse DNS and exempted from scoring. Features: Zero impact on legitimate visitors — trap links are hidden from humans and search engines Configurable injection method (content, footer, or both) Adjustable scoring thresholds and blocking behavior robots.txt integration to signal trap paths as disallowed Analytics dashboard showing bot activity, top IPs, and score distribution Blocked Bots detail page showing full user agent, score, visit history Optional comprehensive tracking mode to monitor blocked bot persistence Automatic log retention and maintenance via WP-Cron Privacy policy suggestion for GDPR compliance Geographic heat map of bot activity by country with two GeoIP provider options MaxMind GeoLite2 local database — all lookups on your server, GDPR-friendly (recommended) ip-api.com external API — simple setup, no license key required Optional AbuseIPDB reporting for eligible blocked public IP addresses, with a one-press catch-up for blocked bots that carry no report yet Lightweight — minimal footprint, geographic tracking is fully optional Third-Party Services Every external service listed below is optional and off by default. No data is sent to any of them unless a site administrator explicitly enables the corresponding feature. MaxMind GeoLite2 (Recommended) When MaxMind GeoLite2 is selected as the GeoIP provider (Settings > Bot Maze > Geographic Tracking), the plugin downloads the GeoLite2-Country database from MaxMind and performs all IP-to-country lookups locally. No visitor data leaves your server. What is downloaded: The GeoLite2-Country database (~60 MB), downloaded weekly via WP-Cron from download.maxmind.com. What is sent to MaxMind: Only your license key during database downloads. No visitor IP addresses are shared. Requires: A free MaxMind license key from maxmind.com/en/geolite2/signup. Service website: https://www.maxmind.com License: GeoLite2 databases are licensed under CC BY-SA 4.0. Terms of service: https://www.maxmind.com/en/geolite2/eula ip-api.com When ip-api.com is selected as the GeoIP provider, the plugin sends visitor IP addresses to ip-api.com to resolve their country of origin. This data is used to display a geographic heat map of bot activity in the admin dashboard. What is sent: The visitor’s IP address only, over unencrypted HTTP. When it is sent: At the time a trap page visit is recorded, only while this provider is selected. Service website: http://ip-api.com Terms of service: https://ip-api.com/docs/legal Privacy policy: ip-api.com does not log queries from the free API endpoint. Note: The free tier only supports HTTP (not HTTPS). If your site must comply with GDPR, use the MaxMind local database option instead. Geographic tracking is off by default and requires explicit opt-in by a site administrator. AbuseIPDB Reporting AbuseIPDB reporting is off by default. It requires explicit enablement plus an administrator-owned AbuseIPDB account and API key from the API dashboard. Protect the API key like a password. An address is queued for reporting in exactly three situations: A non-verified crawler’s persisted score crosses the configured blocking threshold. An address that is already blocked requests a trap page while reporting is on, which is fresh evidence it is still crawling the maze. An administrator presses the catch-up button on the Blocked Bots page, which covers blocked addresses AbuseIPDB has not accepted a report for, whatever the reason. Every queued address must also be publicly routable. Private, loopback, reserved, documentation and multicast addresses are never reported, because AbuseIPDB only accepts reports about addresses reachable on the public internet. Verified search engine crawlers are never scored in the first place, so they are never candidates. The catch-up in (3) reports each address against the time it was actually last seen, rather than the time the button was pressed, and covers addresses seen within your configured data retention period (Settings > Bot Maze > Maintenance, 30 days by default). That is the period you have declared this evidence meaningful for, and the same period after which the plugin deletes the record, so the catch-up offers exactly the blocked addresses your site still holds evidence for. It reports up to 500 addresses per press. In all three cases the report sends only the public IP address, category 19 (Bad Web Bot), the time of the observation being reported, and a generic explanation for security reporting. It sends these four fields over HTTPS to the AbuseIPDB service. It never sends the user agent, referrer, trap URL, session, score, or traversal depth. The plugin limits reports to once per IP address in any 24-hour period. A queued report that cannot be delivered for seven days is abandoned. Delivery runs in the background through WP-Cron, so reports may wait on low-traffic sites and are not real-time. Disabling reporting or clearing the key stops delivery and deletes queued reports. The current free Individual plan includes 1,000 IP checks and reports per day. See AbuseIPDB pricing; your account limit may differ. Review AbuseIPDB’s terms and privacy policy before enabling reporting. Cloudflare IP Ranges When the Trusted Client IP Header is set to Cloudflare (CF-Connecting-IP) (Settings > Bot Maze > Trusted Proxy), the plugin fetches Cloudflare’s published edge IP range lists from cloudflare.com to keep the trusted-proxy allowlist current without any manual action. What is requested: Two public plain-text files — cloudflare.com/ips-v4 and cloudflare.com/ips-v6 — fetched weekly via WP-Cron. What is sent: No visitor or user data. The HTTP request reveals only your server’s own IP address to Cloudflare. Service website: https://www.cloudflare.com Terms of service: https://www.cloudflare.com/terms/ This fetch only runs while the Cloudflare trusted client IP header is selected. If the fetch fails validation, the previously stored list (or a bundled fallback) is kept — a failed response never narrows or widens the trusted set.
Top keywords
- com16×1.45%
- bot13×1.18%
- ip12×1.09%
- trap12×1.09%
- maxmind11×1.00%
- cloudflare10×0.91%
- abuseipdb9×0.82%
- addresses9×0.82%
- blocked9×0.82%
- maze9×0.82%
- only9×0.82%
- address8×0.73%
Cloud Maestro – WAF Security Suite for Cloudflare
Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress. Why would I use a plugin when I can create rules in Cloudflare? If you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin. It’s useful for someone managing: – Their own sites and client sites – Multiple businesses – Separate Cloudflare accounts People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly. The free version supports one Cloudflare account with multiple domains. An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once. 🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare? Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to: Deploy in One Click – Apply comprehensive WAF rules to multiple domains simultaneously Save Time – No more manually configuring rules on each domain, one at a time Enterprise Security – Protect against bots, aggressive crawlers, malicious IPs, and common threats Reduce Mistakes – Maintain consistent security rules across domains ✅ Free Standard Features One Cloudflare account Multiple domains One-click WAF rule deployment Centralized Cloudflare controls Secure API credential storage (AES-256-CBC encryption) Plugin updates The free plugin does not require an upgrade. 🔥 What Gets Protected The plugin deploys 3 optimized trusted security rules (prior versions used 5) that work together to protect your sites: Good Bot Allowlist – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site Managed Challenges for Suspicious Traffic – Automatically challenges requests from certain ASNs and non-US traffic Aggressive Crawler Protection – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.) VPN & Login Protection – Adds extra challenges for VPN traffic and WordPress login attempts Block Known Threats – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors ✨ Premium Upgrade (Optional) For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. Check out our free trial for these features: Multi-Account Management – Automatically manage domains across ALL your Cloudflare accounts Easy Bot Whitelisting – Built-in checkboxes for 50+ trusted services across 8 categories Custom User Agents – Add your own user agent strings to the Good Bot Rule Custom IP Whitelisting – Add trusted IP addresses to the Goot Bot Rule IP Rules management – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks) Bulk DNS Management – Search and manage all Cloudflare DNS record types across all domains, bulk migrate exact old/new values with confirmation modals, and convert A records to CNAME with a single action DNS Manager Reliability – Full record visibility for MX/TXT and other record types, cleaner cache warm-up modal flow, and safer bulk migration previews that only list actual matches Priority Support – Get expert help when you need it Advanced Customization – Fine-tune rules to match your exact requirements Multi-Account Management – Centrally manage unlimited domains across all your Cloudflare accounts 📋 Important Information Rule Replacement: This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep. Compatibility: Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers. Service Monitoring: These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.