
內容簡介
Blockbots 外掛能有效保護您的 WordPress 網站免受機器人、爬蟲和垃圾流量的侵擾。它過濾不必要的自動請求,同時不影響真實訪客和可信搜尋引擎爬蟲的正常訪問。
【主要功能】
• 過濾已知的壞機器人
• 保護登入頁面,防止暴力破解
• 忽略已登入用戶的驗證
• 實時雲端保護,使用持續更新的資料庫
• 深度機器人檢測,識別行為特徵
• 允許自定義用戶代理
外掛標籤
開發者團隊
原文外掛簡介
Blockbots protects your WordPress site from bots, scrapers, and spam traffic. It filters unwanted automated requests while letting real visitors and trusted search engine crawlers through without interruption.
Local Protection (no account required)
Filter Known Bad Bots — Block malicious bots while allowing legitimate crawlers (Google, Bing, Facebook, Twitter, and more).
Protect Login Page — Add bot filtering to wp-login.php to stop brute-force and credential-stuffing attacks.
Ignore Logged-In Users — Skip verification for authenticated users so their experience is never affected.
Allowed User Agents — Add custom user agents that should always be allowed through (one per line).
BlockBots Cloud Service (cloud account required)
Blockbots can connect to the BlockBots cloud service to perform advanced bot detection remotely. When your cloud API key is configured, the plugin acts as a thin client — visitor requests are analysed by BlockBots servers and a verification decision is returned to your site.
Bot detection, fingerprinting, and traffic analysis all happen on BlockBots infrastructure, not on your server.
Cloud-based capabilities managed from your BlockBots cloud account:
Real-Time Cloud Protection — Block bots in real time using a continuously updated cloud database.
Deep Bot Detection — Identify bots by behavioral signatures and browser fingerprinting.
VPN Detection — Identify visitors connecting through VPN services.
Proxy Detection — Detect connections routed through proxy servers.
Emulator Detection — Identify headless browsers and browser emulators.
Cloud Account Panel — Manage allowed countries, custom rules, bot signatures, and traffic analytics from your BlockBots cloud account at panel.blockbots.org.
Connect your cloud account at blockbots.org.
External Services
This plugin loads the BlockBots SDK from the BlockBots CDN in order to provide cloud-based bot protection and browser fingerprint analysis.
The SDK is required because the bot detection engine is maintained and updated remotely as part of the BlockBots cloud service.
This plugin connects to the BlockBots cloud service when a cloud API key is configured.
Why the service is required:
Bot fingerprinting, behavioral analysis, VPN/proxy detection, and real-time threat database lookups require server-side infrastructure that cannot run inside a WordPress plugin. These functions are performed by BlockBots servers and the results are returned to your site.
What processing happens remotely:
When cloud protection is active and a visitor has not yet been verified, the plugin presents a verification page. The BlockBots JavaScript SDK communicates with BlockBots servers to analyse visitor signals and determine whether the visitor is a legitimate human or a bot. Verified visitors receive a signed JWT session cookie; subsequent requests are validated locally without contacting the cloud service again.
What data is transmitted:
* Visitor IP address
* Browser signals collected by the BlockBots JavaScript SDK (fingerprint data)
* Your site domain name
* Your BlockBots cloud API key (used to authenticate requests)
When data is transmitted:
Data is only sent to BlockBots servers when cloud protection is active and a visitor has not yet been verified. Logged-in WordPress users and whitelisted bots are never submitted to the cloud service.
Service status checks:
When a cloud API key is configured, the plugin contacts BlockBots servers twice daily to verify that the cloud service connection is functioning correctly. This check transmits your API key and domain name only.
Service endpoints used:
* Cloud verification: https://blockbots.org/ and subdomains
* Service status check: https://panel.blockbots.org/api/service/status
* Cloud account panel: https://panel.blockbots.org
Terms of Service: https://blockbots.org/terms-of-service
Privacy Policy: https://blockbots.org/privacy
This plugin does not store visitor personal data in the WordPress database.
