WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: botblocker-security (Used by 49 domains)

BotBlocker Security – Firewall & Bot Protection

πŸ‘€ Yevhen Leonidov πŸ“¦ v1.6.15 πŸ”— Plugin Homepage

WordPress Security Plugin & Firewall (WAF)

Every day, automated bots and hackers bombard websites with attacks. Mass botnets, fake search engine crawlers, brute-force login attempts, and spam bots can overwhelm your WordPress site – stealing data, overloading your server, and defacing content. It’s a 24/7 threat to your business. If you’re looking for WordPress site protection, you need a proactive defense that stops these attacks before they reach your website.

BotBlocker Security is the all-in-one solution to keep your site safe from automated threats. This powerful WordPress security plugin and Web Application Firewall (WAF) acts as a dedicated anti-bot firewall, blocking malicious traffic at the front gate without slowing down your site.

BotBlocker’s setup and onboarding experience allows anyone to secure their WordPress site in under 1 minute, regardless of technical expertise. You can rest assured knowing you have enabled the right site protection settings to protect your website.

πŸ”₯ WordPress Firewall (WAF)

BotBlocker Security includes an endpoint firewall/WAF that identifies and blocks malicious traffic before it reaches WordPress. Built and maintained by a team focused 100% on WordPress security, our Web Application Firewall protects your site while reducing server load.

BotBlocker intercepts bad traffic at the earliest stage – even before WordPress or your theme loads. By running as a must-use plugin (MU-plugin) on early init, it blocks threats before WordPress initializes, drastically reducing server load during attacks.

Key Firewall Features:

  • Real-time firewall rule updates via the BotBlocker Threat Defense Feed
  • Real-time IP Blocklist blocks all requests from the most malicious IPs
  • Early-init protection – blocks threats before WordPress loads
  • Cloud-based threat intelligence – cross-checks every visitor against global threat databases
  • No visitor data collected – only technical request parameters analyzed (GDPR/CCPA-compliant)
  • Brute force protection with login attempt limits and multi-layer verification

πŸ“‘ WordPress Security Scanner & Site Protection

Every attempt to access your site is thoroughly analyzed and filtered. BotBlocker provides comprehensive site protection across all entry points:

  • XML-RPC and API Protection – all endpoints blocked by default. Create access rules for trusted services and add allowed URLs for payment plugins
  • Spam Prevention – spammers cannot connect to your site. Automatically block IP addresses that exceed spam comment thresholds
  • File Access Protection – theme and plugin files securely protected from unauthorized access
  • Deep Analysis – User-Agent, Accept-Language, GeoIP, PTR, DNSBL, cookies, browser fingerprint, AdBlock, Incognito detection
  • Network & Protocol Control – block obsolete HTTP/1.0 clients and disable IPv6 if not used. Cloudflare-aware protection blocks origin bypass attempts

πŸ”’ Login Security & 2FA

All login attempts pass through multi-layer filtering and CAPTCHA verification:

  • Two-Factor Authentication Support – 2FA enhanced login security for admin area. Backup codes for recovery access. Universal 2FA app support – works with Google Authenticator, Authy, etc.
  • Multi-layer CAPTCHA Protection – color buttons, animal images, floating shapes, floating math, Google reCAPTCHA v2/v3, and more. Any internal CAPTCHA can be combined with reCAPTCHA v3 for dual-layer protection
  • Brute Force Protection – configurable login attempt limits. Failed attempts trigger temporary bans, with escalating penalties for repeated failures
  • Advanced Anti-bot Challenges – proprietary CAPTCHA designed to be nearly impossible to bypass, even by AI-based anti-CAPTCHA services
  • Intelligent Ban System – failed CAPTCHA results in configurable ban periods. Repeated failures trigger 24-hour bans
  • Admin Access Simplification – special mechanism to ease site administrator login while maintaining security
  • XML-RPC Control – options including complete disabling

πŸ› οΈ Security Tools

Comprehensive tools to block attackers and monitor your site in real-time:

  • Advanced Blocking Rules – block by IP or build rules based on IP Range, Hostname, User Agent, Referrer, PTR record, ASN, country, city, and more
  • IP-PTR-Host Mismatch Detection – automatically detect and block fake crawlers (e.g., fake Googlebots)
  • Blacklist & Whitelist Management – instantly allow or block any IP, ASN, range, or User-Agent
  • Live Traffic Monitoring – see all traffic in real-time: robots, humans, 404 errors, logins/logouts, file requests, and content consumption
  • Server IP Identification – prevent lockouts by automatically identifying and protecting server IPs
  • Visual Dashboard – intuitive charts and stats showing blocked attacks, world map of threat origins, top offending IPs/countries
  • Detailed Security Log – every event logged with IP address, user agent, country, and blocking reason
  • Hide Login URL (Premium Addon)

⚑ Performance & Integration

BotBlocker’s robust defense won’t slow your site down – in fact, it often improves performance under attack:

  • Lightweight & Fast – negligible overhead in normal conditions. Reduces database and server load during attacks
  • Built-in Caching – Redis and Memcached support for high-traffic environments
  • Cache Plugin Compatibility – automatic DONOTCACHEPAGE + Cache-Control: no-store on verification pages. Works with WP Super Cache (PHP mode), W3 Total Cache, WP Rocket, LiteSpeed Cache, Hummingbird, and more. Server-level caches (Nginx FastCGI, Varnish, Cloudflare) may need a cookie-based bypass rule – see docs/CACHE-COMPATIBILITY.md
  • DDoS Protection Compatibility – automatic detection of JS-challenges from DDoS-Guard, Stormwall, and similar services. See docs/DDOS-COMPATIBILITY.md for advanced configuration
  • Seamless Compatibility – works with Cloudflare, CDN services, caching plugins, and optimizers
  • Full IPv6 Support – all security functions work with both IPv4 and IPv6
  • Server Optimization (Premium Addon) – additional performance enhancements for high-traffic sites

πŸ‘€ Easy Setup & User-Friendly Interface

You don’t have to be a security expert to use BotBlocker:

  • Quick Installation Wizard – step-by-step setup guide for configuration in under 1 minute
  • Intuitive Admin Panel – organized settings with clear descriptions and tooltips
  • Multilingual – translated into English, Spanish, German, French, Polish, Russian, Ukrainian, and more
  • No Conflicts – built following WordPress best practices, tested with recent WP versions
  • Adjustable Logging – configurable retention periods with time zone awareness and daylight saving support

Security first – BotBlocker’s on guard!

πŸ”₯ PRO Version

Upgrade to PRO for enhanced protection and performance features:

  • Real-time cloud threat intelligence checks against global databases
  • Hide login URL and protect against targeted attacks
  • Early-init (Before WordPress loads) filtering for maximum performance and security
  • Speed optimization features for high-traffic sites
  • Server optimization features for high-traffic sites
  • Priority support and updates
  • Access to premium add-ons

Features

Detection & Analysis

BotBlocker employs advanced multi-layer detection to identify and block threats:

Detection Mechanisms:

  • Local and cloud signature databases with real-time updates
  • IP reputation and blacklist checks with global threat intelligence
  • DNS-based and PTR lookups to detect fake crawlers
  • Heuristic and behavioral analysis for suspicious patterns
  • Browser fingerprint and feature mismatch detection
  • Header and protocol validation
  • JavaScript challenge and capability verification
  • Multi-layered CAPTCHA verification

Comprehensive Request Analysis:

  • Network & IP: Full IPv4/IPv6 support, blacklist/whitelist, country/GeoIP, ASN, hosting/VPN detection, TOR detection, PTR/DNSBL checks
  • Browser & Client: User-Agent validation, browser/OS/device detection, fingerprint analysis, headless browser detection, JavaScript/cookie support
  • Headers & Protocol: Accept-Language, Referer validation, HTTP version control, Cloudflare/proxy detection
  • Advanced Fingerprinting: Font rendering, WebGL, media devices, touch events, battery API, permissions, timing analysis, plugin verification

CAPTCHA Modes

Choose from various CAPTCHA types to protect your site:

  • Single Button – one-click verification for quick validation
  • Google reCAPTCHA v2 – standard image/checkbox challenge
  • Google reCAPTCHA v3 – invisible background scoring
  • BotBlocker Color CAPTCHA – select colored buttons challenge
  • BotBlocker Digits CAPTCHA – floating math challenge
  • BotBlocker Images CAPTCHA – animal image selection
  • BotBlocker Shapes CAPTCHA – floating shapes challenge
  • Hybrid Mode – combine any CAPTCHA with reCAPTCHA v3 for dual-layer protection

Additional Capabilities

  • Early-init & MU plugin support
  • Real-time cloud threat checks
  • Dynamic and graphical anti-bot challenges
  • Automatic logging with adjustable retention
  • Session tracking and verification
  • No visitor data collected β€” GDPR/CCPA-compliant (see FAQ for admin notification details)

Privacy

BotBlocker Security does not collect or process personal data of your visitors. All cloud analysis is performed on technical parameters only (IP, headers, User-Agent). No personally identifiable information is collected, stored, or transmitted to any external service.

Support and Documentation

License

This plugin is licensed under the GPLv2 or later. See LICENSE.txt for details.

Credits & Authors

BotBlocker Security is developed and maintained by GLOBUS.studio.

  • Concept, architecture & code – Yevhen Leonidov: https://leonidov.dev/
  • Code, code review – Andrii Lukashevych
  • Code, translations – Aleksandr Kinakh

BotBlocker Security – The first line of defense for your WordPress site.

DomainExposuresHeadersLast Checked
p*i*a*e*r*a*l.com βœ… F 2026-06-01 12:22:17
t*c*m*i*s*r*a*.com βœ… F 2026-06-01 07:13:58
s*u*i*h*a*p*o*e.com βœ… F 2026-05-29 15:31:54
d*f*e*c*y.com βœ… A 2026-05-28 08:23:25
a*t*p*c*m.com βœ… F 2026-05-27 20:26:02
i*f*s*i*c*s.com βœ… B 2026-05-27 11:36:48
i*f*g*m.com βœ… A 2026-05-26 14:37:44
h*n*y*t*r*.shop βœ… F 2026-05-26 06:07:44
b*u*o*p*r*v*d*v*.ru βœ… A 2026-05-25 13:02:16
e*o*m*t*k.com βœ… C 2026-05-24 18:31:34
d*e*r*s*i*l*d*y.com βœ… F 2026-05-23 03:37:31
v*g*n.ph βœ… F 2026-05-22 14:35:24
m*y*e*e*o*.ru βœ… A 2026-05-21 22:02:46
r*b*l*m.com βœ… F 2026-05-21 09:21:29
k*a*r.me βœ… F 2026-05-21 00:51:53
i*d*a*r*v*r*i*r*r*.org βœ… F 2026-05-19 14:48:41
b*r*b*l*o*i*u*.com βœ… F 2026-05-19 14:23:32
s*o*m*n*r*v*l.com βœ… F 2026-05-18 17:34:40
l*d*p*e*s*r*.nl βœ… F 2026-05-18 07:20:40
t*a*p*n*m*t*r*a*.com βœ… F 2026-05-18 01:13:34
v*n*l*o*e*.ru βœ… F 2026-05-16 06:06:08
a*p.g*o*u*.studio βœ… F 2026-05-16 05:06:55
s*o*o*u*.com βœ… D 2026-05-15 15:25:26
t*p*o*l*v*n.com βœ… F 2026-05-15 10:08:17
t*o*-*p*a*k*3*.ru βœ… F 2026-05-14 06:29:18
a*n*a*g*a*e*.com βœ… F 2026-05-13 13:13:03
t*p*-*e*l*.com βœ… F 2026-05-13 07:30:46
m*-*l*n*c*1*.ru βœ… F 2026-05-12 20:31:08
s*r*v*d*k*o*.ru βœ… F 2026-05-12 20:31:08
p*d*o*t*k*m.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
a*t*a*a*.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
k*m*r*v*.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
k*s*o*o*s*.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
s*b.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
v*k*a.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
r*b*n*k.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
h*b*r*v*k.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
u*a.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
i*h*v*k.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
n*.s*o*o*u*.com βœ… F 2026-05-12 19:54:50
w*t*e*m*d.com βœ… F 2026-05-12 19:54:45
e*b*s*y*k*t*b*a*d*.com βœ… D 2026-05-11 21:33:55
c*s*e*a*d*a.com βœ… C 2026-05-10 22:18:23
a*l*i*h*.ru βœ… F 2026-05-10 18:15:41
1*t*a*e*p*.com βœ… F 2026-05-08 16:08:41
o*m*n*.net βœ… D 2026-05-08 13:58:28
t*k*p*l*a.ru βœ… F 2026-05-08 08:31:29
s*n*e*n*k*6.com βœ… F 2026-05-03 16:09:12
c*s*a*d*a*i*d*e*.com βœ… F 2026-05-02 12:16:12

Top 50 Plugins

Plugin Count
elementor 1,754,320
contact-form-7 1,726,201
elementor-pro 1,023,432
woocommerce 799,034
revslider 604,515
jetpack 458,801
js_composer 422,662
wp-rocket 325,289
essential-addons-for-elementor-lite 282,799
gravityforms 257,929
complianz-gdpr 247,725
cookie-law-info 224,350
instagram-feed 223,021
google-site-kit 216,572
sitepress-multilingual-cms 215,492
google-analytics-for-wordpress 209,983
header-footer-elementor 205,639
elementskit-lite 198,592
bluehost-wordpress-plugin 189,609
gutenberg 158,792
cookie-notice 145,917
gutenberg-core 143,187
wpforms-lite 127,671
the-events-calendar 127,427
litespeed-cache 125,867
gtranslate 124,470
astra-sites 118,199
popup-maker 113,405
woocommerce-payments 111,119
tablepress 104,688
honeypot 94,265
astra-addon 93,304
coblocks 93,197
all-in-one-seo-pack 91,550
wp-smushit 91,448
duracelltomi-google-tag-manager 91,001
LayerSlider 89,759
bb-plugin 89,288
premium-addons-for-elementor 84,929
akismet 84,581
megamenu 83,847
cleantalk-spam-protect 82,420
mailchimp-for-wp 82,013
woocommerce-gateway-stripe 81,354
ml-slider 78,616
fusion-builder 77,853
ewww-image-optimizer 77,141
formidable 76,561
borlabs-cookie 76,319
wp-pagenavi 76,221

Top 50 Themes

Theme Count
hello-elementor 599,515
Divi 499,956
astra 415,349
flatsome 125,689
Avada 121,634
generatepress 116,522
pub 99,092
oceanwp 81,430
kadence 76,170
enfold 70,055
salient 65,396
twentyseventeen 54,728
bb-theme 54,320
twentytwentyfour 52,991
cocoon-master 51,730
h4 50,741
betheme 50,550
blocksy 49,223
dt-the7 44,884
twentytwentyfive 42,646
neve 38,282
Avada-Child-Theme 36,787
gox 32,884
woodmart 32,364
bridge 32,265
twentytwentyone 31,598
lightning 30,772
twentytwenty 29,387
swell 28,208
Impreza 25,646
bricks 25,293
twentytwentythree 23,684
Newspaper 22,719
twentytwentytwo 19,762
sydney 19,583
epik-redesign 19,297
uncode 18,579
voxel 17,877
twentysixteen 17,750
pro 17,574
storefront 17,445
extendable 14,540
Total 14,391
yith-wonder 13,973
kubio 13,880
hello-theme-child-master 12,968
factory-templates-4 12,761
themify-ultra 12,708
yootheme 12,563
hestia 12,439