Descrição
Every website is visited daily by bots that look for leaks: forgotten backups, .env files, exposed Git folders, old admin tools and weak passwords. BotZoom recognises these bots and blocks them before they find anything.
What the free version does
- Blocks IPs that request files only attackers look for, such as
.env,.git,wp-config.phpbackups and database dumps. - Blocks known scan and attack tools such as sqlmap, Nikto and WPScan.
- Stops brute-force attacks on the login page and XML-RPC.
- Stops bots that hammer your site with requests for pages that do not exist (404 flood).
- Keeps a local log and lets you block or unblock IP addresses yourself.
- Never blocks logged-in users or verified search engines (Google, Bing, Apple, Yandex, DuckDuckGo), so your SEO is safe.
- Everything runs on your own site. Nothing is sent to an external service.
BotZoom Pro
BotZoom Pro connects all your websites to one central panel: WordPress, Joomla and other PHP sites. An IP that attacks one of your sites is blocked on all of them, suspicious IPs are checked against AbuseIPDB and blocks are applied at server level, before WordPress even loads. Read more at botzoom.nl.
BotZoom is made by WNED, a Dutch web hosting company.
Instalação
- Install BotZoom from Plugins > Add New, or upload the plugin folder to
/wp-content/plugins/. - Activate the plugin.
- Click BotZoom in the admin menu to check the settings. The defaults work for most sites.
FAQ
-
Can I lock myself out?
-
No. Logged-in users are never blocked. If you are blocked while logged out, for example after mistyping your password too often, wait until the block expires or ask someone with access to unblock your IP under BotZoom > Blocked IPs. You can also add your own IP address under “Never block”.
-
Does BotZoom block Google?
-
No. Visitors that claim to be a search engine are verified with a reverse and forward DNS check. Verified crawlers are never blocked.
-
My site runs behind Cloudflare or another proxy
-
Set “Visitor IP from” to the header your proxy uses, for example
HTTP_CF_CONNECTING_IPfor Cloudflare. Only change this if your site really runs behind that proxy, otherwise attackers can fake their IP address. -
Does BotZoom protect against DDoS attacks?
-
No. Protection against DDoS attacks is handled by the firewall of your hosting provider. BotZoom is an extra layer against bots that search your site for leaks and vulnerabilities.
-
What data does BotZoom store?
-
For each blocked request: the IP address, time, requested URL and user agent. This data stays in your own database, is used only for security and is deleted automatically after the retention period you set (30 days by default). BotZoom adds a suggested text to your privacy policy under Settings > Privacy.
-
Is all data removed when I delete the plugin?
-
Yes. Deleting the plugin removes its database tables and settings.
Avaliações
There are no reviews for this plugin.
Contribuidores e desenvolvedores
“BotZoom” é um software com código aberto. As seguintes pessoas contribuíram para este plugin.
ContribuidoresTraduzir “BotZoom” para o seu idioma.
Interessado no desenvolvimento?
Navegue pelo código, dê uma olhada no repositório SVN ou assine o registro de desenvolvimento via RSS.
Registro de alterações
1.0.0
- First release.
