Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions cdn-files/plugin-info.json
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
{
"name": "WebDecoy Bot Detection",
"slug": "webdecoy",
"version": "2.9.1",
"version": "2.10.0",
"author": "<a href=\"https://webdecoy.com\">WebDecoy</a>",
"author_profile": "https://webdecoy.com",
"requires": "6.1",
"tested": "7.1",
"requires_php": "7.4",
"download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.9.1.zip",
"download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.10.0.zip",
"sections": {
"description": "<p>WebDecoy provides enterprise-grade bot detection and fraud protection for WordPress websites. Unlike simple CAPTCHA solutions, WebDecoy uses a layered defense approach that analyzes visitors from multiple angles — including deterministic tripwires that catch scanners with zero false positives.</p><h4>Key Features</h4><ul><li>Deterministic tripwires (hidden honeypot paths) — zero-false-positive bot blocking</li><li>Server-side and client-side bot detection</li><li>Invisible proof-of-work challenge (no external CAPTCHA service)</li><li>Comment, login, and registration spam protection</li><li>WooCommerce carding attack prevention</li><li>60+ good bots automatically allowed</li><li>AI crawler detection and blocking</li><li>Optional WebDecoy Cloud: centralized dashboard, rotation-proof device lockouts, and WAF integrations (push confirmed attackers to Cloudflare or AWS WAF — blocked before they reach WordPress)</li></ul>",
"installation": "<ol><li>Upload the plugin files to <code>/wp-content/plugins/webdecoy</code></li><li>Activate the plugin through the Plugins menu</li><li>Tripwires and local protection are active out of the box — no API key required</li><li>Optionally go to WebDecoy &gt; Settings &gt; WebDecoy Cloud to connect for centralized monitoring and enforcement</li></ol>",
"changelog": "<h4>2.9.1</h4><ul><li>Fixed: AI search crawlers and assistants fetching a page for a person are no longer identified as AI training crawlers (Claude-User, Claude-SearchBot, MistralAI-User; PerplexityBot is now a search crawler, as Perplexity documents it).</li><li>Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are let through like other AI search crawlers. Assistants fetching for a person, such as ChatGPT-User and Claude-User, are still refused.</li><li>Added: Perplexity-User, MistralAI-User, Meta-ExternalFetcher and Claude-SearchBot are recognised (186 crawlers).</li></ul><h4>2.9.0</h4><ul><li>Added: per-path crawler rules set in WebDecoy Cloud now apply in WordPress too, by the same rule the edge sensor uses. Cloud rules can only refuse, never allow.</li><li>Changed: crawlers are identified from the shared WebDecoy registry (182, was 54); with Block AI crawlers on, AI agents and assistants are refused along with training crawlers.</li></ul><h4>2.3.1</h4><ul><li>Fixed: Detections forwarded from your site are now identified by the visitor's own request signature. Previously they were identified by your server's outgoing connection, which is the same for every visitor — so every visitor a site reported was grouped into a single &quot;actor&quot; in the dashboard. Only request header names plus Accept-Language and Accept-Encoding are sent; no header values leave your site.</li></ul><h4>2.3.0</h4><ul><li>One-click WebDecoy Cloud connect with automatic key provisioning</li><li>Monthly security report opt-in</li><li>Plan entitlements sync (fails open to free)</li><li>Fixed: Statistics charts growing unbounded with detection data</li></ul><h4>2.1.0</h4><ul><li>JS execution verification to catch non-JS HTTP scrapers</li><li>Challenge token meta tag on page serve; automatic page-serve reporting</li></ul><h4>2.0.0</h4><ul><li>All detection and protection now works locally — no API key required</li><li>Invisible proof-of-work challenge system (SHA-256, no external service)</li><li>Behavioral scoring, statistics page, enhanced detections page</li></ul><h4>1.3.0</h4><ul><li>Bulk IP blocking/unblocking; enhanced good bot detection (60+ bots)</li></ul>",
"changelog": "<h4>2.10.0</h4><ul><li>Added: when connected to WebDecoy Cloud, the plugin counts visits that AI products such as ChatGPT, Claude, Perplexity and Gemini send to your site, for your AI Traffic page. Only the product name, the landing path and a count are sent; nothing about the visitor.</li></ul><h4>2.9.1</h4><ul><li>Fixed: AI search crawlers and assistants fetching a page for a person are no longer identified as AI training crawlers (Claude-User, Claude-SearchBot, MistralAI-User; PerplexityBot is now a search crawler, as Perplexity documents it).</li><li>Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are let through like other AI search crawlers. Assistants fetching for a person, such as ChatGPT-User and Claude-User, are still refused.</li><li>Added: Perplexity-User, MistralAI-User, Meta-ExternalFetcher and Claude-SearchBot are recognised (186 crawlers).</li></ul><h4>2.9.0</h4><ul><li>Added: per-path crawler rules set in WebDecoy Cloud now apply in WordPress too, by the same rule the edge sensor uses. Cloud rules can only refuse, never allow.</li><li>Changed: crawlers are identified from the shared WebDecoy registry (182, was 54); with Block AI crawlers on, AI agents and assistants are refused along with training crawlers.</li></ul><h4>2.3.1</h4><ul><li>Fixed: Detections forwarded from your site are now identified by the visitor's own request signature. Previously they were identified by your server's outgoing connection, which is the same for every visitor — so every visitor a site reported was grouped into a single &quot;actor&quot; in the dashboard. Only request header names plus Accept-Language and Accept-Encoding are sent; no header values leave your site.</li></ul><h4>2.3.0</h4><ul><li>One-click WebDecoy Cloud connect with automatic key provisioning</li><li>Monthly security report opt-in</li><li>Plan entitlements sync (fails open to free)</li><li>Fixed: Statistics charts growing unbounded with detection data</li></ul><h4>2.1.0</h4><ul><li>JS execution verification to catch non-JS HTTP scrapers</li><li>Challenge token meta tag on page serve; automatic page-serve reporting</li></ul><h4>2.0.0</h4><ul><li>All detection and protection now works locally — no API key required</li><li>Invisible proof-of-work challenge system (SHA-256, no external service)</li><li>Behavioral scoring, statistics page, enhanced detections page</li></ul><h4>1.3.0</h4><ul><li>Bulk IP blocking/unblocking; enhanced good bot detection (60+ bots)</li></ul>",
"faq": "<h4>Does WebDecoy slow down my site?</h4><p>No. WebDecoy adds negligible latency; tripwire checks are a fast path lookup and clearance minting is idle-deferred.</p><h4>Will it block search engines?</h4><p>No. WebDecoy automatically allows 60+ known good bots including all major search engines, and tripwires only fire on hidden paths no legitimate crawler follows.</p>"
},
"icons": {
Expand Down
4 changes: 4 additions & 0 deletions changelog.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
*** WebDecoy Bot Detection Changelog ***

= 2.10.0 - 2026-09-24 =
* Added: AI referral counting. When the site is connected to WebDecoy Cloud, a page visit whose referrer (or, without one, whose campaign tags) names an AI product such as ChatGPT, Claude, Perplexity or Gemini adds one to a count for that product and the landing page's path. The counts are sent to WebDecoy every fifteen minutes and appear on the AI Traffic page. Only the product name, the path and the count are sent; nothing about the visitor is stored or sent. Only a browser loading a page counts, and pages served from a full-page cache never reach the plugin, so the figure is a floor. Turn it off with the webdecoy_count_ai_referrals filter.
* Internal: the AI platform table and the vectors the classifier is tested against are generated from WebDecoy's own classifier, like the crawler registry.

= 2.9.1 - 2026-09-24 =
* Fixed: AI search crawlers and assistants that fetch a page for a person are no longer identified as AI training crawlers. Matching is by name with training crawlers checked first, and two over-broad names caught other crawlers: every Anthropic crawler identifies itself with an anthropic.com address, so Claude-User and Claude-SearchBot matched a legacy Anthropic training crawler, and MistralAI-User matched a Mistral training crawler the same way. PerplexityBot is now classified as a search crawler, as Perplexity documents it (not used for training). A cloud path rule that refuses AI training crawlers no longer refuses them.
* Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are now let through like other AI search crawlers; OAI-SearchBot already was. Assistants and agents fetching a page for a person, such as Claude-User, ChatGPT-User and the newly recognised Perplexity-User, are still refused under this setting.
Expand Down
5 changes: 4 additions & 1 deletion readme.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Donate link: https://webdecoy.com
Tags: bot detection, security, spam protection, woocommerce, ai bots
Requires at least: 6.1
Tested up to: 7.1
Stable tag: 2.9.1
Stable tag: 2.10.0
Requires PHP: 7.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
Expand Down Expand Up @@ -285,6 +285,9 @@ The bundled good-bot list (sdk/src/GoodBotList.php) stores a documentation URL f

== Changelog ==

= 2.10.0 =
* Added: when connected to WebDecoy Cloud, the plugin counts visits that AI products such as ChatGPT, Claude, Perplexity and Gemini send to your site, so they appear on your AI Traffic page. Only the AI product's name, the landing page's path and a count are sent, every fifteen minutes; nothing about the visitor. Pages served from a full-page cache are not counted. Turn it off with the webdecoy_count_ai_referrals filter.

= 2.9.1 =
* Fixed: AI search crawlers and assistants that fetch a page for a person are no longer identified as AI training crawlers. Claude-User, Claude-SearchBot and MistralAI-User were matched as training crawlers, and PerplexityBot is now classified as the search crawler Perplexity documents it as. A cloud path rule that refuses AI training crawlers no longer refuses them.
* Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are now let through like other AI search crawlers (OAI-SearchBot already was). Assistants and agents fetching for a person, such as Claude-User and ChatGPT-User, are still refused.
Expand Down
4 changes: 2 additions & 2 deletions webdecoy.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
* Plugin Name: WebDecoy Bot Detection
* Plugin URI: https://webdecoy.com/wordpress
* Description: Protect your WordPress site from bots, spam, and carding attacks with WebDecoy's advanced threat detection.
* Version: 2.9.1
* Version: 2.10.0
* Requires at least: 6.1
* Requires PHP: 7.4
* Author: WebDecoy
Expand Down Expand Up @@ -41,7 +41,7 @@ function str_starts_with(string $haystack, string $needle): bool
}

// Plugin constants
define('WEBDECOY_VERSION', '2.9.1');
define('WEBDECOY_VERSION', '2.10.0');
define('WEBDECOY_PLUGIN_FILE', __FILE__);
define('WEBDECOY_PLUGIN_DIR', plugin_dir_path(__FILE__));
define('WEBDECOY_PLUGIN_URL', plugin_dir_url(__FILE__));
Expand Down
Loading