diff --git a/cdn-files/plugin-info.json b/cdn-files/plugin-info.json index 61b1d4d..3e9d9fd 100644 --- a/cdn-files/plugin-info.json +++ b/cdn-files/plugin-info.json @@ -1,17 +1,17 @@ { "name": "WebDecoy Bot Detection", "slug": "webdecoy", - "version": "2.9.0", + "version": "2.9.1", "author": "WebDecoy", "author_profile": "https://webdecoy.com", "requires": "6.1", "tested": "7.1", "requires_php": "7.4", - "download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.9.0.zip", + "download_url": "https://cdn.webdecoy.com/wordpress/webdecoy-2.9.1.zip", "sections": { "description": "
WebDecoy provides enterprise-grade bot detection and fraud protection for WordPress websites. Unlike simple CAPTCHA solutions, WebDecoy uses a layered defense approach that analyzes visitors from multiple angles — including deterministic tripwires that catch scanners with zero false positives.
/wp-content/plugins/webdecoyNo. WebDecoy adds negligible latency; tripwire checks are a fast path lookup and clearance minting is idle-deferred.
No. WebDecoy automatically allows 60+ known good bots including all major search engines, and tripwires only fire on hidden paths no legitimate crawler follows.
" }, "icons": { diff --git a/changelog.txt b/changelog.txt index f49277c..23fd495 100644 --- a/changelog.txt +++ b/changelog.txt @@ -1,5 +1,10 @@ *** WebDecoy Bot Detection Changelog *** += 2.9.1 - 2026-09-24 = +* Fixed: AI search crawlers and assistants that fetch a page for a person are no longer identified as AI training crawlers. Matching is by name with training crawlers checked first, and two over-broad names caught other crawlers: every Anthropic crawler identifies itself with an anthropic.com address, so Claude-User and Claude-SearchBot matched a legacy Anthropic training crawler, and MistralAI-User matched a Mistral training crawler the same way. PerplexityBot is now classified as a search crawler, as Perplexity documents it (not used for training). A cloud path rule that refuses AI training crawlers no longer refuses them. +* Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are now let through like other AI search crawlers; OAI-SearchBot already was. Assistants and agents fetching a page for a person, such as Claude-User, ChatGPT-User and the newly recognised Perplexity-User, are still refused under this setting. +* Added: Perplexity-User, MistralAI-User and Meta-ExternalFetcher (assistants fetching a page for a person) and Claude-SearchBot (an AI search crawler) are recognised. The registry now knows 186 crawlers. + = 2.9.0 - 2026-09-23 = * Added: per-path crawler rules set in WebDecoy Cloud now apply in WordPress too. If your site is connected and you have told WebDecoy to refuse, say, AI training crawlers on /premium/*, this plugin refuses them there as well, using the same rule the WebDecoy edge sensor uses. Watched paths and sites in Monitor count what would have been refused instead of refusing. The rules are read from WebDecoy twice daily and shown under the AI Crawlers setting; a copy older than two days is not applied. Precedence is simple: cloud rules can only refuse, never allow; Block AI crawlers still refuses site-wide; the custom allowlist exempts a bot from Block AI crawlers but not from a cloud path rule; and this plugin's monitor mode still gates every block. * Changed: known crawlers are now identified from the same crawler registry the WebDecoy dashboard and the other WebDecoy sensors use, instead of a list kept only in this plugin. A crawler is named the same thing here and in your reports. The registry knows 182 crawlers where the old list knew 54, so more search engines (Naver, Seznam, Ecosia, Mojeek and others), more AI crawlers (ByteSpider, Mistral, YouBot and others) and more link-preview, monitoring, SEO and feed services are recognised as what they are. diff --git a/readme.txt b/readme.txt index d081972..9af2886 100644 --- a/readme.txt +++ b/readme.txt @@ -4,7 +4,7 @@ Donate link: https://webdecoy.com Tags: bot detection, security, spam protection, woocommerce, ai bots Requires at least: 6.1 Tested up to: 7.1 -Stable tag: 2.9.0 +Stable tag: 2.9.1 Requires PHP: 7.4 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html @@ -284,6 +284,11 @@ The bundled good-bot list (sdk/src/GoodBotList.php) stores a documentation URL f == Changelog == += 2.9.1 = +* Fixed: AI search crawlers and assistants that fetch a page for a person are no longer identified as AI training crawlers. Claude-User, Claude-SearchBot and MistralAI-User were matched as training crawlers, and PerplexityBot is now classified as the search crawler Perplexity documents it as. A cloud path rule that refuses AI training crawlers no longer refuses them. +* Changed: with Block AI crawlers on, PerplexityBot and Claude-SearchBot are now let through like other AI search crawlers (OAI-SearchBot already was). Assistants and agents fetching for a person, such as Claude-User and ChatGPT-User, are still refused. +* Added: Perplexity-User, MistralAI-User, Meta-ExternalFetcher and Claude-SearchBot are recognised (186 crawlers). + = 2.9.0 = * Added: per-path crawler rules set in WebDecoy Cloud now apply in WordPress too. Connect your site, protect a path in the WebDecoy dashboard and refuse, say, AI training crawlers on it, and this plugin refuses them there as well, by the same rule the WebDecoy edge sensor uses. Watched paths and sites in Monitor count what would have been refused. Cloud rules can only refuse, never allow; Block AI crawlers and the custom allowlist keep working as before. * Changed: known crawlers are identified from the same registry the WebDecoy dashboard uses (182 crawlers, was 54), so a crawler is named the same thing here and in your reports. With Block AI crawlers on, AI agents and assistants that browse for a person (ChatGPT-User, Claude-User and others) are refused along with training crawlers; add a specific one to the custom allowlist to let it through. diff --git a/webdecoy.php b/webdecoy.php index 2c2cb13..be0ef4b 100644 --- a/webdecoy.php +++ b/webdecoy.php @@ -3,7 +3,7 @@ * Plugin Name: WebDecoy Bot Detection * Plugin URI: https://webdecoy.com/wordpress * Description: Protect your WordPress site from bots, spam, and carding attacks with WebDecoy's advanced threat detection. - * Version: 2.9.0 + * Version: 2.9.1 * Requires at least: 6.1 * Requires PHP: 7.4 * Author: WebDecoy @@ -41,7 +41,7 @@ function str_starts_with(string $haystack, string $needle): bool } // Plugin constants -define('WEBDECOY_VERSION', '2.9.0'); +define('WEBDECOY_VERSION', '2.9.1'); define('WEBDECOY_PLUGIN_FILE', __FILE__); define('WEBDECOY_PLUGIN_DIR', plugin_dir_path(__FILE__)); define('WEBDECOY_PLUGIN_URL', plugin_dir_url(__FILE__));