PSB Bot Traffic Controller sits in front of your WordPress site and classifies incoming traffic
into five bot categories:
Each category can be configured independently to block (HTTP 403), rate-limit (HTTP 429 once
a configurable per-hour threshold is exceeded), or allow traffic. A global safety-net cap also
applies to all detected bot traffic regardless of per-category policy.
Detection runs via a free, zero-dependency regex/User-Agent pattern engine by default, curated
from third-party bot-pattern data (see Credits below). An optional WURFL.js-based detection
engine can be enabled for higher accuracy.
For performance, bot interception runs as early as possible via a small mu-plugin installed
automatically into wp-content/mu-plugins/ — this avoids the cost of a full WordPress
bootstrap for traffic that ends up being blocked.
The bundled bot-pattern data (includes/detection/regex/data/bot-patterns.php) is built from
three third-party sources, each under a GPL-compatible license:
No code from these projects is bundled — only pattern/name/category data, transformed at build
time (tools/cmd/build-patterns) into this plugin’s own runtime format.
This plugin makes no outbound HTTP requests and does not integrate with any third-party or
external service. Earlier versions of the bundled pattern data included a per-signature
producer field (an attribution URL crediting the upstream source of each entry); it has been
removed entirely, since it was never fetched or otherwise dereferenced by the plugin at
runtime.