Watrix Bot Guard

Watrix Bot Guard

Details
View on WordPress

Pages that hold a single form – a contact page, a quote request, a download gate – get hammered by scanners and spam bots. The first real damage is to your analytics: page views are inflated and you can no longer read what visitors actually do.

Watrix Bot Guard catches the source of that traffic with four kinds of rules and lets you decide how to deal with it:

  • Path flood – the same IP hitting a specific path (e.g. /contact/) too many times in a short window
  • 404 burst – vulnerability scanners walking through hundreds of non-existent URLs
  • Trap URL – a hidden link that is disallowed in robots.txt; only bots that ignore it will ever follow it
  • Bad User-Agent – empty user agents and signatures of scanners, headless browsers and HTTP libraries

Rules can be added, edited and disabled individually, each with its own paths, threshold, action and block duration.

Record first, block later

Right after activation the plugin runs in log-only mode: every rule records what it sees and nobody is blocked. Look at the dashboard after a few days, see whether the traffic comes from a handful of IPs or is spread out, and only then switch to enforce mode – or take the generated .htaccess / nginx snippet and block those IPs in front of PHP.

What else is included

  • Verified crawler exclusion – Googlebot, Bingbot, Applebot and others are let through only after a reverse-then-forward DNS check; a crawler that claims to be Googlebot but fails the check is treated as a fake and blocked
  • Allow list with CIDR and IPv6 support for your own office and your client’s office
  • Optional grouping by subnet (/24 for IPv4, /64 for IPv6)
  • Early blocking – already-blocked IPs are stopped on init, before the main query runs
  • Dashboard with per-rule, per-IP, per-path and per-user-agent breakdowns of the last 7 days
  • Access log with filters and CSV export
  • Manual block list
  • Server-side snippets: Apache .htaccess, nginx deny, and a plain IP list for your analytics tool’s internal-traffic filter
  • Settings export / import as JSON to roll the same configuration out to other sites
  • WP-CLI: wp bot-guard top | blocks | block | unblock | mode | export | settings | cleanup
  • Optional e-mail / webhook notification when a new IP is auto-blocked (throttled to one per hour)
  • Daily cleanup of expired blocks and of log rows older than the retention period

What it deliberately does not do

  • Login protection and two-factor authentication – there are dedicated plugins for that
  • Country blocking – it would require bundling a GeoIP database

Privacy

The plugin stores the IP address, request path, user agent and referrer of requests that match a rule, in your own database, for the retention period you set (30 days by default). Nothing is sent to WATRIX or to any third party. If you configure a webhook URL, block notifications are sent to that URL and nowhere else. An optional “anonymize IP” setting masks the last octet before storing.

The verified-crawler check performs DNS lookups (reverse and forward) against the visitor’s IP. Results are cached for 12 hours.

Details

Plugin code:
watrix-bot-guard
Plugin version:
1.4.1
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-09-09
Rating:
Times rated:
0
bot
firewall
rate-limit
security
spam