Pages that hold a single form – a contact page, a quote request, a download gate – get hammered by scanners and spam bots. The first real damage is to your analytics: page views are inflated and you can no longer read what visitors actually do.
Watrix Bot Guard catches the source of that traffic with four kinds of rules and lets you decide how to deal with it:
/contact/) too many times in a short windowrobots.txt; only bots that ignore it will ever follow itRules can be added, edited and disabled individually, each with its own paths, threshold, action and block duration.
Right after activation the plugin runs in log-only mode: every rule records what it sees and nobody is blocked. Look at the dashboard after a few days, see whether the traffic comes from a handful of IPs or is spread out, and only then switch to enforce mode – or take the generated .htaccess / nginx snippet and block those IPs in front of PHP.
init, before the main query runs.htaccess, nginx deny, and a plain IP list for your analytics tool’s internal-traffic filterwp bot-guard top | blocks | block | unblock | mode | export | settings | cleanupThe plugin stores the IP address, request path, user agent and referrer of requests that match a rule, in your own database, for the retention period you set (30 days by default). Nothing is sent to WATRIX or to any third party. If you configure a webhook URL, block notifications are sent to that URL and nowhere else. An optional “anonymize IP” setting masks the last octet before storing.
The verified-crawler check performs DNS lookups (reverse and forward) against the visitor’s IP. Results are cached for 12 hours.