[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUYQsTJbuHgySHSqYVdwD-cKtAK-L-TE_tRdjAXnRf28":3,"$f6fTKwrsDtN1jlE7rn17vxhcXGi9ZoZSvaHy8z7cH0A8":125,"$ffyAOPOflcGP8gbPdykQcRaei9dCOcmwHfRp1R_mga8c":130},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":24,"download_link":25,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"botfend-anti-bot-firewall","BotFend Anti-Bot Firewall","4.9.1","Omajemite Don","https:\u002F\u002Fprofiles.wordpress.org\u002Fejesgist\u002F","\u003Cp>BotFend Anti-Bot Firewall is a professional-grade WordPress security suite designed to stop automated attacks, malicious bots, and brute-force attempts before they consume your server resources. Built with a high-performance V4 architecture, it features a smart aggregation engine and an early-loading Web Application Firewall (WAF) that neutralizes threats at the server level.\u003C\u002Fp>\n\u003Cp>Developed by Omajemite Don, BotFend protects your site without slowing it down.\u003C\u002Fp>\n\u003Ch3>Core Features:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Advanced Web Application Firewall (WAF):\u003C\u002Fstrong> Uses \u003Ccode>auto_prepend_file\u003C\u002Fcode> via \u003Ccode>.htaccess\u003C\u002Fcode> or \u003Ccode>.user.ini\u003C\u002Fcode> to block attacks before WordPress even loads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Bot Detection:\u003C\u002Fstrong> Identifies and blocks malicious bots, crawlers, and scrapers using advanced signature detection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Behavioral Analysis:\u003C\u002Fstrong> Monitors visitor behavior patterns to detect and block automated threats that mimic human activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser Fingerprinting:\u003C\u002Fstrong> Generates unique browser fingerprints to track and identify persistent attackers across sessions and IP changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced 404 Detection:\u003C\u002Fstrong> Detects and blocks malicious path scanning, vulnerability probing, and excessive 404 abuse patterns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Protection:\u003C\u002Fstrong> Comprehensive protection against XML-RPC attacks, REST API abuse, author scanning, and WordPress-specific vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Signature Detection:\u003C\u002Fstrong> Real-time pattern matching against known attack signatures and malicious payloads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Log Aggregation:\u003C\u002Fstrong> High-performance database architecture that centralizes logging to prevent database bloat and memory crashes, even under heavy attack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Perpetual Offender Tracking:\u003C\u002Fstrong> Automatically upgrades temporary bans to permanent blocks for IPs that repeatedly attack your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Threat Intelligence:\u003C\u002Fstrong> Integrates with external databases to verify IP reputations on the fly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tor Node Blocking:\u003C\u002Fstrong> Automatically detects and blocks malicious traffic originating from the Tor anonymity network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comprehensive UI:\u003C\u002Fstrong> Clean, intuitive WordPress admin interface with bulk actions, detailed threat analysis timelines, and visual statistics.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Pro Features (Available with License):\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Full Firewall Auto Prepend:\u003C\u002Fstrong> Execute firewall protection at the earliest possible stage of WordPress execution\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Integration:\u003C\u002Fstrong> Synchronize blocked IPs to Cloudflare firewall rules at the edge, blocking attacks before they reach your server\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>IMPORTANT: All external services are DISABLED BY DEFAULT. You must explicitly enable each service in the plugin settings before any data is sent.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin can connect to the following external services to provide enhanced threat protection. No data is sent unless you explicitly enable these features.\u003C\u002Fp>\n\u003Ch3>1. AbuseIPDB API\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Checks the reputation of suspicious IP addresses against a global database of reported abusers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being checked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When AbuseIPDB integration is enabled AND an IP address needs verification (cached for 24 hours)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable AbuseIPDB” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fwww.abuseipdb.com\u002Flegal\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.abuseipdb.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>2. IPHub API\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Detects VPNs, proxies, and non-residential IP addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being checked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When IPHub integration is enabled (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable IPHub” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fiphub.info\u002Flegal\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fiphub.info\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3. IP Geolocation Services\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Determine the country of origin for IP addresses to apply geographic blocking rules\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being geolocated\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When geolocation is enabled (default: OFF) AND an IP needs geolocation (results cached)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable IP Geolocation” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Services used:\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ip-api.com\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Primary geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ipapi.co\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Fallback geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fterms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fprivacy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ipwhois.io\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Secondary fallback geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fipwhois.io\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fipwhois.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>4. Tor Project Exit List\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Downloads the official list of active Tor exit nodes to block anonymous attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads a public list)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> Every 6 hours when Tor blocking is enabled (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable Tor Blocking” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fcheck.torproject.org\u002Ftorbulkexitlist\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use:\u003C\u002Fstrong> https:\u002F\u002Fwww.torproject.org\u002Fabout\u002Ftrademark\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.torproject.org\u002Fabout\u002Fprivacy_policy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>5. dan.me.uk Tor List (Alternative Source)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Alternative source for Tor exit node list when primary source is unavailable\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads a public list)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> Only used as fallback when primary Tor list fails and Tor blocking is enabled\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Disable Tor blocking in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fwww.dan.me.uk\u002Ftorlist\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms\u002FPrivacy:\u003C\u002Fstrong> This is a public service with no formal terms or privacy policy. Use is governed by standard HTTP protocol.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>6. Threat Intelligence Feeds\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Download curated lists of known malicious IP addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads public blocklists)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When threat intelligence is enabled (default: OFF) and feeds need refreshing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable Threat Intelligence” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Feeds used:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>FireHOL:\u003C\u002Fstrong> https:\u002F\u002Ffirehol.org\u002F (Public domain blocklists)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocklist.de:\u003C\u002Fstrong> https:\u002F\u002Fwww.blocklist.de\u002F (Terms: https:\u002F\u002Fwww.blocklist.de\u002Fen\u002Fterms.html)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emerging Threats (Proofpoint):\u003C\u002Fstrong> Real-time threat intelligence feeds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Flegal\u002Flicense\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Flegal\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>7. Google reCAPTCHA\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Provides bot verification on login, registration, and comment forms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Browser interaction data sent to Google’s servers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When reCAPTCHA is enabled AND a user interacts with a protected form\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set reCAPTCHA site key and secret key to empty in plugin settings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>8. Cloudflare API Integration (PRO VERSION)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Synchronize blocked IPs to Cloudflare firewall rules at the edge, blocking attacks before they reach your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> IP addresses, threat scores, authentication credentials, and configuration parameters during API calls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> During manual sync operations, scheduled automatic syncs, and license validation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Available only in Pro version with valid license\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fwww.cloudflare.com\u002Fterms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Data Handling Summary\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>No data is sent to any external service unless you explicitly enable that feature\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>All API results are cached\u003C\u002Fstrong> to minimize external requests\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Regular visitor IPs are never sent\u003C\u002Fstrong> – only suspicious or attacking IPs trigger external lookups\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You can disable ALL external services\u003C\u002Fstrong> in the plugin settings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin works perfectly with all external services disabled\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin respects user privacy:\u003Cbr \u002F>\n– No tracking of regular site visitors\u003Cbr \u002F>\n– No analytics or usage data collected\u003Cbr \u002F>\n– All external services are opt-in (disabled by default)\u003Cbr \u002F>\n– Full transparency: All external service calls are documented above\u003C\u002Fp>\n","Professional security plugin protecting WordPress from malicious bots, spam, and server attacks using an advanced Web Application Firewall.",0,276,100,1,"2026-05-21T16:41:00.000Z","7.0.2","6.4","8.0",[20,21,22,23],"bot-protection","firewall","security","spam-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbotfend-anti-bot-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotfend-anti-bot-firewall.4.9.1.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"ejesgist",2,30,94,"2026-08-29T04:05:46.849Z",[37,56,76,95,112],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":13,"num_ratings":47,"last_updated":48,"tested_up_to":16,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":54,"download_link":55,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"waf-security-suite-for-cloudflare","Cloud Maestro – WAF Security Suite for Cloudflare","1.4","5 Star Plugins (Rob)","https:\u002F\u002Fprofiles.wordpress.org\u002F5starplugins\u002F","\u003Cp>Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why would I use a plugin when I can create rules in Cloudflare?\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin.\u003C\u002Fp>\n\u003Cp>It’s useful for someone managing:\u003Cbr \u002F>\n– Their own sites and client sites\u003Cbr \u002F>\n– Multiple businesses\u003Cbr \u002F>\n– Separate Cloudflare accounts\u003C\u002Fp>\n\u003Cp>People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly.\u003C\u002Fp>\n\u003Cp>The free version supports one Cloudflare account with multiple domains.\u003C\u002Fp>\n\u003Cp>An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once.\u003C\u002Fp>\n\u003Ch3>🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare?\u003C\u002Fh3>\n\u003Cp>Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deploy in One Click\u003C\u002Fstrong> – Apply comprehensive WAF rules to multiple domains simultaneously\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Save Time\u003C\u002Fstrong> – No more manually configuring rules on each domain, one at a time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enterprise Security\u003C\u002Fstrong> – Protect against bots, aggressive crawlers, malicious IPs, and common threats\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce Mistakes\u003C\u002Fstrong> – Maintain consistent security rules across domains\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✅ Free Standard Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>One Cloudflare account\u003C\u002Fli>\n\u003Cli>Multiple domains\u003C\u002Fli>\n\u003Cli>One-click WAF rule deployment\u003C\u002Fli>\n\u003Cli>Centralized Cloudflare controls\u003C\u002Fli>\n\u003Cli>Secure API credential storage (AES-256-CBC encryption)\u003C\u002Fli>\n\u003Cli>Plugin updates\u003Cbr \u002F>\nThe free plugin does not require an upgrade.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔥 What Gets Protected\u003C\u002Fh3>\n\u003Cp>The plugin deploys \u003Cstrong>3 optimized trusted security rules\u003C\u002Fstrong> (prior versions used 5) that work together to protect your sites:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Good Bot Allowlist\u003C\u002Fstrong> – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Managed Challenges for Suspicious Traffic\u003C\u002Fstrong> – Automatically challenges requests from certain ASNs and non-US traffic\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aggressive Crawler Protection\u003C\u002Fstrong> – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VPN & Login Protection\u003C\u002Fstrong> – Adds extra challenges for VPN traffic and WordPress login attempts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block Known Threats\u003C\u002Fstrong> – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✨ Premium Upgrade (Optional)\u003C\u002Fh3>\n\u003Cp>For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. \u003Cstrong>\u003Ca href=\"https:\u002F\u002F5starplugins.com\u002Fcloud-maestro-cloudflare-waf-rules\u002F\" rel=\"nofollow ugc\">Check out our free trial\u003C\u002Fa>\u003C\u002Fstrong> for these features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Multi-Account Management\u003C\u002Fstrong> – Automatically manage domains across ALL your Cloudflare accounts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy Bot Whitelisting\u003C\u002Fstrong> – Built-in checkboxes for 50+ trusted services across 8 categories\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom User Agents\u003C\u002Fstrong> – Add your own user agent strings to the Good Bot Rule\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom IP Whitelisting\u003C\u002Fstrong> – Add trusted IP addresses to the Goot Bot Rule\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Rules management\u003C\u002Fstrong> – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk DNS Management\u003C\u002Fstrong> – Search and manage DNS records across all domains, bulk migrate IP addresses, CNAME targets, and convert A records to CNAME with a single action\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong> – Get expert help when you need it\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Customization\u003C\u002Fstrong> – Fine-tune rules to match your exact requirements\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Account Management\u003C\u002Fstrong> – Centrally manage unlimited domains across all your Cloudflare accounts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📋 Important Information\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Rule Replacement:\u003C\u002Fstrong> This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatibility:\u003C\u002Fstrong> Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service Monitoring:\u003C\u002Fstrong> These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.\u003C\u002Fp>\n","Bulk deploy powerful WAF security rules to multiple Cloudflare domains with one click. Protect your sites from bots, malicious traffic, and threats.",50,1445,4,"2026-06-23T04:57:00.000Z","6.0","7.4",[20,52,21,22,53],"cloudflare","waf-rules","https:\u002F\u002F5starplugins.com\u002Fcloud-maestro-cloudflare-waf-rules\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwaf-security-suite-for-cloudflare.1.4.zip",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":13,"num_ratings":32,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":69,"tags":70,"homepage":69,"download_link":73,"security_score":74,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":75},"botfirewall","BotFirewall | Stop Spam Bots & Secure Login","2.3.5","SafeWeb","https:\u002F\u002Fprofiles.wordpress.org\u002Fhallemmit3\u002F","\u003Cp>\u003Cstrong>BotFirewall\u003C\u002Fstrong> is a powerful and modern plugin designed to protect your WordPress site from malicious bots, spam, and DDoS attacks. Using advanced JavaScript verification and encrypted cookies, BotFirewall ensures robust security without disrupting the experience of real users.\u003C\u002Fp>\n\u003Ch3>Why Do You Need BotFirewall?\u003C\u002Fh3>\n\u003Cp>In today’s internet landscape, bots make up a significant portion of web traffic, and many of them are malicious. They can attack your site, send spam, scrape content, or attempt to hack login pages like \u003Ccode>wp-login.php\u003C\u002Fcode>. BotFirewall addresses these threats by providing \u003Cstrong>smart and flexible protection\u003C\u002Fstrong> that:\u003Cbr \u002F>\n– \u003Cstrong>Blocks bots\u003C\u002Fstrong> with seamless JavaScript verification that most bots cannot pass.\u003Cbr \u002F>\n– \u003Cstrong>Secures key pages\u003C\u002Fstrong> like \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> from unauthorized access.\u003Cbr \u002F>\n– \u003Cstrong>Uses encrypted cookies\u003C\u002Fstrong> to ensure only verified users gain access.\u003Cbr \u002F>\n– \u003Cstrong>Offers customizable settings\u003C\u002Fstrong> through an intuitive interface in the WordPress admin panel.\u003C\u002Fp>\n\u003Ch3>Key Features of BotFirewall\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>JavaScript Verification\u003C\u002Fstrong>: Ensures visitors can execute JavaScript, effectively filtering out most bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted Cookies\u003C\u002Fstrong>: Cookies are tied to IP and User-Agent for enhanced security against spoofing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Page Protection\u003C\u002Fstrong>: Enable or disable protection for \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> pages via settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist and Blacklist\u003C\u002Fstrong>: Configure lists of allowed bots (e.g., Googlebot) and IPs, and block known malicious IPs, including subnet support (e.g., 192.168.0.0\u002F24).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Exclude URLs\u003C\u002Fstrong>: Specify URLs to bypass bot protection entirely (e.g., for APIs or specific pages).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Statistics\u003C\u002Fstrong>: Monitor bot activity with detailed stats – filter by time periods (Last 24 hours, Last Week, Last Month).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Logging\u003C\u002Fstrong>: Logs blocks and successful verifications with URL details, keeping data for the last 30 days.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowed Bots Tab\u003C\u002Fstrong>: Easily select known bots to allow without verification, with quick filters for bot types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recent Activity\u003C\u002Fstrong>: View the latest 10 logged sessions with details like IP, URL, and status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight and Fast\u003C\u002Fstrong>: Optimized for minimal impact on site performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Uninstall\u003C\u002Fstrong>: Removes all data, including logs and settings, upon deactivation and deletion.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Verification Page\u003C\u002Fstrong>: Tailor the text (title, description, countdown), CSS styling, and logo of the verification page to match your site’s design.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced Support\u003C\u002Fstrong>: Get assistance directly through Live Chat in the Support tab for quick resolution of issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How Does BotFirewall Work?\u003C\u002Fh3>\n\u003Cp>BotFirewall employs a multi-layered protection system:\u003Cbr \u002F>\n1. \u003Cstrong>Cookie Check\u003C\u002Fstrong>: If a visitor has a valid cookie, they bypass additional checks.\u003Cbr \u002F>\n2. \u003Cstrong>Whitelist\u003C\u002Fstrong>: Known “good” bots (e.g., search engine crawlers) are automatically allowed.\u003Cbr \u002F>\n3. \u003Cstrong>JavaScript Verification\u003C\u002Fstrong>: If no cookie is present, the visitor is redirected to a verification page where they must execute a JavaScript request. Bots unable to run JavaScript are blocked.\u003Cbr \u002F>\n4. \u003Cstrong>Login Page Protection\u003C\u002Fstrong>: Optionally protect \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> to prevent brute-force attacks.\u003Cbr \u002F>\n5. \u003Cstrong>Post-Verification Redirect\u003C\u002Fstrong>: After successful verification, the user is redirected to their original page, and a cookie is set for future visits.\u003C\u002Fp>\n\u003Ch3>Why BotFirewall is a Must-Have for Your Site\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Spam and DDoS Protection\u003C\u002Fstrong>: Effectively blocks bots that attempt to spam or overload your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security\u003C\u002Fstrong>: Safeguards \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> from unauthorized access and brute-force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexibility\u003C\u002Fstrong>: Customize protection with whitelists, blacklists, cookie lifetime settings, and verification page styling.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transparency\u003C\u002Fstrong>: Detailed statistics and logs let you monitor bot activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ease of Use\u003C\u002Fstrong>: A user-friendly interface in the WordPress admin panel makes configuration a breeze.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Look\u003C\u002Fstrong>: Customize the verification page with your own text, styles, logo, and a modern font (Roboto) for a polished appearance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reliable Support\u003C\u002Fstrong>: Access our support team via Live Chat for help with any technical or security issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>BotFirewall is an \u003Cstrong>essential tool\u003C\u002Fstrong> for WordPress site owners who want to protect their content, users, and server from malicious bots. Install BotFirewall today and secure your site with confidence!\u003C\u002Fp>\n","BotFirewall is a powerful and modern plugin designed to protect your WordPress site from malicious bots, spam, and DDoS attacks.",20,738,"2025-06-05T14:29:00.000Z","6.8.5","5.0","",[71,20,21,72,22],"anti-bot","login-protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotfirewall.2.3.5.zip",92,"2026-03-15T15:16:48.613Z",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":13,"num_ratings":14,"last_updated":86,"tested_up_to":87,"requires_at_least":68,"requires_php":69,"tags":88,"homepage":93,"download_link":94,"security_score":74,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"automatic-break-iframes","SpamShieldX","1.2","Alireza Nejati","https:\u002F\u002Fprofiles.wordpress.org\u002Falireza-nejati\u002F","\u003Cp>SpamShieldX is the ultimate solution for protecting your WordPress website from spam and iframe abuse. Our plugin blocks malicious iframes and prevents unwanted spam sources, keeping your site secure and optimized.\u003C\u002Fp>\n\u003Cp>Whether you’re a blogger, website owner, or developer, SpamShieldX is the perfect tool to enhance your site’s security and performance. Our plugin is lightweight, easy to configure, and seamlessly integrates into your WordPress site.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Block iframe abuse\u003C\u002Fli>\n\u003Cli>Prevent spam from harmful sources\u003C\u002Fli>\n\u003Cli>Protect your content and improve security\u003C\u002Fli>\n\u003Cli>Easy to use and setup\u003C\u002Fli>\n\u003Cli>Regular updates for maximum security\u003C\u002Fli>\n\u003C\u002Ful>\n","SpamShieldX is the ultimate solution for protecting your WordPress website from spam and iframe abuse. Our plugin blocks malicious iframes and prevent &hellip;",10,2430,"2025-04-28T07:01:00.000Z","6.8.6",[89,90,23,91,92],"anti-spam","iframe-blocker","website-security","wordpress-firewall","http:\u002F\u002Fazarsys.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fautomatic-break-iframes.1.2.zip",{"slug":96,"name":97,"version":98,"author":99,"author_profile":100,"description":101,"short_description":102,"active_installs":11,"downloaded":103,"rating":11,"num_ratings":11,"last_updated":104,"tested_up_to":105,"requires_at_least":106,"requires_php":50,"tags":107,"homepage":109,"download_link":110,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":111},"baskerville-ai-security","Baskerville AI Security","1.0.3","eQualitie","https:\u002F\u002Fprofiles.wordpress.org\u002Fequalitie\u002F","\u003Cp>Baskerville is a comprehensive WordPress security plugin that protects your site from malicious bots, AI crawlers, and unwanted traffic using multiple detection methods.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Bot Detection\u003C\u002Fstrong> – Intelligent classification of bots vs. humans with configurable score thresholds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GeoIP Access Control\u003C\u002Fstrong> – Block or allow traffic by country (whitelist\u002Fblacklist modes)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Turnstile\u003C\u002Fstrong> – CAPTCHA challenge for borderline bot scores with precision analytics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser Fingerprinting\u003C\u002Fstrong> – Advanced client-side fingerprinting (Canvas, WebGL, Audio)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Honeypot Detection\u003C\u002Fstrong> – Hidden links to catch AI crawlers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Analytics\u003C\u002Fstrong> – Live feed, traffic statistics, and Turnstile precision metrics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Under Attack Mode\u003C\u002Fstrong> – Emergency mode to challenge all visitors during attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelist\u003C\u002Fstrong> – Bypass firewall for trusted IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form Protection\u003C\u002Fstrong> – Protect login, registration, and comment forms with Turnstile\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Bot Score System:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>0-39: Likely human (allowed)\u003C\u002Fli>\n\u003Cli>40-70: Borderline (optional Turnstile challenge)\u003C\u002Fli>\n\u003Cli>71-100: Likely bot (blocked)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Performance:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Minimal overhead (~1ms with page cache, ~30-50ms without)\u003C\u002Fli>\n\u003Cli>APCu + file-based caching for GeoIP lookups\u003C\u002Fli>\n\u003Cli>Compatible with all major caching plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the following third-party services:\u003C\u002Fp>\n\u003Ch4>Cloudflare Turnstile\u003C\u002Fh4>\n\u003Cp>When Turnstile is enabled, the plugin loads JavaScript from Cloudflare’s servers to display CAPTCHA challenges:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service URL: https:\u002F\u002Fchallenges.cloudflare.com\u002Fturnstile\u002Fv0\u002Fapi.js\u003C\u002Fli>\n\u003Cli>Verification API: https:\u002F\u002Fchallenges.cloudflare.com\u002Fturnstile\u002Fv0\u002Fsiteverify\u003C\u002Fli>\n\u003Cli>Data sent: Turnstile token, visitor IP address\u003C\u002Fli>\n\u003Cli>Purpose: Human verification to prevent bot access\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fli>\n\u003Cli>Terms of Service: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Turnstile is only loaded when you enable it in plugin settings and provide your Cloudflare API keys.\u003C\u002Fp>\n\u003Ch4>MaxMind GeoIP Database\u003C\u002Fh4>\n\u003Cp>When you use the one-click GeoIP database installer, the plugin downloads the GeoLite2-Country database from MaxMind:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Database download URL: https:\u002F\u002Fdownload.maxmind.com\u002F\u003C\u002Fli>\n\u003Cli>Data sent: Your MaxMind license key (required for database download)\u003C\u002Fli>\n\u003Cli>Purpose: Determine visitor country for geo-blocking features\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fprivacy-policy\u003C\u002Fli>\n\u003Cli>Terms of Service: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite2\u002Feula\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The installer also downloads the MaxMind PHP libraries from GitHub:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>GeoIP2 PHP API: https:\u002F\u002Fgithub.com\u002Fmaxmind\u002FGeoIP2-php\u002Farchive\u002Frefs\u002Ftags\u002Fv2.13.0.zip\u003C\u002Fli>\n\u003Cli>MaxMind DB Reader: https:\u002F\u002Fgithub.com\u002Fmaxmind\u002FMaxMind-DB-Reader-php\u002Farchive\u002Frefs\u002Ftags\u002Fv1.11.1.zip\u003C\u002Fli>\n\u003Cli>These are open-source libraries used to read the local GeoIP database. No visitor data is sent to GitHub.\u003C\u002Fli>\n\u003Cli>GitHub Terms of Service: https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fgithub-terms\u002Fgithub-terms-of-service\u003C\u002Fli>\n\u003Cli>GitHub Privacy Statement: https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fprivacy-policies\u002Fgithub-general-privacy-statement\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The database is stored locally on your server. No visitor data is sent to MaxMind during lookups.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Ch4>Data Collected\u003C\u002Fh4>\n\u003Cp>This plugin collects and stores the following visitor data locally in your WordPress database:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP addresses\u003C\u002Fli>\n\u003Cli>Browser fingerprints (Canvas, WebGL, Audio hashes)\u003C\u002Fli>\n\u003Cli>User agent strings\u003C\u002Fli>\n\u003Cli>Country codes (derived from IP)\u003C\u002Fli>\n\u003Cli>Bot scores and classifications\u003C\u002Fli>\n\u003Cli>Timestamps of visits\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data Retention\u003C\u002Fh4>\n\u003Cp>Statistics are automatically deleted after the retention period you configure (default: 14 days). You can adjust this in Settings > Baskerville > Settings.\u003C\u002Fp>\n\u003Ch4>GDPR Compliance\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All data is stored locally on your server\u003C\u002Fli>\n\u003Cli>No visitor data is shared with third parties (except Cloudflare when Turnstile verification occurs)\u003C\u002Fli>\n\u003Cli>Data retention is configurable\u003C\u002Fli>\n\u003Cli>Consider adding disclosure to your site’s privacy policy\u003C\u002Fli>\n\u003C\u002Ful>\n","Advanced WordPress security plugin with AI bot detection, GeoIP access control, and Cloudflare Turnstile integration.",221,"2026-04-03T11:17:00.000Z","6.9.4","6.2",[71,108,21,22,23],"captcha","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbaskerville-ai-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbaskerville-ai-security.1.0.3.zip","2026-04-16T10:56:18.058Z",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":11,"downloaded":120,"rating":11,"num_ratings":11,"last_updated":121,"tested_up_to":87,"requires_at_least":68,"requires_php":50,"tags":122,"homepage":69,"download_link":124,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"bunkr-solution","Bunkr Solution","1.0.0","Bunkr","https:\u002F\u002Fprofiles.wordpress.org\u002Fyfel\u002F","\u003Cp>Bunkr Solution provides enterprise-grade bot protection for your WordPress site through sophisticated server-side analysis.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\n* Real-time behavioral analysis\u003Cbr \u002F>\n* Advanced bot detection\u003Cbr \u002F>\n* Seamless user experience for legitimate visitors\u003Cbr \u002F>\n* Enterprise-grade protection\u003Cbr \u002F>\n* Easy integration with WordPress\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the Bunkr API service to analyze website traffic and provide bot protection. Here’s what you need to know:\u003C\u002Fp>\n\u003Ch4>Service Information\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service\u003C\u002Fstrong>: Bunkr Bot Protection API (https:\u002F\u002Fwpde.bunkr-solution.com)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Real-time analysis of website requests to identify and block malicious bot traffic\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Provider\u003C\u002Fstrong>: Bunkr Solution (https:\u002F\u002Fbunkr-solution.com)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data Transmission\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When data is sent\u003C\u002Fstrong>: Every time a non-admin user visits your website (excluding AJAX requests)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent\u003C\u002Fstrong>:\u003Cbr \u002F>\n* Request metadata: URL, HTTP method, referrer, timestamp\u003Cbr \u002F>\n* Server headers: User-Agent, Accept headers, security headers (Sec-* headers)\u003Cbr \u002F>\n* Network information: IP address, domain name\u003Cbr \u002F>\n* Browser context: Mobile detection, HTTPS status\u003Cbr \u002F>\n* Cookie analysis: Count and types of cookies (WordPress, session, persistent)\u003Cbr \u002F>\n* Request identifier: Unique request identifier\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No sensitive data\u003C\u002Fstrong>: The plugin does not send form data, post content, user credentials, or personal information.\u003C\u002Fp>\n\u003Ch4>Legal Information\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fbunkr-solution.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fbunkr-solution.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>User Consent\u003C\u002Fh4>\n\u003Cp>By installing and activating this plugin, you acknowledge that:\u003Cbr \u002F>\n1. Request data will be sent to Bunkr’s servers for analysis\u003Cbr \u002F>\n2. This data transmission is necessary for the plugin’s bot protection functionality\u003Cbr \u002F>\n3. You have reviewed Bunkr’s terms of service and privacy policy\u003Cbr \u002F>\n4. You are responsible for informing your website users about this data processing if required by applicable privacy laws\u003C\u002Fp>\n","Advanced bot protection for WordPress using real-time behavioral analysis. Blocks malicious traffic while allowing legitimate users seamless access.",973,"2025-10-10T13:14:00.000Z",[89,20,123,21,22],"click-fraud","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbunkr-solution.1.0.2.zip",{"error":126,"url":127,"statusCode":128,"statusMessage":129,"message":129},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fbotfend-anti-bot-firewall\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":14,"versions":131},[132],{"version":6,"download_url":25,"svn_tag_url":133,"released_at":26,"has_diff":134,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":136,"is_current":126},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbotfend-anti-bot-firewall\u002Ftags\u002F4.9.1\u002F",false,[],[]]