| 开发者 | wned |
|---|---|
| 更新时间 | 2026年10月1日 07:32 |
| PHP版本: | 7.0 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
.env files, exposed Git folders, old admin tools and weak passwords. BotZoom recognises these bots and blocks them before they find anything.
What the free version does
.env, .git, wp-config.php backups and database dumps./wp-content/plugins/.No. Logged-in users are never blocked. If you are blocked while logged out, for example after mistyping your password too often, wait until the block expires or ask someone with access to unblock your IP under BotZoom > Blocked IPs. You can also add your own IP address under "Never block".
No. Visitors that claim to be a search engine are verified with a reverse and forward DNS check. Verified crawlers are never blocked.
Set "Visitor IP from" to the header your proxy uses, for example HTTP_CF_CONNECTING_IP for Cloudflare. Only change this if your site really runs behind that proxy, otherwise attackers can fake their IP address.
No. Protection against DDoS attacks is handled by the firewall of your hosting provider. BotZoom is an extra layer against bots that search your site for leaks and vulnerabilities.
For each blocked request: the IP address, time, requested URL and user agent. This data stays in your own database, is used only for security and is deleted automatically after the retention period you set (30 days by default). BotZoom adds a suggested text to your privacy policy under Settings > Privacy.
Yes. Deleting the plugin removes its database tables and settings.