Linux 软件免费装
Banner图

Royal AI Firewall

开发者 royalpluginsteam
更新时间 2026年7月26日 13:20
捐献地址: 去捐款
PHP版本: 8.0 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security bot ai firewall mcp

下载

1.0.2 1.0.3 1.0.4 1.0.5 1.0.0 1.0.1

详情介绍:

https://youtu.be/QKktpbTwyLU Royal AI Firewall logs and controls AI bot traffic at the WordPress layer. Every site on the public web is now visited by AI crawlers — GPTBot, ClaudeBot, PerplexityBot, ByteSpider, CCBot, and dozens of others — and most site owners have no way to see what's happening or decide who gets through. This plugin gives you: Free, Self-Hosted, Fully Featured Royal AI Firewall is fully featured in its free, GPL-licensed release. There is no Pro version — every feature ships in the wp.org plugin, and updates go through the standard WordPress plugin updater. Your data stays on your server. The plugin makes no outbound network calls by default. The bundled bot catalog ships with each plugin release and refreshes automatically when you update Royal AI Firewall, so customers who never opt in to live updates still get fresh bot definitions on every plugin update. If you want even fresher catalogs between releases, an optional toggle in Settings (and on the final wizard step) opts in to one HTTP GET per day to fingerprints.royalplugins.com. The plugin never sends your site's traffic, customer data, IP addresses, or credentials to any third party regardless of toggle state. AI Bots Recognized (68 as of v1.0.2) The bundled catalog covers the major AI bot families. Each entry includes the bot's owner, intended purpose, default policy, and the blocking consequences (for example, "blocking GPTBot may remove your site from ChatGPT search results"). Training crawlers: GPTBot, ClaudeBot, anthropic-ai, Bytespider, TikTokSpider, FacebookBot, Meta-ExternalAgent, GoogleOther, GoogleOther-AI, Google-Extended, Google-CloudVertexBot, MistralBot, KimiBot, cohere-ai, cohere-training-data-crawler, ai2bot, ai2bot-dolma, Amazonbot, PetalBot Retrieval bots (on-demand): ChatGPT-User, OAI-AdsBot, ClaudeBot-User, Claude-Web, claude-code, Perplexity-User, Kimi-User, YandexAdditionalBot, Meta-ExternalFetcher, facebookexternalhit, APIs-Google AI search engines: OAI-SearchBot, PerplexityBot, Claude-SearchBot, Kimi-SearchBot, MistralAI-Index, YandexAdditional, meta-webindexer, Applebot-Extended, MicrosoftCopilotBot, DuckAssistBot, YouBot, PhindBot, iAsk, Komo, Liner, Brave Leo, Andi Search engines (always-allow guarded): Googlebot, Googlebot-Image, Googlebot-Video, Googlebot-News, Bingbot, BingPreview, Applebot, DuckDuckBot Other search engines: Baiduspider Agent browsers (newer category): OperatorAgent, ChatGPT-Atlas, Claude-Computer-Use Dataset scrapers: CCBot (Common Crawl), Diffbot, ImagesiftBot, Omgilibot, Timpibot Other Google crawlers: Storebot-Google, Mediapartners-Google, AdsBot-Google, adidxbot The Dashboard Open the AI Firewall menu in your WordPress admin to see: Per-Bot Policy Controls Each recognized bot row has a dropdown with four options: Major search engines (Googlebot, Bingbot, Applebot, DuckDuckBot) are protected from accidental blocking. The per-bot dropdown is disabled for these bots, and the API rejects block requests for them unless you explicitly enable the "Search engine override" toggle in Settings — with a clear warning that blocking Googlebot removes your site from Google Search. Cloudflare Compatibility If your site is behind Cloudflare, the setup wizard's Cloudflare screen tells you exactly which CF settings to turn off so this plugin can take over the AI-bot layer: And which CF settings to leave on (they don't conflict): The dashboard also detects Cloudflare on every admin page load (looking for cf-ray, cf-connecting-ip, or CDN-Loop: cloudflare headers) and shows a status card with the detection state. A persistent 24-hour state ensures the UI stays stable even when an occasional admin request doesn't pass through CF. Other CDN Compatibility The setup wizard also recognizes 6 additional CDNs by their vendor-forwarded request headers: Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. Detection is header-sniff only — no outbound HTTP, no DNS lookups. When any of these are detected, the wizard shows a compatibility note rather than a network-specific dial-down (Cloudflare remains the only CDN with a full walkthrough because its AI controls are the most common source of operator confusion). Royal AI Firewall sees AI bot traffic that reaches WordPress regardless of which CDN sits in front — if you have edge-side AI-bot rules configured on your CDN, consult its documentation, as the two layers can coexist. Other Security Plugin Compatibility The plugin auto-detects these plugins when they're active and shows compatibility notes on the dashboard and Settings page: WordPress Abilities API & MCP Server Integration This plugin listens for the WordPress Abilities API hooks wp_before_execute_ability and wp_after_execute_ability (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If you have any MCP server plugin installed and an AI agent calls an ability, you'll see it in the MCP Activity widget on the dashboard. If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call from that server with full tool name and result status. Search Engine Guard Major search engines are protected from accidental blocking by default. The dashboard dropdown is disabled for Googlebot, Bingbot, Applebot, and DuckDuckBot. The REST API endpoints reject block attempts on these bots with a 409 Conflict response unless the customer has explicitly enabled the "Search engine override" toggle in Settings. The override toggle includes a clear warning that blocking Googlebot removes the site from Google Search. Telemetry and Data Anonymous usage data is OFF by default. The plugin makes no outbound HTTP call for telemetry unless you explicitly opt in — via the setup wizard's final step or the "Anonymous usage data" toggle in Settings. If you opt in, once per week the plugin POSTs a small JSON payload to telemetry.royalplugins.com. The payload contains: The following are NEVER sent, regardless of toggle state: Data retention: raw payloads are retained for 90 days. Aggregated statistics are retained indefinitely. Per-site fingerprints are purged after 12 months of no reports. You can revoke consent at any time in Settings — the plugin unschedules the weekly cron immediately. The other outbound HTTP call the plugin can make (also opt-in) is a single daily GET request to fingerprints.royalplugins.com for a fresher bot catalog when you enable "Keep catalog updated between releases." That request body is empty and includes only the plugin version in the User-Agent header. See the "External Services" section below. Log retention defaults to 7 days. The retention window is filterable via raif_log_retention_days for developers who need a different value. How Activation Works On activation the plugin: No outbound HTTP calls are made until the customer explicitly opts in to live catalog updates on the wizard's final screen or via Settings → Bot fingerprint database. The plugin is fully functional without ever making a network call — the bundled catalog refreshes from the plugin zip on every plugin update. On deactivation the plugin unschedules all WP-Cron events. Data is preserved by default so a re-activation continues where you left off. To remove all data on uninstall, check the "Delete all logs, tables, and options when the plugin is uninstalled" toggle in Settings → Data before deactivating.

安装:

  1. In your WordPress dashboard, go to Plugins → Add New and search for Royal AI Firewall.
  2. Click Install Now, then Activate.
  3. The 4-step setup wizard runs automatically on first activation. Walk through it to detect Cloudflare and pick a default policy. The wizard is skippable.
  4. Open AI Firewall in the admin menu to see the dashboard.
  5. Wait 2–6 hours for the first AI bot hits to appear, or run a manual test with curl:
curl -A "GPTBot/1.2" https://your-site.com/

屏幕截图:

  • Setup wizard, welcome step — one-screen summary of what the plugin does before the walkthrough starts.
  • Setup wizard, environment detection — the wizard reports which security plugins and MCP servers it found on the site and how it will coexist with each.
  • Setup wizard, Cloudflare screen — step-by-step list of which Cloudflare settings to turn off so this plugin can take over the AI-bot layer.
  • Setup wizard, default policy — pick the global stance (Log only, Block training crawlers, or Block all) with a plain-language description of what each mode does.
  • Settings page — default policy, search engine override, Cloudflare detection diagnostic, security plugin compatibility, bot fingerprint database status, log retention, telemetry opt-in.

升级注意事项:

1.0.5 New Bot Access page detects upstream blocks against verified search bots, real response bytes on every log row, and a Royal Tools submenu for free companion plugins. 1.0.4 Setup wizard now detects six more CDNs (Bunny, Fastly, KeyCDN, Sucuri, StackPath, Akamai) alongside Cloudflare, and the dashboard hero shows total hits, blocked, allowed, and distinct bots side by side. 1.0.3 Bot policy import/export as JSON, wizard compatibility catalog grows to 23 plugins, new anonymous usage data toggle (opt-in, off by default). 1.0.2 Bot catalog refreshed to 68 recognized AI bots with 13 new vendor-verified entries. 1.0.1 Wizard compatibility step now recognizes 19 popular security and caching plugins and renders only the ones actively installed. 1.0.0 Initial release.

常见问题:

Do I still need Cloudflare?

Yes, if you use Cloudflare for DDoS protection, general WAF rules, SSL/TLS, or caching. Keep Cloudflare's core protections on. This plugin handles only the AI-bot-specific layer at WordPress, so you can dial down Cloudflare's AI Audit / AI Labyrinth / custom AI-blocking WAF rules. The setup wizard's Cloudflare screen lists exactly which CF toggles to flip.

Will this block Googlebot?

No. Googlebot, Bingbot, Applebot, and DuckDuckBot are protected from accidental blocking. The per-bot dropdown is disabled for these bots by default. To block any of them, you must explicitly enable the "Search engine override" toggle in Settings, which warns clearly that blocking Googlebot removes your site from Google Search.

Does this work with other security plugins?

Yes. Edge-firewall security plugins run their own firewalls before WordPress loads, so AI bots they block won't appear in this plugin's dashboard — but the two layers don't conflict. The plugin auto-detects popular security plugins on activation and shows compatibility notes.

Does this work with Royal MCP and other MCP server plugins?

Yes. The plugin hooks into the WordPress Abilities API (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call with full detail.

What happens to my data if I uninstall?

By default, data is preserved. The plugin's tables and logs survive uninstall so a reinstall picks up where you left off. To delete everything on uninstall, check the "Delete all logs, tables, and options when the plugin is uninstalled" toggle in Settings → Data before deactivating.

My dashboard shows zero hits even though AI bots are visiting my site. What's wrong?

Almost always a caching plugin caching the REST API response. The plugin already does four things to prevent this — a cache-buster query string on every dashboard request, nocache_headers() + DONOTCACHEPAGE constant on the handler, explicit Cache-Control: no-store response headers, and built-in compatibility filters that opt out of caching for the most common cache plugins. If you use a different cache plugin or a server-side cache (nginx fastcgi_cache, Cloudflare Page Rules, Varnish), exclude the path /wp-json/royal-ai-firewall/* from REST API caching in that plugin's settings.

How often is the bot catalog updated?

A fresh bot catalog ships with every Royal AI Firewall release, so every time you update the plugin through your wp-admin → Plugins screen you get the newest catalog automatically — no outbound network call required. Plugin updates typically ship every 2–4 weeks, faster after major AI-vendor launches. If you want catalogs fresher than the per-release cadence, an optional Settings toggle ("Keep catalog updated between releases") opts in to one HTTP GET per day to fingerprints.royalplugins.com. That toggle is off by default; no outbound HTTP call is ever made until you turn it on.

Does the plugin phone home or make outbound network calls?

No, not by default. Out of the box the plugin makes zero outbound HTTP calls. The bot catalog ships bundled with the plugin and refreshes on every plugin update. If you explicitly enable the "Keep catalog updated between releases" toggle in Settings or on the final wizard step, the plugin will then make one HTTP GET per day to fetch a fresher catalog — but only after that opt-in, and only that one call. Turning the toggle back off immediately unschedules the cron. No telemetry, license checks, or analytics calls are ever made regardless of toggle state.

Is there a Pro version?

No. Every feature ships in the free release on WordPress.org. No upgrade prompts, no license keys, no SaaS subscription.

What if I'm behind a different CDN?

The setup wizard also recognizes Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. The classifier and per-bot controls work at the WordPress layer regardless of which CDN sits in front. Cloudflare gets a full dial-down walkthrough because its AI controls are the most common source of operator confusion; other CDNs get a compatibility note instead.

Does the plugin slow down my site?

The hot-path classification logic has a hard budget of under 5 milliseconds per request and is enforced by a continuous-integration test. The classifier runs in-process against a 68-entry pre-compiled pattern list. Logging is buffered and flushed on the WordPress shutdown hook (after the response is sent), so the response latency a visitor sees is not affected by database writes.

How is bot identity verified — can a bad actor just pretend to be Googlebot?

This release identifies bots by matching the User-Agent header against the bundled fingerprint catalog. A spoofed User-Agent will match a real bot's record, so treat the dashboard as the answer to "what's claiming to be each bot" rather than a verified attribution. For the search-engine guard, blocking is still off by default — a spoofed Googlebot UA can't be blocked unless you explicitly enable the Search engine override toggle, and managing the actual edge layer (Cloudflare, your CDN, or a security plugin running before WordPress) remains the right place to enforce identity at the network level.

更新日志:

1.0.5 1.0.4 1.0.3 1.0.2 1.0.1 1.0.0