ShopBouncer

Description

ChatGPT, Claude, Perplexity and Meta AI now browse stores and place orders for real customers. Google Analytics can’t show you most of that traffic, and anything can call itself “ChatGPT”.

ShopBouncer adds an AI Shoppers dashboard to WooCommerce (or to Tools on any WordPress site):

  • Which AI agents visit, split into agents shopping for a person and crawlers that index or train.
  • Verified or not, and by whom. Agents that sign their requests with Web Bot Auth (RFC 9421 HTTP Message Signatures), such as ChatGPT’s agent and Google’s agent, are checked cryptographically against their operator’s published keys, and the dashboard names the operator that signed.
  • Impostors spotted. OpenAI, Anthropic and Perplexity publish the IP ranges their agents use. A visitor calling itself ChatGPT, Claude or Perplexity from outside those ranges is flagged as an impostor; one from inside them is marked verified by IP. Agents whose operator publishes neither keys nor ranges are marked “unverified (name only)”.
  • Sales sent by AI assistants. How much shoppers who clicked through from ChatGPT, Perplexity, Gemini, Claude, Copilot and other assistants spent, read from WooCommerce’s own Order Attribution. ShopBouncer adds no tracking of its own.
  • Where they go: product pages, cart, checkout, customer accounts, APIs.
  • Orders placed by AI agents and the revenue they bring, with the agent’s identity check and signature headers saved on each order as evidence, shown in an “AI agent evidence” box on the order screen.
  • Alerts when impostors visit and when unverified agents reach your checkout.
  • A setup check that proves everything works on your own server: the official IP lists download, a real and a fake “ChatGPT” visit get the right verdicts, and your proxy settings are right.
  • An optional weekly AI Shopper Report by email, sent by your own site.

Privacy by design

  • No IP addresses or visitor identifiers are stored. An agent’s IP is compared with its operator’s published ranges in memory; only the outcome is kept.
  • Human visitors are never recorded.
  • Visit history is deleted automatically after 90 days (configurable).
  • No data is sent to ShopBouncer. See “External services” below.
  • The weekly report (off until you enter an address) is sent by your own site with WordPress’s mail function.

Built to stay out of the way

Human requests cost one string check. Agent visits are written after the page has been sent. The plugin is compatible with WooCommerce High-Performance Order Storage and the Cart and Checkout blocks.

External services

ShopBouncer connects to the services below, and only to them. None of these requests contains any data about your store’s visitors, customers or orders. Like any web request, each one reveals your server’s IP address and the user agent “ShopBouncer/1.1.0 (+https://shopbouncer.com)”. Everything downloaded is public data, cached on your site, and used only to check whether a visiting AI agent is who it claims to be.

OpenAI

What: the IP address lists OpenAI publishes for its agents (ChatGPT-User, OAI-SearchBot, GPTBot), and the public signing keys of ChatGPT’s agent.
Why: to check whether a visitor calling itself ChatGPT really came from OpenAI.
What is sent, and when: a plain download request, with no data from your site, to https://openai.com/chatgpt-user.json, https://openai.com/searchbot.json or https://openai.com/gptbot.json when a visitor claiming to be that agent arrives and the cached copy is more than 6 hours old (also when you open the AI Shoppers setup check); and to https://chatgpt.com/.well-known/http-message-signatures-directory when a signed request names chatgpt.com and the cached keys are more than an hour old.
Terms of use: https://openai.com/policies/row-terms-of-use/
Privacy policy: https://openai.com/policies/row-privacy-policy/

Anthropic (claude.com)

What: the IP address list Anthropic publishes for its agents (Claude-User, Claude-SearchBot, ClaudeBot). claude.com is Anthropic’s website.
Why: to check whether a visitor calling itself Claude really came from Anthropic.
What is sent, and when: a plain download request, with no data from your site, to https://claude.com/crawling/bots.json when a visitor claiming to be one of those agents arrives and the cached copy is more than 6 hours old (also when you open the setup check).
Terms of service: https://www.anthropic.com/legal/consumer-terms
Privacy policy: https://www.anthropic.com/legal/privacy

Perplexity

What: the IP address lists Perplexity publishes for Perplexity-User and PerplexityBot.
Why: to check whether a visitor calling itself Perplexity really came from Perplexity.
What is sent, and when: a plain download request, with no data from your site, to https://www.perplexity.ai/perplexity-user.json or https://www.perplexity.ai/perplexitybot.json when a visitor claiming to be that agent arrives and the cached copy is more than 6 hours old (also when you open the setup check).
Terms of service: https://www.perplexity.ai/hub/legal/terms-of-service
Privacy policy: https://www.perplexity.ai/hub/legal/privacy-notice

Google

What: the public signing keys of Google’s AI agent (Google-Agent).
Why: to verify requests that Google’s agent signs with Web Bot Auth.
What is sent, and when: a plain download request, with no data from your site, to https://agent.bot.goog/.well-known/http-message-signatures-directory when a signed request names agent.bot.goog and the cached keys are more than an hour old.
Terms of service: https://policies.google.com/terms
Privacy policy: https://policies.google.com/privacy

Links only (no data is sent)

The dashboard links to shopbouncer.com: the free store scanner, the IP checker and the design-partner program. Nothing is sent unless you click a link. Privacy notice: https://shopbouncer.com/privacy

The optional weekly report is sent by your own site with WordPress’s mail function, to the address you enter. It does not go through ShopBouncer or any other service.

Screenshots

Installation

  1. Install and activate the plugin.
  2. Open WooCommerce AI Shoppers (or Tools AI Shoppers without WooCommerce).
  3. Visits appear as soon as an AI agent loads a page.

FAQ

Does it block anything?

No. This plugin only observes and reports. It never changes what visitors or agents see.

How do you know an agent is really ChatGPT?

An agent is verified in one of two ways. If it signs its request with Web Bot Auth, the signature is checked against the public keys its operator publishes; ShopBouncer only uses the key directories of operators that document them (OpenAI for ChatGPT’s agent, Google for Google-Agent), and the dashboard names the operator that signed. If it doesn’t sign, its IP address is checked against the ranges its operator publishes: inside means verified by IP, outside means impostor. A user-agent string with nothing to check it against is recorded as “unverified (name only)”, because anyone can send it.

My site is behind Cloudflare or another proxy. Does the IP check still work?

Yes, once you tell ShopBouncer where the visitor’s IP arrives: open the AI Shoppers page and set “Visitor IP comes from” to Cloudflare, X-Forwarded-For or X-Real-IP. The page warns you when it detects a proxy header. Until then, requests from private addresses are left unchecked rather than flagged.

Where does the “sales sent by AI assistants” figure come from?

From WooCommerce’s built-in Order Attribution (WooCommerce 8.5 and later), which already records where each order came from. ShopBouncer counts the paid orders whose source is an AI assistant’s website, such as chatgpt.com or perplexity.ai. If Order Attribution is switched off, the dashboard tells you where to turn it on.

Does it slow my store down?

No measurable impact for human visitors. Agent visits are recorded after the response is finished.

What happens when I uninstall?

The visit table and settings are deleted. Evidence saved on agent orders stays on those orders, because it is part of the order record.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“ShopBouncer” is open source software. The following people have contributed to this plugin.

Contributors

Translate “ShopBouncer” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.0

  • New: sales sent by AI assistants (ChatGPT, Perplexity, Gemini, Claude, Copilot and more), from WooCommerce Order Attribution.
  • New: redesigned dashboard: a one-line summary, a real-vs-fake bar for every agent, and daily visits split by verdict.
  • New: setup check that tests impostor detection live on your server.
  • New: optional weekly AI Shopper Report email.
  • Improved: IP lists are accepted only when complete, so a partly downloaded list can never create false impostors.
  • Improved: signatures are checked only against documented key directories (OpenAI for ChatGPT’s agent, Google for Google-Agent). Keys are matched by thumbprint or key id, and expired keys are ignored.
  • Improved: all request data is sanitized with WordPress functions and then validated.

1.0.0

  • First public release: AI Shoppers dashboard, Web Bot Auth signature verification, impostor detection against operators’ published IP ranges, agent order tagging with an evidence box on each agent order.