{"id":344035,"date":"2026-07-22T13:09:49","date_gmt":"2026-07-22T13:09:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/webdecoy-bot-detection\/"},"modified":"2026-07-22T16:40:40","modified_gmt":"2026-07-22T16:40:40","slug":"webdecoy","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/webdecoy\/","author":23536506,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.2.3","stable_tag":"2.2.3","tested":"7.0.2","requires":"6.1","requires_php":"7.4","requires_plugins":null,"header_name":"WebDecoy Bot Detection","header_author":"WebDecoy","header_description":"Protect your WordPress site from bots, spam, and carding attacks with WebDecoy's advanced threat detection.","assets_banners_color":"151b28","last_updated":"2026-07-22 16:40:40","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/webdecoy.com","header_plugin_uri":"https:\/\/webdecoy.com\/wordpress","header_author_uri":"https:\/\/webdecoy.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":35,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.2.3":{"tag":"2.2.3","author":"webdecoy1","date":"2026-07-22 16:40:40"}},"upgrade_notice":{"2.0.0":"<p>Major update! All protection now works without an API key. Existing API keys continue working \u2014 premium features auto-enable. Settings are preserved.<\/p>","1.3.5":"<p>Security improvements and WooCommerce 9.4 compatibility. Recommended upgrade.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3618969,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3618969,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3618969,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3618969,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.2.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3618969,"resolution":"1","location":"assets","locale":"","width":1544,"height":965},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3618969,"resolution":"2","location":"assets","locale":"","width":1544,"height":1372},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3618969,"resolution":"3","location":"assets","locale":"","width":1544,"height":1072},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3618969,"resolution":"4","location":"assets","locale":"","width":1544,"height":1072},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3618969,"resolution":"5","location":"assets","locale":"","width":1544,"height":1072},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3618969,"resolution":"6","location":"assets","locale":"","width":1544,"height":1072},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3618969,"resolution":"7","location":"assets","locale":"","width":1544,"height":1072}},"screenshots":{"1":"Protection settings \u2014 configure detection and blocking","2":"Statistics page \u2014 30-day detection trends and threat distribution","3":"Detections log \u2014 view threats with scores and MITRE tactics","4":"Blocked IPs \u2014 manage blocked addresses with expiration","5":"Dashboard widget \u2014 threat overview at a glance","6":"WebDecoy Cloud \u2014 optional premium features","7":"WooCommerce checkout protection settings","8":"Challenge page \u2014 invisible proof-of-work for suspicious visitors"}},"plugin_section":[262246],"plugin_tags":[22770,1174,600,2419,286],"plugin_category":[45,54],"plugin_contributors":[272798],"plugin_business_model":[],"class_list":["post-344035","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-bot-detection","plugin_tags-firewall","plugin_tags-security","plugin_tags-spam-protection","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-webdecoy1","plugin_committers-webdecoy1"],"banners":{"banner":"https:\/\/ps.w.org\/webdecoy\/assets\/banner-772x250.png?rev=3618969","banner_2x":"https:\/\/ps.w.org\/webdecoy\/assets\/banner-1544x500.png?rev=3618969","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/webdecoy\/assets\/icon-128x128.png?rev=3618969","icon_2x":"https:\/\/ps.w.org\/webdecoy\/assets\/icon-256x256.png?rev=3618969","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-1.png?rev=3618969","caption":"Protection settings \u2014 configure detection and blocking"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-2.png?rev=3618969","caption":"Statistics page \u2014 30-day detection trends and threat distribution"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-3.png?rev=3618969","caption":"Detections log \u2014 view threats with scores and MITRE tactics"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-4.png?rev=3618969","caption":"Blocked IPs \u2014 manage blocked addresses with expiration"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-5.png?rev=3618969","caption":"Dashboard widget \u2014 threat overview at a glance"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-6.png?rev=3618969","caption":"WebDecoy Cloud \u2014 optional premium features"},{"src":"https:\/\/ps.w.org\/webdecoy\/assets\/screenshot-7.png?rev=3618969","caption":"WooCommerce checkout protection settings"}],"raw_content":"<!--section=description-->\n<p>WebDecoy is a <strong>free, fully-functional<\/strong> bot detection and protection plugin that works 100% locally. Unlike CAPTCHA solutions that frustrate visitors, WebDecoy uses invisible multi-layer detection \u2014 legitimate users never see challenges or interruptions.<\/p>\n\n<p><strong>Works immediately on activation.<\/strong> No account needed. No API key required. No external connections at all until you optionally connect a WebDecoy Cloud account.<\/p>\n\n<h4>Why WebDecoy?<\/h4>\n\n<ul>\n<li><strong>Zero friction<\/strong> \u2014 Humans never see CAPTCHAs or challenges<\/li>\n<li><strong>Zero configuration<\/strong> \u2014 Install, activate, done<\/li>\n<li><strong>Zero dependencies<\/strong> \u2014 Everything runs locally on your server<\/li>\n<li><strong>Multi-layer detection<\/strong> \u2014 Server-side + client-side + proof-of-work challenges<\/li>\n<li><strong>Free forever<\/strong> \u2014 Full protection at no cost. Premium cloud features are optional.<\/li>\n<\/ul>\n\n<h4>Free Features (No API Key Needed)<\/h4>\n\n<p><strong>Server-Side Detection<\/strong>\n* User-Agent analysis and HTTP header inspection\n* Good bot verification (reverse DNS for Googlebot, Bingbot, etc.)\n* MITRE ATT&amp;CK path analysis (admin probing, config file access)\n* Rate limiting with automatic blocking\n* IP blocking (individual + CIDR, IPv4\/IPv6, expiration)<\/p>\n\n<p><strong>Client-Side Detection<\/strong>\n* WebDriver detection (Selenium, Puppeteer, Playwright)\n* Headless browser detection (Chrome headless, PhantomJS)\n* Automation framework detection\n* Behavioral analysis (mouse movement, click patterns, scroll behavior)\n* Canvas\/WebGL fingerprinting\n* AI crawler detection (GPTBot, ClaudeBot, PerplexityBot)<\/p>\n\n<p><strong>Invisible Proof-of-Work Challenges<\/strong>\n* SHA-256 challenges solved in background (no user interaction)\n* Challenge mode for suspicious requests (checkbox widget, auto-solves)\n* Difficulty scales based on threat signals\n* No external CAPTCHA service needed<\/p>\n\n<p><strong>Form Protection<\/strong>\n* Comment spam protection\n* Login brute force protection\n* Registration spam prevention\n* Invisible honeypot fields on comment, login, and registration forms<\/p>\n\n<p><strong>WooCommerce Protection<\/strong>\n* Checkout carding attack prevention\n* Velocity limiting (configurable attempts per time window)\n* Card testing pattern detection\n* WooCommerce Blocks compatible<\/p>\n\n<p><strong>Local Dashboard &amp; Analytics<\/strong>\n* Detection log with threat scores and MITRE tactic mapping\n* Statistics page with 30-day trend charts\n* Blocked IPs management\n* Dashboard widget with threat overview\n* CSV export\n* Automatic data cleanup (30 days)<\/p>\n\n<p><strong>Smart Bot Recognition<\/strong>\n* 60+ known good bots automatically allowed\n* Search engines, social media, monitoring services, SEO tools\n* Optional AI crawler blocking\n* Custom allowlist support<\/p>\n\n<h4>Premium Features (Optional WebDecoy Cloud)<\/h4>\n\n<p>Connect an API key to unlock cloud-powered intelligence:<\/p>\n\n<ul>\n<li><strong>IP Reputation<\/strong> \u2014 AbuseIPDB integration, threat scoring<\/li>\n<li><strong>VPN\/Proxy Detection<\/strong> \u2014 Identify visitors hiding behind VPNs, proxies, and Tor<\/li>\n<li><strong>GeoIP Enrichment<\/strong> \u2014 Geographic data from MaxMind<\/li>\n<li><strong>Cloud Sync<\/strong> \u2014 Forward detections to centralized dashboard<\/li>\n<li><strong>Cross-Site Intelligence<\/strong> \u2014 Aggregate threat data from all WebDecoy customers<\/li>\n<li><strong>Advanced Analytics<\/strong> \u2014 Cloud dashboard at app.webdecoy.com with indefinite history<\/li>\n<li><strong>Webhooks &amp; Alerts<\/strong> \u2014 Automated response chains, email notifications<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/webdecoy.com\/pricing\">Explore Plans<\/a> | <a href=\"https:\/\/app.webdecoy.com\/register\">Start Free Trial<\/a><\/p>\n\n<h4>Threat Scoring<\/h4>\n\n<p>WebDecoy uses an intelligent scoring system (0-100):<\/p>\n\n<ul>\n<li>0-19: MINIMAL \u2014 Allow (likely human)<\/li>\n<li>20-39: LOW \u2014 Log only<\/li>\n<li>40-59: MEDIUM \u2014 Optional challenge<\/li>\n<li>60-74: HIGH \u2014 Challenge or block<\/li>\n<li>75-100: CRITICAL \u2014 Automatic block<\/li>\n<\/ul>\n\n<p>The threshold is fully configurable to match your site's needs.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin can optionally connect to the following external services when you provide an API key:<\/p>\n\n<h4>WebDecoy Cloud \u2014 ingest.webdecoy.com and api.webdecoy.com<\/h4>\n\n<p>This plugin only contacts WebDecoy Cloud when you explicitly connect an account by entering an API key on the WebDecoy Cloud settings tab. With no API key configured, no data is ever sent to these services.<\/p>\n\n<p>What is sent, and when:\n* When a detection or rule violation occurs: the visitor's IP address, user agent, request path, threat score and detection flags are sent to ingest.webdecoy.com so the event appears in your cloud dashboard.\n* When you use an IP-reputation filter rule (e.g. ip.abuse_score, ip.tor): the visitor's IP address is sent to ingest.webdecoy.com to look up reputation\/geo data.\n* When validating your key or forwarding a WooCommerce checkout detection: your API key, organization ID and the detection data above are sent to api.webdecoy.com \/ ingest.webdecoy.com.<\/p>\n\n<p>All requests are made server-side over HTTPS. This is an optional cloud service provided by WebDecoy.\nTerms of Service: https:\/\/webdecoy.com\/terms\nPrivacy Policy: https:\/\/webdecoy.com\/privacy<\/p>\n\n<p><strong>Without an API key, the plugin operates 100% locally \u2014 no external connections on the front end or back end.<\/strong> Chart.js (used for the admin Statistics charts) is bundled with the plugin, not loaded from a CDN.<\/p>\n\n<h4>Bundled third-party libraries<\/h4>\n\n<p>Chart.js v4.5.1 (MIT license) is included at admin\/js\/vendor\/chart.umd.min.js for the admin Statistics charts. It is the official distribution build; the human-readable source is available at https:\/\/github.com\/chartjs\/Chart.js\/releases\/tag\/v4.5.1 . No other third-party libraries are bundled.<\/p>\n\n<h4>Reference URLs in the good-bot database<\/h4>\n\n<p>The bundled good-bot list (sdk\/src\/GoodBotList.php) stores a documentation URL for each known bot (e.g. developer.amazon.com\/amazonbot, api.slack.com\/robots) purely as reference metadata shown alongside detections. These URLs are never requested by the plugin \u2014 no connection of any kind is made to them.<\/p>\n\n<h3>Privacy Policy<\/h3>\n\n<p>WebDecoy collects the following data locally for bot detection purposes:<\/p>\n\n<ul>\n<li>IP addresses<\/li>\n<li>User agent strings<\/li>\n<li>HTTP headers<\/li>\n<li>Browser fingerprint signals<\/li>\n<li>Request patterns<\/li>\n<\/ul>\n\n<p>This data is stored in your WordPress database and automatically cleaned up after 30 days. No data is sent externally unless you configure a WebDecoy Cloud API key.<\/p>\n\n<p>For more information, see our <a href=\"https:\/\/webdecoy.com\/privacy\">Privacy Policy<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>webdecoy<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install directly from the WordPress plugin repository<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li><strong>That's it!<\/strong> Protection is active immediately with sensible defaults<\/li>\n<\/ol>\n\n<h4>Optional: Connect to WebDecoy Cloud<\/h4>\n\n<ol>\n<li>Go to <strong>WebDecoy &gt; Settings &gt; WebDecoy Cloud<\/strong> tab<\/li>\n<li>Enter your API key from your <a href=\"https:\/\/app.webdecoy.com\">WebDecoy dashboard<\/a><\/li>\n<li>Click \"Test Connection\" to verify<\/li>\n<li>Cloud features (threat intel, VPN detection, etc.) activate automatically<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20api%20key%3F\"><h3>Do I need an API key?<\/h3><\/dt>\n<dd><p><strong>No.<\/strong> WebDecoy works 100% locally without any API key or account. All detection, blocking, rate limiting, form protection, and WooCommerce protection works out of the box. The API key is only needed for optional cloud features like IP reputation and VPN detection.<\/p><\/dd>\n<dt id=\"what%20does%20webdecoy%20cloud%20add%3F\"><h3>What does WebDecoy Cloud add?<\/h3><\/dt>\n<dd><p>WebDecoy Cloud adds threat intelligence feeds (AbuseIPDB, VPNAPI, MaxMind), centralized monitoring across multiple sites, indefinite detection history, and automated response features like webhooks and email alerts. <a href=\"https:\/\/webdecoy.com\/pricing\">Compare plans<\/a>.<\/p><\/dd>\n<dt id=\"does%20webdecoy%20slow%20down%20my%20site%3F\"><h3>Does WebDecoy slow down my site?<\/h3><\/dt>\n<dd><p>No. WebDecoy adds less than 5ms of latency to requests. Server-side detection runs in milliseconds. The client-side scanner loads asynchronously with the <code>defer<\/code> attribute and doesn't block page rendering.<\/p><\/dd>\n<dt id=\"will%20it%20block%20legitimate%20visitors%3F\"><h3>Will it block legitimate visitors?<\/h3><\/dt>\n<dd><p>WebDecoy is designed to minimize false positives. You can adjust the sensitivity and blocking threshold. Start with \"Log only\" mode to monitor before enabling blocking. Good bots (Googlebot, Bingbot, etc.) are automatically recognized.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. WebDecoy works alongside popular caching plugins. The client-side scanner runs after page load, and server-side checks happen before caching.<\/p><\/dd>\n<dt id=\"what%20about%20search%20engine%20bots%3F\"><h3>What about search engine bots?<\/h3><\/dt>\n<dd><p>WebDecoy automatically recognizes and allows 60+ legitimate bots including Googlebot, Bingbot, and other search engine crawlers. Good bot verification uses reverse DNS lookup. Your SEO won't be affected.<\/p><\/dd>\n<dt id=\"can%20i%20block%20ai%20training%20crawlers%3F\"><h3>Can I block AI training crawlers?<\/h3><\/dt>\n<dd><p>Yes. WebDecoy can identify and optionally block AI crawlers like GPTBot, ClaudeBot, PerplexityBot, and others. Enable this in Settings &gt; Good Bots.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. WebDecoy includes specialized carding protection for WooCommerce including checkout velocity limiting, card testing detection, and automatic fraud blocking. Compatible with both classic checkout and WooCommerce Blocks.<\/p><\/dd>\n<dt id=\"is%20my%20data%20secure%3F\"><h3>Is my data secure?<\/h3><\/dt>\n<dd><p>Without an API key, the plugin makes <strong>zero external connections<\/strong> \u2014 visitors' browsers never contact third-party servers, and neither does your server. Chart.js (admin charts) is bundled with the plugin. All detection data stays on your server, and detection logs are automatically cleaned up after 30 days. When you optionally connect WebDecoy Cloud, all communication is encrypted over HTTPS (see External Services below).<\/p><\/dd>\n<dt id=\"how%20does%20the%20proof-of-work%20challenge%20work%3F\"><h3>How does the proof-of-work challenge work?<\/h3><\/dt>\n<dd><p>When a suspicious visitor is detected and your block action is set to \"Challenge\", they see a checkbox widget. Clicking it starts a SHA-256 puzzle that solves in the background (typically under 1 second for humans). Bots and automation tools take much longer or fail entirely. No external CAPTCHA service is involved.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.2.3<\/h4>\n\n<ul>\n<li>Changed: All CSS and JavaScript is now loaded via the WordPress dependency APIs (wp_register_style\/script, wp_add_inline_script, wp_print_styles\/scripts) \u2014 no more raw style\/script tags<\/li>\n<li>Changed: The \"Protected by WebDecoy\" credit on the challenge page is now opt-in (Settings &gt; Blocking) and off by default<\/li>\n<li>Changed: Updated bundled Chart.js to v4.5.1 (latest stable)<\/li>\n<li>Changed: Removed the load_plugin_textdomain() call (unneeded since WordPress 4.6 for directory-hosted plugins)<\/li>\n<\/ul>\n\n<h4>2.2.2<\/h4>\n\n<ul>\n<li>Fixed: A PHP 7.4 fatal error in good-bot verification (use of a PHP 8 function)<\/li>\n<li>Fixed: Timezone-safe date handling throughout<\/li>\n<li>Changed: The bundled SDK now uses the WordPress HTTP API exclusively (removed the raw cURL fallback)<\/li>\n<li>Changed: Requires WordPress 6.1+; tested up to WordPress 7.0<\/li>\n<li>Internal: Full WordPress Plugin Check compliance (resolved 69 flagged items)<\/li>\n<\/ul>\n\n<h4>2.2.1<\/h4>\n\n<ul>\n<li>Changed: Chart.js (admin Statistics charts) is now bundled with the plugin instead of loaded from a CDN \u2014 the plugin makes no external requests until you connect a WebDecoy Cloud account<\/li>\n<li>Changed: Clarified the External Services disclosure<\/li>\n<li>Internal: Refactored the self-hosted updater into its own module<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Added: Tripwires \u2014 deterministic, zero-false-positive blocking of hidden honeypot paths (on by default)<\/li>\n<li>Added: Honeytoken \u2014 auto-injected invisible decoy link armed as a tripwire (on by default)<\/li>\n<li>Added: Filter rules \u2014 expression-based rules with an admin rule builder (ip.* \/ req.* fields)<\/li>\n<li>Added: IP enrichment (VPN\/proxy\/Tor, geo, ASN, abuse score) powering ip.* filter fields<\/li>\n<li>Added: wd_clearance enforcement loop \u2014 silent cookie minting + tripwire forwarding for rotation-proof device lockouts<\/li>\n<li>Added: Stealth-browser (F1) detection \u2014 catches automation that patches native browser functions<\/li>\n<li>Added: Deceptive tripwire responses \u2014 fake .env\/wp-config\/SQL\/phpinfo with per-site canary credentials; canary logins flagged as critical<\/li>\n<li>Added: WordPress-native traps \u2014 fake vulnerable-plugin paths, optional XML-RPC trap, author-enumeration canary<\/li>\n<li>Added: WooCommerce honeytoken coupons \u2014 a hidden decoy coupon; applying it is a deterministic bot signal<\/li>\n<li>Added: IP allowlist (Settings \u2192 Blocking)<\/li>\n<li>Improved: Rate limiting runs as a rule \u2014 proper 429 + Retry-After + X-RateLimit-* headers, sliding-window algorithm, per-IP\/route\/user keying<\/li>\n<li>Improved: Resilient violation reporting (DB spool + cron retry, no page latency)<\/li>\n<li>Changed: Consolidated onto a single detector path; removed legacy dead code<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added: JS execution verification \u2014 detects non-JS HTTP scrapers<\/li>\n<li>Added: Challenge token meta tag for premium page serve tracking<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li><strong>Major: All detection and protection now works locally \u2014 no API key required<\/strong><\/li>\n<li>Added: Invisible proof-of-work (PoW) challenge system<\/li>\n<li>Added: Behavioral scoring for form submissions<\/li>\n<li>Added: Statistics page with Chart.js detection trend charts<\/li>\n<li>Added: Enhanced detections page with date filters, CSV export, bulk actions<\/li>\n<li>Added: WebDecoy Cloud settings tab (optional premium features)<\/li>\n<li>Added: Cloud upsell sections throughout dashboard<\/li>\n<li>Improved: Settings page restructured \u2014 Protection tab is now default<\/li>\n<li>Improved: Dashboard widget with cloud intelligence upsell<\/li>\n<li>Changed: CDN update checker gated behind WEBDECOY_SELF_HOSTED constant<\/li>\n<li>Changed: Version bump to 2.0.0 signaling architecture change<\/li>\n<li>Fixed: PHP 7.4 str_ends_with polyfill (already present)<\/li>\n<\/ul>\n\n<h4>1.3.8<\/h4>\n\n<ul>\n<li>Fixed: Removed no_plugins trigger (deprecated in modern browsers, caused false positives)<\/li>\n<\/ul>\n\n<h4>1.3.7<\/h4>\n\n<ul>\n<li>Version bump<\/li>\n<\/ul>\n\n<h4>1.3.6<\/h4>\n\n<ul>\n<li>Protection hooks only activate when API key is validated as active<\/li>\n<li>E2E test compatibility<\/li>\n<\/ul>\n\n<h4>1.3.5<\/h4>\n\n<ul>\n<li>Security improvements and code hardening<\/li>\n<li>Updated WooCommerce compatibility to 9.4<\/li>\n<li>Performance optimizations for detection checks<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Major performance improvements<\/li>\n<li>Added bulk IP blocking\/unblocking<\/li>\n<li>Enhanced good bot detection (60+ bots)<\/li>\n<li>Improved WooCommerce checkout protection<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>","raw_excerpt":"Zero-config bot, spam, and carding protection. Works instantly on activation, with no account, API key, or external connections.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/344035","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=344035"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/webdecoy1"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=344035"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=344035"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=344035"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=344035"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=344035"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=344035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}