• Resolved jordantrizz

    (@jordantrizz)


    Hello,

    I was wondering why there is no method to define a bot or human by a custom user agent string? You can block user agents, but you can’t categorize a user agent as bot or human or even IP’s.

    Additionally, you should be able to whitelist existing defined bots via user agent from rate limiting and blocking.

    Thanks,

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @jordantrizz, thanks for your suggestions.

    User-Agent isn’t an authoritative bot vs. human signal as they’re extremely easy to spoof. It’d be a simple bypass if used in the plugin solely for trust/allowlist decisions unless cross-checked with the IP that visited and the official list of IPs normally associated with that User-Agent.

    I can certainly make the suggestion to the team, as they’re all discussed internally. We can’t provide ongoing updates here on the forums about the status of requests but will document releases in our changelog. As the forums are publicly searchable, if you wish to expand on your use-case, you can always email feedback @ wordfence . com privately.

    Many thanks,
    Peter.

    Thread Starter jordantrizz

    (@jordantrizz)

    Hello Peter,

    Thanks for responding, totally understand and agree. However, for automated attacks using the same user agent then my suggestion will work.

    The fact that we can’t configure the firewalls existing function down to the categorization of bot or human really limits it’s use.

    Cheers,

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.