ScraperGuard helps you block known AI scrapers (often called “good bots”) by matching their User-Agent string.
You can:
- Select specific bots to block, or block all known bots.
- Add your own custom User-Agent substrings (one per line).
- Block via Apache
.htaccess(fast, before WordPress loads) or via WordPress-level blocking (can show basic stats).
Important notes:
- This plugin can block “good bots” that identify themselves. It cannot stop “bad bots” that ignore rules and/or spoof User-Agents. For that you may need additional security measures (WAF, rate limiting, bot protection).
.htaccessblocking works on Apache hosting only, and requires a writable.htaccessfile.- WordPress-level blocking only affects requests that reach WordPress (it won’t block direct hits to static files unless they route through WordPress).
- Country blocking (geo blocking) can use a country header (fast) or an IP lookup (works without Cloudflare but is slower).
The settings page is under Tools ScraperGuard.
External Services
This plugin can optionally connect to third-party IP geolocation services to determine the visitor’s country for country-based blocking. This feature is disabled by default and only activates when you explicitly enable “Country blocking” in the settings.
When country blocking is enabled and the “Country detection method” is set to “Auto” or “IP lookup”:
- Service used: The plugin uses either ipwho.is or ipapi.co (configurable in settings)
- Data sent: The visitor’s IP address is sent to the selected service
- When data is sent: Only when a request is received and no country header is available from your server/proxy
- Purpose: To determine the visitor’s country code (ISO-2) for geo-blocking
- Caching: Results are cached locally for 24 hours by default (configurable 1-168 hours) to minimize requests
- Privacy: IP addresses are sent to external services. Ensure compliance with your privacy policy and local regulations.
ipwho.is (default provider):
* Service provider: ipwho.is
* Privacy policy: https://ipwho.is/
* Terms of service: https://ipwho.is/
* No API key required
ipapi.co (alternative provider):
* Service provider: ipapi.co
* Privacy policy: https://ipapi.co/privacy/
* Terms of service: https://ipapi.co/terms/
* No API key required for basic usage
Important: If you keep the “Country detection method” set to “Header only” (the default), or if you don’t enable country blocking at all, no data is sent to external services.