Skip to content

Bot protection

Pick one of four protection levels, let verified bots and your own paths through, and see what each level really does on Cloudflare.

Bot protection decides what happens to automated traffic at Cloudflare, before it reaches WordPress. Open your site, then Bot protection, to see the level of the environment you are looking at and change it.

Pick a protection level

  1. Open your site, then Bot protection.
  2. Under Protection level, choose Change level.
  3. Pick one of the four cards. Each card shows what happens to each kind of traffic: allow, challenge, or block.
  4. Choose Change protection level. The button stays off until you pick a level other than the current one.

Avaloi applies the level through a job, and the change shows in the site's activity log. Every new environment, live, staging, or multidev, starts on Block automations.

The levels

Traffic Block malicious traffic Block automations Challenge bots Challenge everyone
Verified bots Allow Allow Allow Allow
Known automation tools Allow Block Challenge Challenge
Clients without browser headers Allow Allow Challenge Challenge
Everyone else Allow Allow Allow Challenge
Malicious traffic Block Block Block Block
  • Block malicious traffic is the always-on protection every site has. It needs no rule of its own.
  • Block automations is recommended for most sites. It blocks scripts and scrapers that say what they are.
  • Challenge bots suits a site seeing more scraping, spam, or suspicious traffic. Clients that do not look like a browser get a Cloudflare check instead of a block.
  • Challenge everyone suits a site under active attack. Every visitor sees a short Cloudflare check before the site loads, and scripts, webhooks, and apps that call your site fail unless you add them as exceptions. Turn it back down when the attack stops.

What each row means

  • Verified bots: search engines, uptime monitors, and other bots on Cloudflare's verified bot list. You can turn this off.
  • Known automation tools: requests with no user agent, or one from a scripting tool or headless browser, such as curl, Python, Go, Java, Scrapy, or HeadlessChrome.
  • Clients without browser headers: requests with no Accept-Language header, or on HTTP/1.0. Real browsers always send the header and never use HTTP/1.0.
  • Everyone else: people, and any bot that looks like a browser.
  • Malicious traffic: known attacks, stopped by Cloudflare's Free Managed Ruleset, Avaloi's WordPress hardening rule, and the login rate limit.

What the levels cannot do

Avaloi's sites share one Cloudflare zone on the Free plan. That plan has no Cloudflare Bot Management, so there is no bot score that tells likely humans from likely bots, and no list of AI crawlers by behavior. Avaloi does not pretend otherwise: a bot that copies a real browser's user agent and headers falls under Everyone else, and only Challenge everyone stops it. Cloudflare's threat score is no longer used by Cloudflare, so no level relies on it.

Each level that does something beyond the baseline is one Cloudflare rule that every site on that level shares. Your site joins a level by adding its domains to that rule, so a new site never needs a rule of its own. If a shared rule is ever full, the tab says so, your level is saved, and the baseline still applies until there is room.

Turn bot protection off or on

Choose Disable on the Protection level card to turn bot protection off. The always-on protection still blocks malicious traffic. Choose Enable to turn it back on at the level you had before.

Let verified bots through

Allow verified bots is on by default, so bots on Cloudflare's verified list always pass, at every level. Turn it off only to stop crawlers.

Exceptions

Choose Add exception to let a path, such as a webhook URL, or an IP address or range, such as your office, skip bot protection. Remove an exception from its three dot menu. Certificate checks under /.well-known/ always pass, and Challenge everyone also lets /wp-cron.php through so scheduled tasks keep running.

Staging and multidev

Staging and multidev environments start on Block automations too. They also refuse known search engine crawlers at the edge and tell search engines not to index them. See Staging privacy.

Always on

Every site blocks requests for wp-config.php, .env, .git, debug.log, PHP files in uploads, XML-RPC, and author scans on the home page. Every site also limits each address to 5 requests to wp-login.php every 10 seconds, then blocks it for 10 seconds. Cloudflare's Free Managed Ruleset runs on every request.

Read the traffic counts

The Requests card shows requests, challenges, and blocks for the last 24 hours, from Cloudflare, for your site's domains only. Blocks and challenges include the always-on rules. Verified bot counts need Cloudflare Bot Management, which the avaloi.com zone does not have, so that number says "Not on this plan".

The card stays hidden when Cloudflare cannot count security events per domain on the zone's plan. Avaloi does not show counts for the whole zone, because they would include other customers' sites.

Limits

  • Four levels, one per environment.
  • Login protection: 5 requests every 10 seconds to wp-login.php from one address, then a 10 second block.
  • Traffic counts cover the last 24 hours.

Quick answers

A service that calls my site gets blocked or challenged. Add its path or its address as an exception, or pick Block malicious traffic.

Will Google still crawl my site? Yes, at every level, while Allow verified bots is on.

I cannot log in and see a block page. Your address sent more than 5 login requests in 10 seconds. Wait 10 seconds and try again.

The tab says the shared Cloudflare rules are full. Your level is saved but not enforced yet. The always-on protection still applies. Try again later or contact support.

API

  • GET /v1/environments/{id}/bot-protection returns enabled, level, matrix_key, the exceptions, where the rule runs, and the last 24 hours of counts.
  • PUT /v1/environments/{id}/bot-protection takes level (block_malicious, block_automations, challenge_bots, or challenge_everyone) and enabled. Fields you leave out keep their value. The older mode field still works: off turns protection off, challenge means Challenge bots, and block means Block automations.
  • GET /v1/environments/{id}/bot-protection/stats

AI agents can call the set_bot_protection tool on the Avaloi MCP server. It asks for your approval first.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.