J
by jtzl 5 (1 reviews)

JTZL's Bot Maze

AI bot protection through invisible trap link mazes — hidden links lure bots into a maze of fake content for detection and blocking.

JTZL's Bot Maze ranks #37,115 among WordPress.org plugins with 10+ active installations, is #1,709 of 4,566 in the Security category, a 5/5 rating from 1 reviews, and was last updated Sep 9, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.1
v1.6.2 Current Version v1.6.2
Updated 1 week ago Last Update on 09 Sep, 2026
Refreshed 11 hours ago Last Refreshed on
#1,709 of 4,566 in Security Top 50% by installs Downloads -71.8% this week Actively maintained
View on WordPress.org
Rank
#37,115
No change
Active Installs
10+
-28.6%
KW Avg Position
18
1 better
Downloads
577
+6 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (1 reviews)

Next Milestone 20

Total Progress 30%
10+ 20+
23,853
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 7 more installs to reach 20+

Rank Changes

38,513 40,766 43,020 45,273 47,526 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
35,548 38,659 41,771 44,883 47,994 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Current #37,115
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
0 10 20 30 40 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
1 reviews
Overall 100%
5
1 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Frequently Asked Questions

Common questions about JTZL's Bot Maze

No. Trap links are hidden from humans using CSS and include rel="nofollow". Trap pages send X-Robots-Tag: noindex, nofollow headers. The plugin also adds Disallow rules to robots.txt for the trap path.
The plugin adds a Disallow rule for the trap base path so well-behaved crawlers (Googlebot, Bingbot, and similar) stay out of the trap maze instead of wasting crawl budget on it. It does this through the robots.txt that WordPress generates — the "virtual" robots.txt — using the standard robots_txt filter. It does not write a file to your server. What this means in practice: No physical robots.txt file: the rule is added automatically, alongside whatever WordPress and other plugins (e.g. your SEO plugin's sitemap line) already output. A static robots.txt file exists at your site root: your web server serves that file directly and WordPress never runs, so neither this plugin nor any other can modify it. The rule will not appear until you add it to that file. An SEO plugin manages robots.txt: the rule is added at a late priority so it survives plugins that replace the generated file (such as Rank Math's editor). Yoast appends without removing other rules, so it is unaffected. If the rule still doesn't appear, add it through that plugin's robots.txt editor. The Settings page verifies whether the rule is actually being served and, if it isn't, shows you the exact lines to add: User-agent: * Disallow: /your-trap-base-path/ (replace your-trap-base-path with your configured Trap Base Path). For safety, the plugin never creates or overwrites a physical robots.txt on its own — creating one would shadow WordPress's virtual file and drop other plugins' directives. Where a writable robots.txt already exists, it offers an optional one-click button to append the rule for you; otherwise it shows the lines to paste.
Yes. Trap link injection happens during content rendering, so cached pages will include the trap links. The trap pages themselves are served dynamically and should be excluded from page caching (they use custom query vars that most caching plugins ignore by default).
Known search engine crawlers are verified via reverse DNS lookup. Verified crawlers are exempted from bot scoring even if they follow trap links.
Trap pages are generated from a built-in content template engine that produces realistic-looking text. The content varies based on a seed value to ensure each page looks different.
Block (403) — Returns a 403 Forbidden response. Lowest server cost. Light tarpit — Serves a decoy trap page with more trap links. No delay. Full tarpit — Same as light tarpit but adds a 1-second delay, holding the PHP worker longer.
Check the Bot Maze analytics dashboard in the WordPress admin. It shows total trap visits, unique bot IPs, score distribution, and top offenders.
Cloudflare mode trusts the CF-Connecting-IP header only when the request comes from Cloudflare's published edge IP ranges. Because those edge IPs are shared by every Cloudflare customer, this proves a request came from some Cloudflare edge, not specifically from your zone. In plain terms: your server must not be reachable directly by its own IP address — only through Cloudflare. Putting your site behind Cloudflare's proxy (the orange cloud) hides your server's IP but does not block direct connections to it; if someone discovers the IP, they can still reach the server and bypass Cloudflare. A quick check: if your site still loads when you request it by its raw server IP, the origin is exposed. To lock the origin down, use any one of: Cloudflare Tunnel (your server has no public inbound port at all), Authenticated Origin Pulls (the origin requires Cloudflare's client certificate), or a firewall that allows inbound web traffic only from Cloudflare's IP ranges. If your origin stays reachable directly, visitor IP attribution can be influenced by requests outside your zone, and bots can bypass Cloudflare's own protections by hitting the origin directly.

Sign In / Register

You need to sign in or register to use this feature.