

Bot overview with stats, protection settings, and one-click recommended settings.
AI companies crawl the web to train their models, and some of them crawl hard. They take your content without asking, use up your server’s resources, and can slow your store down for real customers.
ddosNull AI Crawler & Scraper Blocker lets you decide, bot by bot, which AI crawlers get into your site. Everything is set up on activation. You don’t need to edit any files.
Disallow rules are added to your robots.txt, so well-behaved crawlers stop visiting.Blocking these services would hide your site from AI answers, shopping agents, or social shares, so they stay allowed unless you block them:
OAI-SearchBot, ChatGPT-User, ChatGPT AgentPerplexityBot, Perplexity-UserClaude-SearchBot, Claude-UserApplebot (Siri, Spotlight, Safari). The AI-training opt-out, Applebot-Extended, is blocked.Google-Agent, GoogleAgent-URLContext. The AI-training opt-out, Google-Extended, is blocked.DuckAssistBotMistralAI-UserAmzn-User, AmazonBuyForMefacebookexternalhit (link previews on Facebook, WhatsApp, and Instagram), meta-externalfetcherSearch engines such as Googlebot and Bingbot are not AI crawlers and are never affected.
This plugin stops bots that identify themselves. Many scrapers pretend to be a regular Chrome or Safari browser and rotate through thousands of IP addresses. The only way to catch those is by how they behave.
ddosNull Shield (free) detects bots by behavior and adds Layer-7 DDoS protection, without DNS changes. When both plugins are active, they work together:
This plugin can download the list of known AI crawlers from the ai.robots.txt project, which is hosted on GitHub. It only does so after an administrator turns on Automatic bot list updates in the plugin settings (off by default). Once enabled, the download runs once a day through WP-Cron, and also when you click the refresh icon on the settings page. With the setting off, the plugin makes no external requests.
https://raw.githubusercontent.com/ai-robots-txt/ai.robots.txt/main/robots.jsonThe plugin makes no other external requests.
This plugin does not store visitors’ IP addresses or any other personal data. For each bot it keeps only a count of blocked requests and the time of the most recent one.
The settings screen is a React app. Its uncompiled source code is included in the admin-src/ folder. To build it, run cd admin-src && npm install && npm run build.