WebDecoy Plugin Lets WordPress Owners Monitor Bot Activity Before Blocking
Developer Chris has released WebDecoy, a free open-source WordPress plugin designed to help site owners detect and inspect suspicious bot activity before applying any blocking rules. The plugin operates in a 'monitor mode' that records malicious request attempts — such as fake registrations, brute-force logins, and probes for sensitive files like .env — without automatically blocking them. Users can install it via WP-CLI or the WordPress plugin directory, and core functionality works locally without an account or API key. A controlled test on an isolated WordPress 7.1 and PHP 8.3.33 environment confirmed the plugin successfully logged a simulated bot request targeting a known tripwire path. The developer recommends running tests in a staging environment and correlating timestamps and detection flags in the log to accurately identify which requests triggered alerts.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in