Bot protection that never shows a CAPTCHA
A large share of the raw traffic hitting any site is automated: content scrapers, password-guessing scripts, spam bots and exploit scanners. ScaleShield, the security and speed layer in front of your site, identifies that traffic and turns it away before it touches your PHP or your database. Real visitors never see a puzzle. There is nothing to install.
Only the first request reaches your site. The rest cost you nothing: no PHP started, no database queried.
Bot filtering
Much of your raw traffic was never a person
Four kinds of automated traffic hammer every site on the internet. ScaleShield identifies each one in front of your site and drops it, so your managed WordPress site spends its resources on real visitors only.
Content scrapers
Copy your pages wholesale: product descriptions, prices, articles. Dropped before they cost you a single PHP worker.
Credential stuffers
Work through stolen password lists against your login page. They meet the browser check, never your login form.
Spam bots
Flood comment and contact forms with junk. Filtered in front of your site, before your forms ever see them.
Exploit scanners
Probe every site they can find for known weaknesses. Turned away before your application code runs.
Bot protection is one job of ScaleShield, which handles TLS, firewall rules, bot filtering and caching for every G7Cloud site. Because the filtering happens in front of your site rather than inside it, junk traffic consumes zero PHP workers and zero database connections.
The browser check your visitors never see
Traffic that looks automated gets a quick, invisible browser check: a small piece of work that a real browser completes in a moment. A person browsing on their phone never notices it happened. A bot fails it and is turned away.
The check runs on its own and asks nothing of your visitor, so there is no puzzle for a customer to abandon their basket over.
- Real visitors pass through without noticing
- Bots fail the check and are turned away in front of your site
- Ordinary browsing is never interrupted by a puzzle
- Applied automatically: no settings for you to tune
Nothing to click, nothing to type, nothing to prove. The browser does the proving.
Verified. Passes straight through, never challenged, never blocked. Your pages are indexed exactly as before.
Caught. The claim fails verification, so it is treated as the scraper it is.
Your SEO is safe
Fake Googlebot is caught. The real one never is.
Pretending to be a search-engine crawler is a favourite disguise for scrapers, because a user-agent header is trivial to fake. ScaleShield checks the claim instead: a visitor claiming to be Googlebot or Bingbot is verified against Google's and Bing's own published address ranges.
Genuine search-engine crawlers are never challenged and never blocked, so bot protection never costs you a ranking. Impostors are treated as the bots they are.
- Crawler claims verified against the address ranges Google and Bing publish
- Verified crawlers are never challenged or blocked
- Impostors are filtered like any other bot
Bots lose their favourite hiding places
Filtering the obvious bots is the easy part. ScaleShield also closes off the places bots operate from and bans the ones that keep coming back.
Datacentre networks challenged
Bots run from datacentre and hosting networks, where servers live and people don’t. Traffic from those networks can be challenged with the browser check before it reaches your site.
Trap links only bots follow
Hidden links that a person browsing normally would never touch. A bot that follows one identifies itself, and repeat offenders are banned automatically.
A reputation that decays
Every address carries a reputation score built from its behaviour. The score decays over time, so one bad request years ago does not brand a visitor forever.
Your login page stops being a target
wp-login is the path attackers actually hit on a WordPress site. Scripts work through stolen password lists against it around the clock, and each attempt normally costs your site a full WordPress boot: PHP started, database queried.
On G7Cloud, repeated password-guessing meets the browser check instead of your login form. The script fails and is turned away in front of your site. You sign in exactly as you always did.
Login protection is one layer of WordPress security on G7Cloud. The managed firewall adds WordPress-aware rules on the same paths attackers actually hit, wp-login and xmlrpc included.
The guessing never reaches your login form, so it never costs you a WordPress boot.
Nothing changes for you. You sign in the same way, at the same speed.
One capability of the layer in front of your site
Bot protection ships as part of ScaleShield on every plan, Free included. It is on the moment your site goes live, at no extra cost. The firewall and the cache are worth knowing too, and the ScaleShield page covers the whole layer.
Bot protection FAQ
What the bot filtering in front of your site does and doesn't do.
Will bot protection block Google or hurt my SEO?
No. A visitor claiming to be Googlebot or Bingbot is verified against Google's and Bing's own published address ranges. Genuine search-engine crawlers are never challenged and never blocked, so your site is indexed exactly as before. Only impostors pretending to be crawlers are treated as bots.
Will my visitors ever see a CAPTCHA?
No. Traffic that looks automated gets an invisible browser check: a small piece of work a real browser completes in a moment. A real visitor passes without noticing anything happened. The check never asks them to solve a puzzle or type anything.
Is bot protection included on every plan?
Yes. Bot protection is part of ScaleShield, the security and speed layer in front of every site on G7Cloud, including sites on the Free plan. It is not an add-on and there is no security surcharge.
What kinds of bots does ScaleShield stop?
Content scrapers, credential-stuffing scripts aimed at login pages, comment and form spam bots, exploit scanners, and scrapers disguised as search-engine crawlers. They are identified and dropped in front of your site, so they never consume your PHP workers or your database.
Are bans permanent?
No. Repeat offenders are banned automatically, using trap links that only bots follow and a per-address reputation score built from behaviour. The score decays over time, so one bad request years ago does not brand a visitor forever.
Do I still need a bot-blocking plugin on WordPress?
A plugin can only inspect a request after WordPress has booted, so a blocked bot has already cost you PHP and database work. ScaleShield drops bot traffic in front of your site instead, before your site spends anything on it. You no longer need a plugin just to filter traffic.
How does login protection work?
Repeated password-guessing against wp-login meets the browser check instead of your login form. The script fails the check and is turned away in front of your site. You sign in exactly as you always did.