Visitor Filters
Core Platform Features

Secure and Optimize Your Site

Protect your application from malicious bots and web scrapers, analyze user behaviors, and automate threat responses with our powerful suite of developer-first features.

New

AI Security Assistant

Weekly plain-language digests, vetted rule suggestions, and a copilot chat grounded in your own traffic.

The assistant analyzes your last 30 days of traffic and recommends vetted protection templates you can apply in one click — always installed in dry-run mode first. The Security Copilot answers plain-language questions about your protection, blocks, and anomalies using your real metrics, and a weekly AI digest lands in your inbox like a briefing from a security analyst. Every AI feature runs under a per-tenant cost guardrail.

Popular

Advanced Rule Engine

Create precise block, challenge, or redirect actions using our powerful rule editor.

Define granular access policies using criteria like IP range, User-Agent, country, request path, rate limits, and custom headers. Choose from multiple actions including raw block, JavaScript challenge, Captcha, redirection, or traffic throttling.

New

First-Party CAPTCHA

A privacy-friendly proof-of-work challenge with risk-adaptive difficulty — no third parties, embeddable on your forms.

Suspicious visitors solve a small computational puzzle before they get through — no image grids, no tracking, no external service. Tokens are encrypted, replay-protected, and bound to the visitor, and the difficulty scales with the risk score. Use it as a rule action, let the managed threat-feed rule trigger it automatically, or embed the same widget on your own forms. Cloudflare Turnstile and hCaptcha remain available as alternatives.

Geo-Blocking & City Filters

Restrict or prioritize access by country or city levels using live IP location databases.

Keep unwanted regional traffic away from your servers. Block or challenge entire countries or narrow down constraints to specific cities. Ideal for localized compliance and optimizing resource usage.

New

IP Threat Intelligence

A managed feed of known-malicious IP ranges scores every visitor and can trigger rules automatically.

A curated blocklist of known-bad IP ranges syncs on a schedule and feeds directly into every visitor's risk score. Turn on the managed rule template to block or challenge listed IPs with one toggle, inspect the threat context right inside enforcement and session views, and let the retroactive sweep re-check recent sessions whenever new ranges are listed — so you know if a threat visited before it was known.

Core

IP Whitelists & Blacklists

Manage global white/black lists of IP addresses and CIDR ranges with instant propagation.

Allow trusted partners and internal APIs bypass security checks with whitelists, while instantly locking out known malicious actors using static blacklists. Supports individual IPv4/IPv6 addresses and CIDR subnets.

Pro

Smart Anomaly Detection

Identify and challenge suspicious scraping patterns or sudden request rate spikes automatically.

Analyze behavioral metrics dynamically. If a client exceeds safe request velocity, acts like a headless browser, or scrapes content aggressively, our system triggers progressive security challenges without interrupting human visitors.

Smart

Honeytokens & Decoys

Place invisible traps to instantly catch and ban automated scanners and malicious bots.

Inject hidden endpoints, hidden inputs, or fake directory paths in your HTML. Genuine visitors will never see them, but scrapers and vulnerability scanners will interact with them, leading to an immediate and permanent IP ban.

Real-Time Insights Dashboard

Monitor live web traffic, active challenges, and blocked threats as they happen.

Powered by Laravel Reverb WebSockets. Experience zero-delay traffic monitoring. View geographical distributions, incoming paths, block rates, and visitor browser details live without manual page refreshes.

Pro

Visual Interaction Heatmaps

Track mouse movements, clicks, and scroll depths to understand visual engagement.

See your web pages through your users' eyes. Identify which call-to-actions get clicked, how far users scroll down, and identify dead zones where users get frustrated. All tracked privacy-safely without collecting personal identifiers.

Instant

Multi-Channel Alerting

Get notified on Slack, Discord, Email, or Webhooks when specific security thresholds are breached.

Never miss a security event. Define notification triggers for anomaly detections, high-rate bot attacks, honeytoken triggers, or custom rule matches. Deliver payload data securely with signed webhooks.

Developer

Robust REST API v1

Integrate VisitorFilters programmatically to retrieve analytics or update rule tables on the fly.

Manage sites, fetch security events, toggle rules, update white/blacklists, and retrieve heatmap data through our developer REST API. Authenticate requests securely using scoped API keys.

Automated PDF/CSV Reports

Receive automated security summaries and visitor analytics reports directly in your inbox.

Configure daily, weekly, or monthly reports. Get PDF security performance summaries or export raw event logs in CSV format. Keep your team and stakeholders informed with clean, structured summaries automatically.

Multi-User

Granular Team Collaboration

Collaborate securely with role-based access controls for your team members.

Invite developers, analysts, and administrators. Assign custom roles (Owner, Admin, Member, Read-Only) to isolate settings adjustments and billing details from daily analytics viewing.

Easy

Official WordPress Plugin

Protect your WordPress site in minutes with our lightweight, official plugin.

Install our official plugin directly from the WordPress repository. Enter your site keys to immediately load the analytics script and sync local rule actions. Features built-in support for WooCommerce checkout protection.

Protect your web applications today

Start on Free without a card, or try Pro with a 14-day trial.