RokthamBot Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
RokthamBot is an AI bot management plugin for WordPress. It identifies, fingerprints, rate-limits, and blocks AI scrapers while protecting your search engine visibility. With 148+ AI bots in its database, per-bot policy controls, verified bot detection, emergency lockdown, and AI referral traffic tracking, RokthamBot gives you complete control over who accesses your content.
Why You Need This
AI crawlers including GPTBot, ClaudeBot, PerplexityBot, Bytespider, CCBot, and 140+ others scrape WordPress sites every day, causing:
- CPU spikes from repeated database queries
- Bandwidth bloat from automated scraping
- Content theft — your content used to train AI models without consent
- Rising hosting costs from bot traffic
robots.txt is advisory only — AI bots can choose to ignore it. RokthamBot enforces real technical blocks.
Free Features
- 148+ AI Bot Detection and Blocking — Pre-loaded with GPTBot, ClaudeBot, PerplexityBot, Bytespider, CCBot, and 140+ others from OpenAI, Anthropic, Google, Meta, Amazon, ByteDance, Perplexity, Cohere, Mistral, and more
- Per-Bot Policy Controls — Allow / Block / Log Only / Use Default for each bot independently
- Master “Block All AI Bots” Panic Button — One-click blanket block for all detected AI crawlers
- Emergency Lockdown Mode (HTTP 451) — Instantly lock down your entire site with a single action, returning HTTP 451 (Unavailable For Legal Reasons)
- IP and User Agent Whitelist (CIDR Support) — Whitelist trusted IPs using CIDR notation and specific User-Agent strings
- Verified Bot Detection — Multi-layer verification using IP ranges and reverse-DNS lookup to confirm bot identity
- “Block Only Fakes” Feature — Automatically block spoofed bots while allowing verified real ones through
- AI Referral Traffic Tracking — Track referrals from ChatGPT, Perplexity, Gemini, Claude, Copilot, Meta AI, and other AI-powered services
- robots.txt Manager with Live Preview — Manage and preview your robots.txt rules directly from the admin
- Per-Page Protection Control — Enable or disable bot protection on individual pages via a meta box in the editor
- Content Poisoning for AI Scrapers — Serve corrupted data to detected scrapers to degrade training value
- Rate Limiting per Bot Category — Apply sliding window rate limits with exponential backoff per bot category
- Search Engine Visibility Guard — Google, Bing, DuckDuckBot, Applebot, and YandexBot protected from accidental blocks
- CDN Auto-Detection — Auto-detect Cloudflare, AWS CloudFront, Bunny CDN, Fastly, Sucuri, Akamai, StackPath, and KeyCDN
- AI Readiness Score Diagnostic — Get a 0-100 score evaluating how well your site is prepared for the AI era
- RSL 1.0 Machine-Readable Licensing Framework — Define machine-readable licensing terms for AI consumption
- Meta Tags Protection — Automatic noai and noimageai meta tags to signal AI restrictions
- WooCommerce Product Protection — Dedicated protection for WooCommerce product pages and REST API endpoints
- Email Notification System — Blocked alert notifications and daily digest summaries
- REST API Endpoints — Programmatic access to bot analytics, policies, and controls
- WP-CLI Commands — Manage bot policies and view analytics from the command line
- Setup Wizard for First-Time Configuration — Guided onboarding with CDN detection, policy selection, and search engine protection
- Admin Dashboard with Traffic Analytics — Real-time stats with hero cards showing blocked, allowed, and logged bot traffic
- Bot Control Panel with Per-Bot Policy Management — Dedicated panel for managing individual bot policies
- Search Engine Monitor — Verify Googlebot, Bingbot, and other search engine access in real-time
- Full Multisite Support — Managed per-site or synced across the network using JSON export/import
- Clean Uninstall — Removes all data completely when the plugin is deleted
How It Works
- Install & Activate — No configuration required for basic protection
- Run Setup Wizard — CDN detection, default policy selection (60 seconds)
- Monitor Dashboard — See AI bot traffic in real-time
- Adjust Policies — Per-bot Allow/Block/Log-only controls
Per-Bot Granular Control
One company runs multiple crawlers. OpenAI alone operates GPTBot (training), OAI-SearchBot (search), and ChatGPT-User (live fetch). Blocking one does not block the others. RokthamBot lists each bot separately so you can:
- Block training data extraction (GPTBot)
- Allow search indexing (OAI-SearchBot)
- Monitor live fetches (ChatGPT-User)
Search Engine Protection
Search engines (Googlebot, Bingbot, Applebot, DuckDuckBot, YandexBot) are protected by default. Their policy dropdowns are locked. To override, you must explicitly disable the Search Engine Guard in Settings with a warning.
Verified Bot Detection
RokthamBot goes beyond User-Agent string matching. It verifies bots using IP ranges and reverse-DNS lookup (FCrDNS) to confirm the bot is actually who it claims to be. Spoofed bots are flagged and can be blocked separately using the “Block Only Fakes” feature.
Emergency Lockdown
When you need to instantly shut down all AI bot access, Emergency Lockdown mode blocks all AI crawlers and returns HTTP 451 (Unavailable For Legal Reasons). This is ideal for legal disputes or when you need to stop scraping immediately.
AI Referral Traffic Tracking
Track which AI-powered services are sending traffic to your site. RokthamBot tracks referrals from ChatGPT, Perplexity, Gemini, Claude, Copilot, Meta AI, and other AI services, giving you insight into AI-driven discovery.
Privacy & Security
- All bot detection works locally — DNS verification uses your server’s resolver (see External Services above)
- IP addresses can be anonymized in logs
- No data is sent to third parties
- Clean uninstall removes all data
External Services
This plugin performs DNS lookups (reverse DNS verification) to verify bot authenticity through FCrDNS (Forward-Confirmed reverse DNS). This is used by the “Verified Bot Detection” feature to confirm that claimed bots are genuine.
What data is sent: IP addresses of incoming requests are looked up via DNS to verify bot identity.
When: Only when a known bot (GPTBot, ClaudeBot, PerplexityBot, etc.) makes a request to your site.
Service: Standard DNS resolution (no third-party service; uses your server’s configured DNS resolver).
This lookup is passive and does not send any user data to external servers.
Third Party Domain Verification
For FCrDNS verification, the plugin checks that bot IP addresses resolve to domains owned by the bot operator. The following domain patterns are used for verification:
- OpenAI: openai.com, azure.com
- Anthropic: anthropic.com, amazonaws.com
- Google: googlebot.com, google.com, googlehosted.com
- Microsoft: search.msn.com, bing.com, microsoft.com
- Perplexity: perplexity.ai, perplexity.com
- Meta: facebook.com, fb.com, meta.com
- Apple: apple.com, applebot.ai
- Amazon: amazonaws.com, amazon.com
- Yandex: yandex.net, yandex.ru, yandex.com
- DuckDuckGo: duckduckgo.com
- ByteDance: bytedance.com, byteoversea.com
- Common Crawl: commoncrawl.org
These domain checks are performed locally on your server using standard DNS resolution. No data is transmitted to these services.
Privacy
RokthamBot does not collect, store, or transmit any personal data. All bot detection and rate limiting runs entirely on your local server. No external API calls are made. IP addresses can be anonymized in logs through the plugin settings. The plugin stores only bot traffic logs locally in the WordPress database. You have full control over data retention and can purge logs at any time. When the plugin is uninstalled, all data is completely removed.= Minimum Requirements =
- WordPress 5.8 or higher
- PHP 7.4 or higher
- MySQL 5.6 or higher
Credits
RokthamBot is developed and maintained by Muhammad Sadiq Ali.
Contributing
Bug reports and contributions are welcome via the plugin’s GitHub repository.
Screenshots
No screenshots provided

