
Anti-bot
for websites
We block bots, scrapers and behavioural-factor manipulation in real time. Connect via DNS or PHP agent — works with any stack. 99.9% accuracy, no CAPTCHA.
What the anti-bot
blocks
Six main categories of automated threats — all blocked transparently for the end user.
Behavioural bots
Imitate real visitors: click, scroll, fill in forms. They damage behavioural factors and drag down search rankings.

Scrapers and parsers
Copy product catalogues, prices, contacts and unique content. They load up the server and feed competitors.

Spam bots
Flood contact forms, comments and sign-ups with junk submissions.
Brute force and exploits
Try admin passwords, scan for CMS and plugin vulnerabilities.
Junk traffic
Bots flood the server with parasite requests, slow the site down and burn through plan limits.
Bad IPs and proxies
Datacenters, VPNs, bot farms and anonymous proxies — the source of 90% of malicious traffic.
Three steps
to clean traffic
A request comes in
The user request hits the BotHunt edge proxy or the PHP agent on your site. Analysis starts instantly.

40+ signals analysed
The anti-bot inspects TLS signature, ASN reputation, fingerprinting and behavioural patterns. 99.9% accuracy.

Decision is instant
Bots get HTTP 403 or a challenge. Real users pass through with no delay and no CAPTCHA.

Set up protection in 5 minutes
Sign up, add your site, install the script — and get 14 days of free bot protection

Two equal
options
DNS integration
A single A record in DNS routes traffic through the BotHunt edge proxy. Works with any stack: Tilda, Bitrix, WordPress, Next.js, static sites, Node.js, Python.
- No code changes required
- TLS termination and automatic Let's Encrypt
- Hides origin IP from direct attacks
PHP agent
Server-side agent via require_once or auto_prepend_file.
- Works with WordPress, Bitrix, Laravel, MODX
- Access to server variables
- Ready-made WordPress plugin
Detection
pipeline
40+ signals checked in cascade within 4-12 milliseconds. If a bot is identified at an early stage, the remaining steps are skipped.
TLS / TCP
Handshake analysis before the server starts serving the page. Headless clusters get exposed at the network layer.
- JA3 / JA4
- TCP-fingerprint
- TLS-cipher
IP / ASN
Subnet reputation, AS type and membership in anonymiser pools. 90% of bot traffic comes from datacenters.
- ASN-репутация
- Datacenter
- VPN
- Proxy
Fingerprint
Technical browser and device fingerprints. Impossible to forge without a full real-Chrome emulator.
- Canvas
- WebGL
- Audio
- Hardware
- Fonts
Behaviour
Mouse curves, click timings and event order. Stronger than any fingerprint — humans move along Bezier curves, bots in straight lines.
- Bezier curve
- Timings
- Scroll
- Order
Headless
Signatures of popular automation tools: specific APIs, navigator flags and characteristic CDP-protocol behaviour.
- Puppeteer
- Playwright
- BAS
- Zenno
- CDP
BotHunt vs alternatives
| Parameter | BotHunt | CAPTCHA | Cloudflare | DataDome |
|---|---|---|---|---|
| Transparent for users | Yes | No | Yes | Yes |
| Behavioural-factor protection | Yes | No | Partial | Yes |
| Russian jurisdiction | Yes | Depends | No | No |
| Billing in rubles | Yes | Depends | No (USD) | No (USD) |
| Starting price | $9/month | Free | $20/month | from $3000/month |
| DNS connection | Yes | — | Yes | Yes |
| PHP agent | Yes | — | No | No |
| Minimum contract | Monthly | — | Yearly | Yearly |
Deep dives and guides
on bot protection
Frequently asked
questions
Answers to the most common questions about setup and operation of the anti-bot service.
Didn't find
your answer?
Message us on Telegram or email — we usually reply within an hour.

