Bots stop.
Block fraud.
Crawlers & AI allow.
Let buyers through.
Without Cloudflare & Co.
Traffic Guard Shield Rate Limiter is the first SEO-safe crawl governance layer for WordPress & WooCommerce. It decides based on identity, URL type, frequency, and cost — not IP. Google & Bing get through freely. AI crawlers understand. Junk bots are blocked. Local, without external reverse proxy.
Three protective layers between you and a bad day.
When someone installs a plugin anew, they worry about one thing: that something hangs, buyers are missing, the shop crashes. That's exactly what the plugin is built for. It only takes effect when you feel confident. And if something does go wrong, you have three emergency exits — all accessible without backend login.
Shadow Mode: observe for 7 days without blocking.
Plugin makes all decisions — but blocks no one. You only see what it would have blocked. Seven days are enough to recognize how much load actually comes from outside and whether the decisions fit your shop.
Auto-Safe-Mode activates if you forget it.
More than 50 bans in 10 minutes? Plugin switches automatically back to shadow mode and sends you an email. No lost revenue due to a misconfiguration that nobody would have noticed. Self-healing, really.
Emergency bypass via FTP — even without backend.
WordPress not reachable? An empty file wp-content/tgsrl-disable.flag via FTP — plugin does nothing. No update, no cache, no reset needed. Works even if you cannot log in.
The problem explained simply:
Problems arise when HTML elements such as filters, pagination, and buttons are also crawled.
Google does it cleanly: one bot, one plan, one crawl rate. Filter and sort parameters are recognized as crawl traps and ignored.
AI models do not. They query everything — every link, every filter, every pagination, every button. On a typical shop that quickly adds up to 200 queries per second — from a single crawler.
Multiplied by thirteen active AI bots, five SEO tools and several cache preloaders: Your server works around the clock — but not for buyers.
And it gets worse: Hover functions like Wishlist, Quick View and "Add to Cart" also trigger real server requests with bots — three additional queries per product tile that never lead to a purchase.
Bots nibble at your shop category. Crawlers carry away entire products. Buyers wait.
As long as everyone can access it simultaneously, the buyer comes last. Traffic Guard Shield changes the order — without blocking crawlers or AI bots.
823 auto-bans. 223 fake-bots exposed. 196 AI crawlers limited. Zero genuine buyers affected.
Excerpt from the live logbook of a productive WooCommerce shop with around 800,000 products. Real numbers, no extrapolation. What happens here in 24 hours, Cloudflare would either let through — or with false CAPTCHAs also hit real buyers.
/wp-config.bak & Co.Less load. Faster loading times. More reachable customers.
Real test with a solid WooCommerce shop (1,000 products, 100,000+ requests/month). Lower is better for load and load time, higher is better for availability.
// Data basis: 100,000+ requests/month over 4 weeks per setup. "Cache" = WP Rocket or NitroPack solo. "+ TGSRL" = identical cache setup plus Traffic Guard Shield. Measured with New Relic, Query Monitor, GTmetrix.
Convinced?Buy license, test 7 days shadow mode — if it doesn't fit, uninstall instead of discussing.
Buy & test now! →What is bot load costing you right now — in real money?
Three inputs, instant answer. We calculate with realistic values from productive audit shops — what bot load, traffic spikes and slow filter URLs actually cost in practice. Move the sliders to your shop values and see how quickly the license pays for itself. For medium WooCommerce shops typically within the first day.
Your shop metrics
Values are calculated locally in your browser only — nothing is sent, stored, or tracked.
Your result
// Assumptions: Bot share 65% (industry-typical for unprotected WordPress/WooCommerce shops from our audit logs). Hidden buyer loss due to load spikes, 502s, and slow loads: 12% of real visitors do not purchase who otherwise would. Plugin effect: recovers approximately 75% of that → effective additional share approximately 9%. Actual effect varies depending on shop, bot load, hosting, and cache setup. No guarantee of achieving these values — Shadow Mode measures the real numbers for your shop in 7 days.
What shop operators say who have left Cloudflare.
Six anonymized feedback reports from the beta and audit phases. Domain and personal names have been removed for data protection reasons; the content has been adopted unchanged.
We hit CPU limits daily at our provider and Cloudflare kept blocking our real buyers with challenges. Seven days in shadow mode showed: nearly 70% of our traffic was bots. Today our server load is at a third of the previous state, we removed Cloudflare from the stack, TTFB stable below 200 ms.
With 800,000 products, AI crawlers and SEO tools pushed our server to the limit every hour. With Traffic Guard Shield, protection kicks in before WordPress — the database breathes again. Load times from 4.1 to 1.2 seconds, and without swapping out a single cache plugin.
We currently deploy the plugin at 23 customer shops. Previously, we had to switch to Cloudflare Pro during every traffic spike — which caused false CAPTCHAs for real buyers and generated SEO tickets. Now: one MU plugin, shadow mode for 7 days, then go live. Provider tickets due to CPU are completely gone.
My blog with over 40,000 articles was literally torn apart by ClaudeBot and GPTBot — sometimes 1,500 requests per hour from a single IP. A hosting upgrade was already on the table. Traffic Guard Shield contained it in the first week without my real readers noticing anything. AI visibility remains — only the expensive filter and parameter URLs are closed.
We had a complex Cloudflare setup with Page Rules, WAF and Bot Fight Mode — maintenance effort five hours per month. Now everything directly in the WP backend, German manufacturer, all data stays local. Bonus: TTFB has halved because no US edge is in the way anymore. And real buyers never see a captcha.
Skeptical after three other security plugins that all eventually blocked real buyers too. After 7 days in shadow mode I was convinced: over 12,000 blocked junk requests, of which according to logs only four could possibly have been real buyers — and all were already logged in and thus never affected anyway. Cancelled Cloudflare subscription, server CPU down to around 30%.
Representative audit testimonials from the beta phase. Domain and personal names have been anonymized to protect our beta testers (abbreviated first names + industry designation). Content reproduced unchanged; complete originals are available.
Google, Bing and AI are allowed to understand.
Bots and preloaders are not allowed to destroy.
Seven days of shadow mode are enough to see how much load actually comes from outside.
Install now · 129€/yearSeven layers of protection. One decision per request.
No dumb IP blocking. Instead, a prioritized request flow that evaluates identity, URL type, cost score, and frequency in a single step — before WordPress starts a single database query.
Human Safety Layer
Logged-in users, browsers with WC session, and HMAC-signed "Verified-Human" cookies are never blocked. Period.
Google & Bing hardware lock
14 verified user agents with reverse & forward DNS (A + AAAA). Real search engines always get through — fakes are banned in the first second.
URL-Cost-Score (20 categories)
One filter combination with three values costs 60. One product page costs 1. Cost budgets per IP per SUM(cost) from SQLite — exact, not estimated.
AI Visibility Mode
Three switches: allow · limited · block. Recommended: limited — AI sees products, but not filter combinations that will grill your database.
WC Filter Performance Guard
Disabled expensive COUNT(DISTINCT) and SQL_CALC_FOUND_ROWS for bots on shop archives. Real users keep all counts and pagination.
Honeypot & Probing Trap
16 invisible trap URLs (/wp-config.bak,/.env.bak,/phpmyadmin/) → 24h ban. Login & probing are counted separately.
Shadow & Auto-Safe Mode
First observe, then block. More than 50 bans in 10 minutes? Plugin automatically switches to shadow mode & alerts via email.
10-tab admin interface
Dashboard, settings, IP lists, compatibility, .htaccess editor, robots.txt manager (11 presets), analysis, logs, tools — everything in the WP backend.
Reverse proxy & CDN trust
GTranslate-CDN, NitroPack-Self-Crawl, Load balancer: Plugin extracts the real client IP from trust headers (X-GT-CLIENTIP,X-Real-IP) — with public IP hardening against spoofing.
3-source logging
Apache .htaccess-Blocks (403/429), Preload-JSONL (before WordPress) and Plugin-SQLite (real-time) — all three sources in one view. Cron import with auto-detection for All-Inkl, cPanel, Plesk.
htaccess Auto-Sync
Plugin automatically places its blocks before GTranslate & WordPress. Order analysis detects 4 critical violations (bot protection after [L,QSA]) — with clear instructions instead of risky auto-sort.
Emergency Bypass via File
An empty file wp-content/tgsrl-disable.flag via FTP — plugin does nothing. Fast reset without backend login. Unbreakable.
All features in detail
A · Human-Safety-Layer
A1Logged-in users bypass — no rate limit, no auto-banA2Critical WC paths dynamically — Cart, Checkout, Account, Order-Pay disabledwc_get_page_id()A3Verified-Human-Cookie (HMAC) — 24h, HttpOnly, SameSite=Lax, four issuance conditionsA5WC Session Detection — Cart Hash & Session CookieA6Auto-Safe-Mode — 50+ Bans / 10 min → Shadow + MailA7Emergency Bypass via File —tgsrl-disable.flagA8Deep Pagination — 302 for humans, 410 for botsA9Auto-ban protection — Search engines, users and AI never auto-banned
B · Bot Protection
B1Google & Bing Hardware Lock — 14 UAs, DNS A+AAAA, not disableableB2Bot registry with 7 trust tiers — fromlogged_inbiscommerce_botB3Fake bot detection — Reverse + Forward DNS, instant 1h banB4AI Visibility Mode — allow / limited / block, 13 AI crawlers
C · Intelligent detection
C1URL cost model — 20 categories, cumulativeSUM(cost)C2Sitemap rate limiting — 5 req / 5min for unverified botsC3Login & probing separate — own counters, max 10 / 5 / windowC4Request Sampling — under extreme load: every Nth request
D · WooCommerce Filter Guard
D1Dynamic filter counts optimize — Off / bots only / AllD2Hide count badges — Woodmart, Flatsome, Astra, OceanWPD3Disable SQL_CALC_FOUND_ROWS for bots on shop archivesD4Auto-detection — WooCommerce + theme detected, recommendation displayed
E · Monitoring & Alerts
E1Shadow/Block Badges — yellow (logged in) vs. red (blocked)E2Mode Banner — EMERGENCY · SHADOW · SAFEE3Email Alerts — Instant + weekly reportE4Log Export CSV — UTF-8 BOM, Excel-compatibleE5Auto-Cleanup — 30 days / 10 MB limit + VACUUM
F · Shop archive detection (dynamic)
- Shop page aus
wc_get_page_id('shop') - Category & tag basis aus
woocommerce_permalinks - Attribute Taxonomies aus
wc_get_attribute_taxonomies() - Manual additions via textarea
- WC pages Cart/Checkout/Account also dynamically — no hardcoding
G · Cache Governance
G1WP Rocket — 3 filters: Reject, Preload Exclude, Links ExclusionG2NitroPack:DONOTCACHEPAGE+X-Nitro-Disabled: 1G3GTranslate IP list updated daily, service crawler limit
H · .htaccess Management
H1Snippet Generator — bot filter, deep pagination, login protection, 40 countriesH2Editor + Backup — Dark theme, Safe-Save, rollback last 10 versions
I · robots.txt management
I111 presets — WC paths, filters, pagination, SEO scraper, AII2Editor + auto-insert + backup — same backup system as .htaccess
J · SEO Tools (Tools tab)
- URL test lab — "What would happen with this URL?"
- Sitemap Audit — SSL fix, 3 fallback URLs
- noindex audit
- Preflight Check — 10-Point Health
- Action Scheduler Health
- MU Plugin Generator · Settings Import/Export
L · security
- Cloudflare spoofing protection — 15 IPv4 + 7 IPv6 ranges
- IPv6 CIDR per
inet_pton() - DNS A+AAAA Forward-Verify
- SQLite with random file name
- 404-guessing can be disabled
- noindex for filter URLs & versioned DB migration
M · Honeypot
- 16 invisible trap URLs —
/wp-config.bak,/.env.bak,/phpmyadmin/,/.git/configamong others - 24h Ban on hit — no warning system for spam bots
N · Reverse Proxy & Multi-Source NEW 1.2
N1Reverse Proxy Trust — real client IP fromX-GT-CLIENTIP,X-Real-IP,X-Forwarded-Forwith public IP hardeningN2GTranslate-CDN-Mode — Trust-header evaluation when REMOTE_ADDR is your own server IPN33-source logging — Apache .htaccess + preload JSONL + plugin SQLite, shared view with source filterN4Apache Log Import — Auto-detection All-Inkl, cPanel, Plesk · Cron 3:00 AM · max 5 MB per runN5Anti-Self-Ban Protection — Server IPs rejected at DB level with audit log + one-click cleanupN6REST API whitelist — cookie banner (Borlabs, Real Cookie Banner, Complianz) · 19 endpoints · 300 req/minN7htaccess Auto-Sync — Insert before GTranslate / WordPress · Sequence analysis with 4 critical violationsN8Language prefix for deep pagination —/fr/,/zh-cn/,/pt-br/Read from GTranslate settingsN9IP-Detection-Diagnostics — Tools tab shows REMOTE_ADDR vs. real IP vs. trust headers live
Seven typical requests. Seven different responses.
Click a row to see the reasoning. This exact logic runs live in milliseconds before WordPress wakes up.
Protect your hosting and server effectively before something happens.
Traffic spikes cost you customers in real-time — and provider tickets the next day. Traffic Guard Shield intervenes before the expensive WordPress initialization, not only when your server is already struggling.
Why our plugin is more effective than any slow security plugin.
Wordfence, iThemes, Sucuri & Co. do a good job — defending against brute-force, malware, and known exploits. But they intervene after WordPress, not before. With pure crawl and bot traffic load, that's exactly the wrong place.
Classic security plugins
Wordfence · iThemes Security · Sucuri · All In One Security
- ✕Run INSIDE WordPress. Every bot request already has DB connection, plugins loaded and memory consumed before the security plugin even decides.
- ✕Focus on malware & logins, not on crawl load. Wordfence blocks brute-force, but not 200 req/s of an AI crawler fetching valid URLs.
- ✕Own CPU load: Every Wordfence rule costs computing time. With high traffic, the plugins themselves become a burden — a known effect on shared hosting.
- ✕No crawl governance: Filter URLs, pagination and AI tier classes are not a topic. Google & ChatGPT are treated the same as an attacker.
- ✕SEO risk in aggressive mode. Quickly block Googlebot too because the user agent rule was too strict. Rankings gone, ticket opened.
Traffic Guard Shield Rate Limiter
VASTCOB · WP-native · since 2010
- ✓Intervenes BEFORE WordPress. Eigener Mu-Plugin-Loader entscheidet in < 1 ms, ohne dass eine einzige WP-Datei zusätzlich geladen wird.
- ✓Crawl rather than malware focus: 13 AI crawlers detected (3× OpenAI, 3× Anthropic, 2× Perplexity, 2× Apple, Google, Cohere, DuckDuckGo), cost score per IP, tier classes for Google/Bing/AI/Unknown.
- ✓Saves load itself: Instead of costing additional CPU, the plugin cuts expensive queries before they arise. Cost-Score Dashboard shows it live.
- ✓Reverse-proxy & CDN-aware: GTranslate-CDN, NitroPack-Self-Crawl & load balancer correctly recognized. Real client IP from trust headers, never self-bans.
- ✓SEO-safe by default: Verified Googlebot is confirmed via reverse DNS and never blocked. Shadow mode for 7 days of testing without risk.
Why not simply use Cloudflare or Wordfence?
Reverse proxies and security plugins solve a different problem. Traffic Guard Shield is not a bot blocker and not a WAF — it is an SEO-safe crawl governance layer that intercepts before the expensive query, without routing your traffic through an external network.
| Criterion | Traffic Guard ShieldVASTCOB · WP-native | Cloudflare Bot ManagementReverse proxy | Wordfence PremiumWP Security Plugin | Sucuri FirewallWAF / CDN | .htaccess onlyDIY |
|---|---|---|---|---|---|
| SEO & AI | |||||
| Google & Bing guaranteed not blocked | Hardware lock14 UAs, DNS A+AAAA, not disableable | configurableCAPTCHA loops known | Whitelist required | Whitelist required | DIY |
| AI crawler granular (allow / limited / block) | 13 AI BotsCost-based | allow / block | allow / block | ||
| SEO-safe 410 Gone for crawl traps | automaticFilter out of index | 403 / Challenge | 403 | 403 | manual |
| Reverse Proxy / CDN Setups (GTranslate CDN, NitroPack) | native trust header supportX-GT-CLIENTIP, X-Real-IP, X-Forwarded-For | own edge only | often conflicts | ||
| Multi-language support (WPML / Polylang / GTranslate) | Language prefix-aware/fr/, /zh-cn/ from GT Settings | ||||
| Reverse + Forward DNS verification (A+AAAA) | built-inAlso IPv6 Googlebots | reverse only | reverse only | ||
| Performance & Load Peaks | |||||
| URL-Cost-Score instead of just Request-Count | 20 categoriesFilter combination = 60 | rate only | rate only | rate only | |
| Hooks before the WP database query | auto_prepend_filePHP before WP-Boot | Edgeexternal hop | in WP | Edge | Apache |
| 3-source logging (Apache + Preload + Plugin) | unifiedSource filter, Apache cron import | edge logs only | plugin logs only | WAF logs only | |
| WC Filter Performance Guard | built-in | ||||
| Compatible with NitroPack / WP Rocket / FlyingPress | 3 filtersFilter URLs not in preload | Cache conflicts | no integration | no integration | |
| Data protection & hosting | |||||
| 100% local — data does not leave the server | 100% local | US-Edge | local | US/Edge | local |
| Cookie banner whitelist (REST API) | 19 endpointsBorlabs, Real Cookie Banner, Complianz | ||||
| Cloudflare Spoofing Protection | 15 IPv4 + 7 IPv6 Ranges | N/A | partially | partially | |
| Auto-Safe-Mode on misconfiguration | 50 / 10 min → Shadow | ||||
| Emergency bypass via FTP file | tgsrl-disable.flag |
Dashboard login | Dashboard login | Dashboard login | Rename file |
| Honeypot with 16 trap URLs | built-in | Live Traffic Trap | |||
| Cost | |||||
| Ongoing costs for medium-sized shop | 129 €/yearUpdates included | 200–2,000 $/monthBot Management only in Business+ | 99 $/year | ~ $200/year | 0 €but no Cost-Score |
Cost-Score: One URL is not a URL.
A crawler that 60 times /produkt/eames-stuhl/ queries, costs 60. A crawler that runs once ?filter_farbe=rot,blau,gruen&orderby=price calls, costs 90. This exact difference decides between success or peak load.
/produkt/eames-stuhl//blog/ratgeber//stoffe/vorhang-stoffe//shop//shop/page/12/?orderby=price?filter_farbe=rot?per_page=96?s=suchbegriff/shop/page/84/?filter_farbe=rot,blau,gruen+ Zusatz-PenaltyCost-Budgets per IP
Each IP receives a cost budget per time window. Verified browser users have a very generous budget of 2,000. Unknown crawlers get 100 — enough for meaningful indexing, too little to strain your database.
The sum is per SUM(cost) calculated from a SQLite database with WAL mode — exact, not estimated, with sub-millisecond latency.
Browser without cookie: 1,000
Google / Bing: ∞ on clean URLs
AI crawler: 60 req/min
Unknown / SEO tool: 100
Spoofed bot: immediate 1h ban
Convinced?Measure cost score and pre-WP boot directly in your own shop — seven days shadow mode without risk.
Buy & test now! →How much load you are currently generating in direct comparison
Real test with a solid WooCommerce shop (1,000 products, 100,000+ requests/month). Measured was the actual server load that still triggers database queries after the respective protection layer. Lower is better.
Two insights that almost every plugin gets wrong.
Direct excerpts from production logs showing why superficial bot detection fails — and why parameter URLs are the actual bottleneck for every WooCommerce shop.
Auto-ban entries that look like Google — but are not.
In a real audit, the auto-bans came almost entirely from Google/AdsBot-like IPs. Only: a large portion of them were fakes.
These are not real users. But with 66.249.* and 72.14.* would be blind blocking dangerous — Google uses these ranges for Googlebot, AdsBot, Mediapartners, and more.
What is "Spoofing"? A bot simply sets User-Agent: Googlebot in its request header. Enough plugins fall for it — and end up blocking the real Googlebot because too many "Googlebots" came at the same time.
Google recommends three steps for verification — the Traffic Guard Shield performs all three automatically:
crawl-66-249-79-4.googlebot.com)googlebot.com,google.com or googleusercontent.com?Only when all three checks ✓ are passed does the request receive Trust Tier 1. If one fails: classification spoofed → immediate 1h ban.
Why Filter, search and ?add-to-cart= explode with AI crawlers.
From a real daily report: a single AI crawler generates the majority of expensive requests.
ClaudeBot crawls Mass Product Pages, sometimes with problematic parameters such as ?add-to-cart=. That is Features, no content — they present the same product in countless variants and inflate the crawl infinitely.
Instead of blocking completely, the plugin differentiates cleanly:
This applies analogously to ChatGPT (GPTBot), Perplexity, Apple, DuckAssist and others. Clean content is welcome — parameter functions that show nothing new are consistently blocked. AI visibility remains intact, load drops drastically.
With NitroPack or WP Rocket — never with both.
Cache & Crawl Governance are two tools that complement each other. The Traffic Guard Shield brings three dedicated filters for each cache provider, so filter URLs are not constantly pre-warmed — because an empty cache is cheaper than 50,000 pre-rendered filter combinations.
What the integration actually does
rocket_cache_reject_uri,rocket_preload_exclude_urls,rocket_preload_links_exclusions. Filter URLs neither cached nor prewarmed.DONOTCACHEPAGE + X-Nitro-Disabled: 1 on expensive URLs.cache_preloader classified — trust level 0.Three cache plugins that we recommend for WooCommerce.
With WordPress & WooCommerce experience since 2010, we have managed hundreds of shops live. Here is the honest ranking — selected based on real performance in production shops, not marketing promises.
Aggressive edge caching, automatic image optimization, and critical CSS in one. Delivers measurably the best Core Web Vitals on large shops — perfectly combined with our plugin against filter preloading.
Solid page cache, excellent preloader, and the full WordPress-native filter ecosystem. Ideal if you want maximum control and easy debugging — our plugin controls its three preload filters directly.
Modern setup, very small, very fast. A real alternative for teams who find WP Rocket too "heavyweight" — with excellent lazy loading and cache logic that our plugin integrates seamlessly.
Ready for peaceful server nights? Install the plugin and observe in shadow mode.
Buy plugin · 129€/yearMany settings. Simple management. No additional programming required.
Everything directly in the WordPress backend. From emergency bypass to the .htaccess editor with backup to the URL test lab.
Frequently asked questions before purchase.
We have been operating the plugin for months on production shops with over 50,000 products. Here are the questions that real shop operators ask.
REMOTE_ADDR contains its own server IP (typical with GTranslate CDN mode, NitroPack self-crawl or hosting load balancers) and reads the real visitor IP from trust headers such as X-GT-CLIENTIP,X-Real-IP or X-Forwarded-For. Public IP hardening prevents header spoofing via private or reserved IP ranges. Anti-self-ban protection at database level categorically prevents your own server IP from being accidentally banned — with audit log and one-click cleanup in the Tools tab.license.vastcob.com. All request logs, IP lists, cost calculations, and bot detections happen locally in an SQLite database on your server. No US edge, no external tracker, no third party sees your traffic.tgsrl-disable.flag via FTP — plugin no longer does anything. (2) Auto-Safe-Mode activates automatically after 50+ bans in 10 minutes and alerts via email. (3) .htaccess and robots.txt editor automatically create backups before each change with one-click rollback (last 10 versions)..htaccess blocks bots/countries directly at the web server (403/429), the logs are automatically imported via cron at 3:00 AM. (2) Preload script runs via auto_prepend_file before WordPress and writes JSONL logs in real time. (3) Plugin SQLite records all plugin decisions with cost score and bot classification. Source Filter in the Logs tab shows you at a glance which layer is currently working. Apache Log Reader has auto-detection for All-Inkl, cPanel, and Plesk — suitable for shared hosting (max. 5 MB per import run).Don't feel like getting your hands dirty? We'll take care of it.
Install the plugin, configure it for your shop, activate shadow mode — and actively monitor for 48 hours to ensure everything runs smoothly. You purchase only the license; we handle the rest. After 48 hours, you receive a clear recommendation: go live or fine-tune.
What we specifically take over for you
- ✓Plugin installation on your server — Apache, Nginx or LiteSpeed, MU-plugin mode activated for pre-WP boot.
- ✓Configuration tailored to your shop — theme, cache plugin, multilingual setup and WC paths detected and configured.
- ✓.htaccess & robots.txt snippets cleanly implemented, including backups and sequence verification.
- ✓Shadow mode activated + baseline measurement on day 0 — You see exactly what changes.
- ✓48 hours of active monitoring by VASTCOB: bot traffic, auto-bans, honeypot hits, suspicious cases.
- ✓Immediate adjustments for anomalies during the 48 hours — no waiting for ticket response.
- ✓Email support throughout the entire period — direct line to the developer team.
- ✓Final recommendation after 48 hours: go live, continue monitoring, or fine-tune.
- ✓Installation fully taken over
- ✓Configured for your shop
- ✓48 hours active monitoring
- ✓Direct developer support
- ✓Conclusion recommendation included
// Note: The setup service is a standalone product and can also be booked separately after plugin purchase. We will contact you within 24 hours after ordering to arrange an appointment. License costs are not included in the price.
No more traffic spikes that you don't understand.
Install the Traffic Guard Shield Rate Limiter. Enable shadow mode. Observe for seven days. You will be surprised how much load actually comes from outside — and how quiet your server becomes afterward.
Blocking bots with the WordPress Rate Limiter Plugin
With the WordPress Rate Limiter Plugin Traffic Guard Shield, you decide on identity, URL type, and cost score per request before WordPress or your database even wake up. Ordinary bot filters check IP lists or user-agent strings. This is no longer sufficient today, as modern crawlers rotate their identities or fake real search engine user agents.
Instead of blocking or allowing, it checks in less than a millisecond whether the call comes from a logged-in user, a browser with a valid session, a verified Googlebot, or an unknown bot. The plugin loads as an MU-plugin before all other components and thus takes effect before any PHP initialization.
Real search engines are recognized by reverse and forward DNS verification on A and AAAA records and are never blocked. Junk bots that pretend to be Googlebot are immediately kicked out. Sixteen invisible honeypot URLs like /wp-config.bak or /.env.bak additionally mark probing attempts, which directly leads to a 24-hour ban and ends brute-force attacks without warning.
WooCommerce Rate Limiter Plugin against AI crawlers and bots
The WooCommerce Rate Limiter Plugin categorizes AI crawlers into their own tier. GPTBot, ClaudeBot, PerplexityBot, and six other AI bots are treated separately from real browsers, search engines, and junk bots. You decide per mode whether these crawlers are allowed to read product pages, are stopped in the filter combination, or are completely blocked.
The recommended mode is limited. AI sees the catalog with real product pages and blog content but does not get access to multiple filter combinations, ?add-to-cart calls, or deep pagination. This protects the database from load peaks without destroying AI visibility. This very differentiation is missing from classic bot blockers and makes the Rate Limiter Plugin WooCommerce an independent crawl governance layer.
The cost score logic evaluates each URL based on its real effort. A simple product page costs one point. A filter combination with three active values and a sorting can cost sixty points or more. Cost budgets per IP are summed up in an SQLite database in WAL mode, precisely and without estimation.
WordPress Security and More Performance with Less Load – License for 129 Euros per Year Including Auto-Updates
The license for the WordPress Rate Limiter Plugin currently costs 129 Euros per year, regularly 189 Euros. All updates during the license period, the auto-update mechanism via the integrated license SDK, and German-language support directly from the manufacturer are included. There are no hidden tier levels or additional modules that would need to be purchased separately.
If the license is invalid, the plugin continues to run; only updates are paused. Feature switches remain active, and you do not lose access to the admin interface. License information is checked exclusively against license.vastcob.com. All request logs, IP lists, and cost calculations remain local on your own server.
Included are all twenty-three modules from eleven thousand lines of audited PHP code, including URL Cost Score, Google and Bing Hardware Lock, AI Visibility Mode, WC Filter Performance Guard, Honeypot, Shadow Mode, and Auto-Safe Mode. The ten tabs of the admin interface include Dashboard, IP Lists, Compatibility, .htaccess Editor, robots.txt Manager, Logs, and a dedicated URL Test Lab.
Mitigating Load Peaks with the WordPress Rate Limiter Plugin
Load peaks today rarely result from attacks but rather from normal crawl traffic. Nine active AI bots, five SEO tools, and several cache preloaders can overload a WooCommerce shop with fifty thousand products within minutes. The WordPress Rate Limiter Plugin cuts off this load before PHP, MariaDB, or Redis even wake up.
In a test with a medium-sized WooCommerce shop and 3.2 million requests per month, the combination of Cost Score Filter, AI Visibility Mode, and cache plugin reduces database load to fourteen percent. Pure caching solutions like WP Rocket or NitroPack alone result in around fifty-four percent. This ultimately means up to seven times more real buyers on identical hardware.
Those who wish to avoid the risk of directly activating a productive shop can start in Shadow Mode. For seven days, all decisions are made, but no one is actually blocked. Auto-Safe Mode intervenes in parallel if more than fifty bans occur within ten minutes and sends an email alert. An emergency bypass via FTP file is possible at any time.