The only security plugin you need!

Bots stop.
Block fraud.
Crawlers & AI allow.
Let buyers through.
Without Cloudflare & Co.

Traffic Guard Shield Rate Limiter is the first SEO-safe crawl governance layer for WordPress & WooCommerce. It decides based on identity, URL type, frequency, and cost — not IP. Google & Bing get through freely. AI crawlers understand. Junk bots are blocked. Local, without external reverse proxy.

Up to 72% less server load — your existing hosting plan is sufficient again, no upgrade needed.
TTFB under 320 ms instead of 1,450 ms — faster load times, higher conversion rate, better SEO.
+38 % more genuine buyers reach the shop — even during peak times, on the same server.
Cloudflare subscription becomes unnecessary100% local, no US edge, never CAPTCHAs for genuine buyers.
AI visibility remains intact — Google, Bing, ChatGPT, Claude & Perplexity continue to understand your shop.
13.000+Lines of verified PHP code
25Modules, one plugin
13AI crawler detected
0 msexternal reverse proxy
tgsrl · request stream · /var/log/tgsrl.live REC ●
0
Allowed
0
Blocked
0
Cost saved
Works with WordPress 5.8+ WooCommerce NitroPack WP Rocket FlyingPress Woodmart · Flatsome · Astra PHP 8.3+ WPML · Polylang · GTranslate (with CDN mode) Reverse proxy / CDN setups
You cannot break anything

Three protective layers between you and a bad day.

When someone installs a plugin anew, they worry about one thing: that something hangs, buyers are missing, the shop crashes. That's exactly what the plugin is built for. It only takes effect when you feel confident. And if something does go wrong, you have three emergency exits — all accessible without backend login.

1

Shadow Mode: observe for 7 days without blocking.

Plugin makes all decisions — but blocks no one. You only see what it would have blocked. Seven days are enough to recognize how much load actually comes from outside and whether the decisions fit your shop.

Standard after installation · Zero risk for real buyers
2

Auto-Safe-Mode activates if you forget it.

More than 50 bans in 10 minutes? Plugin switches automatically back to shadow mode and sends you an email. No lost revenue due to a misconfiguration that nobody would have noticed. Self-healing, really.

Active from the first minute · Auto-Recovery without login
3

Emergency bypass via FTP — even without backend.

WordPress not reachable? An empty file wp-content/tgsrl-disable.flag via FTP — plugin does nothing. No update, no cache, no reset needed. Works even if you cannot log in.

Unbreakable · seconds to recovery
Additionally: Real buyers (logged in, with WC session or Verified-Human cookie) are never blocked. Cart, checkout, and account are a firmly protected path class. Googlebot and Bing are recognized via hardware lock (DNS A+AAAA) and never auto-banned. Even in live mode, your SEO ranking remains untouched.
Why websites and especially shops crash at all

The problem explained simply:

Problems arise when HTML elements such as filters, pagination, and buttons are also crawled.

Google does it cleanly: one bot, one plan, one crawl rate. Filter and sort parameters are recognized as crawl traps and ignored.

AI models do not. They query everything — every link, every filter, every pagination, every button. On a typical shop that quickly adds up to 200 queries per second — from a single crawler.

Multiplied by thirteen active AI bots, five SEO tools and several cache preloaders: Your server works around the clock — but not for buyers.

And it gets worse: Hover functions like Wishlist, Quick View and "Add to Cart" also trigger real server requests with bots — three additional queries per product tile that never lead to a purchase.

// Realistic number of measured WooCommerce shops, 2026
200 req/s · +187%
Color: red
Material
Price 0–50
Size: M
Brand
Sorting
Eames EA 2172.890 €
Aeron1.659 €
Vitra ID1.149 €
USM Kitos789 €
Wilkhahn1.490 €
Sedus BD690 €
128485
Background · 12 min read time Crawler flood 2026: Why WordPress shops are collapsing now The complete analysis: how ClaudeBot, GPTBot & Co. have changed load behavior since January 2026 — with logs, hosting plan thresholds, and concrete protection strategies.

Bots nibble at your shop category. Crawlers carry away entire products. Buyers wait.

As long as everyone can access it simultaneously, the buyer comes last. Traffic Guard Shield changes the order — without blocking crawlers or AI bots.

Bots nibble → block
Crawler carry away → limit
Buyer comes first → allow through
What the plugin decided yesterday — 24 hours, one real shop

823 auto-bans. 223 fake-bots exposed. 196 AI crawlers limited. Zero genuine buyers affected.

Excerpt from the live logbook of a productive WooCommerce shop with around 800,000 products. Real numbers, no extrapolation. What happens here in 24 hours, Cloudflare would either let through — or with false CAPTCHAs also hit real buyers.

11.05.2026 · 00:00–23:59 Source: Plugin SQLite logs
1,699 evaluated decisions
823
Auto-Bans triggered
Suspicious IPs according to probing patterns
232
Expensive search bot requests stopped
Googlebot/Bing on filter combinations
223
Spoofed Googlebots exposed
User-Agent log, DNS says: no Google
196
AI-Crawler limited
ClaudeBot · GPTBot · Perplexity · OAI
114
Honeypot hits
Probing on /wp-config.bak & Co.
66
Hard limit reached
More than 120 req/min from one IP
17
Bot Cost Overrun
Unknown bots over budget
15
Filter count blocked
3+ active filters without browser session
Time IP (anonymized) Actor Action Cost
06:52 66.249.•••.••• GoogleOther 410 GONE · Filter 16
06:21 91.245.•••.••• Spoofed "Google-InspectionTool" BAN 1h · DNS-Verify fail
05:47 216.73.•••.••• I'm ready to translate German text to English following your rules. Please provide the German text you'd like me to translate. 410 GONE · AI Limit 10
14:34 124.198.•••.••• Probing /wp-config.bak BAN 24h · Honeypot
17:48 89.247.•••.••• Unknown · 4 filters active BLOCK · Cost Cap 181
02:35 52.167.•••.••• bingbot/2.0 · Page 11 410 GONE · Deep pagination 13
// IPs shortened for privacy reasons · Complete logs available anytime in WP Admin · CSV export with one click
Read the details How 823 auto-bans happen in one day Which bot classes account for the largest share, how the plugin detects spoofing and where the honeypots are located — the detailed background article on the 2026 crawler flood.

Less load. Faster loading times. More reachable customers.

Real test with a solid WooCommerce shop (1,000 products, 100,000+ requests/month). Lower is better for load and load time, higher is better for availability.

CPU load (daily average)Server load average
−72%
Before
92%
+ Cache
71%
+ TGSRL
26%
Bots never reach the database. PHP workers remain reserved for buyers.
TTFB Time-to-First-ByteWait time until first response
−68%
Before
1.450 ms
+ Cache
820 ms
+ TGSRL
320 ms
Pre-WP-Boot greift in < 1 ms. Was nicht durchkommt, kostet keinen PHP-Cycle.
Accessibility for genuine buyersErfolgreiche Page-Loads < 2 s
+38%
Before
62%
+ Cache
74%
+ TGSRL
96%
During peak times, more buyers reach the shop. 502 errors and CPU limits practically disappear.

// Data basis: 100,000+ requests/month over 4 weeks per setup. "Cache" = WP Rocket or NitroPack solo. "+ TGSRL" = identical cache setup plus Traffic Guard Shield. Measured with New Relic, Query Monitor, GTmetrix.

Convinced?Buy license, test 7 days shadow mode — if it doesn't fit, uninstall instead of discussing.

Buy & test now! →
Live calculator · Your numbers

What is bot load costing you right now — in real money?

Three inputs, instant answer. We calculate with realistic values from productive audit shops — what bot load, traffic spikes and slow filter URLs actually cost in practice. Move the sliders to your shop values and see how quickly the license pays for itself. For medium WooCommerce shops typically within the first day.

Your shop metrics

Values are calculated locally in your browser only — nothing is sent, stored, or tracked.

Monthly page viewsRequests including bot traffic, before filter
100.000
10 k100 k1 million5 million
Conversion rateshare of visitors who buy
2,0 %
0,5 %1,5 %3 %5 %
Ø Cart SizeAverage Order Value Net
100 €
20 €100 €250 €500 €

Your result

Of which bot traffic (~65 %) 65,000 PVs
Real visitors per month 35.000
Lost customers due to traffic spikes ~84 / month
Recovered from this with TGSRL ~63 / month
Additional Revenue per Month
6.300
75.600€ per year · net
Amortization after < 1 DaysFrom 129 € license becomes mathematically 200+× more per year.

// Assumptions: Bot share 65% (industry-typical for unprotected WordPress/WooCommerce shops from our audit logs). Hidden buyer loss due to load spikes, 502s, and slow loads: 12% of real visitors do not purchase who otherwise would. Plugin effect: recovers approximately 75% of that → effective additional share approximately 9%. Actual effect varies depending on shop, bot load, hosting, and cache setup. No guarantee of achieving these values — Shadow Mode measures the real numbers for your shop in 7 days.

Voices from the audit phase

What shop operators say who have left Cloudflare.

Six anonymized feedback reports from the beta and audit phases. Domain and personal names have been removed for data protection reasons; the content has been adopted unchanged.

9,5/10 Reviewer Score · Audit Phase 2026

We hit CPU limits daily at our provider and Cloudflare kept blocking our real buyers with challenges. Seven days in shadow mode showed: nearly 70% of our traffic was bots. Today our server load is at a third of the previous state, we removed Cloudflare from the stack, TTFB stable below 200 ms.

TK
Tobias K.Owner · WooCommerce Shop for Home Textiles

With 800,000 products, AI crawlers and SEO tools pushed our server to the limit every hour. With Traffic Guard Shield, protection kicks in before WordPress — the database breathes again. Load times from 4.1 to 1.2 seconds, and without swapping out a single cache plugin.

SM
Sandra M.Managing Director · Online Shop for Furniture Fabrics

We currently deploy the plugin at 23 customer shops. Previously, we had to switch to Cloudflare Pro during every traffic spike — which caused false CAPTCHAs for real buyers and generated SEO tickets. Now: one MU plugin, shadow mode for 7 days, then go live. Provider tickets due to CPU are completely gone.

MT
Markus T.Agency management · WordPress agency

My blog with over 40,000 articles was literally torn apart by ClaudeBot and GPTBot — sometimes 1,500 requests per hour from a single IP. A hosting upgrade was already on the table. Traffic Guard Shield contained it in the first week without my real readers noticing anything. AI visibility remains — only the expensive filter and parameter URLs are closed.

JH
Jens H.Content Creator · Affiliate Platform

We had a complex Cloudflare setup with Page Rules, WAF and Bot Fight Mode — maintenance effort five hours per month. Now everything directly in the WP backend, German manufacturer, all data stays local. Bonus: TTFB has halved because no US edge is in the way anymore. And real buyers never see a captcha.

PW
Petra W.E-Commerce Manager · B2B Industrial Shop

Skeptical after three other security plugins that all eventually blocked real buyers too. After 7 days in shadow mode I was convinced: over 12,000 blocked junk requests, of which according to logs only four could possibly have been real buyers — and all were already logged in and thus never affected anyway. Cancelled Cloudflare subscription, server CPU down to around 30%.

DR
Daniel R.Owner · Online Bookstore

Representative audit testimonials from the beta phase. Domain and personal names have been anonymized to protect our beta testers (abbreviated first names + industry designation). Content reproduced unchanged; complete originals are available.

" Regular users are allowed to purchase.
Google, Bing and AI are allowed to understand.
Bots and preloaders are not allowed to destroy.
— Design principle · Traffic Guard Shield
Buyer Google · Bing AI crawler SEO Tools Junk bots Click fraud

Seven days of shadow mode are enough to see how much load actually comes from outside.

Install now · 129€/year 189 €
How it works

Seven layers of protection. One decision per request.

No dumb IP blocking. Instead, a prioritized request flow that evaluates identity, URL type, cost score, and frequency in a single step — before WordPress starts a single database query.

Human Safety Layer

Logged-in users, browsers with WC session, and HMAC-signed "Verified-Human" cookies are never blocked. Period.

A1 — A9

Google & Bing hardware lock

14 verified user agents with reverse & forward DNS (A + AAAA). Real search engines always get through — fakes are banned in the first second.

B1 · DNS-verified

URL-Cost-Score (20 categories)

One filter combination with three values costs 60. One product page costs 1. Cost budgets per IP per SUM(cost) from SQLite — exact, not estimated.

C1 · live cost

AI Visibility Mode

Three switches: allow · limited · block. Recommended: limited — AI sees products, but not filter combinations that will grill your database.

B4 · 13 AI-Crawler

WC Filter Performance Guard

Disabled expensive COUNT(DISTINCT) and SQL_CALC_FOUND_ROWS for bots on shop archives. Real users keep all counts and pagination.

D1 — D4

Honeypot & Probing Trap

16 invisible trap URLs (/wp-config.bak,/.env.bak,/phpmyadmin/) → 24h ban. Login & probing are counted separately.

M · 16 traps

Shadow & Auto-Safe Mode

First observe, then block. More than 50 bans in 10 minutes? Plugin automatically switches to shadow mode & alerts via email.

A6 · self-healing

10-tab admin interface

Dashboard, settings, IP lists, compatibility, .htaccess editor, robots.txt manager (11 presets), analysis, logs, tools — everything in the WP backend.

K · 10 tabs

Reverse proxy & CDN trust

GTranslate-CDN, NitroPack-Self-Crawl, Load balancer: Plugin extracts the real client IP from trust headers (X-GT-CLIENTIP,X-Real-IP) — with public IP hardening against spoofing.

N1 · Multi-Source Setup

3-source logging

Apache .htaccess-Blocks (403/429), Preload-JSONL (before WordPress) and Plugin-SQLite (real-time) — all three sources in one view. Cron import with auto-detection for All-Inkl, cPanel, Plesk.

N2 · Apache + Preload + Plugin

htaccess Auto-Sync

Plugin automatically places its blocks before GTranslate & WordPress. Order analysis detects 4 critical violations (bot protection after [L,QSA]) — with clear instructions instead of risky auto-sort.

I'm ready to translate German text to English following your rules. Please provide the German text you'd like me to translate.

Emergency Bypass via File

An empty file wp-content/tgsrl-disable.flag via FTP — plugin does nothing. Fast reset without backend login. Unbreakable.

A7 · failsafe
All features in detail

A · Human-Safety-Layer

  • A1Logged-in users bypass — no rate limit, no auto-ban
  • A2Critical WC paths dynamically — Cart, Checkout, Account, Order-Pay disabled wc_get_page_id()
  • A3Verified-Human-Cookie (HMAC) — 24h, HttpOnly, SameSite=Lax, four issuance conditions
  • A5WC Session Detection — Cart Hash & Session Cookie
  • A6Auto-Safe-Mode — 50+ Bans / 10 min → Shadow + Mail
  • A7Emergency Bypass via Filetgsrl-disable.flag
  • A8Deep Pagination — 302 for humans, 410 for bots
  • A9Auto-ban protection — Search engines, users and AI never auto-banned

B · Bot Protection

  • B1Google & Bing Hardware Lock — 14 UAs, DNS A+AAAA, not disableable
  • B2Bot registry with 7 trust tiers — from logged_in bis commerce_bot
  • B3Fake bot detection — Reverse + Forward DNS, instant 1h ban
  • B4AI Visibility Mode — allow / limited / block, 13 AI crawlers

C · Intelligent detection

  • C1URL cost model — 20 categories, cumulative SUM(cost)
  • C2Sitemap rate limiting — 5 req / 5min for unverified bots
  • C3Login & probing separate — own counters, max 10 / 5 / window
  • C4Request Sampling — under extreme load: every Nth request

D · WooCommerce Filter Guard

  • D1Dynamic filter counts optimize — Off / bots only / All
  • D2Hide count badges — Woodmart, Flatsome, Astra, OceanWP
  • D3Disable SQL_CALC_FOUND_ROWS for bots on shop archives
  • D4Auto-detection — WooCommerce + theme detected, recommendation displayed

E · Monitoring & Alerts

  • E1Shadow/Block Badges — yellow (logged in) vs. red (blocked)
  • E2Mode Banner — EMERGENCY · SHADOW · SAFE
  • E3Email Alerts — Instant + weekly report
  • E4Log Export CSV — UTF-8 BOM, Excel-compatible
  • E5Auto-Cleanup — 30 days / 10 MB limit + VACUUM

F · Shop archive detection (dynamic)

  • Shop page aus wc_get_page_id('shop')
  • Category & tag basis aus woocommerce_permalinks
  • Attribute Taxonomies aus wc_get_attribute_taxonomies()
  • Manual additions via textarea
  • WC pages Cart/Checkout/Account also dynamically — no hardcoding

G · Cache Governance

  • G1WP Rocket — 3 filters: Reject, Preload Exclude, Links Exclusion
  • G2NitroPack: DONOTCACHEPAGE + X-Nitro-Disabled: 1
  • G3GTranslate IP list updated daily, service crawler limit

H · .htaccess Management

  • H1Snippet Generator — bot filter, deep pagination, login protection, 40 countries
  • H2Editor + Backup — Dark theme, Safe-Save, rollback last 10 versions

I · robots.txt management

  • I111 presets — WC paths, filters, pagination, SEO scraper, AI
  • I2Editor + auto-insert + backup — same backup system as .htaccess

J · SEO Tools (Tools tab)

  • URL test lab — "What would happen with this URL?"
  • Sitemap Audit — SSL fix, 3 fallback URLs
  • noindex audit
  • Preflight Check — 10-Point Health
  • Action Scheduler Health
  • MU Plugin Generator · Settings Import/Export

L · security

  • Cloudflare spoofing protection — 15 IPv4 + 7 IPv6 ranges
  • IPv6 CIDR per inet_pton()
  • DNS A+AAAA Forward-Verify
  • SQLite with random file name
  • 404-guessing can be disabled
  • noindex for filter URLs & versioned DB migration

M · Honeypot

  • 16 invisible trap URLs/wp-config.bak,/.env.bak,/phpmyadmin/,/.git/config among others
  • 24h Ban on hit — no warning system for spam bots

N · Reverse Proxy & Multi-Source NEW 1.2

  • N1Reverse Proxy Trust — real client IP from X-GT-CLIENTIP,X-Real-IP,X-Forwarded-For with public IP hardening
  • N2GTranslate-CDN-Mode — Trust-header evaluation when REMOTE_ADDR is your own server IP
  • N33-source logging — Apache .htaccess + preload JSONL + plugin SQLite, shared view with source filter
  • N4Apache Log Import — Auto-detection All-Inkl, cPanel, Plesk · Cron 3:00 AM · max 5 MB per run
  • N5Anti-Self-Ban Protection — Server IPs rejected at DB level with audit log + one-click cleanup
  • N6REST API whitelist — cookie banner (Borlabs, Real Cookie Banner, Complianz) · 19 endpoints · 300 req/min
  • N7htaccess Auto-Sync — Insert before GTranslate / WordPress · Sequence analysis with 4 critical violations
  • N8Language prefix for deep pagination/fr/,/zh-cn/,/pt-br/ Read from GTranslate settings
  • N9IP-Detection-Diagnostics — Tools tab shows REMOTE_ADDR vs. real IP vs. trust headers live
Decision Engine — interactive

Seven typical requests. Seven different responses.

Click a row to see the reasoning. This exact logic runs live in milliseconds before WordPress wakes up.

Prevention instead of damage control

Protect your hosting and server effectively before something happens.

Traffic spikes cost you customers in real-time — and provider tickets the next day. Traffic Guard Shield intervenes before the expensive WordPress initialization, not only when your server is already struggling.

Greift in < 1 msBefore WordPress, database, or cache even work. No expensive query, no PHP worker, no warmed cache is wasted.
Protects against hosting surprisesNo sudden provider emails due to CPU limits. No 502 walls when campaigns start. You retain control over your own load.
7× more real buyers on the same hardwareBy cutting off bot traffic early, CPU, RAM, and DB pool remain reserved for humans. Measurably in the Cost-Score Dashboard, not promised.
Without external network, without vendor lock-inNo reverse proxy, no DNS changes, no third party sees your traffic. Everything runs locally in your WordPress installation.
Recommendation for what is probably the best hosting:
Test all-inclusive now →
Vs. classic security plugins

Why our plugin is more effective than any slow security plugin.

Wordfence, iThemes, Sucuri & Co. do a good job — defending against brute-force, malware, and known exploits. But they intervene after WordPress, not before. With pure crawl and bot traffic load, that's exactly the wrong place.

Reactive · slow

Classic security plugins

Wordfence · iThemes Security · Sucuri · All In One Security

  • Run INSIDE WordPress. Every bot request already has DB connection, plugins loaded and memory consumed before the security plugin even decides.
  • Focus on malware & logins, not on crawl load. Wordfence blocks brute-force, but not 200 req/s of an AI crawler fetching valid URLs.
  • Own CPU load: Every Wordfence rule costs computing time. With high traffic, the plugins themselves become a burden — a known effect on shared hosting.
  • No crawl governance: Filter URLs, pagination and AI tier classes are not a topic. Google & ChatGPT are treated the same as an attacker.
  • SEO risk in aggressive mode. Quickly block Googlebot too because the user agent rule was too strict. Rankings gone, ticket opened.
Makes sense as login/malware protection — but in the wrong place for load protection.
Präventiv · < 1 ms

Traffic Guard Shield Rate Limiter

VASTCOB · WP-native · since 2010

  • Intervenes BEFORE WordPress. Eigener Mu-Plugin-Loader entscheidet in < 1 ms, ohne dass eine einzige WP-Datei zusätzlich geladen wird.
  • Crawl rather than malware focus: 13 AI crawlers detected (3× OpenAI, 3× Anthropic, 2× Perplexity, 2× Apple, Google, Cohere, DuckDuckGo), cost score per IP, tier classes for Google/Bing/AI/Unknown.
  • Saves load itself: Instead of costing additional CPU, the plugin cuts expensive queries before they arise. Cost-Score Dashboard shows it live.
  • Reverse-proxy & CDN-aware: GTranslate-CDN, NitroPack-Self-Crawl & load balancer correctly recognized. Real client IP from trust headers, never self-bans.
  • SEO-safe by default: Verified Googlebot is confirmed via reverse DNS and never blocked. Shadow mode for 7 days of testing without risk.
Complements your security plugin — does not replace it. Both together = protection against malware and against load.
Ready to really protect your hosting?
Buy plugin · 129€/year →
Direct Comparison

Why not simply use Cloudflare or Wordfence?

Reverse proxies and security plugins solve a different problem. Traffic Guard Shield is not a bot blocker and not a WAF — it is an SEO-safe crawl governance layer that intercepts before the expensive query, without routing your traffic through an external network.

Criterion Traffic Guard ShieldVASTCOB · WP-native Cloudflare Bot ManagementReverse proxy Wordfence PremiumWP Security Plugin Sucuri FirewallWAF / CDN .htaccess onlyDIY
SEO & AI
Google & Bing guaranteed not blocked Hardware lock14 UAs, DNS A+AAAA, not disableable configurableCAPTCHA loops known Whitelist required Whitelist required DIY
AI crawler granular (allow / limited / block) 13 AI BotsCost-based allow / block allow / block
SEO-safe 410 Gone for crawl traps automaticFilter out of index 403 / Challenge 403 403 manual
Reverse Proxy / CDN Setups (GTranslate CDN, NitroPack) native trust header supportX-GT-CLIENTIP, X-Real-IP, X-Forwarded-For own edge only often conflicts
Multi-language support (WPML / Polylang / GTranslate) Language prefix-aware/fr/, /zh-cn/ from GT Settings
Reverse + Forward DNS verification (A+AAAA) built-inAlso IPv6 Googlebots reverse only reverse only
Performance & Load Peaks
URL-Cost-Score instead of just Request-Count 20 categoriesFilter combination = 60 rate only rate only rate only
Hooks before the WP database query auto_prepend_filePHP before WP-Boot Edgeexternal hop in WP Edge Apache
3-source logging (Apache + Preload + Plugin) unifiedSource filter, Apache cron import edge logs only plugin logs only WAF logs only
WC Filter Performance Guard built-in
Compatible with NitroPack / WP Rocket / FlyingPress 3 filtersFilter URLs not in preload Cache conflicts no integration no integration
Data protection & hosting
100% local — data does not leave the server 100% local US-Edge local US/Edge local
Cookie banner whitelist (REST API) 19 endpointsBorlabs, Real Cookie Banner, Complianz
Cloudflare Spoofing Protection 15 IPv4 + 7 IPv6 Ranges N/A partially partially
Auto-Safe-Mode on misconfiguration 50 / 10 min → Shadow
Emergency bypass via FTP file tgsrl-disable.flag Dashboard login Dashboard login Dashboard login Rename file
Honeypot with 16 trap URLs built-in Live Traffic Trap
Cost
Ongoing costs for medium-sized shop 129 €/yearUpdates included 200–2,000 $/monthBot Management only in Business+ 99 $/year ~ $200/year 0 €but no Cost-Score
★ Important to understand
Cloudflare, Wordfence and Sucuri solve WAF, DDoS and malware scans — and they're good at it. But crawl governance is not a WAF problem: an AI bot requesting 200 filter URLs per second is technically correct traffic. Recognizing it requires knowledge of WooCommerce URL structures, cost models and SEO consequences — not a generic edge network.
Buy plugin · 129 €/year 189 € Auto-updates · German support
The cornerstone

Cost-Score: One URL is not a URL.

A crawler that 60 times /produkt/eames-stuhl/ queries, costs 60. A crawler that runs once ?filter_farbe=rot,blau,gruen&orderby=price calls, costs 90. This exact difference decides between success or peak load.

Product page/produkt/eames-stuhl/
1
Blog Articles/blog/ratgeber/
1
Category homepage/stoffe/vorhang-stoffe/
3
Shop archive/shop/
5
Pagination 6–19/shop/page/12/
8
orderby?orderby=price
8
Filter (individual)?filter_farbe=rot
15
per_page?per_page=96
15
Search?s=suchbegriff
20
Pagination 20+/shop/page/84/
25
Filter (Multiple)?filter_farbe=rot,blau,gruen
30
Filter (3+ active)+ Zusatz-Penalty
60

Cost-Budgets per IP

Each IP receives a cost budget per time window. Verified browser users have a very generous budget of 2,000. Unknown crawlers get 100 — enough for meaningful indexing, too little to strain your database.

The sum is per SUM(cost) calculated from a SQLite database with WAL mode — exact, not estimated, with sub-millisecond latency.

// Cost budgets (configurable)
Verified Human: 2,000 · no rate limit
Browser without cookie: 1,000
Google / Bing: ∞ on clean URLs
AI crawler: 60 req/min
Unknown / SEO tool: 100
Spoofed bot: immediate 1h ban

Convinced?Measure cost score and pre-WP boot directly in your own shop — seven days shadow mode without risk.

Buy & test now! →

How much load you are currently generating in direct comparison

Real test with a solid WooCommerce shop (1,000 products, 100,000+ requests/month). Measured was the actual server load that still triggers database queries after the respective protection layer. Lower is better.

No protection whatsoeverCache only kicks in after DB hit
100%
Caching onlyWP Rocket / NitroPack solo
78%
Cloudflare Bot Mgmt.Edge-block, no cost score
54%
Wordfence Premiumonly takes effect in WordPress
62%
Traffic Guard Shield+ caching of your choice
14%
Concretely means: on the same server your shop processes up to 7× more real buyers — or you can get by with a significantly smaller hosting plan. Cost-Score and Pre-WP-Boot are the difference: bots never reach the database in the first place.
From practice

Two insights that almost every plugin gets wrong.

Direct excerpts from production logs showing why superficial bot detection fails — and why parameter URLs are the actual bottleneck for every WooCommerce shop.

#1Google detection is not trivial

Auto-ban entries that look like Google — but are not.

In a real audit, the auto-bans came almost entirely from Google/AdsBot-like IPs. Only: a large portion of them were fakes.

IPauto-bans
72.14.199.97195×
72.14.199.9830×
66.249.79.418×
66.249.79.2
72.14.199.99
66.249.76.74
154.201.89.73

These are not real users. But with 66.249.* and 72.14.* would be blind blocking dangerous — Google uses these ranges for Googlebot, AdsBot, Mediapartners, and more.

What is "Spoofing"? A bot simply sets User-Agent: Googlebot in its request header. Enough plugins fall for it — and end up blocking the real Googlebot because too many "Googlebots" came at the same time.

Google recommends three steps for verification — the Traffic Guard Shield performs all three automatically:

1
Check Reverse-DNS — IP → Hostname (e.g. crawl-66-249-79-4.googlebot.com)
2
Check domain — ends on googlebot.com,google.com or googleusercontent.com?
3
Forward DNS reverse — Hostname → IP, A & AAAA. Does it match the original IP?

Only when all three checks ✓ are passed does the request receive Trust Tier 1. If one fails: classification spoofed → immediate 1h ban.

#2Parameter URLs are the bottleneck

Why Filter, search and ?add-to-cart= explode with AI crawlers.

From a real daily report: a single AI crawler generates the majority of expensive requests.

EvaluationValue
IP216.73.216.5
User-AgentClaudeBot
Actionai_expensive_block
Cost value31
Number of hits≈ 1.450

ClaudeBot crawls Mass Product Pages, sometimes with problematic parameters such as ?add-to-cart=. That is Features, no content — they present the same product in countless variants and inflate the crawl infinitely.

Instead of blocking completely, the plugin differentiates cleanly:

/product/eames-chair/Pass
/blog/how-do-i-care-for-leather/Pass
?add-to-cart=482410 Gone
?filter_color=red,blue,green410 Gone
?s=search term429 Retry
/shop/page/84/410 Gone

This applies analogously to ChatGPT (GPTBot), Perplexity, Apple, DuckAssist and others. Clean content is welcome — parameter functions that show nothing new are consistently blocked. AI visibility remains intact, load drops drastically.

Dive deeper · Background article Crawler flood 2026: The complete analysis for WordPress & WooCommerce How AI crawlers will behave in 2026, which hosting plans will buckle now, and which protection strategies actually work — the detailed technical article with logs, measurement data and step-by-step audit instructions.
Do you want this depth for your shop?
Buy plugin · 129€/year →
The ideal combination

With NitroPack or WP Rocket — never with both.

Cache & Crawl Governance are two tools that complement each other. The Traffic Guard Shield brings three dedicated filters for each cache provider, so filter URLs are not constantly pre-warmed — because an empty cache is cheaper than 50,000 pre-rendered filter combinations.

VC
Crawl Governance · Layer 1
Traffic Guard Shield decides what arrives
+ ONE OF THREE ↓
Cache · Option A
NitroPack aggressive edge caching
🚀
Cache · Option B
WP Rocket Page Cache + Preloader
Cache · Option C
FlyingPress lean, modern, fast
!
Never run two cache plugins simultaneously. Double minification, broken critical paths, and unpredictable cache states are the result. Choose one — the Traffic Guard Shield comes with ready-made integrations for all three.

What the integration actually does

WP Rocket — 3 filters automaticallyrocket_cache_reject_uri,rocket_preload_exclude_urls,rocket_preload_links_exclusions. Filter URLs neither cached nor prewarmed.
NitroPack — headers & constantsDONOTCACHEPAGE + X-Nitro-Disabled: 1 on expensive URLs.
FlyingPress — cache & preload exclusion Filter and pagination URLs are removed from the critical path.
GTranslate — IP list updated dailyTranslation crawler with its own clean limit. Real users with language switcher never affected.
Cache-Preloader not recognized as botNitroPack, WP-Rocket and GTranslate as cache_preloader classified — trust level 0.
Our cache recommendation

Three cache plugins that we recommend for WooCommerce.

With WordPress & WooCommerce experience since 2010, we have managed hundreds of shops live. Here is the honest ranking — selected based on real performance in production shops, not marketing promises.

★ Top recommendation
NitroPack
for maximum performance

Aggressive edge caching, automatic image optimization, and critical CSS in one. Delivers measurably the best Core Web Vitals on large shops — perfectly combined with our plugin against filter preloading.

// rel=sponsored · Affiliate link
🚀
WP Rocket
the proven all-rounder

Solid page cache, excellent preloader, and the full WordPress-native filter ecosystem. Ideal if you want maximum control and easy debugging — our plugin controls its three preload filters directly.

// rel=sponsored · Affiliate link
FlyingPress
the lean alternative

Modern setup, very small, very fast. A real alternative for teams who find WP Rocket too "heavyweight" — with excellent lazy loading and cache logic that our plugin integrates seamlessly.

// rel=sponsored · Affiliate link

Ready for peaceful server nights? Install the plugin and observe in shadow mode.

Buy plugin · 129€/year 189 €
Admin interface

Many settings. Simple management. No additional programming required.

Everything directly in the WordPress backend. From emergency bypass to the .htaccess editor with backup to the URL test lab.

Clear answers

Frequently asked questions before purchase.

We have been operating the plugin for months on production shops with over 50,000 products. Here are the questions that real shop operators ask.

Does the plugin block my real buyers?
No. Logged-in users are completely bypassed (A1). Browsers with WooCommerce session are recognized as human (A5). Verified browsers receive a 24h HMAC cookie and a cost budget of 2,000 (A3). On cart, checkout and account pages there is an additional hard guarantee: real users are always free there (A2). Auto-Safe Mode kicks in if something goes wrong anyway.
What happens to my Google ranking?
Google and Bing are recognized as verified search engines via DNS verification (A + AAAA records) and are never blocked or auto-banned (B1, A9). Filter URLs receive a clean 410 Gone — the SEO best practice for removing crawl traps from the index instead of rendering them endlessly.
Do I still need Cloudflare or Wordfence?
Cloudflare and Wordfence solve a different problem (DDoS, WAF, malware scans). Traffic Guard Shield complements these tools — it is a dedicated crawl governance layer that intercepts before the expensive WordPress query. Many customers use it as a replacement for Cloudflare bot management because it works much more precisely and without an external reverse proxy.
How fast is the Decision-Engine?
The SQLite database runs in WAL mode with sampling option. A decision typically takes less than one millisecond. In standalone mode (auto_prepend_file), the decision is made before WordPress even starts.
What about ChatGPT, Claude, and Perplexity?
Thirteen AI crawlers (GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, anthropic-ai, Claude-Web, PerplexityBot, Perplexity-User, Applebot, Applebot-Extended, Google-Extended, cohere-ai, DuckAssistBot) are managed in their own tier class. You can control them in three modes: allow (fully allowed), limited (recommended — see products, not filter combinations) or block (caution, impairs AI visibility).
Does this also work with reverse proxy or CDN setups (e.g. GTranslate-CDN)?
Yes, even particularly well. The plugin automatically recognizes when REMOTE_ADDR contains its own server IP (typical with GTranslate CDN mode, NitroPack self-crawl or hosting load balancers) and reads the real visitor IP from trust headers such as X-GT-CLIENTIP,X-Real-IP or X-Forwarded-For. Public IP hardening prevents header spoofing via private or reserved IP ranges. Anti-self-ban protection at database level categorically prevents your own server IP from being accidentally banned — with audit log and one-click cleanup in the Tools tab.
Can I test it risk-free before purchasing?
Yes. The plugin starts in shadow mode: It makes all decisions but blocks no one — instead it only logs what it would have blocked. This way you can see for 7 days how the protection would take effect before you activate it.
Do data leave my server?
No, with one exception: license pings to license.vastcob.com. All request logs, IP lists, cost calculations, and bot detections happen locally in an SQLite database on your server. No US edge, no external tracker, no third party sees your traffic.
What if something goes wrong?
Three protection layers: (1) Emergency bypass per tgsrl-disable.flag via FTP — plugin no longer does anything. (2) Auto-Safe-Mode activates automatically after 50+ bans in 10 minutes and alerts via email. (3) .htaccess and robots.txt editor automatically create backups before each change with one-click rollback (last 10 versions).
What hosting requirements?
PHP 8.3+, WordPress 5.8+, SQLite extension (available on 99% of all shared hosting). Works on Strato, IONOS, All-Inkl, Hetzner, Mittwald, Raidboxes, WP-Engine — anywhere WordPress runs. Apache recommended for .htaccess integration; the plugin also runs with Nginx (without the .htaccess layer).
Updates & Support?
Auto-updates via integrated license SDK (v2.2.1). With invalid license, the plugin continues to run — only updates pause. Support via email, German manufacturer, German documentation.
Does the plugin replace my hosting provider or my security plugin?
No — and that is intentional. Your hosting provider is responsible for hardware, backups, and availability. Your security plugin (Wordfence, iThemes, Sucuri) protects against malware, login brute-force, and known exploits. The Traffic Guard Shield Rate Limiter sits in front and handles something different: crawl load, AI bots, expensive filter URLs, and cost score per request. All three together provide genuine all-around protection — separately, each covers its task without interfering with the others.
Is this compatible with my existing security plugin?
Yes, without conflicts. Since Traffic Guard Shield loads as a mu-plugin before all other plugins, Wordfence & Co. only see what has passed through us. Effect: Your security plugin suddenly has much less to do, since bot noise has already been filtered out — which in turn saves CPU and reduces false Wordfence alerts. Recommended combination: Traffic Guard Shield for load & crawl, Wordfence/iThemes for malware & login.
What does 3-source logging mean?
Three protection layers, three log sources — all in one view: (1) Apache .htaccess blocks bots/countries directly at the web server (403/429), the logs are automatically imported via cron at 3:00 AM. (2) Preload script runs via auto_prepend_file before WordPress and writes JSONL logs in real time. (3) Plugin SQLite records all plugin decisions with cost score and bot classification. Source Filter in the Logs tab shows you at a glance which layer is currently working. Apache Log Reader has auto-detection for All-Inkl, cPanel, and Plesk — suitable for shared hosting (max. 5 MB per import run).
Does this work with cookie banners like Borlabs, Real Cookie Banner, or Complianz?
Yes. Cookie banners write consent for anonymous visitors back via REST API — if that is blocked, consent storage fails and the banner appears endlessly. TGSRL has a REST API whitelist for 19 cookie banner endpoints (Borlabs Cookie, Real Cookie Banner, Complianz, Cookiebot, etc.) with its own counter (default 300 req/min). The whitelist is active by default and can be fine-tuned in the settings tab. Real visitors can thus give consent normally, while bot requests on other REST routes remain rate-limited.
Compatible with everything you know... WordPress 5.8+ WooCommerce Wordfence · iThemes · Sucuri Cloudflare · BunnyCDN · KeyCDN Strato · IONOS · All-Inkl · Hetzner Mittwald · Raidboxes · WP Engine Apache · Nginx · LiteSpeed WPML · Polylang · GTranslate (with CDN mode) Reverse proxy / CDN setups 100% local · no US edge
Optional · premium setup service

Don't feel like getting your hands dirty? We'll take care of it.

Install the plugin, configure it for your shop, activate shadow mode — and actively monitor for 48 hours to ensure everything runs smoothly. You purchase only the license; we handle the rest. After 48 hours, you receive a clear recommendation: go live or fine-tune.

What we specifically take over for you

  • Plugin installation on your server — Apache, Nginx or LiteSpeed, MU-plugin mode activated for pre-WP boot.
  • Configuration tailored to your shop — theme, cache plugin, multilingual setup and WC paths detected and configured.
  • .htaccess & robots.txt snippets cleanly implemented, including backups and sequence verification.
  • Shadow mode activated + baseline measurement on day 0 — You see exactly what changes.
  • 48 hours of active monitoring by VASTCOB: bot traffic, auto-bans, honeypot hits, suspicious cases.
  • Immediate adjustments for anomalies during the 48 hours — no waiting for ticket response.
  • Email support throughout the entire period — direct line to the developer team.
  • Final recommendation after 48 hours: go live, continue monitoring, or fine-tune.
Day 0Installation & Baseline
+24hFirst evaluation
+48hRecommendation & Handover
Recommended
Setup Service + 48h MonitoringOne-time · no follow-up costs
99
one-time · plus license · all prices net
  • Installation fully taken over
  • Configured for your shop
  • 48 hours active monitoring
  • Direct developer support
  • Conclusion recommendation included
Book setup service · 99 € →
Booking possible at any time — even retroactively if you want to try it yourself first.

// Note: The setup service is a standalone product and can also be booked separately after plugin purchase. We will contact you within 24 hours after ordering to arrange an appointment. License costs are not included in the price.

No more traffic spikes that you don't understand.

Install the Traffic Guard Shield Rate Limiter. Enable shadow mode. Observe for seven days. You will be surprised how much load actually comes from outside — and how quiet your server becomes afterward.

// Auto-Updates · German Support · 15+ Years WP+Woo Experience

Blocking bots with the WordPress Rate Limiter Plugin

With the WordPress Rate Limiter Plugin Traffic Guard Shield, you decide on identity, URL type, and cost score per request before WordPress or your database even wake up. Ordinary bot filters check IP lists or user-agent strings. This is no longer sufficient today, as modern crawlers rotate their identities or fake real search engine user agents.

Instead of blocking or allowing, it checks in less than a millisecond whether the call comes from a logged-in user, a browser with a valid session, a verified Googlebot, or an unknown bot. The plugin loads as an MU-plugin before all other components and thus takes effect before any PHP initialization.

Real search engines are recognized by reverse and forward DNS verification on A and AAAA records and are never blocked. Junk bots that pretend to be Googlebot are immediately kicked out. Sixteen invisible honeypot URLs like /wp-config.bak or /.env.bak additionally mark probing attempts, which directly leads to a 24-hour ban and ends brute-force attacks without warning.

WooCommerce Rate Limiter Plugin against AI crawlers and bots

The WooCommerce Rate Limiter Plugin categorizes AI crawlers into their own tier. GPTBot, ClaudeBot, PerplexityBot, and six other AI bots are treated separately from real browsers, search engines, and junk bots. You decide per mode whether these crawlers are allowed to read product pages, are stopped in the filter combination, or are completely blocked.

The recommended mode is limited. AI sees the catalog with real product pages and blog content but does not get access to multiple filter combinations, ?add-to-cart calls, or deep pagination. This protects the database from load peaks without destroying AI visibility. This very differentiation is missing from classic bot blockers and makes the Rate Limiter Plugin WooCommerce an independent crawl governance layer.

The cost score logic evaluates each URL based on its real effort. A simple product page costs one point. A filter combination with three active values and a sorting can cost sixty points or more. Cost budgets per IP are summed up in an SQLite database in WAL mode, precisely and without estimation.

WordPress Security and More Performance with Less Load – License for 129 Euros per Year Including Auto-Updates

The license for the WordPress Rate Limiter Plugin currently costs 129 Euros per year, regularly 189 Euros. All updates during the license period, the auto-update mechanism via the integrated license SDK, and German-language support directly from the manufacturer are included. There are no hidden tier levels or additional modules that would need to be purchased separately.

If the license is invalid, the plugin continues to run; only updates are paused. Feature switches remain active, and you do not lose access to the admin interface. License information is checked exclusively against license.vastcob.com. All request logs, IP lists, and cost calculations remain local on your own server.

Included are all twenty-three modules from eleven thousand lines of audited PHP code, including URL Cost Score, Google and Bing Hardware Lock, AI Visibility Mode, WC Filter Performance Guard, Honeypot, Shadow Mode, and Auto-Safe Mode. The ten tabs of the admin interface include Dashboard, IP Lists, Compatibility, .htaccess Editor, robots.txt Manager, Logs, and a dedicated URL Test Lab.

Mitigating Load Peaks with the WordPress Rate Limiter Plugin

Load peaks today rarely result from attacks but rather from normal crawl traffic. Nine active AI bots, five SEO tools, and several cache preloaders can overload a WooCommerce shop with fifty thousand products within minutes. The WordPress Rate Limiter Plugin cuts off this load before PHP, MariaDB, or Redis even wake up.

In a test with a medium-sized WooCommerce shop and 3.2 million requests per month, the combination of Cost Score Filter, AI Visibility Mode, and cache plugin reduces database load to fourteen percent. Pure caching solutions like WP Rocket or NitroPack alone result in around fifty-four percent. This ultimately means up to seven times more real buyers on identical hardware.

Those who wish to avoid the risk of directly activating a productive shop can start in Shadow Mode. For seven days, all decisions are made, but no one is actually blocked. Auto-Safe Mode intervenes in parallel if more than fifty bans occur within ten minutes and sends an email alert. An emergency bypass via FTP file is possible at any time.