WPIntell

botfend-anti-bot-firewall

BotFend Anti-Bot Firewall

Professional security plugin protecting WordPress from malicious bots, spam, and server attacks using an advanced Web Application Firewall.

0
254
5.0
4
6
0

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

32 / 69 rows with source links

46.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

37 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

61 days
46 206 -77.7% 259

Source Evidence

Open evidence explorer
complaint review · high severity · relevance 0.98
A lot of useful protective, anti-bot features

A lot of useful protective, anti-bot features: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
A lot of useful protective, anti-bot features BotFend has a lot of security features and pretty advanced protection from bots using various scoring parameters like external blocklists, 404 access count and general rate-limit, bot traps, files protection etc..
complaint support · high severity · relevance 0.98
Feedback – ideas to improve

Feedback – ideas to improve: users show security, bugs, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
2 “Enable Reverse DNS Verification” checkbox may be moved one item up to be right after “Enable Crawler Verification” and be named similarly, so it is apparent these are two options of a same thing.
complaint support · high severity · relevance 0.96
VPN blocking should not be default

VPN blocking should not be default: users show security, missing feature, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Blocking these people by default (as your plugin seems to be doing) on a General settings tab, seems like bad idea.
mixed support · high severity · relevance 0.95
PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase

PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase: users show bugs, compatibility, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase Hello, I am on WP 7.0, PHP 8.5, plugin 4.9.1 and today at /wp-admin/site-health.php?tab=debug is critical error preventing page to load: https://justpaste.it/2g65l it happens in /wp-content/plugins/botfend-anti-bot-firewall/botfend-anti-bot-firewall.php on line 536 Hello, I am on
mixed support · high severity · relevance 0.95
Plugin is (maybe wrongly) scoring even internal sub-requests 404

Plugin is (maybe wrongly) scoring even internal sub-requests 404: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Plugin is (maybe wrongly) scoring even internal sub-requests 404 Hello, one would expect to score bad visitors who tries to access pages that does not exist, but the plugin seems to be scoring particular elements of a web page not being found, which may/can NOT be fault of a visitor, because maybe admin just misconfigured website to link to non existing elem
complaint review · high severity · relevance 0.79
Good security plugin

Good security plugin: users show security pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Good security plugin This plugins does what it says….
complaint support · medium severity · relevance 0.69
Mention default value for each scoring parameter?

Mention default value for each scoring parameter?: users show support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Mention default value for each scoring parameter?
complaint support · medium severity · relevance 0.69
Score explained in relation to blocking

Score explained in relation to blocking: users show missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
(like for example “Allowed: 404” with possible tooltip “Allowed request despite Advanced 404 detection”) Can this be improved to be which score triggers blocking and so each request clearly tell if allowed or blocked?

Competitor Context

5 shown
ClickCease Click Fraud Protection weak incumbent · intel 72.5 · weakness 59.7
weak incumbent
below-average rating 11 collected complaint signal(s) bugs support 2 source links Evidence only
Evidence only

This row is useful source evidence, but it has not been promoted into a build-worthy commercial opportunity.

JTZL's Bot Maze praise owner · intel 37.4 · weakness 14.5
praise owner
1 unresolved support thread(s) 1 collected complaint signal(s) bugs compatibility 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
CHEQ Essentials watchlist · intel 29.1 · weakness 19.3
watchlist
1 collected complaint signal(s) bugs support 1 source link Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test spam protection lockouts, bot/spam defenses, risky access changes, and incident alerts
Cloud Maestro – WAF Security Suite for Cloudflare praise owner · intel 27.1 · weakness 12.7
praise owner
1 source link Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

8 shown from 8 collected
complaint Good security plugin (5 stars) review · 2026-06-28T13:35:29+00:00 · high severity · bot protection

Good security plugin: users show security pain that may indicate a product gap.

Evidence: Good security plugin This plugins does what it says….
security trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase support · 2026-06-16T05:45:36+00:00 · high severity · bot protection

PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase: users show bugs, compatibility, performance pain that may indicate a product gap.

Evidence: PHP Fatal error: Uncaught Error: Call to private method BotFendDatabaseDatabase Hello, I am on WP 7.0, PHP 8.5, plugin 4.9.1 and today at /wp-admin/site-health.php?tab=debug is critical error preventing page to load: https://justpaste.it/2g65l it happens in /wp-content/plugins/botfend-anti-bot-firewall/botfend-anti-bot-firewall.php on line 536 Hello, I am on
bugs compatibility performance missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Mention default value for each scoring parameter? support · 2026-06-15T14:02:51+00:00 · medium severity · bot protection

Mention default value for each scoring parameter?: users show support pain that may indicate a product gap.

Evidence: Mention default value for each scoring parameter?
support value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint A lot of useful protective, anti-bot features (5 stars) review · 2026-06-12T06:19:16+00:00 · high severity · bot protection

A lot of useful protective, anti-bot features: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: A lot of useful protective, anti-bot features BotFend has a lot of security features and pretty advanced protection from bots using various scoring parameters like external blocklists, 404 access count and general rate-limit, bot traps, files protection etc..
security bugs compatibility missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Plugin is (maybe wrongly) scoring even internal sub-requests 404 support · 2026-06-12T06:04:34+00:00 · high severity · bot protection

Plugin is (maybe wrongly) scoring even internal sub-requests 404: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: Plugin is (maybe wrongly) scoring even internal sub-requests 404 Hello, one would expect to score bad visitors who tries to access pages that does not exist, but the plugin seems to be scoring particular elements of a web page not being found, which may/can NOT be fault of a visitor, because maybe admin just misconfigured website to link to non existing elem
security bugs compatibility missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Score explained in relation to blocking support · 2026-06-12T05:27:39+00:00 · medium severity · bot protection

Score explained in relation to blocking: users show missing feature pain that may indicate a product gap.

Evidence: (like for example “Allowed: 404” with possible tooltip “Allowed request despite Advanced 404 detection”) Can this be improved to be which score triggers blocking and so each request clearly tell if allowed or blocked?
missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint VPN blocking should not be default support · 2026-06-12T04:48:35+00:00 · high severity · bot protection

VPN blocking should not be default: users show security, missing feature, support pain that may indicate a product gap.

Evidence: Blocking these people by default (as your plugin seems to be doing) on a General settings tab, seems like bad idea.
security missing feature support reliable trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Feedback – ideas to improve support · 2026-06-11T19:19:24+00:00 · high severity · bot protection

Feedback – ideas to improve: users show security, bugs, performance pain that may indicate a product gap.

Evidence: 2 “Enable Reverse DNS Verification” checkbox may be moved one item up to be right after “Enable Crawler Verification” and be named similarly, so it is apparent these are two options of a same thing.
security bugs performance missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts