Blacklist Manager Premium / Advanced Protection August 3, 2026

Configure Verified Beneficial Bots

Recognize beneficial automation with provider verification and roll out Detect, Shadow, or Enforce policy safely.

Applies to Premium 2.6.4+ Premium Stable Verified August 3, 2026

Verified beneficial bots separates known commerce, search, ads, preview, SEO, archive, user-triggered, and AI automation from malicious checkout traffic. Verification uses provider data such as published CIDRs or forward-confirmed reverse DNS; a User-Agent claim alone is never trusted.

Blacklist Manager Anti-bots advanced tuning showing Verified beneficial bots, Shadow rollout mode, and enabled provider controls
Premium 2.6.4 recognizes beneficial automation through provider verification and supports Detect, Shadow, and Enforce rollout modes.

Open the feature

Go to Blacklist Manager > Settings > Anti-bots.

Choose a safe rollout mode

  • Detect only: identify and log verified automation without changing checkout policy.
  • Shadow policy: calculate the controlled policy and evidence without enforcing the stop; recommended for rollout.
  • Enforce controlled stop: stop verified automation before order or payment creation without counting it as malicious.
  1. Enable Verified beneficial bots and select only providers relevant to the store.
  2. Start in Shadow policy and refresh the verified bot feeds.
  3. Review freshness diagnostics and Activity Log evidence, including verification method, raw/effective score, suppressed reasons, and transaction outcome.
  4. Keep payment-abuse and other hard evidence enabled; verified automation does not bypass hard security signals.
  5. Move to Enforce controlled stop only after representative commerce/search crawlers verify correctly.

WP-CLI inspection

Use wp bmp-antibot bots status, wp bmp-antibot bots list, wp bmp-antibot bots refresh, or wp bmp-antibot bots verify on staging. Run wp bmp-antibot test-risk for the broader anti-bot smoke suite.

Verify the result

  • Feed health is fresh or explicitly using a last-known-good cache.
  • A forged User-Agent without provider verification receives no trusted policy change.
  • Verified commerce automation can omit expected human-browser proofs but cannot create an order or payment.
  • Rate-limit and Activity Log records use a separate verified-automation identity.

Important notes

  • Existing sites that completed Setup Wizard inherit the prior Anti-bot module state and begin in Shadow mode when these options are first added.
  • DNS and feed availability can change; do not move to Enforce while verification health is stale or unexplained.

Related Guides

Continue from Blacklist Manager Premium documentation to the complete product workflow.

Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.

Need support?

Still stuck?

Open a support request and include this article title, your plugin version, and what you already tried.

Open Support