Home / Documentation / Getting started
TMB Bot Guard

Getting started

Install TMB Bot Guard, choose safe defaults, and verify the complete protection workflow.

Before you begin

You need a WordPress administrator account. If the site uses a full-page host or CDN cache, begin in Standard mode and change modes only if testing proves that cached page views bypass WordPress.

Recommended first-time setup

  1. Install and activate TMB Bot Guard, then open TMB Bot Guard → Settings.
  2. Keep Strikes Before Blocking at 3 and Strike Reset Time at 12 hours. This gives you evidence before a hard block while still stopping repeated suspicious activity.
  3. Choose Access Denied Page unless you have a specific blocked-visitor page and understand redirect caching.
  4. Leave Cache Compatibility Mode off for the first test.
  5. Enable Browser Request Checks, Browsing Pattern Checks, and Activity Logging. Leave optional browser validation and crawler DNS verification off until the basic workflow is confirmed.
  6. Review Trusted Service Groups. Enable only the monitoring, CDN, SEO, analytics, security, or development services the site actually uses.
  7. Enable GA4 only if you want security events in analytics, then choose the existing-site or custom connection.
  8. Save changes.
Example: ordinary business siteUse 3 strikes, a 12-hour reset, Access Denied Page, Standard mode, Browser Request Checks, Browsing Pattern Checks, Activity Logging, and only the Monitoring Services trusted-service group.

Verify the installation

  1. Open Testing Tools and review Plugin Status. Confirm the detection mode, strike limit, reset time, and analytics state.
  2. Select Add Test Strike.
  3. Open Activity Logs and confirm the controlled event was recorded.
  4. Open Strike Management and confirm the test address appears.
  5. Clear the test strike, then reload the table to confirm it is gone.
  6. If GA4 is enabled, select Test GA4 Event and verify it through your analytics debugging tools.
Do not test with a real visitor’s address. Use the built-in test action or a controlled browser session, and keep another administrator session available if testing active blocking.

What to configure next

  • Read the Settings reference before changing detection weights or trusted proxy addresses.
  • Use the tutorials for false positives, cache testing, GA4, and premium rollout.
  • Introduce Rate Limiting and Geographic Analysis in observation mode before active enforcement.