Home / FAQ
TMB Bot Guard

Frequently asked questions

Clear answers about setup, progressive strikes, caching, analytics, privacy, licensing, and everyday site management.

Getting started

What does TMB Bot Guard protect my site from?

Bot Guard reviews eligible WordPress page visits for signs of automated or malicious traffic. It can record suspicious activity, progressively block repeat offenders, allow trusted services, and help you investigate what happened.

Does the Free plan require a license key?

No. Install and activate the plugin, then configure the core protection settings. A customer-entered license key is required only for paid plans.

What settings are recommended for a new installation?

For most sites, begin with Standard Mode, a three-strike limit, a 12-hour strike reset time, the Access Denied Page, Browser Request Checks, Browsing Pattern Checks, and Activity Logging.

Where can I find an explanation of every setting?

Open the Settings Reference in the Documentation section. It explains every field on the main Settings tab, its default or recommended starting point, the effect of changing it, and examples of when to use it.

Should I change several detection settings at once?

Change one related group at a time, save, run a controlled test, and review Activity Logs. Changing several weights, trust rules, and enforcement options together makes it difficult to identify which change affected the result.

Will Bot Guard block search engines or monitoring services?

Recognized services can be trusted through built-in service groups, custom trusted-service entries, IP whitelisting, and optional verification for Google and Bing crawler addresses. Enable only the services your site actually uses.

Strikes and blocking

What is a strike?

A strike is a confirmed suspicious page request associated with an IP address. It records the event for review and moves that address closer to the configured blocking limit.

Why doesn’t Bot Guard block every suspicious visit immediately?

A progressive strike system gives the site owner evidence and time to review an unusual request before it becomes a hard block. Repeated suspicious behavior is still blocked automatically when it reaches the selected limit.

What happens when an address reaches the strike limit?

Bot Guard denies access using the configured blocked-visitor experience. The block remains while the strike record is active, unless an administrator clears it or whitelists the address.

How can I correct a false positive?

Review the event in Activity Logs, then clear the address’s strikes or add a narrow temporary or permanent whitelist entry. Record a reason so other administrators understand the decision.

Do strikes expire automatically?

Yes. Active strikes expire after the configured Strike Reset Time when no newer strike refreshes the record.

Can a whitelisted address still have a blocked strike record?

Yes. The whitelist takes precedence without deleting the strike record. If you remove the whitelist entry while the blocking strikes are still active, the block applies again immediately.

Can one page visit create strikes for the page icon, images, or scripts?

Ordinary static resources such as icons, images, stylesheets, and scripts are excluded from strike detection. One suspicious document visit should create no more than one bot-detection strike.

Detection modes and caching

What is the difference between Standard Mode and Cache Compatibility Mode?

Standard Mode checks a request before WordPress displays the page and is recommended for most sites. Cache Compatibility Mode uses a small browser script to ask WordPress for a check when an aggressive full-page cache would otherwise bypass the plugin.

Do Standard Mode and Cache Compatibility Mode run together?

No. They use different entry points and are mutually exclusive, preventing one page view from being processed by both modes.

When should I enable Cache Compatibility Mode?

Enable it only when Standard Mode cannot see visits served directly from a host or CDN page cache and the cache cannot be configured to let Bot Guard run first.

Why does a blocked visitor see an overlay in Cache Compatibility Mode?

A cached page can appear before WordPress performs the browser-assisted check. If the response says the visitor is blocked, the script applies the blocked-access experience over that page.

Analytics, logging, and privacy

Can I measure bot activity in Google Analytics 4?

Yes. Bot Guard can send bot-detected and bot-blocked events through your existing GA4 or Google Tag Manager setup, or through a separately configured GA4 property or GTM container.

What information is included in GA4 security events?

Events can include the event type, anonymized IP information, strike count, time, and affected page. Bot Guard does not send the raw visitor IP address in these analytics events.

What is the difference between Activity Logs and the WordPress debug log?

Activity Logs are the plugin’s bounded, user-facing history of security decisions. The WordPress debug log is a technical troubleshooting file and receives additional Bot Guard detail only when the relevant diagnostic logging is enabled.

How long does Bot Guard keep information?

Strike records expire according to the configured reset time, Activity Logs are limited to 500 recent entries, and temporary whitelist entries expire automatically. Other enabled modules use their documented bounded storage and cleanup behavior.

Testing, licensing, and premium features

Can I test Bot Guard without intentionally blocking real visitors?

Yes. Use Testing Tools to add a controlled strike and test a GA4 event. When introducing Rate Limiting or Geographic Analysis, begin with logging or review-only actions before enabling active enforcement.

What is Diagnostic Mode?

Diagnostic Mode records additional troubleshooting information and refreshes status checks more frequently. Enable it temporarily while investigating a problem, then turn it off afterward.

Which features require a paid plan?

Starter adds email security notifications and weekly reports. Professional adds monthly reports, rate limiting, geographic analysis, priority support, and broader site coverage. Enterprise and Lifetime expand license coverage, while Lifetime also includes lifetime product updates. Review the Pricing page for the current comparison.

How should I introduce a premium enforcement feature?

Begin with observation: Log Only for Rate Limiting, and tracking or Flag for Review for Geographic Analysis. Test provider and email connections, review legitimate traffic, then introduce throttling, delays, or blocking after confirming the settings.

Can I move a paid license to another website?

Deactivate the license on the current site before activating it on the replacement site. Your license must also have an available site activation under its plan allowance.

What should I include in a support request?

Include the plugin version, WordPress version, detection mode, relevant Activity Log details, and the exact error message. Never send passwords, private signing keys, or your complete license key.

Still looking for an answer?

Browse the full guides or send the details of your issue to support.