=== Bot Guard: bot protection ===
Contributors: oweb-solutions
Tags: bots, antibot, security, spam, scraping
Requires at least: 5.0
Tested up to: 6.8
Requires PHP: 7.2
Stable tag: 1.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Connects your site to the free Bot Guard service (bot-guard.ru): blocks bots, scrapers and form spam, lets real search engine bots through.

== Description ==

Bot Guard checks every request from a visitor who is not logged in: the User-Agent, the IP address and its network (data centers, clouds), behaviour signals and form submissions that did not come from your own pages. Genuine Googlebot, YandexBot and Bingbot are confirmed with a reverse and forward DNS check; fakes are blocked. Suspicious visitors get a silent browser check instead of a CAPTCHA.

If bot-guard.ru is unavailable or slow, the plugin blocks nothing and your site works as usual (fail-open). Logged-in users, WP-Cron and WP-CLI are never checked.

The plugin contains all of its logic. It does not download or run any code from a remote server.

The Bot Guard service is currently free of charge.

== Installation ==

1. Upload the `bot-guard` folder to `/wp-content/plugins/` or install the zip via Plugins, Add New, Upload Plugin.
2. Activate the plugin.
3. Add your site in your account at https://bot-guard.ru/ (free).
4. Open Settings, Bot Guard, enter your site ID (it is in the URL of your site page in the account) and save.

== External services ==

This plugin connects to the Bot Guard service (https://bot-guard.ru/), operated by oWeb Solutions. It is required for the plugin to work: the service decides whether a request comes from a bot.

What is sent and when: for every request from a visitor who is not logged in, the plugin sends the visitor's IP address, User-Agent, HTTP method, referer, Accept-Language and the requested URL, together with your site ID, to https://bot-guard.ru/botguard. When the service asks for a silent browser check, the plugin also calls https://bot-guard.ru/get-captcha, and the visitor's browser calls https://bot-guard.ru/get-cookie/ to receive a check cookie.

Service terms of use: https://bot-guard.ru/terms/
Service privacy policy: https://bot-guard.ru/privacy/

Please mention this in your own site privacy policy.

== Frequently Asked Questions ==

= What happens if bot-guard.ru is down? =

Nothing is blocked. Requests that cannot be checked in time are let through.

= Does it work with page caching plugins? =

The check runs before WordPress renders the page. If your cache serves pages without running PHP (for example, server-level caching), protection will not run on those pages.

== Changelog ==

= 1.1.0 =
* Security: the plugin no longer downloads or executes PHP code from bot-guard.ru; all logic is built in.
* Removes the old downloaded code left by 1.0.x on first run.
* Removed the "Refresh protection code" button (nothing to refresh).

= 1.0.0 =
* First release.

== Upgrade Notice ==

= 1.1.0 =
Recommended security update: the plugin no longer downloads code from a remote server.
