Служба поддержки работает 24/7 — мы всегда на связи по вопросам хостинга и серверов.Открыт прием заявок на аренду выделенных серверов и размещение оборудования в дата-центре.Напоминаем: рекомендуем включить резервное копирование для дополнительной защиты данных.Доступна новая линейка VPS/VDS с NVMe-дисками и увеличенной производительностью.Технические работы на части серверов завершены. Все сервисы работают в штатном режиме.

MODULE FOR 1C-BITRIX

Good Solutions

Antibot — website protection from bots and scrapers

The Anti-bot module automatically protects websites from bots, scrapers, and suspicious traffic using a set of rules and a JS Challenge. The system analyzes User-Agent, IP address, GeoIP location, UTM tags, and browser behavior to distinguish between real users and automated scripts.

Technical details

Published
07.05.2026
Updated
17.09.2026
Version
1.0.7
Installed
Less than 50 times
Suitable editions
«First Site», Start, Standard, Small Business, Business
Responsiveness
No
Composite support
No
Compatible with Sites24
Yes
Developer
Good Solutions

What this solution does

The Anti-bot module automatically protects websites from bots, scrapers, and suspicious traffic using a set of rules and a JS Challenge. The system analyzes User-Agent, IP address, GeoIP location, UTM tags, and browser behavior to distinguish between real users and automated scripts.

When rules are triggered, the module either blocks the request entirely (returning a 403 status code) or displays an intermediate JS challenge page. This page allows only genuine browsers to pass through without hindering legitimate visitors.

Key functions of the module:

Filtering out basic scrapers and scanners that use suspicious or missing User-Agent headers.

Blocking traffic from unwanted countries (GeoIP blacklist) or, conversely, restricting access to specific regions only.

Protection against brute-force attacks and mass automated traffic targeting public pages and forms.

Preserving the integrity of statistics and SEO metrics by reducing the share of non-targeted visits.

How it works:

The module activates on every request via the early OnPageStart event, retrieving data on IP, User-Agent, country, and UTM tags.

The first step involves checking IP and UTM whitelists; requests from trusted sources are allowed to pass immediately.

The module sequentially checks the User-Agent blacklist and, if necessary, the country-based rule (block_foreign). Requests matching these lists receive a 403 response and do not reach the site.

For borderline cases, a JS-Challenge is used: the module displays a special HTML page that executes a simple script and sets a 'human' flag in the cookie. Bots without JavaScript support cannot proceed further.

All triggered rules are logged with the date, IP address, URL, 'bot/human' flag, and blocking reason.

Flexible traffic configuration. The module supports IP and User-Agent allowlists and blocklists, a GeoIP filter, and configurable UTM tags for SEO bots or internal checks.

Soft protection via JS-Challenge. Instead of a hard 403 rejection, the module can display a lightweight intermediate page that a standard browser passes in a fraction of a second, while bots cannot.

Detailed traffic logging. The admin panel includes a section listing protection triggers, showing the total number of requests, the count of blocked requests, and the number of real users.

General iT can install and configure this module and check how it works on your website.

UPDATE HISTORY

What’s new

7 releases
1.0.7 (26.08.2026)Latest update

What's new in version 1.0.7:

Safe export of the log to CSV with filter and sorting support has been added to 'Honest Analytics'.

A separate option to block explicit headless browsers with the User-Agent 'HeadlessChrome' has been added.

The headless browser blocking option is disabled by default to avoid interfering with PF services, Lighthouse, and headless monitoring.

1.0.6 (25.08.2026)

What's new in version 1.0.6:

The 405 response when opening a URL with the service parameter 'gs_antibot_action' has been fixed.

Random GET requests with the service parameter are now redirected to the same URL without that parameter.

The response to a successful JS check ends immediately after returning JSON and no longer triggers page rendering.

The 'gs_antibot_action' parameter has been excluded from pagination, metadata, and the site component cache.

1.0.5 (27.07.2026)

What's new in version 1.0.5:

A blacklist for individual IP addresses and CIDR subnets with support for IPv4 and IPv6 has been added.

A quick command to add IPs to the blacklist has been added to the 'Honest Analytics' log.

Triggering a network rule is now logged with the reason 'BLOCK_IP_RULE' and the exact IP/CIDR rule.

Geolocation has been switched to standard 1C-Bitrix handlers without calling an incompatible external IP-API.

For an undefined country, a safe option has been added: either skip the visitor or show a JS-Challenge.

Validation of IP addresses and CIDR subnets before saving settings has been added.

Compatibility with demo mode and the challenge-token protection mechanism of version 1.0.4 has been preserved.

1.0.4 (13.07.2026)

What's new in version 1.0.4:

Added compatibility with the demo mode of the 1C-Bitrix Marketplace.

Strengthened antibot_token verification: the global salt has been replaced with an individual installation secret, MD5 has been replaced with HMAC-SHA256, hourly rotation and hash_equals() have been added.

Behavioral antibot_behavior is now signed by the server via HMAC and validated by its expiration time. Unsigned client-side JSON is no longer considered trusted.

Retrieval of human- and behavior-tokens is protected by Bitrix sessid and a short-lived server-side challenge bound to the IP address and token purpose.

Search and advertising User-Agents are verified via reverse and forward DNS, so browser string spoofing no longer allows automatic bypass of protection.

UTM exclusions apply only to visitors who have already passed the JS-Challenge.

Removed the non-cryptographic fallback secret generator: if random_bytes() is unavailable, the module safely terminates the operation.

Public protection is correctly disabled after the demo period expires and does not block site traffic.

Clear messages for the expired demo period have been added to the settings and log.

The include.php file has been prepared for obfuscation of the demo version in accordance with Bitrix requirements.

1.0.3 (02.06.2026)

What's new in version 1.0.3:

Enhanced admin journal security: added a whitelist for sort fields and output escaping for user data (IP, URL, User-Agent).

Added a safe fallback for the old database schema: the journal opens without a fatal error even before the migration is executed.

Strengthened IP geolocation validation: IP validation + switching to an HTTPS request to ip-api.

Added a log table structure migration during updates (automatic addition of DECISION_CODE and MATCHED_RULE columns if they are missing).

Added a JS behavioral signal (lightweight fingerprint token: mouse/scroll/keypress/touch + webdriver).

In the suspicious direct traffic branch, a challenge is added if the behavioral signal is missing or invalid.

Added a new setting: "Enable JS behavioral signal".

Safe defaults preserved: advertising bots in the whitelist, Suspicious traffic mode set to monitor by default.

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

How do I purchase a solution?
Submit a request on the solution page. A manager will check your selection, confirm the terms and arrange the purchase. We can also help with installation and setup.
Is a 1C-Bitrix licence included?
The default price covers the solution itself. If the developer offers a bundle with a 1C-Bitrix licence, you can select it separately on the solution page.
Can I try a solution first?
Available online demos and trial periods are shown on the solution page. The trial length depends on the solution.
How much does renewal cost?
Renewal is calculated as 50% of the full solution price before discounts. A manager will confirm the renewal terms and period before you order.
Can you help implement the solution?
Yes. We can build a website or store based on a template, or install, configure and check a module for compatibility. The scope and cost of the work are agreed separately.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot