Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.

MODULE FOR 1C-BITRIX

Web Heroes

Anti Bot — website protection (anti-spam) from unwanted traffic, spam, and bots

The Anti Bot module for 1C-Bitrix protects websites from unwanted traffic, spam, and automated requests without reducing performance. The system filters incoming data by geography, Autonomous System Numbers (ASN), IP addresses, and User-Agent strings.

Technical details

Published
11.06.2026
Updated
14.09.2026
Version
1.2.2
Installed
Less than 50 times
Compatible editions
'First Site', 'Start', 'Standard', 'Small Business', 'Business', 'Corporate Portal', 'Enterprise', 'Online Store + CRM'
Responsiveness
Yes
Composite Support
Yes
Compatible with Sites24
No
Developer
Web Heroes

What this solution does

The Anti Bot module for 1C-Bitrix protects websites from unwanted traffic, spam, and automated requests without reducing performance. The system filters incoming data by geography, Autonomous System Numbers (ASN), IP addresses, and User-Agent strings.

Features include country-based blocking with access control for 249 countries using a local .mmdb database, eliminating the need for external queries. The module also supports ASN filtering to block entire provider networks, data centers, and VPN services by their autonomous system numbers.

Precise access management is provided via white and black IP lists with tagging capabilities and support for bulk imports. The built-in bot filtering system includes predefined groups for search engines, social networks, and monitoring services, along with the ability to create custom User-Agent rules.

The JS Challenge mechanism replaces direct blocking with a puzzle captcha that real users can solve but automated bots cannot. Integrated statistics display charts, top countries, and an event log with details on URL, ASN, and User-Agent; event history is retained for 7 days. To optimize performance, geolocation data is cached in the database, and ASN data is cached for 7 days, ensuring minimal load on each request.

When needed, General iT can implement “Anti Bot — website protection (anti-spam) from unwanted traffic, spam, and bots”, configure the module and verify it against the current website setup.

UPDATE HISTORY

What’s new

4 releases
1.2.2 (14.09.2026)Latest update

Anti Bot 1.2.2

Fixed a JS Challenge (slide puzzle) error: on an inaccurate first attempt, the one-time verification token would expire, causing all subsequent attempts to fail with the error "Try again" regardless of the answer's correctness — now the token remains valid until successful completion, and a miss does not prevent trying the same puzzle again

The attempt limit for verification has been moved to a fixed time window: with continuous traffic from a shared IP address (mobile operator, VPN, office network), the window no longer extends indefinitely and no longer causes permanent blocking of legitimate visitors

A verification attempt is now consumed only on failure: successful completion and a random click without dragging the fragment do not reduce the limit

Anti Bot 1.2.1

Added local storage of the ASN (provider) database on the server — a separate option in settings, similar to the existing local country database; when enabled, it operates without external requests and without a 7-day cache, updating automatically every 3 days

Local storage of the country and ASN databases is now enabled automatically during module installation and updates, with current databases downloaded immediately — without requiring the administrator to visit settings

Developer blocklist: IP/ASN entries deactivated on the WBHR side are now automatically removed from client site blacklists during the next synchronization — manually added administrator entries are not affected

The "Update Now" button report and daily synchronization now include the count of removed outdated entries

When updating the local country (and ASN) database, the dependent cache is now cleared across all sites in the installation so that new data is applied immediately, not after TTL expiration

The module now sends the installation domain to the blocklist server (blocklist.solutions.wbhr.ru) with each request for the current list — a technical tag for activity statistics, which does not affect the composition or format of received lists

Anti Bot 1.2.0

Added JS Challenge (slide puzzle) as an alternative to hard blocking for the IP blacklist and for blocking by ASN — enabled via separate options in the module settings, independently for each site.

Upon successful completion of the JS Challenge for an IP/ASN in the blacklist, access is granted for 20 minutes, after which verification is requested again.

Added the "Disable JS Challenge" flag for individual entries in the IP and ASN blacklists — forces hard blocking of a specific entry even when the JS Challenge option is enabled.

Added bulk actions in the IP and ASN blacklists: delete selected entries, enable/disable the JS Challenge restriction — selection via checkboxes on entries or via "Select All".

Added bulk deletion of entries in the IP whitelist — via checkboxes or via "Select All".

Added the setting "Install ASN and IP blocks from developers" (independent for each site) — a curated database of known spammers and bots from WBHR, automatically updated once daily.

Entries from the developer database are marked with the tag "[Black List WBHR]" and never modify or delete entries added manually by the administrator.

Added a manual button to request an update of the developer database "Update Now" with a report on the number of received and added IPs and ASNs.

Added GoogleAssociationService, Schema-Markup-Validator, Instagram, and Telegram to the built-in allowed User-Agent groups — eliminates false blocks and CAPTCHA for real users opening the site via the built-in browsers of Instagram and Telegram, as well as for the schema.org markup validator.

Anti Bot 1.0.1

Fixed a multisite error: when accessing the module admin panel without an explicit site_id in the URL, the "Countries" tab and other settings could display data for the wrong site.

Added a statistics filter: by date/time range, IP address, ASN, country, action, and User-Agent.

Added statistics "Top User-Agent by number of requests"

Enhanced catalog protection with debug logging: protected directory, random filename, centralized message sanitization

1.2.1 (21.08.2026)

Anti Bot 1.2.1

Local storage of the ASN database (providers) has been added to the server as a separate option in settings, similar to the existing local country database; when enabled, it operates without external requests and without the 7-day cache, and is automatically updated every 3 days.

Local storage for the country and ASN databases is now automatically enabled during module installation and updates, with current databases downloaded immediately, eliminating the need for the administrator to visit settings.

Developer blocklist: IP/ASN records deactivated on the WBHR side are now automatically removed from client site blacklists during the next synchronization; records manually added by an administrator are not affected.

The report for the "Update Now" button and daily synchronization now includes the count of removed outdated records.

When updating the local country (and ASN) database, the dependent cache is now cleared across all sites in the installation so that new data is applied immediately, rather than waiting for TTL expiration.

The module now sends the installation domain to the blocklist server (blocklist.solutions.wbhr.ru) with each request for the current list; this is a technical tag for activity statistics and does not affect the composition or format of the received lists.

Anti Bot 1.2.0

A JS Challenge (sliding puzzle) has been added as an alternative to hard blocking for blacklisted IP addresses and ASN blocking; it can be enabled via separate options in module settings, independently for each site.

Upon successful completion of the JS Challenge for a blacklisted IP/ASN, access is granted for 20 minutes, after which verification is requested again.

A "Disable JS Challenge" flag has been added for individual blacklisted IP and ASN records, enforcing hard blocking for specific records even when the JS Challenge option is enabled.

Bulk actions have been added for IP and ASN blacklists: deletion of selected records, and enabling/disabling the JS Challenge restriction; selection is possible via checkboxes on records or via "select all".

Added bulk deletion of records in the IP whitelist — via checkboxes or using 'Select All'

Added the setting 'Install ASN and IP blocks from developers' (independent for each site) — a curated database of known spammers and bots from WBHR, automatically updated once daily

Records from the developer database are marked with the tag '[Black List WBHR]' and never modify or delete records added manually by the administrator

Added a manual button to request an update of the developer database 'Update Now' with a report on the number of received and added IP and ASN addresses

Added GoogleAssociationService, Schema-Markup-Validator, Instagram, and Telegram to the built-in allowed User-Agent groups — eliminates false blocks and CAPTCHA for real users opening the site via the built-in browsers of Instagram and Telegram, as well as for the schema.org markup validator

Anti Bot 1.0.1

Fixed a multi-site error: when accessing the module admin panel without an explicit site_id in the URL, the 'Countries' tab and other settings could display data for the wrong site

Added statistics filter: by date/time range, IP address, ASN, country, action, and User-Agent

Added statistics 'Top User-Agent by number of requests'

Strengthened protection of the debug log directory: protected directory, random file name, centralized message sanitization

1.2.0 (06.08.2026)

Anti Bot 1.2.0

Added JS Challenge (slide puzzle) as an alternative to strict blocking for the IP blacklist and for blocking by ASN — enabled via separate options in the module settings, independently for each site.

Upon successful completion of the JS Challenge for the IP/ASN blacklist, access is granted for 20 minutes, after which verification is requested again.

Added the "Disable JS Challenge" flag for individual entries in the IP and ASN blacklists — enforces strict blocking for a specific entry even when the JS Challenge option is enabled.

Added bulk actions in the IP and ASN blacklists: delete selected entries, enable/disable the JS Challenge restriction — selection via checkboxes on entries or via "Select All".

Added bulk deletion of entries in the IP whitelist — via checkboxes or via "Select All".

Added the "Install ASN and IP blocks from developers" setting (independent for each site) — a curated database of known spammers and bots from WBHR, automatically updated once daily.

Entries from the developer database are marked with the tag "[Black List WBHR]" and never modify or delete entries added manually by the administrator.

Added a manual button to request an update of the developer database "Update Now" with a report on the number of received and added IP and ASN entries.

Added GoogleAssociationService, Schema-Markup-Validator, Instagram, and Telegram to the built-in allowed User-Agent groups — eliminates false blocks and CAPTCHA for real users opening the site via the built-in browsers of Instagram and Telegram, as well as for the schema.org markup validator.

Anti Bot 1.0.1

Fixed a multisite error: when accessing the module admin panel without an explicit site_id in the URL, the "Countries" tab and other settings could display data for the wrong site.

Added a statistics filter: by date/time range, IP address, ASN, country, action, and User-Agent.

Added statistics "Top User-Agent by number of requests".

Enhanced catalog protection with debug logging: protected directory, random filename, centralized message sanitization

1.0.1 (11.07.2026)

Anti Bot 1.0.1

Fixed the path to the debug log in the settings description: it previously indicated /upload/wbhr_antibot/debug.log; the current path is /bitrix/tmp/wbhr_antibot/debug.log.

Fixed a multi-site error: when accessing the module admin panel without an explicit site_id in the URL, the 'Countries' tab and other settings could display data for the wrong site.

When uninstalling the module, the service option ~bsm_stop_date is now correctly removed, which previously could interfere with reinstallation via the Marketplace.

Added a statistics filter: by date/time range, IP address, ASN, country, action, and User-Agent.

Added 'Top User-Agent by number of requests' statistics.

Top blocked countries and top User-Agents are now displayed in two columns.

Statistics filtering has been accelerated thanks to new indexes in the events table; they are created automatically and are compatible with MySQL and PostgreSQL.

Strengthened protection of the debug log directory (/bitrix/tmp/wbhr_antibot/): added .htaccess to block access and an index.php stub.

The diagnostic log of the geo-database update agent is now written only when debug mode is enabled (previously it was always written, regardless of the setting).

Full request URLs, absolute server paths, and fragments of API response content have been removed from the diagnostic messages of the geo-database update agent.

The debug log filename now contains a random suffix (generated once and stored in the module options) so that the log path cannot be guessed from the outside.

HTTP status codes of geo-service responses in the log are generalized into categories (2xx/4xx/5xx) instead of exact codes.

Added automatic cleanup of rotated debug logs (.old) older than 7 days.

Log message sanitization has been moved to a single point (Logger::sanitize); now URLs and excessively long API responses are automatically truncated for all module log sources, not just where it was done manually.

Raw API response bodies and full JSON dumps of results have been removed from AsnDb and GeoApi logs; only fields significant for diagnostics remain.

Added the setting 'Mask IP addresses in debug log' (disabled by default) — when enabled, the last two octets of IPv4 are replaced with 'x.x'

The hint for the debug mode setting now explicitly warns that visitor IP addresses are logged when enabled

Added a safety cleanup of absolute file system paths from exception texts before writing to the log

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

What does the price cover?
The displayed price covers the solution itself. Platform licensing, installation and customisation are checked separately. If the page offers bundles, select the required option before submitting a request.
How do I check compatibility?
Compare the supported editions and solution version in the technical details with your project. Before installing on a live website, we recommend making a backup and checking the solution in a test environment.
Is there a trial?
The developer lists a trial of 7 days. The trial button opens the installer in your website control panel. Check the required features and compatibility before purchasing.
How much does this solution’s renewal cost?
The current renewal price is 2,000 ₽. Before you order, a manager will confirm the renewal period and whether it applies to your licence.
Can you help with implementation?
We can help install the module, check its settings and verify how it works in your project. Compatibility with other customisations and the scope of work are assessed before we begin.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot