BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Lubber – The Silent Bad Bot Blocker icon
Actively maintained Tested with WP 7.1 #8 in AI Crawlers

Lubber – The Silent Bad Bot Blocker

Silently blocks AI crawlers (GPTBot, ClaudeBot), scrapers and bad bots before WordPress loads - no error signal, and your analytics stay clean.

Active installs<10New
Downloads · 30d246• 0% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads242Since Sep 2026
Support resolved—No recent threads
RequiresWP 6.2PHP 7.4+
Downloads · 7d123▲ +78.3% week over week
Our verdict

Solid choice

Lubber is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 days ago, and scores 64/100 on our health check.

  • Actively developed — last update 3 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

102030Sep 15Sep 22Sep 30
Yesterday12
Daily average (1y)15
Peak day40Sep 27, 2026
Last 12 months246

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Lubber stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
AI Crawlers >100 776 Best AI Crawlers plugins →
block bots >100 1,688 Best block bots plugins →
bot protection >100 1,180 Best bot protection plugins →
scraper #54 217 Best scraper plugins →
security >100 10,000 Best security plugins →

About Lubber – The Silent Bad Bot Blocker

From the official readme · v1.1.1

Description

Lubber blocks AI crawlers, content scrapers and bad bots at the server level – including the ones that ignore your robots.txt – and does it silently, so the bot never learns it was blocked.

Most WordPress security plugins block bad traffic with a 403 Forbidden page. That tells the bot operator “you’ve been caught” – so they change their fingerprint and come right back, and in the meantime a 403 still costs your server a full page load.

Lubber takes a different approach, adapted from a real six-figure-request bot-traffic investigation: matching requests get a normal 200 OK response with a tiny, harmless-looking static page instead – no error, no signal for the bot to react to, and no database query or theme render for your server to pay for. Because the decoy page never loads Google Analytics, AdSense, or any tracking script, bot hits also stop polluting your traffic reports and ad impressions.

What it does

  • Maintained bot directory – a categorized, regularly-updated list of AI training crawlers, AI search/answer engines, SEO/marketing scrapers, and generic scrapers/scanners, each with a plain-English description of what it actually is. Untick anything you want to explicitly allow; new bots added in a future update are protected against automatically.
  • Named-crawler blocklist – always blocks the bots above, plus any custom names you add yourself, regardless of referrer.
  • Outdated-browser rule – optionally blocks requests claiming a Chrome version older than a threshold you set, even when the bot fakes a referrer.
  • No-referrer detection, in three independently adjustable strengths – from a narrow “missing trailing slash” pattern up to a broad “any request with no referrer” rule for sites that know their traffic is overwhelmingly search-driven.
  • Built-in protection for real crawlers – Google, Bing, and Apple’s crawlers are recognized two independent ways (by name and by their official published IP ranges) so a bot can never bypass detection just by copying a real crawler’s name.
  • Exclusions for genuine visitors – Android traffic, AI-assistant referrals (ChatGPT/Perplexity/Claude/Gemini, which often strip the referrer for real human clicks), your own IP addresses, logged-in sessions, and WP-CLI are never touched.
  • An activity log right in your dashboard – see what got blocked, by which rule, without needing server/SSH access. Includes a 14-day trend chart, a top-blocked-User-Agents and top-targeted-URLs report, and one-click CSV export.
  • A built-in self-test tool – type in a User-Agent, referrer, and URL to see which rule (if any) would catch it, against your currently saved settings, with nothing logged and no real request needed.
  • Everything is a toggle. No PHP editing required to enable, disable, or tune any rule.

Performance

The plugin hooks as early as a normal plugin can (plugins_loaded, priority 0) so a blocked request exits before the main query, before your theme, and before most other plugins run. An optional, off-by-default “Early Loading Mode” goes further, intercepting before WordPress core itself finishes loading, for sites that want the absolute lowest possible cost per blocked request.

Privacy

This plugin never sends any data anywhere, and by default it never makes any outbound network request at all. Everything – the block rules, the IP allowlist, the activity log – stays in your own database, and the bundled Google/Bing/Apple crawler IP ranges are used as-is out of the box. If you explicitly turn on “Auto-update crawler IP ranges” in the Advanced tab, the plugin makes up to three outbound requests per day – one each to Google, Bing, and Apple’s own published IP range lists – to keep those ranges current; no data about your site or its visitors is included in any of those requests. The Advanced tab also shows exactly which ranges are currently active and whether they’re the bundled defaults or a fetched copy.

External services

This plugin connects to Google, Bing, and Apple to download their official
crawler/bot IP address ranges, used to build a verified allowlist so
legitimate search engine crawlers are never blocked by mistake. This is
opt-in and off by default (“Auto-update crawler IP ranges” in the Advanced
tab); when enabled, it runs on a daily schedule.

No user or visitor data is sent to these services – each is a one-way
download of a public IP range file, not a data submission.

  • Google: fetches https://www.gstatic.com/ipranges/goog.json
    Terms: https://policies.google.com/terms – Privacy: https://policies.google.com/privacy
  • Bing: fetches https://www.bing.com/toolbox/bingbot.json
    Terms: https://www.microsoft.com/en-us/servicesagreement – Privacy: https://privacy.microsoft.com/en-us/privacystatement
  • Apple: fetches https://search.developer.apple.com/applebot.json
    Terms: https://www.apple.com/legal/internet-services/terms/site.html – Privacy: https://www.apple.com/legal/privacy/en-ww/

Installation

  1. Upload the plugin files to /wp-content/plugins/lubber, or install directly from the Plugins screen in your dashboard.
  2. Activate the plugin.
  3. Go to Settings → Lubber to review the default rules, add your own IP address to the allowlist, and turn on any additional rules you want.

Frequently asked questions

Will this block Google or Bing?

No. Real Google, Bing, and Apple crawlers are checked two independent ways before any rule can apply – by their User-Agent and by their official, published IP ranges – so a configuration mistake in one layer can’t expose the other.

How do I block AI crawlers like GPTBot and ClaudeBot?

Activate Lubber – the “Always block named bots” rule is on by default and its bot directory already includes AI training crawlers (such as GPTBot, ClaudeBot, CCBot and Bytespider) and AI search/answer crawlers (such as PerplexityBot and OAI-SearchBot). Each one can be switched off individually under Settings → Lubber → Rules, and you can add your own names to the custom list.

How is this different from blocking AI bots in robots.txt?

robots.txt is a polite request – well-behaved crawlers honor it, but a scraper can simply ignore it. Lubber matches the request itself on your server, so it works on bots that never read robots.txt, and it answers with a harmless-looking page instead of an error so the bot gets no signal to change its name and come back.

Will blocking AI crawlers hurt my Google or Bing rankings?

No. Googlebot, Bingbot and Applebot (Apple’s search crawler) are never blocked – they’re recognized by both their User-Agent and their official published IP ranges. Be aware that AI search and answer crawlers (for example ChatGPT-User, OAI-SearchBot and PerplexityBot) fetch pages so AI assistants can cite them; if you want those citations, untick them in the bot directory and only block the AI training crawlers.

Will this block real visitors who don’t send a referrer?

The two rules enabled by default (named-crawler blocklist and missing-trailing-slash detection) are deliberately narrow and low-risk. The broader “any no-referrer request” rule is off by default and clearly labeled as aggressive – only enable it once you’ve confirmed most of your real traffic arrives via search engines or another referrer.

Does this replace a full security plugin?

No. This plugin does one thing – detect and quietly decoy bot/scraper traffic before it costs you server resources or pollutes your analytics. It is not a firewall, malware scanner, or login-hardening tool.

Where is blocked traffic logged?

In a dedicated database table, viewable under Settings → Lubber → Activity Log. Nothing is written to server log files, and old entries are pruned automatically based on your configured retention period.

Changelog

Removes two bot-directory entries that could never match a request (robots.txt-only tokens). No settings are changed or lost.

1.1.1

  • Fix: Removed “Google-Extended” and “Applebot-Extended” from the bot directory. They are robots.txt control tokens, not User-Agents – Google and Apple crawl with their normal Googlebot/Applebot User-Agents – so a User-Agent match on them could never fire, and listing them wrongly implied Lubber stops Google/Apple AI training. Real Googlebot and Applebot remain protected.
  • Improved: Plugin listing now leads with what Lubber does for AI crawlers (GPTBot, ClaudeBot and others), with new FAQs on blocking AI crawlers, how this differs from robots.txt, and whether it affects search rankings.

1.1.0

  • New: Maintained, categorized bot directory (AI training, AI search/answer, SEO/marketing, generic scrapers) with per-bot toggles, merged automatically with your own custom named-crawler list.
  • New: Activity Log 14-day trend chart, top-blocked-User-Agents and top-targeted-URLs reports, and one-click CSV export.
  • New: Self-test tool on the Rules tab – check which rule would catch a given User-Agent/referrer/URL without a real request.
  • New: “Exclude iPhone” shared exclusion, alongside the existing “Exclude Android” one.
  • Changed: Rules tab redesigned for clarity – real toggle switches, one-line rules, and the bot directory/worked examples tucked behind expandable details instead of one long page.
  • Fix: The default named-crawler list previously included a plain “applebot” entry, which (since this module runs before any verified-crawler exemption, by design) could match real Apple Search’s own crawler UA too, contradicting this plugin’s own claim that Apple’s real crawler is never blocked. Replaced with “applebot-extended” (Apple’s separate AI-training crawler) in the new bot directory; any site that already has the old entry stored has it removed automatically.

1.0.1

  • Fix: Next/Previous page and column-sort links on the Activity Log tab no longer jump to the Rules tab.

1.0.0

  • Initial release.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Lubber alternatives

All AI Crawlers plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Better Robots.txt – AI-Ready Crawl Control & Bot Governance Better Robots.txt – AI-Ready Crawl Control & Bot Governance Replace the default WordPress robots.txt workflow with a smarter, structured version you… by Pagup 5K+ ★★★★★★★★★★ 4.5 (102) 2 weeks ago 87
2 Prime SEO – AI SEO, LLMs.txt Generator, AI Bots Manager & AI Crawler Stats Prime SEO AI SEO plugin: llms.txt generator, AI bots manager (GPTBot, ClaudeBot, PerplexityBot), AI… by primeseo 100+ ★★★★★★★★★★ 5 (2) 1 week ago 64
3 SEO & AI Readiness Check SEO & AI Readiness Check See what search engines and AI crawlers find on your site: titles, meta, H1, schema… by meinseocoach 30+ ★★★★★★★★★★ No reviews 1 week ago 67
4 Blaze AI Discovery for WooCommerce Blaze AI Discovery for WooCommerce AI visibility for WooCommerce: check AI crawler access, score products for ChatGPT, build a… by blazecommerce 30+ ★★★★★★★★★★ No reviews 1 month ago 63
5 AJ Agent Crawl Optimizer – AI Readiness Scanner & llms.txt for WordPress AJ Agent Crawl Optimizer llms.txt + AI-readiness scanner for WordPress: get found by ChatGPT & Claude, manage AI… by Ajay Maurya 20+ ★★★★★★★★★★ 5 (3) 3 months ago 65
6 AI Crawlers Visibility, Analytics & Control AI Crawlers Visibility, Analytics & Control Monitor AI crawlers and MCP traffic, inventory agents and tools, control access, and… by miniOrange 10+ ★★★★★★★★★★ 5 (1) 2 weeks ago 68
7 GetCited — AI Visibility GetCited — AI Visibility Optimize for AI search. The AI visibility plugin — manage crawlers, generate llms.txt… by heytc 10+ ★★★★★★★★★★ No reviews 8 months ago 38
8 SurfacedBy AI Visibility – AI Traffic, Crawler Analytics & llms.txt SurfacedBy AI Visibility See which AI crawlers read your site, which AI assistants send shoppers, and which visits… by SurfacedBy <10 ★★★★★★★★★★ No reviews 2 days ago 64
9 PSB Bot Traffic Controller PSB Bot Traffic Controller Block, limit, or allow AI crawlers, search bots, and scrapers by category — with rate… by paulborile <10 ★★★★★★★★★★ No reviews 1 month ago 60
10 Visora — AI Visibility Visora — AI Visibility Get your site found and cited by AI answer engines — simply. Control which AI assistants… by timbalabuch <10 ★★★★★★★★★★ No reviews 2 months ago 55

FAQ

Lubber – The Silent Bad Bot Blocker: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is Lubber free?

Yes. Lubber is free to download and use from the official WordPress.org plugin directory.

Is Lubber safe to use in 2026?

Lubber is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 days ago, and scores 64/100 on our health check.

How many websites use Lubber?

Lubber is active on <10 WordPress websites and has been downloaded 242 times since it launched in September 2026. It was downloaded 246 times in the last 30 days.

Does Lubber work with WordPress 7.1?

Yes. The developer has tested Lubber up to WordPress 7.1.2, the latest release. It requires WordPress 6.2 or newer.

What PHP version does Lubber need?

Lubber requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Lubber last updated?

The latest version, 1.1.1, was released on September 28, 2026 (3 days ago).

Who makes Lubber?

Lubber is developed and maintained by techpot.

What are the best alternatives to Lubber?

The most popular alternatives to Lubber are Better Robots.txt (5K+ installs), Prime SEO (100+ installs) and SEO & AI Readiness Check (30+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.