BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Royal AI Firewall icon
Actively maintained Tested with WP 7.1

Royal AI Firewall

See every AI agent on your site. Decide who gets your content — block, allow, or log-only for GPTBot, ClaudeBot, PerplexityBot, and 60+ others.

Active installs20+10+ tier
Downloads · 30d384▲ +56.1% vs prev. 30d
Rating—0 reviews
Health score67/100Good
All-time downloads1KSince Jul 2026
Support resolved—No recent threads
RequiresWP 6.4PHP 8.0+
Downloads · 7d186▲ 3.9× week over week
Our verdict

Solid choice

Royal AI Firewall is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites and was last updated 8 hours ago, and scores 67/100 on our health check.

  • Actively developed — last update 8 hours ago
  • Tested with the latest WordPress (7.1)
  • Small user base (20+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

163350Jul 2Aug 15Sep 29
Yesterday21
Daily average (1y)11
Peak day67Sep 28, 2026
Last 12 months990

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Royal AI Firewall stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
AI >100 6,528 Best AI plugins →
bot >100 3,053 Best bot plugins →
firewall #85 954 Best firewall plugins →
mcp >100 521 Best mcp plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.0100.0%

About Royal AI Firewall

From the official readme · v1.0.11

Description

Every AI company is scraping WordPress sites to train models, feed AI search engines, and answer questions using your content — usually without your knowledge and rarely with a link back. Royal AI Firewall gives you agency at the WordPress layer: see every AI agent hitting your site, and decide who gets through with one-click per-bot policies.

Whether you want to allow AI search engines but block training crawlers, log everything for a month before deciding anything, or block every AI bot with one click — this plugin gives you the visibility and enforcement to make that choice.

This plugin gives you:

  • A live dashboard of which AI agents have visited your site in the last 24 hours
  • A per-bot dropdown to allow, block, or log-only any of 60+ recognized AI bots
  • A master “Block all AI bots” panic button on every dashboard load
  • A first-run setup wizard that detects your CDN (Cloudflare, Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, or Akamai) and, when it finds Cloudflare, tells you exactly which CF settings to dial down so this plugin can take over the AI-bot layer
  • Compatibility detection for GuardPress and other popular security plugins
  • A bundled bot fingerprint catalog that refreshes on every plugin update, with an optional opt-in to fetch fresher catalogs daily from fingerprints.royalplugins.com (see External Services below)

Free, Self-Hosted, Fully Featured

Royal AI Firewall is fully featured in its free, GPL-licensed release. There is no Pro version — every feature ships in the wp.org plugin, and updates go through the standard WordPress plugin updater.

Your data stays on your server. The plugin never sends your site’s traffic, customer data, IP addresses, or credentials to any third party. See the External Services section below for the full list of endpoints the plugin can contact, when, and how to disable each one.

AI Bots Recognized (69 as of v1.0.6)

The bundled catalog covers the major AI bot families. Each entry includes the bot’s owner, intended purpose, default policy, and the blocking consequences (for example, “blocking GPTBot may remove your site from ChatGPT search results”).

Training crawlers: GPTBot, ClaudeBot, anthropic-ai, Bytespider, TikTokSpider, FacebookBot, Meta-ExternalAgent, GoogleOther, GoogleOther-AI, Google-Extended, Google-CloudVertexBot, MistralBot, KimiBot, cohere-ai, cohere-training-data-crawler, ai2bot, ai2bot-dolma, Amazonbot, PetalBot

Retrieval bots (on-demand): ChatGPT-User, OAI-AdsBot, ClaudeBot-User, Claude-Web, claude-code, Perplexity-User, Kimi-User, YandexAdditionalBot, Meta-ExternalFetcher, facebookexternalhit, APIs-Google

AI search engines: OAI-SearchBot, PerplexityBot, Claude-SearchBot, Kimi-SearchBot, MistralAI-Index, YandexAdditional, meta-webindexer, Applebot-Extended, MicrosoftCopilotBot, DuckAssistBot, YouBot, PhindBot, iAsk, Komo, Liner, Brave Leo, Andi

Search engines (always-allow guarded): Googlebot, Googlebot-Image, Googlebot-Video, Googlebot-News, Google-InspectionTool, Bingbot, BingPreview, Applebot, DuckDuckBot

Other search engines: Baiduspider

Agent browsers (newer category): OperatorAgent, ChatGPT-Atlas, Claude-Computer-Use

Dataset scrapers: CCBot (Common Crawl), Diffbot, ImagesiftBot, Omgilibot, Timpibot

Other Google crawlers: Storebot-Google, Mediapartners-Google, AdsBot-Google, adidxbot

The Dashboard

Open the AI Firewall menu in your WordPress admin to see:

  • A hero metric — total AI bot hits in the last 24 hours and the number of distinct bots involved
  • A per-bot list with hit count, bandwidth used, and a one-click policy dropdown for each row
  • An MCP / Abilities API activity widget when an MCP server plugin (Royal MCP or any plugin implementing the WordPress Abilities API) is detected on your site
  • A Cloudflare visibility status card with an honest estimate of how many AI bots may have been filtered by Cloudflare at the edge before reaching WordPress
  • Click any bot row to expand a drill-down view: top URLs the bot hit, recent activity, and what blocking the bot would cost you

Per-Bot Policy Controls

Each recognized bot row has a dropdown with four options:

  • Use default policy — falls back to your global mode (Log only, Block training, or Block all)
  • Always allow — bot is allowed regardless of default mode
  • Log only — bot is allowed and recorded; never blocked
  • Block — bot receives a 403 response immediately, before WordPress runs any heavy work

Major search engines (Googlebot, Bingbot, Applebot, DuckDuckBot) are protected from accidental blocking. The per-bot dropdown is disabled for these bots, and the API rejects block requests for them unless you explicitly enable the “Search engine override” toggle in Settings — with a clear warning that blocking Googlebot removes your site from Google Search.

Cloudflare Compatibility

If your site is behind Cloudflare, the setup wizard’s Cloudflare screen tells you exactly which CF settings to turn off so this plugin can take over the AI-bot layer:

  • AI Audit → set to “Allow”
  • AI Labyrinth → OFF
  • Custom WAF rules blocking AI bots → DELETE (the per-bot controls in this plugin replace them)
  • Security Level → Medium or Low

And which CF settings to leave on (they don’t conflict):

  • DDoS protection
  • Managed WAF rules
  • SSL/TLS
  • Bot Fight Mode (basic tier)
  • Browser Integrity Check
  • Caching

The dashboard also detects Cloudflare on every admin page load (looking for cf-ray, cf-connecting-ip, or CDN-Loop: cloudflare headers) and shows a status card with the detection state. A persistent 24-hour state ensures the UI stays stable even when an occasional admin request doesn’t pass through CF.

Other CDN Compatibility

The setup wizard also recognizes 6 additional CDNs by their vendor-forwarded request headers: Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. Detection is header-sniff only — no outbound HTTP, no DNS lookups.

When any of these are detected, the wizard shows a compatibility note rather than a network-specific dial-down (Cloudflare remains the only CDN with a full walkthrough because its AI controls are the most common source of operator confusion). Royal AI Firewall sees AI bot traffic that reaches WordPress regardless of which CDN sits in front — if you have edge-side AI-bot rules configured on your CDN, consult its documentation, as the two layers can coexist.

Other Security Plugin Compatibility

The plugin auto-detects these plugins when they’re active and shows compatibility notes on the dashboard and Settings page:

  • Edge-firewall security plugins — their firewalls run before WordPress loads. AI bots they block at their layer won’t appear in this plugin’s dashboard, but the two layers don’t conflict.
  • WordPress-layer security plugins — coexist cleanly at the WordPress layer.
  • GuardPress (Royal Plugins) — first-party Royal Plugins integration.
  • Royal MCP (Royal Plugins) — when Royal MCP is detected, MCP tool invocations from connected AI agents appear in the MCP Activity widget on the dashboard.

WordPress Abilities API & MCP Server Integration

This plugin listens for the WordPress Abilities API hooks wp_before_execute_ability and wp_after_execute_ability (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If you have any MCP server plugin installed and an AI agent calls an ability, you’ll see it in the MCP Activity widget on the dashboard.

If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call from that server with full tool name and result status.

Search Engine Guard

Major search engines are protected from accidental blocking by default. The dashboard dropdown is disabled for Googlebot, Bingbot, Applebot, and DuckDuckBot. The REST API endpoints reject block attempts on these bots with a 409 Conflict response unless the customer has explicitly enabled the “Search engine override” toggle in Settings. The override toggle includes a clear warning that blocking Googlebot removes the site from Google Search.

Telemetry and Data

Anonymous usage data is OFF by default. The plugin makes no outbound HTTP call for telemetry unless you explicitly opt in — via the setup wizard’s final step or the “Anonymous usage data” toggle in Settings.

If you opt in, once per week the plugin POSTs a small JSON payload to telemetry.royalplugins.com. The payload contains:

  • Plugin version
  • WordPress version
  • PHP version
  • An opaque one-way hash of your site URL — used only to count unique installs. The URL itself cannot be recovered from the hash (SHA-256 with a per-install random salt that never leaves your site).
  • Whether you have completed the setup wizard
  • How many per-bot policy overrides you have configured
  • A bucketed range for AI bot hits in the last 24 hours (e.g. “11–50”)

The following are NEVER sent, regardless of toggle state:

  • Your site URL or domain (only its salted hash)
  • Customer email addresses
  • Invocation log contents
  • Specific IP addresses
  • Specific bot identities
  • User-Agent strings of visitors

Data retention: raw payloads are retained for 90 days. Aggregated statistics are retained indefinitely. Per-site fingerprints are purged after 12 months of no reports. You can revoke consent at any time in Settings — the plugin unschedules the weekly cron immediately.

The other outbound HTTP call the plugin can make (also opt-in) is a single daily GET request to fingerprints.royalplugins.com for a fresher bot catalog when you enable “Keep catalog updated between releases.” That request body is empty and includes only the plugin version in the User-Agent header. See the “External Services” section below.

Log retention defaults to 7 days. The retention window is filterable via raif_log_retention_days for developers who need a different value.

How Activation Works

On activation the plugin:

  • Creates five custom database tables: raif_invocation_log, raif_daily_rollup, raif_bot_policy, raif_bot_access_baseline, raif_page_type_daily
  • Seeds safe default options (Log only mode; telemetry off; uninstall data-delete off; live catalog updates off)
  • Schedules WP-Cron events for hourly rollup and daily log prune, both running entirely inside your WordPress install with no network calls
  • Loads the bundled bot fingerprint catalog from the plugin zip
  • Redirects the activating admin to the 4-step setup wizard
  • The wizard is skippable from any step

No outbound HTTP calls are made until the customer explicitly opts in to live catalog updates on the wizard’s final screen or via Settings → Bot fingerprint database. The plugin is fully functional without ever making a network call — the bundled catalog refreshes from the plugin zip on every plugin update.

On deactivation the plugin unschedules all WP-Cron events. Data is preserved by default so a re-activation continues where you left off. To remove all data on uninstall, check the “Delete all logs, tables, and options when the plugin is uninstalled” toggle in Settings → Data before deactivating.

External Services

The plugin can contact five categories of endpoint. Two are opt-in and off by default. Three run automatically to support features the plugin advertises (bot signature verification, bot-access alerting, and Content Signals). Every endpoint is disable-able. No customer data, IP address, credentials, or site traffic is ever transmitted to any third party.

You can globally block every outbound request by setting define( 'WP_HTTP_BLOCK_EXTERNAL', true ); in wp-config.php. The plugin degrades cleanly when blocked.

1. Royal AI Firewall Fingerprint Catalog (opt-in, off by default)

  • Endpoint: https://fingerprints.royalplugins.com/v1/index.json
  • When it runs: Only when the customer enables the “Keep catalog updated between releases” toggle. Off by default.
  • Frequency: Once per day via WordPress cron (raif_fingerprint_update).
  • Data sent: None. Request body is empty. User-Agent header carries the plugin version (e.g. royal-ai-firewall/X.Y.Z), plus a standard If-None-Match cache validator. No site URL, no IP address, no customer data.
  • Data received: A JSON catalog of recognized AI bot fingerprints, approximately 55 KB.
  • How to disable: Untick the toggle in Settings → Bot fingerprint database, or filter raif_fingerprint_endpoint to an empty string.
  • Privacy Policy: royalplugins.com/privacy/
  • Terms of Service: royalplugins.com/terms/

2. Anonymous Usage Telemetry (opt-in, off by default)

  • Endpoint: https://telemetry.royalplugins.com/v1/raif/report
  • When it runs: Only when the customer enables the telemetry toggle in Settings → Data.
  • Frequency: Once per week via WordPress cron (raif_telemetry_report).
  • Data sent: Plugin version, WordPress version, PHP version, a locally-salted install fingerprint hash (not derivable back to a URL), coarse-bucketed feature-usage counters. No site URL, no IP address, no bot hit content, no customer data.
  • How to disable: Untick the telemetry toggle in Settings → Data.
  • Privacy Policy: royalplugins.com/privacy/

3. Web Bot Auth Key Directories (runs automatically)

  • Endpoints:
    • https://openai.com/.well-known/http-message-signatures-directory (OpenAI)
    • https://www.anthropic.com/.well-known/http-message-signatures-directory (Anthropic)
    • https://www.perplexity.ai/.well-known/http-message-signatures-directory (Perplexity)
    • https://developers.google.com/.well-known/http-message-signatures-directory (Google)
    • https://www.facebook.com/.well-known/http-message-signatures-directory (Meta)
  • When it runs: Weekly via WordPress cron (raif_web_bot_auth_refresh), scheduled at activation.
  • Data sent: None. Request body is empty. Default WordPress wp_remote_get User-Agent. No site URL, no customer data.
  • Data received: Public JWK signing keys the operators publish so RAIF can verify cryptographically-signed bot requests (RFC 9421 Web Bot Auth). Keys are cached locally.
  • Purpose: Enables the “trust verified operator” policy tier so bots that sign their requests with published keys can be distinguished from user-agent spoofers.
  • How to disable: Filter raif_web_bot_auth_directories to an empty array, or block outbound HTTP globally with WP_HTTP_BLOCK_EXTERNAL.

4. Bot Access Self-Probe (runs automatically)

  • Endpoint: Your own site’s home URL (home_url()).
  • When it runs: Twice daily via WordPress cron (raif_bot_access_check), scheduled at activation.
  • Data sent: Two GET requests. One with a browser User-Agent, one with a Googlebot User-Agent. No body, no site data beyond the requests themselves.
  • Data received: HTTP status code and a truncated response body used to detect whether upstream CDNs/hosts are silently blocking real search-engine bots.
  • Purpose: Powers the “Bot Access” alerting that warns when your site becomes unreachable to major search bots. Zero external calls; the probe loops back to your own origin.
  • How to disable: Untick “Enable bot access monitoring” in Settings, or filter raif_bot_access_probe_enabled to false.

5. Content Signals robots.txt read (runs automatically)

  • Endpoint: Your own site’s /robots.txt (via home_url( '/robots.txt' )).
  • When it runs: At most once every six hours during a live bot request that requires signal evaluation. Loops back to your own origin.
  • Data sent: One GET request. No body, no site data.
  • Data received: Your robots.txt content, parsed for Content Signals declarations (ai_train, ai_input, search).
  • Purpose: Lets the classifier know which AI purposes you’ve opted out of so it can flag violators.
  • How to disable: Delete the Content Signals lines from your robots.txt, or filter raif_content_signals_source to return an empty array.

DNS lookups. For search-engine bots that publish a verification method (Googlebot, Bingbot, Applebot, DuckDuckBot, YandexBot), the plugin performs reverse-DNS and forward-confirm lookups against the bot’s IP. These are DNS queries, not HTTP requests; they hit whatever resolver your PHP install is configured to use. Cached for 24 hours per IP.

Dashboard rendering, bot classification, policy decisions, and logging all run entirely inside your WordPress install. The endpoints above are the complete list; no license check, license activation, or analytics beacon is ever contacted.

Installation

  1. In your WordPress dashboard, go to Plugins → Add New and search for Royal AI Firewall.
  2. Click Install Now, then Activate.
  3. The 4-step setup wizard runs automatically on first activation. Walk through it to detect Cloudflare and pick a default policy. The wizard is skippable.
  4. Open AI Firewall in the admin menu to see the dashboard.
  5. Wait 2–6 hours for the first AI bot hits to appear, or run a manual test with curl:

    curl -A “GPTBot/1.2” https://your-site.com/

Frequently asked questions

Do I still need Cloudflare?

Yes, if you use Cloudflare for DDoS protection, general WAF rules, SSL/TLS, or caching. Keep Cloudflare’s core protections on. This plugin handles only the AI-bot-specific layer at WordPress, so you can dial down Cloudflare’s AI Audit / AI Labyrinth / custom AI-blocking WAF rules. The setup wizard’s Cloudflare screen lists exactly which CF toggles to flip.

Will this block Googlebot?

No. Googlebot, Bingbot, Applebot, and DuckDuckBot are protected from accidental blocking. The per-bot dropdown is disabled for these bots by default. To block any of them, you must explicitly enable the “Search engine override” toggle in Settings, which warns clearly that blocking Googlebot removes your site from Google Search.

Does this work with other security plugins?

Yes. Edge-firewall security plugins run their own firewalls before WordPress loads, so AI bots they block won’t appear in this plugin’s dashboard — but the two layers don’t conflict. The plugin auto-detects popular security plugins on activation and shows compatibility notes.

Does this work with Royal MCP and other MCP server plugins?

Yes. The plugin hooks into the WordPress Abilities API (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call with full detail.

What happens to my data if I uninstall?

By default, data is preserved. The plugin’s tables and logs survive uninstall so a reinstall picks up where you left off. To delete everything on uninstall, check the “Delete all logs, tables, and options when the plugin is uninstalled” toggle in Settings → Data before deactivating.

My dashboard shows zero hits even though AI bots are visiting my site. What’s wrong?

Almost always a caching plugin caching the REST API response. The plugin already does four things to prevent this — a cache-buster query string on every dashboard request, nocache_headers() + DONOTCACHEPAGE constant on the handler, explicit Cache-Control: no-store response headers, and built-in compatibility filters that opt out of caching for the most common cache plugins. If you use a different cache plugin or a server-side cache (nginx fastcgi_cache, Cloudflare Page Rules, Varnish), exclude the path /wp-json/royal-ai-firewall/* from REST API caching in that plugin’s settings.

How often is the bot catalog updated?

A fresh bot catalog ships with every Royal AI Firewall release, so every time you update the plugin through your wp-admin → Plugins screen you get the newest catalog automatically — no outbound network call required. Plugin updates typically ship every 2–4 weeks, faster after major AI-vendor launches. If you want catalogs fresher than the per-release cadence, an optional Settings toggle (“Keep catalog updated between releases”) opts in to one HTTP GET per day to fingerprints.royalplugins.com. That toggle is off by default; no outbound HTTP call is ever made until you turn it on.

Does the plugin phone home or make outbound network calls?

No, not by default. Out of the box the plugin makes zero outbound HTTP calls. The bot catalog ships bundled with the plugin and refreshes on every plugin update. If you explicitly enable the “Keep catalog updated between releases” toggle in Settings or on the final wizard step, the plugin will then make one HTTP GET per day to fetch a fresher catalog — but only after that opt-in, and only that one call. Turning the toggle back off immediately unschedules the cron. No telemetry, license checks, or analytics calls are ever made regardless of toggle state.

Is there a Pro version?

No. Every feature ships in the free release on WordPress.org. No upgrade prompts, no license keys, no SaaS subscription.

What if I’m behind a different CDN?

The setup wizard also recognizes Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. The classifier and per-bot controls work at the WordPress layer regardless of which CDN sits in front. Cloudflare gets a full dial-down walkthrough because its AI controls are the most common source of operator confusion; other CDNs get a compatibility note instead.

Does the plugin slow down my site?

The hot-path classification logic has a hard budget of under 5 milliseconds per request and is enforced by a continuous-integration test. The classifier runs in-process against a 68-entry pre-compiled pattern list. Logging is buffered and flushed on the WordPress shutdown hook (after the response is sent), so the response latency a visitor sees is not affected by database writes.

How is bot identity verified — can a bad actor just pretend to be Googlebot?

This release identifies bots by matching the User-Agent header against the bundled fingerprint catalog. A spoofed User-Agent will match a real bot’s record, so treat the dashboard as the answer to “what’s claiming to be each bot” rather than a verified attribution. For the search-engine guard, blocking is still off by default — a spoofed Googlebot UA can’t be blocked unless you explicitly enable the Search engine override toggle, and managing the actual edge layer (Cloudflare, your CDN, or a security plugin running before WordPress) remains the right place to enforce identity at the network…

Changelog

Adds AI traffic by page type, a bot × page-type heatmap, and blind-spot detection to the dashboard.

1.0.11

  • New: Dashboard tile shows AI bot traffic grouped by page type over the last 7 days.
  • New: Bot × page-type matrix heatmap on the dashboard.
  • New: Blind-spot detection flags page types under-served by AI crawlers.
  • Fix: Bot access alert emails now render as HTML in all mail clients.
  • Fix: Dashboard sibling-plugin cards correctly recognize Pro editions.
  • Fix: Request classification now applies to every request path.
  • Fix: Dashboard “Allowed” count now reflects log-only traffic in default mode.
  • Fix: Self-test on the WP dashboard widget now correctly identifies its own probe.
  • Fix: Uninstall and “Erase all logs” now clear every custom table.
  • Fix: Client IP extraction from Cloudflare headers now requires the direct peer to be a Cloudflare edge.
  • Fix: Major search engine guard now defers when the reverse-DNS verifier says the request is spoofed.
  • Fix: External Services section in the readme now describes every endpoint the plugin can contact.

1.0.9

  • Enhancement: Bot access alert emails now render as HTML with a clearer summary of what triggered the alert.
  • Enhancement: Destructive uninstall (opt-in) now removes every plugin option and transient.

1.0.8

  • New: Royal AI Firewall now flags AI bots that ignore your declared Content Signals and can optionally auto-block repeat violators.
  • New: Content Signals dashboard widget shows your declared preferences and violation counts over the past 7 days.
  • New: Invocation history has a dedicated Violations tab for reviewing every bot that crossed your declared signals.
  • New: Web Bot Auth signature verification recognizes cryptographically signed requests from OpenAI, Anthropic, Perplexity, Google, and Meta.
  • New: Per-operator policy toggles let you trust verified requests or block requests that impersonate an operator without a valid signature.
  • New: The plugin now publishes an auth.txt file at your site root so AI operators know which identification methods you accept.
  • Enhancement: Bot catalog updated with Doubaobot, Perplexity-Comet, and DeepSeekBot.
  • Enhancement: Every bot entry now carries an AI purpose classification used for Content Signals matching.

1.0.7

  • Feature: AI Traffic Overview dashboard widget in wp-admin — see AI bot traffic at a glance.
  • Feature: Activity Log admin page with paginated invocation history.
  • Feature: “Try a bot check” self-test button verifies the firewall is watching right after install.
  • Enhancement: Invocation log indexed on source and policy_action for faster widget queries at scale.
  • Enhancement: Cross-plugin composition — dashboard widget surfaces Royal MCP, GuardPress, ForgeCache, and SiteVault integration status.
  • Enhancement: Tested up to WordPress 7.1.

1.0.6

  • Enhancement: Bot Access page now includes a reverse-DNS self-test and per-bot verification breakdown.
  • Enhancement: Bot Access reverse-DNS self-test is now cached for 60 seconds so admin renders stay fast.
  • Enhancement: Google Search Console URL Inspection tool is now recognized and verified as a legitimate Google crawler.
  • Fix: Baseline collection counter now reads Day 1 on install day instead of Day 2.
  • Fix: Passive bot-access detector no longer flags low-volume search engines as collapsed on natural crawl gaps.
  • Fix: Combined bot-access alert now requires two or more watched bots to go silent at once before escalating to high-confidence.

1.0.5

  • Feature: Bot Access page shows verified Googlebot, Bingbot, Applebot, and DuckDuckBot hits against a rolling 30-day baseline and alerts if verified hits collapse.
  • Feature: Reverse-DNS bot verification distinguishes real search-engine bots from spoofed User-Agents on every log row.
  • Feature: Dual-request active probe fires every 12 hours to catch upstream WAF or CDN rules that block bots before rankings drop.
  • Feature: Royal Tools submenu lists free companion plugins with one-click install links.
  • Enhancement: Custom top header bar on every Royal AI Firewall admin page with View Docs and Support buttons.
  • Enhancement: Lightweight admin footer showing family links and current plugin version.
  • Enhancement: Dashboard now records real response body size in bytes for every AI bot hit.
  • Fix: Dashboard stat cards no longer render doubled percent signs.

Full changelog on WordPress.org →

Screenshots

Dashboard — hero metric of AI bot hits in the last 24 hours, per-bot list with dropdown controls, MCP Activity widget when applicable, and Cloudflare visibility status when Cloudflare is detected.
Dashboard — hero metric of AI bot hits in the last 24 hours, per-bot list with dropdown…
Setup wizard, welcome step — one-screen summary of what the plugin does before the walkthrough starts.
Setup wizard, welcome step — one-screen summary of what the plugin does before the…
Setup wizard, environment detection — the wizard reports which security plugins and MCP servers it found on the site and how it will coexist with each.
Setup wizard, environment detection — the wizard reports which security plugins and MCP…
Setup wizard, Cloudflare screen — step-by-step list of which Cloudflare settings to turn off so this plugin can take over the AI-bot layer.
Setup wizard, Cloudflare screen — step-by-step list of which Cloudflare settings to turn…
Setup wizard, default policy — pick the global stance (Log only, Block training crawlers, or Block all) with a plain-language description of what each mode does.
Setup wizard, default policy — pick the global stance (Log only, Block training crawlers…
Settings page — default policy, search engine override, Cloudflare detection diagnostic, security plugin compatibility, bot fingerprint database status, log retention, telemetry opt-in.
Settings page — default policy, search engine override, Cloudflare detection diagnostic…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Royal AI Firewall alternatives

All AI plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Elementor Website Builder – more than just a page builder Elementor Website Builder – more than just a page builder The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel… by Elementor 10M+ ★★★★★★★★★★ 4.5 (7.3K) 7 hours ago 92
2 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) All in One SEO AIOSEO is the WordPress SEO plugin. Boost SEO rankings with AI SEO tools, schema, meta… by Syed Balkhi 2M+ ★★★★★★★★★★ 4.7 (5.2K) 7 days ago 98
3 AI Agent by SiteGround AI Agent by SiteGround Manage your WordPress site with AI - create content, install plugins, and perform site… by SiteGround 1M+ ★★★★★★★★★★ 1.6 (97) 9 hours ago 66
4 Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates Premium Addons for Elementor 90+ Elementor widgets & addons, 600+ templates, Mega Menu, WooCommerce, Display Conditions… by Leap13 600K+ ★★★★★★★★★★ 4.9 (1.7K) 2 days ago 96
5 Angie – Agentic AI Angie – Agentic AI Build anything your site needs. Manage it through an agentic AI conversation inside… by Elementor 100K+ ★★★★★★★★★★ 3.1 (18) 1 week ago 73
6 AI Engine – The Chatbot, AI Framework & MCP for WordPress AI Engine – The Chatbot, AI Framework & MCP for WordPress AI meets WordPress. Your site can now chat, write poetry, solve problems, and maybe make… by Jordy Meow 90K+ ★★★★★★★★★★ 4.9 (867) 5 days ago 96
7 AI Provider for Anthropic AI Provider for Anthropic Anthropic (Claude) provider for the PHP AI Client SDK. by WordPress.org 60K+ ★★★★★★★★★★ No reviews 1 month ago 59
8 AI AI AI features, experiments and capabilities for WordPress. by WordPress.org 50K+ ★★★★★★★★★★ 4.6 (9) 1 month ago 82
9 AI Provider for OpenAI AI Provider for OpenAI AI Provider for OpenAI for the PHP AI Client SDK. by WordPress.org 50K+ ★★★★★★★★★★ No reviews 1 week ago 63
10 AI Provider for Google AI Provider for Google Google AI (Gemini) provider for the PHP AI Client SDK. by WordPress.org 40K+ ★★★★★★★★★★ No reviews 1 week ago 78

FAQ

Royal AI Firewall: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 30, 2026

Is Royal AI Firewall free?

Yes. Royal AI Firewall is free to download and use from the official WordPress.org plugin directory.

Is Royal AI Firewall safe to use in 2026?

Royal AI Firewall is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites and was last updated 8 hours ago, and scores 67/100 on our health check.

How many websites use Royal AI Firewall?

Royal AI Firewall is active on 20+ WordPress websites and has been downloaded 1,033 times since it launched in July 2026. It was downloaded 384 times in the last 30 days.

Does Royal AI Firewall work with WordPress 7.1?

Yes. The developer has tested Royal AI Firewall up to WordPress 7.1.2, the latest release. It requires WordPress 6.4 or newer.

What PHP version does Royal AI Firewall need?

Royal AI Firewall requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Royal AI Firewall last updated?

The latest version, 1.0.11, was released on September 30, 2026 (8 hours ago).

Who makes Royal AI Firewall?

Royal AI Firewall is developed and maintained by Royal Plugins.

What are the best alternatives to Royal AI Firewall?

The most popular alternatives to Royal AI Firewall are Elementor Website Builder (10M+ installs), All in One SEO (2M+ installs) and AI Agent by SiteGround (1M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.