Royal AI Firewall
See every AI agent on your site. Decide who gets your content — block, allow, or log-only for GPTBot, ClaudeBot, PerplexityBot, and 60+ others.
Solid choice
Royal AI Firewall is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites and was last updated 8 hours ago, and scores 67/100 on our health check.
- Actively developed — last update 8 hours ago
- Tested with the latest WordPress (7.1)
- Small user base (20+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Royal AI Firewall stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| AI | >100 |
| bot | >100 |
| firewall | #85 |
| mcp | >100 |
| security | >100 |
Version adoption
Share of active sites per release.
About Royal AI Firewall
From the official readme · v1.0.11Description
Every AI company is scraping WordPress sites to train models, feed AI search engines, and answer questions using your content — usually without your knowledge and rarely with a link back. Royal AI Firewall gives you agency at the WordPress layer: see every AI agent hitting your site, and decide who gets through with one-click per-bot policies.
Whether you want to allow AI search engines but block training crawlers, log everything for a month before deciding anything, or block every AI bot with one click — this plugin gives you the visibility and enforcement to make that choice.
This plugin gives you:
- A live dashboard of which AI agents have visited your site in the last 24 hours
- A per-bot dropdown to allow, block, or log-only any of 60+ recognized AI bots
- A master “Block all AI bots” panic button on every dashboard load
- A first-run setup wizard that detects your CDN (Cloudflare, Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, or Akamai) and, when it finds Cloudflare, tells you exactly which CF settings to dial down so this plugin can take over the AI-bot layer
- Compatibility detection for GuardPress and other popular security plugins
- A bundled bot fingerprint catalog that refreshes on every plugin update, with an optional opt-in to fetch fresher catalogs daily from fingerprints.royalplugins.com (see External Services below)
Free, Self-Hosted, Fully Featured
Royal AI Firewall is fully featured in its free, GPL-licensed release. There is no Pro version — every feature ships in the wp.org plugin, and updates go through the standard WordPress plugin updater.
Your data stays on your server. The plugin never sends your site’s traffic, customer data, IP addresses, or credentials to any third party. See the External Services section below for the full list of endpoints the plugin can contact, when, and how to disable each one.
AI Bots Recognized (69 as of v1.0.6)
The bundled catalog covers the major AI bot families. Each entry includes the bot’s owner, intended purpose, default policy, and the blocking consequences (for example, “blocking GPTBot may remove your site from ChatGPT search results”).
Training crawlers: GPTBot, ClaudeBot, anthropic-ai, Bytespider, TikTokSpider, FacebookBot, Meta-ExternalAgent, GoogleOther, GoogleOther-AI, Google-Extended, Google-CloudVertexBot, MistralBot, KimiBot, cohere-ai, cohere-training-data-crawler, ai2bot, ai2bot-dolma, Amazonbot, PetalBot
Retrieval bots (on-demand): ChatGPT-User, OAI-AdsBot, ClaudeBot-User, Claude-Web, claude-code, Perplexity-User, Kimi-User, YandexAdditionalBot, Meta-ExternalFetcher, facebookexternalhit, APIs-Google
AI search engines: OAI-SearchBot, PerplexityBot, Claude-SearchBot, Kimi-SearchBot, MistralAI-Index, YandexAdditional, meta-webindexer, Applebot-Extended, MicrosoftCopilotBot, DuckAssistBot, YouBot, PhindBot, iAsk, Komo, Liner, Brave Leo, Andi
Search engines (always-allow guarded): Googlebot, Googlebot-Image, Googlebot-Video, Googlebot-News, Google-InspectionTool, Bingbot, BingPreview, Applebot, DuckDuckBot
Other search engines: Baiduspider
Agent browsers (newer category): OperatorAgent, ChatGPT-Atlas, Claude-Computer-Use
Dataset scrapers: CCBot (Common Crawl), Diffbot, ImagesiftBot, Omgilibot, Timpibot
Other Google crawlers: Storebot-Google, Mediapartners-Google, AdsBot-Google, adidxbot
The Dashboard
Open the AI Firewall menu in your WordPress admin to see:
- A hero metric — total AI bot hits in the last 24 hours and the number of distinct bots involved
- A per-bot list with hit count, bandwidth used, and a one-click policy dropdown for each row
- An MCP / Abilities API activity widget when an MCP server plugin (Royal MCP or any plugin implementing the WordPress Abilities API) is detected on your site
- A Cloudflare visibility status card with an honest estimate of how many AI bots may have been filtered by Cloudflare at the edge before reaching WordPress
- Click any bot row to expand a drill-down view: top URLs the bot hit, recent activity, and what blocking the bot would cost you
Per-Bot Policy Controls
Each recognized bot row has a dropdown with four options:
- Use default policy — falls back to your global mode (Log only, Block training, or Block all)
- Always allow — bot is allowed regardless of default mode
- Log only — bot is allowed and recorded; never blocked
- Block — bot receives a 403 response immediately, before WordPress runs any heavy work
Major search engines (Googlebot, Bingbot, Applebot, DuckDuckBot) are protected from accidental blocking. The per-bot dropdown is disabled for these bots, and the API rejects block requests for them unless you explicitly enable the “Search engine override” toggle in Settings — with a clear warning that blocking Googlebot removes your site from Google Search.
Cloudflare Compatibility
If your site is behind Cloudflare, the setup wizard’s Cloudflare screen tells you exactly which CF settings to turn off so this plugin can take over the AI-bot layer:
- AI Audit → set to “Allow”
- AI Labyrinth → OFF
- Custom WAF rules blocking AI bots → DELETE (the per-bot controls in this plugin replace them)
- Security Level → Medium or Low
And which CF settings to leave on (they don’t conflict):
- DDoS protection
- Managed WAF rules
- SSL/TLS
- Bot Fight Mode (basic tier)
- Browser Integrity Check
- Caching
The dashboard also detects Cloudflare on every admin page load (looking for cf-ray, cf-connecting-ip, or CDN-Loop: cloudflare headers) and shows a status card with the detection state. A persistent 24-hour state ensures the UI stays stable even when an occasional admin request doesn’t pass through CF.
Other CDN Compatibility
The setup wizard also recognizes 6 additional CDNs by their vendor-forwarded request headers: Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. Detection is header-sniff only — no outbound HTTP, no DNS lookups.
When any of these are detected, the wizard shows a compatibility note rather than a network-specific dial-down (Cloudflare remains the only CDN with a full walkthrough because its AI controls are the most common source of operator confusion). Royal AI Firewall sees AI bot traffic that reaches WordPress regardless of which CDN sits in front — if you have edge-side AI-bot rules configured on your CDN, consult its documentation, as the two layers can coexist.
Other Security Plugin Compatibility
The plugin auto-detects these plugins when they’re active and shows compatibility notes on the dashboard and Settings page:
- Edge-firewall security plugins — their firewalls run before WordPress loads. AI bots they block at their layer won’t appear in this plugin’s dashboard, but the two layers don’t conflict.
- WordPress-layer security plugins — coexist cleanly at the WordPress layer.
- GuardPress (Royal Plugins) — first-party Royal Plugins integration.
- Royal MCP (Royal Plugins) — when Royal MCP is detected, MCP tool invocations from connected AI agents appear in the MCP Activity widget on the dashboard.
WordPress Abilities API & MCP Server Integration
This plugin listens for the WordPress Abilities API hooks wp_before_execute_ability and wp_after_execute_ability (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If you have any MCP server plugin installed and an AI agent calls an ability, you’ll see it in the MCP Activity widget on the dashboard.
If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call from that server with full tool name and result status.
Search Engine Guard
Major search engines are protected from accidental blocking by default. The dashboard dropdown is disabled for Googlebot, Bingbot, Applebot, and DuckDuckBot. The REST API endpoints reject block attempts on these bots with a 409 Conflict response unless the customer has explicitly enabled the “Search engine override” toggle in Settings. The override toggle includes a clear warning that blocking Googlebot removes the site from Google Search.
Telemetry and Data
Anonymous usage data is OFF by default. The plugin makes no outbound HTTP call for telemetry unless you explicitly opt in — via the setup wizard’s final step or the “Anonymous usage data” toggle in Settings.
If you opt in, once per week the plugin POSTs a small JSON payload to telemetry.royalplugins.com. The payload contains:
- Plugin version
- WordPress version
- PHP version
- An opaque one-way hash of your site URL — used only to count unique installs. The URL itself cannot be recovered from the hash (SHA-256 with a per-install random salt that never leaves your site).
- Whether you have completed the setup wizard
- How many per-bot policy overrides you have configured
- A bucketed range for AI bot hits in the last 24 hours (e.g. “11–50”)
The following are NEVER sent, regardless of toggle state:
- Your site URL or domain (only its salted hash)
- Customer email addresses
- Invocation log contents
- Specific IP addresses
- Specific bot identities
- User-Agent strings of visitors
Data retention: raw payloads are retained for 90 days. Aggregated statistics are retained indefinitely. Per-site fingerprints are purged after 12 months of no reports. You can revoke consent at any time in Settings — the plugin unschedules the weekly cron immediately.
The other outbound HTTP call the plugin can make (also opt-in) is a single daily GET request to fingerprints.royalplugins.com for a fresher bot catalog when you enable “Keep catalog updated between releases.” That request body is empty and includes only the plugin version in the User-Agent header. See the “External Services” section below.
Log retention defaults to 7 days. The retention window is filterable via raif_log_retention_days for developers who need a different value.
How Activation Works
On activation the plugin:
- Creates five custom database tables:
raif_invocation_log,raif_daily_rollup,raif_bot_policy,raif_bot_access_baseline,raif_page_type_daily - Seeds safe default options (Log only mode; telemetry off; uninstall data-delete off; live catalog updates off)
- Schedules WP-Cron events for hourly rollup and daily log prune, both running entirely inside your WordPress install with no network calls
- Loads the bundled bot fingerprint catalog from the plugin zip
- Redirects the activating admin to the 4-step setup wizard
- The wizard is skippable from any step
No outbound HTTP calls are made until the customer explicitly opts in to live catalog updates on the wizard’s final screen or via Settings → Bot fingerprint database. The plugin is fully functional without ever making a network call — the bundled catalog refreshes from the plugin zip on every plugin update.
On deactivation the plugin unschedules all WP-Cron events. Data is preserved by default so a re-activation continues where you left off. To remove all data on uninstall, check the “Delete all logs, tables, and options when the plugin is uninstalled” toggle in Settings → Data before deactivating.
External Services
The plugin can contact five categories of endpoint. Two are opt-in and off by default. Three run automatically to support features the plugin advertises (bot signature verification, bot-access alerting, and Content Signals). Every endpoint is disable-able. No customer data, IP address, credentials, or site traffic is ever transmitted to any third party.
You can globally block every outbound request by setting define( 'WP_HTTP_BLOCK_EXTERNAL', true ); in wp-config.php. The plugin degrades cleanly when blocked.
1. Royal AI Firewall Fingerprint Catalog (opt-in, off by default)
- Endpoint: https://fingerprints.royalplugins.com/v1/index.json
- When it runs: Only when the customer enables the “Keep catalog updated between releases” toggle. Off by default.
- Frequency: Once per day via WordPress cron (
raif_fingerprint_update). - Data sent: None. Request body is empty. User-Agent header carries the plugin version (e.g.
royal-ai-firewall/X.Y.Z), plus a standardIf-None-Matchcache validator. No site URL, no IP address, no customer data. - Data received: A JSON catalog of recognized AI bot fingerprints, approximately 55 KB.
- How to disable: Untick the toggle in Settings → Bot fingerprint database, or filter
raif_fingerprint_endpointto an empty string. - Privacy Policy: royalplugins.com/privacy/
- Terms of Service: royalplugins.com/terms/
2. Anonymous Usage Telemetry (opt-in, off by default)
- Endpoint: https://telemetry.royalplugins.com/v1/raif/report
- When it runs: Only when the customer enables the telemetry toggle in Settings → Data.
- Frequency: Once per week via WordPress cron (
raif_telemetry_report). - Data sent: Plugin version, WordPress version, PHP version, a locally-salted install fingerprint hash (not derivable back to a URL), coarse-bucketed feature-usage counters. No site URL, no IP address, no bot hit content, no customer data.
- How to disable: Untick the telemetry toggle in Settings → Data.
- Privacy Policy: royalplugins.com/privacy/
3. Web Bot Auth Key Directories (runs automatically)
- Endpoints:
https://openai.com/.well-known/http-message-signatures-directory(OpenAI)https://www.anthropic.com/.well-known/http-message-signatures-directory(Anthropic)https://www.perplexity.ai/.well-known/http-message-signatures-directory(Perplexity)https://developers.google.com/.well-known/http-message-signatures-directory(Google)https://www.facebook.com/.well-known/http-message-signatures-directory(Meta)
- When it runs: Weekly via WordPress cron (
raif_web_bot_auth_refresh), scheduled at activation. - Data sent: None. Request body is empty. Default WordPress
wp_remote_getUser-Agent. No site URL, no customer data. - Data received: Public JWK signing keys the operators publish so RAIF can verify cryptographically-signed bot requests (RFC 9421 Web Bot Auth). Keys are cached locally.
- Purpose: Enables the “trust verified operator” policy tier so bots that sign their requests with published keys can be distinguished from user-agent spoofers.
- How to disable: Filter
raif_web_bot_auth_directoriesto an empty array, or block outbound HTTP globally withWP_HTTP_BLOCK_EXTERNAL.
4. Bot Access Self-Probe (runs automatically)
- Endpoint: Your own site’s home URL (
home_url()). - When it runs: Twice daily via WordPress cron (
raif_bot_access_check), scheduled at activation. - Data sent: Two
GETrequests. One with a browser User-Agent, one with a Googlebot User-Agent. No body, no site data beyond the requests themselves. - Data received: HTTP status code and a truncated response body used to detect whether upstream CDNs/hosts are silently blocking real search-engine bots.
- Purpose: Powers the “Bot Access” alerting that warns when your site becomes unreachable to major search bots. Zero external calls; the probe loops back to your own origin.
- How to disable: Untick “Enable bot access monitoring” in Settings, or filter
raif_bot_access_probe_enabledto false.
5. Content Signals robots.txt read (runs automatically)
- Endpoint: Your own site’s
/robots.txt(viahome_url( '/robots.txt' )). - When it runs: At most once every six hours during a live bot request that requires signal evaluation. Loops back to your own origin.
- Data sent: One
GETrequest. No body, no site data. - Data received: Your robots.txt content, parsed for Content Signals declarations (
ai_train,ai_input,search). - Purpose: Lets the classifier know which AI purposes you’ve opted out of so it can flag violators.
- How to disable: Delete the Content Signals lines from your robots.txt, or filter
raif_content_signals_sourceto return an empty array.
DNS lookups. For search-engine bots that publish a verification method (Googlebot, Bingbot, Applebot, DuckDuckBot, YandexBot), the plugin performs reverse-DNS and forward-confirm lookups against the bot’s IP. These are DNS queries, not HTTP requests; they hit whatever resolver your PHP install is configured to use. Cached for 24 hours per IP.
Dashboard rendering, bot classification, policy decisions, and logging all run entirely inside your WordPress install. The endpoints above are the complete list; no license check, license activation, or analytics beacon is ever contacted.
Installation
- In your WordPress dashboard, go to Plugins → Add New and search for Royal AI Firewall.
- Click Install Now, then Activate.
- The 4-step setup wizard runs automatically on first activation. Walk through it to detect Cloudflare and pick a default policy. The wizard is skippable.
- Open AI Firewall in the admin menu to see the dashboard.
-
Wait 2–6 hours for the first AI bot hits to appear, or run a manual test with curl:
curl -A “GPTBot/1.2” https://your-site.com/
Frequently asked questions
Do I still need Cloudflare?
Yes, if you use Cloudflare for DDoS protection, general WAF rules, SSL/TLS, or caching. Keep Cloudflare’s core protections on. This plugin handles only the AI-bot-specific layer at WordPress, so you can dial down Cloudflare’s AI Audit / AI Labyrinth / custom AI-blocking WAF rules. The setup wizard’s Cloudflare screen lists exactly which CF toggles to flip.
Will this block Googlebot?
No. Googlebot, Bingbot, Applebot, and DuckDuckBot are protected from accidental blocking. The per-bot dropdown is disabled for these bots by default. To block any of them, you must explicitly enable the “Search engine override” toggle in Settings, which warns clearly that blocking Googlebot removes your site from Google Search.
Does this work with other security plugins?
Yes. Edge-firewall security plugins run their own firewalls before WordPress loads, so AI bots they block won’t appear in this plugin’s dashboard — but the two layers don’t conflict. The plugin auto-detects popular security plugins on activation and shows compatibility notes.
Does this work with Royal MCP and other MCP server plugins?
Yes. The plugin hooks into the WordPress Abilities API (WP 6.9+) and logs every ability invocation regardless of which MCP server triggers it. If Royal MCP 1.4.33 or later is installed, an additional first-party bridge captures every MCP tool call with full detail.
What happens to my data if I uninstall?
By default, data is preserved. The plugin’s tables and logs survive uninstall so a reinstall picks up where you left off. To delete everything on uninstall, check the “Delete all logs, tables, and options when the plugin is uninstalled” toggle in Settings → Data before deactivating.
My dashboard shows zero hits even though AI bots are visiting my site. What’s wrong?
Almost always a caching plugin caching the REST API response. The plugin already does four things to prevent this — a cache-buster query string on every dashboard request, nocache_headers() + DONOTCACHEPAGE constant on the handler, explicit Cache-Control: no-store response headers, and built-in compatibility filters that opt out of caching for the most common cache plugins. If you use a different cache plugin or a server-side cache (nginx fastcgi_cache, Cloudflare Page Rules, Varnish), exclude the path /wp-json/royal-ai-firewall/* from REST API caching in that plugin’s settings.
How often is the bot catalog updated?
A fresh bot catalog ships with every Royal AI Firewall release, so every time you update the plugin through your wp-admin → Plugins screen you get the newest catalog automatically — no outbound network call required. Plugin updates typically ship every 2–4 weeks, faster after major AI-vendor launches. If you want catalogs fresher than the per-release cadence, an optional Settings toggle (“Keep catalog updated between releases”) opts in to one HTTP GET per day to fingerprints.royalplugins.com. That toggle is off by default; no outbound HTTP call is ever made until you turn it on.
Does the plugin phone home or make outbound network calls?
No, not by default. Out of the box the plugin makes zero outbound HTTP calls. The bot catalog ships bundled with the plugin and refreshes on every plugin update. If you explicitly enable the “Keep catalog updated between releases” toggle in Settings or on the final wizard step, the plugin will then make one HTTP GET per day to fetch a fresher catalog — but only after that opt-in, and only that one call. Turning the toggle back off immediately unschedules the cron. No telemetry, license checks, or analytics calls are ever made regardless of toggle state.
Is there a Pro version?
No. Every feature ships in the free release on WordPress.org. No upgrade prompts, no license keys, no SaaS subscription.
What if I’m behind a different CDN?
The setup wizard also recognizes Bunny CDN, Fastly, KeyCDN, Sucuri, StackPath, and Akamai. The classifier and per-bot controls work at the WordPress layer regardless of which CDN sits in front. Cloudflare gets a full dial-down walkthrough because its AI controls are the most common source of operator confusion; other CDNs get a compatibility note instead.
Does the plugin slow down my site?
The hot-path classification logic has a hard budget of under 5 milliseconds per request and is enforced by a continuous-integration test. The classifier runs in-process against a 68-entry pre-compiled pattern list. Logging is buffered and flushed on the WordPress shutdown hook (after the response is sent), so the response latency a visitor sees is not affected by database writes.
How is bot identity verified — can a bad actor just pretend to be Googlebot?
This release identifies bots by matching the User-Agent header against the bundled fingerprint catalog. A spoofed User-Agent will match a real bot’s record, so treat the dashboard as the answer to “what’s claiming to be each bot” rather than a verified attribution. For the search-engine guard, blocking is still off by default — a spoofed Googlebot UA can’t be blocked unless you explicitly enable the Search engine override toggle, and managing the actual edge layer (Cloudflare, your CDN, or a security plugin running before WordPress) remains the right place to enforce identity at the network…
Changelog
Adds AI traffic by page type, a bot × page-type heatmap, and blind-spot detection to the dashboard.
1.0.11
- New: Dashboard tile shows AI bot traffic grouped by page type over the last 7 days.
- New: Bot × page-type matrix heatmap on the dashboard.
- New: Blind-spot detection flags page types under-served by AI crawlers.
- Fix: Bot access alert emails now render as HTML in all mail clients.
- Fix: Dashboard sibling-plugin cards correctly recognize Pro editions.
- Fix: Request classification now applies to every request path.
- Fix: Dashboard “Allowed” count now reflects log-only traffic in default mode.
- Fix: Self-test on the WP dashboard widget now correctly identifies its own probe.
- Fix: Uninstall and “Erase all logs” now clear every custom table.
- Fix: Client IP extraction from Cloudflare headers now requires the direct peer to be a Cloudflare edge.
- Fix: Major search engine guard now defers when the reverse-DNS verifier says the request is spoofed.
- Fix: External Services section in the readme now describes every endpoint the plugin can contact.
1.0.9
- Enhancement: Bot access alert emails now render as HTML with a clearer summary of what triggered the alert.
- Enhancement: Destructive uninstall (opt-in) now removes every plugin option and transient.
1.0.8
- New: Royal AI Firewall now flags AI bots that ignore your declared Content Signals and can optionally auto-block repeat violators.
- New: Content Signals dashboard widget shows your declared preferences and violation counts over the past 7 days.
- New: Invocation history has a dedicated Violations tab for reviewing every bot that crossed your declared signals.
- New: Web Bot Auth signature verification recognizes cryptographically signed requests from OpenAI, Anthropic, Perplexity, Google, and Meta.
- New: Per-operator policy toggles let you trust verified requests or block requests that impersonate an operator without a valid signature.
- New: The plugin now publishes an auth.txt file at your site root so AI operators know which identification methods you accept.
- Enhancement: Bot catalog updated with Doubaobot, Perplexity-Comet, and DeepSeekBot.
- Enhancement: Every bot entry now carries an AI purpose classification used for Content Signals matching.
1.0.7
- Feature: AI Traffic Overview dashboard widget in wp-admin — see AI bot traffic at a glance.
- Feature: Activity Log admin page with paginated invocation history.
- Feature: “Try a bot check” self-test button verifies the firewall is watching right after install.
- Enhancement: Invocation log indexed on source and policy_action for faster widget queries at scale.
- Enhancement: Cross-plugin composition — dashboard widget surfaces Royal MCP, GuardPress, ForgeCache, and SiteVault integration status.
- Enhancement: Tested up to WordPress 7.1.
1.0.6
- Enhancement: Bot Access page now includes a reverse-DNS self-test and per-bot verification breakdown.
- Enhancement: Bot Access reverse-DNS self-test is now cached for 60 seconds so admin renders stay fast.
- Enhancement: Google Search Console URL Inspection tool is now recognized and verified as a legitimate Google crawler.
- Fix: Baseline collection counter now reads Day 1 on install day instead of Day 2.
- Fix: Passive bot-access detector no longer flags low-volume search engines as collapsed on natural crawl gaps.
- Fix: Combined bot-access alert now requires two or more watched bots to go silent at once before escalating to high-confidence.
1.0.5
- Feature: Bot Access page shows verified Googlebot, Bingbot, Applebot, and DuckDuckBot hits against a rolling 30-day baseline and alerts if verified hits collapse.
- Feature: Reverse-DNS bot verification distinguishes real search-engine bots from spoofed User-Agents on every log row.
- Feature: Dual-request active probe fires every 12 hours to catch upstream WAF or CDN rules that block bots before rankings drop.
- Feature: Royal Tools submenu lists free companion plugins with one-click install links.
- Enhancement: Custom top header bar on every Royal AI Firewall admin page with View Docs and Support buttons.
- Enhancement: Lightweight admin footer showing family links and current plugin version.
- Enhancement: Dashboard now records real response body size in bytes for every AI bot hit.
- Fix: Dashboard stat cards no longer render doubled percent signs.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Royal AI Firewall alternatives
All AI plugins →FAQ
Royal AI Firewall: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is Royal AI Firewall free?
Yes. Royal AI Firewall is free to download and use from the official WordPress.org plugin directory.
Is Royal AI Firewall safe to use in 2026?
Royal AI Firewall is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites and was last updated 8 hours ago, and scores 67/100 on our health check.
How many websites use Royal AI Firewall?
Royal AI Firewall is active on 20+ WordPress websites and has been downloaded 1,033 times since it launched in July 2026. It was downloaded 384 times in the last 30 days.
Does Royal AI Firewall work with WordPress 7.1?
Yes. The developer has tested Royal AI Firewall up to WordPress 7.1.2, the latest release. It requires WordPress 6.4 or newer.
What PHP version does Royal AI Firewall need?
Royal AI Firewall requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Royal AI Firewall last updated?
The latest version, 1.0.11, was released on September 30, 2026 (8 hours ago).
Who makes Royal AI Firewall?
Royal AI Firewall is developed and maintained by Royal Plugins.
What are the best alternatives to Royal AI Firewall?
The most popular alternatives to Royal AI Firewall are Elementor Website Builder (10M+ installs), All in One SEO (2M+ installs) and AI Agent by SiteGround (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card