Drupal is a registered trademark of Dries Buytaert
Release: Excel Serialization 2.1.2 Minor update available for module xls_serialization (2.1.2). Release: Time Zone Field 8.x-1.14 Minor update available for module tzfield (8.x-1.14). Module Revived: Entity API 8.x-1.7 Module entity updated after 17 months of inactivity (8.x-1.7). Release: Varbase - The Ultimate Drupal CMS Starter Kit (Bootstrap Ready) 10.1.2 Minor update available for distribution varbase (10.1.2). Release: MCP Sentinel 2.8.0 Minor update available for module mcp_sentinel (2.8.0). Release: Vartheme Bs5 4.1.1 Minor update available for theme vartheme_bs5 (4.1.1). Release: Varbase Heroslider 1.1.3 Minor update available for module varbase_heroslider (1.1.3). Release: Varbase Demo 1.1.2 Minor update available for module varbase_demo (1.1.2). Release: Varbase Dashboards 2.0.3 Minor update available for module varbase_dashboards (2.0.3). Security Coverage: Role Aware Maxlength Module role_aware_maxlength now has official Drupal security advisory coverage.

BotShield

22 sites No security coverage
View on drupal.org

BotShield helps Drupal sites detect and manage automated bot traffic. It allows you to classify bots, apply custom rate limits or blocks, gather geographical data, and generate reports to fine-tune crawler access.

BotShield helps Drupal sites detect bot traffic, apply per-bot/IP rate limits or blocks, enrich events with geo data, and provide reports to safely tune crawler access.

BotShield is a Drupal module that gives site administrators visibility and control over automated traffic. It classifies bots, enforces configurable policies, and provides reports for safe tuning.

Features

  • Classifies known and custom bots using User-Agent rules.
  • Supports per-bot actions: allow, rate_limit, and block.
  • Supports IP/CIDR rules and override file support for always-allow IPs.
  • Adds path-group rules and per-group thresholds.
  • Includes flood safety-net controls, including stricter unknown-bot handling.
  • Enriches events with geo data from headers, GeoLite2 MMDB, and optional free API fallback.
  • Provides report pages: dashboard, status, log, map, and alerts.
  • Supports customizable 429 response messaging.
  • Includes retention cleanup via cron.

Use cases

  • High-traffic sites needing crawler control without blocking all bots.
  • Editorial/operations teams needing visibility into bot behavior and origin.
  • Sites that want Drupal-native bot controls and reporting.

Post-Installation

  1. Grant permissions at /admin/people/permissions:
    • administer botshield for settings managers.
    • view botshield reports for report viewers.
  2. Configure BotShield at /admin/config/system/botshield.
  3. Start with Traffic scope = anonymous while tuning.
  4. Set thresholds, flood controls, and bot policies.
  5. If using MMDB upload, configure $settings['file_private_path'] and upload GeoLite2-City.mmdb.
  6. Verify dependencies and health at /admin/reports/botshield/status.
  7. Tune behavior with /admin/reports/botshield/log and /admin/reports/botshield/map.
  8. Review setup guidance at /admin/reports/botshield/help.
  9. Ensure cron runs for retention cleanup.

Additional Requirements

  • Drupal core 10/11.
  • Required core modules: file, system.
  • Composer dependency for local GeoLite2 lookups: geoip2/geoip2.
  • Private files configured for MMDB and override-file uploads.
  • Optional outbound HTTP access if free API geo fallback is enabled.
  • Mail transport configured if alert email is enabled.
  • Redis module (plus cache-bin mapping) for better performance at scale.
  • An SMTP/mail module for reliable alert delivery.
  • Drush for cache clear and cron operations.
  • GeoLite2 City MMDB for improved geo coverage.

Similar projects

  • CAPTCHA/Honeypot modules focus on form spam; BotShield focuses on request-level bot traffic across routes.
  • Manual IP ban tools are static/manual; BotShield adds automated per-bot and per-group enforcement.
  • Edge/CDN bot controls are external; BotShield provides Drupal-native policy logic and reporting.

Community Documentation

  • Project README (installation, settings, dependencies).
  • In-module guide: /admin/reports/botshield/help.

Activity

Tracked releases
9
Tracked since
Feb 2026
Latest release
5 months ago
Releases (12 mo)
9 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.0.8 Stable Mar 7, 2026
1.0.x-dev Dev Mar 6, 2026
1.0.7 Stable Mar 5, 2026
1.0.6 Stable Mar 5, 2026
1.0.5 Stable Feb 27, 2026
1.0.4 Stable Feb 27, 2026
1.0.3 Stable Feb 27, 2026
1.0.1 Stable Feb 27, 2026
1.x-dev Dev Feb 18, 2026