Probe

See what sees your bot.Or see what your protection misses.

Probe is being built as a benchmarking layer across the bot-protection ecosystem. Test your own browser, scraper, crawler or HTTP client against independent detection techniques and against real protection products wherever direct integration or controlled test environments are available.

The goal is not a single generic "bot score." Probe will show how the same client is classified across different protection systems, signal families and network-intelligence sources.

Join the waitlist

In development · Pre-launch

your stack Your client Scraper, crawler, browser, HTTP client or agent, unmodified
benchmark harness WhoScrapes Probe Protection systems, open detectors and WhoScrapes detectors evaluate the same session
result Comparison report Product outcomes, plus a per-layer diagnostic explanation
probe · client report Illustrative · not real data
Protection systems
Protection AnativePASS
Protection BcontrolledCHALLENGED
Protection CcontrolledBLOCKED
Protection DnativePASS
Protection EcontrolledUNKNOWN
Detection layers
TLS / transportimplementedPASS
HTTP/2 consistencyimplementedPASS
Browser automationmodeledDETECTED
CDP instrumentationimplementedDETECTED
Browser integritymodeledPASS
IP reputationimplementedDETECTED
Session behaviorimplementedPASS

Product outcomes and independently observed signals are reported separately. A signal WhoScrapes observes is not presented as the reason a product made its decision unless the vendor exposes that information. No source code upload and no SDK required; you do not need WhoScrapes Run to use Probe.

Benchmark across protection systems.

Different anti-bot systems make different decisions about the same client. Probe is designed to test that difference directly: a standardized benchmark harness for the bot-protection ecosystem, with WhoScrapes' own detectors explaining and complementing the product outcomes.

One client. Many protection stacks. A browser that passes one protection system may fail another. Probe is intended to make those differences measurable by running the same client against multiple independent protection environments under controlled conditions.
Your client
  • Real products · native & controlled
  • Protection system A
  • Protection system B
  • Protection system C
  • Protection system D
  • Network intelligence
  • IP intelligence provider A
  • IP intelligence provider B
  • Detectors
  • Open-source detectors
  • WhoScrapes detector suite
Comparison report
target coverage Planned · not live
  • Commercial bot managementPlanned
  • WAF / edge protectionPlanned
  • CAPTCHA & active challengesPlanned
  • Device / fraud intelligencePlanned
  • IP & network intelligencePlanned
  • Open-source detectorsPlanned
  • WhoScrapes atomic detectorsIn development
probe · network classification Illustrative · not real data
Provider AResidential proxy
Provider BResidential
Provider CProxy
Provider DClear

Detection is not limited to browser anti-bot products. Probe plans to compare independent IP and network-intelligence providers too; the disagreement between them is itself a useful result.

Example research and integration targets

Bot management & WAF
Cloudflare Bot Management · AWS WAF Bot Control · DataDome · Akamai Bot Manager · HUMAN / PerimeterX · F5 / Shape · Imperva · Vercel BotID · Kasada · Radware · Netacea
CAPTCHA & challenges
Google reCAPTCHA · hCaptcha · Arkose Labs
Device intelligence
Fingerprint
IP & network intelligence
MaxMind · IPinfo · Spur · IPQualityScore · GreyNoise · AbuseIPDB · CrowdSec · other reputation and proxy datasets
Open-source detectors
BotD · CreepJS · OWASP CRS · Coraza · JA4 · p0f

Examples represent technologies WhoScrapes intends to research or integrate with. No affiliation, partnership or completed integration is implied. Names are trademarks of their respective owners.

Which products react? Which signals fire?

A protection system is not a signal. Probe keeps the two apart: the product outcome says what happened, the detection layers help explain it.

Protection systems
CloudflareAkamaiDataDomeAWS WAF Bot ControlHUMANF5 / ShapeImpervaFingerprintreCAPTCHAhCaptchaArkoseKasada…
Detection layers
NetworkTLSHTTP/2HeadersBrowser runtimeAutomationDevice fingerprintBehaviorSessionIP reputationChallengesWAF
Conceptual only · not a claim about proprietary vendor implementations
Protection ↓ / Layer →TLSBrowserIPBehaviorSession
Cloudflare
DataDome
Akamai
AWS

Every result says where it came from.

A detection result is only useful if you know what produced it. Probe is designed to label each result with one of five sources. Native and Controlled are real-product benchmarks.

Real-product benchmarks

NativeReal product

The actual vendor product or API evaluates the request: through a vendor API or SDK, a WhoScrapes-controlled hostname configured behind the product, or a supported edge / WAF integration. This is the strongest result.

Example format
Protection system A
SourceNATIVE
OutcomeCHALLENGED
ControlledReal product

A real protection product evaluates the client in an environment operated by WhoScrapes, provided by a benchmark partner, or explicitly authorized for benchmarking. This matters for enterprise systems that cannot simply be called through an API. The product is real even when WhoScrapes has no access to its proprietary internal score.

Potential future coverage: Akamai Bot Manager, HUMAN / PerimeterX, F5 / Shape, Imperva, DataDome, Kasada, Radware, Netacea.

PASSCHALLENGEDBLOCKEDSOFT BLOCKUNKNOWN

Detectors & research

Implemented

WhoScrapes implements and measures the detector itself.

JA4 / TLS, HTTP/2, header consistency, browser / runtime consistency, CDP instrumentation, JavaScript integrity, WebGL / Canvas / device signals, behavior, session continuity, IP / network classification, honeypots, WAF rules.

Modeled

WhoScrapes implements a comparable signal family based on public vendor documentation and research.

Browser inconsistency, automated-browser signals, token / session reuse, suspicious navigation, environment spoofing, coordinated activity, sensor tampering, unusual request signatures. Modeled results do not claim to reproduce a vendor's proprietary scoring model.

Observed

The result comes from publicly observable behavior or research rather than direct access to the protection system.

Signal families Probe is designed to cover

Transport & protocol

  • TLS fingerprints
  • HTTP/2 and HTTP/3 fingerprints
  • Request and header consistency
  • Crawler authentication

Browser & runtime

  • Browser fingerprinting
  • Browser environment consistency
  • Automation framework artifacts
  • CDP / browser instrumentation
  • JavaScript integrity
  • Canvas, WebGL, WebGPU
  • Fonts, audio, device characteristics

Behavior & session

  • Behavioral signals
  • Navigation patterns
  • Session continuity
  • Request velocity
  • Coordinated activity
  • Honeypot links

Challenges & rules

  • Active JavaScript challenges
  • Proof-of-work challenges
  • WAF rules

Network & reputation

  • IP reputation
  • VPN, proxy, datacenter detection
  • ASN / network reputation