The actual vendor product or API evaluates the request: through a vendor API or SDK, a WhoScrapes-controlled hostname configured behind the product, or a supported edge / WAF integration. This is the strongest result.
Probe
See what sees your bot.Or see what your protection misses.
Probe is being built as a benchmarking layer across the bot-protection ecosystem. Test your own browser, scraper, crawler or HTTP client against independent detection techniques and against real protection products wherever direct integration or controlled test environments are available.
The goal is not a single generic "bot score." Probe will show how the same client is classified across different protection systems, signal families and network-intelligence sources.
In development · Pre-launch
Product outcomes and independently observed signals are reported separately. A signal WhoScrapes observes is not presented as the reason a product made its decision unless the vendor exposes that information. No source code upload and no SDK required; you do not need WhoScrapes Run to use Probe.
Active protection testing is intended for domains you own or are authorized to test, confirmed through DNS TXT, an HTTP verification file, or an account-level domain ownership workflow.
Benchmark across protection systems.
Different anti-bot systems make different decisions about the same client. Probe is designed to test that difference directly: a standardized benchmark harness for the bot-protection ecosystem, with WhoScrapes' own detectors explaining and complementing the product outcomes.
- Real products · native & controlled
- Protection system A
- Protection system B
- Protection system C
- Protection system D
- Network intelligence
- IP intelligence provider A
- IP intelligence provider B
- Detectors
- Open-source detectors
- WhoScrapes detector suite
- Commercial bot managementPlanned
- WAF / edge protectionPlanned
- CAPTCHA & active challengesPlanned
- Device / fraud intelligencePlanned
- IP & network intelligencePlanned
- Open-source detectorsPlanned
- WhoScrapes atomic detectorsIn development
Detection is not limited to browser anti-bot products. Probe plans to compare independent IP and network-intelligence providers too; the disagreement between them is itself a useful result.
Example research and integration targets
- Bot management & WAF
- Cloudflare Bot Management · AWS WAF Bot Control · DataDome · Akamai Bot Manager · HUMAN / PerimeterX · F5 / Shape · Imperva · Vercel BotID · Kasada · Radware · Netacea
- CAPTCHA & challenges
- Google reCAPTCHA · hCaptcha · Arkose Labs
- Device intelligence
- Fingerprint
- IP & network intelligence
- MaxMind · IPinfo · Spur · IPQualityScore · GreyNoise · AbuseIPDB · CrowdSec · other reputation and proxy datasets
- Open-source detectors
- BotD · CreepJS · OWASP CRS · Coraza · JA4 · p0f
Examples represent technologies WhoScrapes intends to research or integrate with. No affiliation, partnership or completed integration is implied. Names are trademarks of their respective owners.
Which products react? Which signals fire?
A protection system is not a signal. Probe keeps the two apart: the product outcome says what happened, the detection layers help explain it.
| Protection ↓ / Layer → | TLS | Browser | IP | Behavior | Session |
|---|---|---|---|---|---|
| Cloudflare | |||||
| DataDome | |||||
| Akamai | |||||
| AWS |
Every result says where it came from.
A detection result is only useful if you know what produced it. Probe is designed to label each result with one of five sources. Native and Controlled are real-product benchmarks.
Real-product benchmarks
A real protection product evaluates the client in an environment operated by WhoScrapes, provided by a benchmark partner, or explicitly authorized for benchmarking. This matters for enterprise systems that cannot simply be called through an API. The product is real even when WhoScrapes has no access to its proprietary internal score.
Potential future coverage: Akamai Bot Manager, HUMAN / PerimeterX, F5 / Shape, Imperva, DataDome, Kasada, Radware, Netacea.
Detectors & research
WhoScrapes implements and measures the detector itself.
JA4 / TLS, HTTP/2, header consistency, browser / runtime consistency, CDP instrumentation, JavaScript integrity, WebGL / Canvas / device signals, behavior, session continuity, IP / network classification, honeypots, WAF rules.
WhoScrapes implements a comparable signal family based on public vendor documentation and research.
Browser inconsistency, automated-browser signals, token / session reuse, suspicious navigation, environment spoofing, coordinated activity, sensor tampering, unusual request signatures. Modeled results do not claim to reproduce a vendor's proprietary scoring model.
The result comes from publicly observable behavior or research rather than direct access to the protection system.
Signal families Probe is designed to cover
Transport & protocol
- TLS fingerprints
- HTTP/2 and HTTP/3 fingerprints
- Request and header consistency
- Crawler authentication
Browser & runtime
- Browser fingerprinting
- Browser environment consistency
- Automation framework artifacts
- CDP / browser instrumentation
- JavaScript integrity
- Canvas, WebGL, WebGPU
- Fonts, audio, device characteristics
Behavior & session
- Behavioral signals
- Navigation patterns
- Session continuity
- Request velocity
- Coordinated activity
- Honeypot links
Challenges & rules
- Active JavaScript challenges
- Proof-of-work challenges
- WAF rules
Network & reputation
- IP reputation
- VPN, proxy, datacenter detection
- ASN / network reputation