XFOXSUITE BOT PROTECTION

Your website.
Your traffic rules.

Filter unwanted traffic before your PHP page runs. Install a small guard file, then manage every website from one dashboard.

500 free requests · 1 website · No automatic trial charges

Traffic decisions
Illustration

YOUR RULES, APPLIED BEFORE THE PAGE LOADS

Incoming requestGET /

VPN / proxy detected

Matched your IP rule

Access denied

Missing User-Agent

Matched your header rule

Access denied

No matching block rule

Continue to your website

Allowed

Separate rules for every website. One place to manage them.

PHP installationIP + request rulesRedirect or denyUsage you can track

The controls you need

Make the decision before traffic reaches your page.

Decide who gets through

Filter VPN and proxy traffic, hosting networks, countries, individual IPs, and IP ranges. Add exceptions for visitors you trust.

Look beyond the IP

Match supported request headers and block an empty User-Agent. Combine request rules with IP intelligence.

Choose the next step

Show Access denied or redirect blocked visitors. Let accepted visitors continue to your page or send them to another URL.

Understand every decision

See recent traffic, matched rules, and IP lookup results. Turn on monitor mode when you want to log matches and allow visitors.

Keep control of uncertainty

Multiple IP lookup providers offer fallback coverage. Choose whether incomplete IP intelligence should allow or block a request.

Manage each site separately

Use separate site credentials and rules. Rotate a secret whenever needed, with request allowances shared across your account.

A small install. Central control.

Add it once.
Adjust your rules anytime.

  1. 1

    Add your website

    Enter the hostname, such as example.com, in Bot Protection.

  2. 2

    Install the PHP guard

    Download xfox-guard.php and place the generated snippet at the top of your PHP entry file.

  3. 3

    Set your rules

    Choose what to block, choose the visitor action, and inspect the activity log.

index.php
<?php
require_once __DIR__ . '/xfox-guard.php';

xfox_guard([
    'site_id' => 'YOUR_SITE_ID',
    'site_secret' => 'YOUR_SITE_SECRET',
]);
?>

<!-- Your page continues here -->

The dashboard generates your credentials. The service endpoint is built into the guard file. New websites start with Monitor only off; you can enable it to observe rules before enforcing them.

Simple request pricing

Start small. Add room as you grow.

All plans include the same traffic rules. Choose your request and website limits.

Free trial

Try it on a real website.

$0

one-time allowance

  • 500 requests
  • 1 website
  • All traffic rules and visitor actions
  • Activity log and quota alerts
  • No automatic trial charges
Start free trial

Starter

For a small collection of sites.

$50

every 30 days

  • 10,000 requests
  • Up to 5 websites
  • All traffic rules and visitor actions
  • Activity log and quota alerts
  • Optional wallet auto-renew
Choose Starter
Most room to grow

Pro

More traffic. More websites.

$100

every 30 days

  • 50,000 requests
  • Up to 15 websites
  • All traffic rules and visitor actions
  • Activity log and quota alerts
  • Optional wallet auto-renew
Choose Pro

Need more requests?

Active Starter and Pro subscribers can add 10,000 requests for $25.

No automatic overage charges

Prices in USD. Paid plans run for 30 days. Trial is available once per account. Unused included requests reset on renewal.
Purchased credits carry over and require an active paid subscription to use.

Before you get started

What do I need to install it?

A PHP website with the cURL extension and permission to edit the PHP entry file. Add your hostname in the dashboard, download xfox-guard.php, and include the generated snippet before any page output. You do not need to move your domain or change DNS.

What counts as a request?

Each valid evaluation uses one request, including allowed traffic, blocked traffic, monitor mode, and dashboard API tests. The allowance is shared across your websites. Looking up the same IP again still counts as a request.

What happens when my requests run out?

Visitors see Access denied until you activate a paid plan or buy more request credits. An alert is sent at 90% usage, once per allowance. Recharging your wallet alone does not add requests: you must also buy a plan or a request pack.

Can I buy extra requests?

Yes. An active Starter or Pro subscription can buy 10,000 additional requests for $25. Unused purchased credits carry over, but can only be used with an active paid subscription. Included plan requests reset on renewal.

How does renewal work?

Plans run for 30 days and are paid from your XFOXSUITE wallet. Auto-renew is off by default. Enable it to renew from your wallet at expiry. If the wallet is short, visitors see Access denied until the subscription renews. You can switch auto-renew off at any time.

Is this a firewall or a guarantee that every bot is blocked?

It is a rule-based filter for requests reaching your protected PHP pages. It does not provide network-level DDoS protection, cover files that bypass your PHP guard, or guarantee identification of every bot. IP classifications can be incomplete. If the Guard API itself is unreachable, the PHP helper currently allows traffic.

Put your traffic rules to work.

Try Bot Protection with 500 requests on one website. Add a paid plan when you need more.

Start your free trial
Accepted Payments

Crypto checkout

Fund your balance with the token and network you prefer.

Native assets and USDT deposits are credited to your XFOXSUITE balance after network confirmation.

BTCBitcoin

Bitcoin

ETHEthereum

Ethereum

BNBBNB

BNB Smart Chain

TRXTRON

TRON

USDTTether

Ethereum ERC-20

USDTTether

TRON TRC-20

USDTTether

BNB Smart Chain BEP-20

$

USD balance

Spend across every product