=== Forge AI Bot Log – AI Crawler Detection, Verification & Blocking ===
Contributors: forgeonline
Tags: ai, bots, crawler, robots.txt, analytics
Requires at least: 5.8
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.2.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

See which AI bots crawl your site, learn what each one does, control their access, and get a monthly email summary.

== Description ==

**Any script can claim to be GPTBot. This plugin checks whether it really is.**

Most AI bot trackers read the user-agent string and take it at face value — so a scraper that sends `User-agent: GPTBot` gets logged as OpenAI. Forge AI Bot Log verifies each visit against the crawler's own published infrastructure using forward-confirmed reverse DNS — the technique Google, OpenAI and Anthropic recommend for confirming their own crawlers — and labels every hit **Verified** or **Spoofed**. You find out which AI traffic genuinely came from OpenAI, and which was something else wearing its name.

Verification covers every crawler that publishes a way to check it, including OpenAI, Anthropic, Google, Perplexity, Amazon, Apple and Meta. Bots with no published verification method are labelled honestly rather than guessed at.

Beyond verification, **Forge AI Bot Log** shows you exactly which AI crawlers and assistants are visiting your WordPress site — GPTBot, ClaudeBot, Google-Extended, PerplexityBot, Bytespider and many more — and explains what each one actually does.

= Key features =

* **Live dashboard** — bot visits for the last 24 hours, 7 days, 30 days, plus a complete searchable log.
* **Bot directory** — click any bot for a plain-English explanation of who owns it, whether it trains AI models / powers AI search / fetches pages live, and whether it obeys robots.txt.
* **Most-crawled content** — see which of your pages AI bots are reading most.
* **Verified / Spoofed labelling** — forward-confirmed reverse DNS on every tracked hit, so impersonators are flagged instead of trusted. Results are cached and throttled to keep it off the critical path.
* **Access control** — block or allow each bot with one click (writes robots.txt rules), plus a hard-block .htaccess snippet for bots that ignore robots.txt.
* **Monthly email summary** — sent to the site admin on the 1st of each month at 9am, covering the previous month.
* **New-bot alerts** — optional email the first time a brand-new AI bot appears.
* **Reliable capture** — an in-PHP logger, an optional must-use early logger, and a server access-log importer for sites behind full-page caching or a CDN.
* **Privacy-friendly** — only logs bots (not human visitors), with optional IP anonymisation and configurable data retention.
* **CSV export** — download the full or filtered activity log for your own analysis.

= Why it matters =

AI crawlers may use your content to train models, cite you in AI search answers, or read your pages on a user's behalf. Forge AI Bot Log makes that traffic visible and gives you the controls to manage it.

== Installation ==

1. Upload the `forge-ai-bot-log` folder to `/wp-content/plugins/`, or install via Plugins → Add New.
2. Activate the plugin.
3. Visit **Forge AI Bot Log** in the admin menu.
4. (Optional, for cached sites) Copy `mu-plugin/forge-ai-bot-log-mu.php` into `/wp-content/mu-plugins/` for earlier capture, or use Settings → Import from server access log.

== Frequently Asked Questions ==

= Does this slow down my site? =
No. It logs only matched AI bots, on an early hook, and reverse-DNS verification is throttled and cached.

= Will it catch bots if I use a caching plugin or CDN? =
Full-page caches can serve bots without running PHP. Use the included must-use early logger and/or the access-log importer to capture those hits.

= Does blocking a bot really stop it? =
robots.txt is advisory. Well-behaved bots obey it; some (e.g. Bytespider) are reported to ignore it. The plugin also generates an .htaccess hard-block snippet for those.

== External services ==

Cross-promotion feed (optional). If you enter a promo feed URL in Settings, the plugin fetches that URL to populate the "more plugins" block in its own emails. Only the request is made; no site, user, or visitor data is transmitted. No feed URL is configured by default.

== Changelog ==

= 1.2.2 =
* Fixed: genuine bots visiting over IPv6 are no longer incorrectly marked "Spoofed" by DNS verification.

= 1.2.1 =
* Removed the remote bot-list auto-updater; the bundled bot list now updates via plugin releases.

= 1.2.0 =
* Added an External services disclosure for the optional promo feed.
* Added a Settings shortcut to the Plugins screen.
* New-bot alert emails are now sent on a background schedule instead of during the visit.

= 1.1.1 =
* Fixed: the .htaccess hard-block snippet now only lists bots you've actually blocked that ignore robots.txt, so it can't accidentally suggest blocking an allowed retrieval bot.

= 1.1.0 =
* Added cross-promotion: advertise your other plugins in the monthly summary and new-bot alert emails, with optional remote feed and automatic UTM tracking.

= 1.0.0 =
* Initial release.
