Ross ROSS = Recommend OSS · open-source software intelligence for agents

mitchellkrogza/nginx-ultimate-bad-bot-blocker

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders observed · 2026-08-28

github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker · Shell · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 99
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3693
  • days_rel: n/a
  • days_push: 7
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4781 stars · 522 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A drop-in Nginx configuration package that blocks bad bots, spam referrers, vulnerability scanners, malware, adware, and fake Googlebots, with anti-DDOS rate limiting and a Fail2Ban jail for repeat offenders. It ships generated blocklists (7,000+ bad referrers, 700 bad user-agents) and is maintained as a regularly updated release.

Use cases

  • block bad bots from my nginx site
  • stop referrer spam in nginx access logs
  • block fake googlebot user agents
  • protect wordpress from theme detector scanners
  • add anti-ddos rate limiting to nginx
  • ban repeat offender IPs with fail2ban
  • block vulnerability scanners hitting my server

When to choose

  • you run Nginx and want a maintained, ready-made blocklist config without writing your own rules
  • you need to cut down bot traffic, spam referrers, and scanner noise at the web server level
  • you want Fail2Ban integration for repeat offenders

When to avoid

  • you use Apache, Caddy, or a CDN/WAF instead of Nginx
  • you need per-application, dynamic bot detection rather than static blocklists
  • you cannot safely include large generated config files in your Nginx setup

Facets

plugin · maturity active

security rate-limiting middleware security web-development self-hosted self-hosted bot-blocking referrer-spam anti-ddos fail2ban nginx-config user-agent-filtering nginx linux web-server

1 source

Member repositories

RepositoryRoleHealth v2
mitchellkrogza/nginx-ultimate-bad-bot-blockermain77

For agents

markdown · JSON · MCP: product_card(name="mitchellkrogza/nginx-ultimate-bad-bot-blocker")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem