# mitchellkrogza/nginx-ultimate-bad-bot-blocker

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders

Repository: https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
Canonical: https://ross.abutalabs.com/products/nginx-ultimate-bad-bot-blocker
Language: Shell
License: NOASSERTION
License Family: other
Topics: nginx, nginx-server, bot-blocker, bots, spam-blocker, spambot-security, spam-protection, spam-filtering, spam-prevention, spam-referers, porn-filter, gambling-filter, scanners, vulnerability-scanners, referer-blocker, referrer-spam, spyware, adware, malware, spam-referrer-blocker
Last push: 2026-08-26T23:07:03+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 3693, "days_push": 7, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4781, forks 522 (observed 2026-08-28T04:08:59.607492+00:00)

## What it is
A drop-in Nginx configuration package that blocks bad bots, spam referrers, vulnerability scanners, malware, adware, and fake Googlebots, with anti-DDOS rate limiting and a Fail2Ban jail for repeat offenders. It ships generated blocklists (7,000+ bad referrers, 700 bad user-agents) and is maintained as a regularly updated release.

## Use cases
- block bad bots from my nginx site
- stop referrer spam in nginx access logs
- block fake googlebot user agents
- protect wordpress from theme detector scanners
- add anti-ddos rate limiting to nginx
- ban repeat offender IPs with fail2ban
- block vulnerability scanners hitting my server

## When to choose
- you run Nginx and want a maintained, ready-made blocklist config without writing your own rules
- you need to cut down bot traffic, spam referrers, and scanner noise at the web server level
- you want Fail2Ban integration for repeat offenders

## When to avoid
- you use Apache, Caddy, or a CDN/WAF instead of Nginx
- you need per-application, dynamic bot detection rather than static blocklists
- you cannot safely include large generated config files in your Nginx setup

## Facets
- artifact type: plugin
- maturity: active
- function: security, rate-limiting, middleware
- domain: security, web-development, self-hosted
- platform: self-hosted
- tags: bot-blocking, referrer-spam, anti-ddos, fail2ban, nginx-config, user-agent-filtering, nginx, linux, web-server

## Member repositories
- mitchellkrogza/nginx-ultimate-bad-bot-blocker (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:59.607492+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:18:44.277362+00:00, confidence not recorded.
  - readme: https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker (fetched 2026-08-28T04:08:59.607492+00:00, sha 6f3ac08d81de)
- Data as of 2026-08-30T08:39:29.467469+00:00.
