@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
@WebDecoy

Web Decoy

Bot detection and remediation tools. Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop AI scrapers and sophisticated bots.

Bot detection and remediation for the AI era.
Passive honeypots, behavioral analysis, and vision AI CAPTCHA to stop scrapers and sophisticated bots.

Website · Live Demo · npm · WordPress


Open Source Projects

ProjectWhat it does
FCaptchaSelf-hosted CAPTCHADetects bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Go, Python, and Node.js servers. Privacy-first, no external dependencies.
Node SDKBot detection middlewareTLS fingerprinting (JA3/JA4), rate limiting, and rules engine for Express, Fastify, and Next.js. Two-tier analysis with fail-open design.
WordPress PluginWordPress bot protectionZero-config bot detection for WordPress and WooCommerce. SHA-256 proof-of-work challenges, behavioral scoring, rate limiting, and carding defense. Works on activation with no external dependencies.

What We're Building

Web Decoy is a platform for detecting and responding to automated threats — from basic scrapers to AI-powered agents that use vision models to navigate sites like humans do.

  • Decoy links — invisible honeypot traps that catch bots ignoring robots.txt, including GPTBot, ClaudeBot, and 20+ AI crawlers
  • Endpoint decoys — API honeypots that catch credential stuffing, injection attacks, and path enumeration with zero false positives
  • Behavioral analysis — TLS fingerprinting, mouse entropy, keystroke cadence, and timezone consistency checks
  • Vision AI detection — purpose-built to detect screenshot-and-click automation (Claude Computer Use, OpenAI Operator, and similar)
  • Response automation — integrates with Cloudflare, AWS WAF, and custom webhooks for real-time blocking

Quick Start

FCaptcha — one command:

docker run -d -p 3000:3000 -e FCAPTCHA_SECRET=my-secret ghcr.io/webdecoy/fcaptcha

Node SDK — add to any Express app:

npm install @webdecoy/express
import{webdecoy}from'@webdecoy/express';app.use(webdecoy({apiKey: process.env.WEBDECOY_API_KEY,threatScoreThreshold: 70,}));

WordPress — install and activate:

  1. Download from GitHub Releases
  2. WordPress Admin → Plugins → Add New → Upload Plugin
  3. Activate — protection starts immediately, zero configuration needed

Contributing

FCaptcha and the Node SDK are MIT-licensed. The WordPress plugin is GPLv2+. Issues and PRs welcome.

Pinned Loading

  1. FCaptchaFCaptchaPublic

    Self-hosted, invisible CAPTCHA that detects AI agents driving real browsers. GDPR, WCAG 2.2 AA, and EAA: no cookies, no third-party data sharing, and no visual or audio puzzle. With a false-positiv…

    JavaScript 196 16

  2. wordpress-pluginwordpress-pluginPublic

    WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense

    PHP 1

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…