Bot Detection.Which anti-bot guards that site?
Identify the bot-management and anti-bot vendor protecting any site — DataDome, HUMAN (PerimeterX), Kasada, Cloudflare Bot Management, Imperva and more — detected from response headers, cookies and challenge behaviour. Passive and non-intrusive.
Try: nike.comcloudflare.comleboncoin.fr
—
—
Detection signals
Passive detection reads response headers, cookies and challenge behaviour. Some bot-management runs only on login, checkout or API paths, or reveals itself solely in client-side JavaScript — so a “none detected” here doesn’t guarantee a site is unprotected.
Bot management is one layer of defense. A free assessment reviews your whole security and delivery posture.
WAF Detector in four questions.
Cloud BOT MGMT, CDN-bundled WAF or appliance: identified from response signatures and challenge behavior.
How the edge treats ordinary requests: challenges, cookies, header rewrites, and what that costs in latency.
Every fingerprint that fired, so a security team can verify the identification independently.
Security layers are delivery layers; the report notes what the detected stack typically adds to response times.
How it works.
A transparent look at exactly what the tool checks, and how it reaches its answer.
WAF products leave consistent fingerprints in headers, cookies and block-page markup; we match them against a maintained library.
CoreBot-management vendors drop tell-tale cookies and headers — datadome, _px3, _abck, __cf_bm, x-kpsdk — matched against a maintained signature set.
CoreA plain, harmless request reveals block or challenge pages (including Kasada’s bare 429) that identify active bot protection. No attack or exploit traffic is ever sent.
PrincipleDetection reads response headers and cookies only; protection that runs solely in JavaScript or on login/checkout paths is reported as such rather than missed silently.
SupportingWhat you’ll get.
The product or service in front, with confidence scoring.
IncludedChallenges, cookies and header rewrites seen during detection.
IncludedWhat the detected stack typically means for latency and caching.
IncludedEvidence included, ready for a security review thread.
IncludedWho it’s for.
Know what actually protects a property you’re acquiring, auditing or integrating with.
Confirm the WAF you pay for is the WAF that answers, misrouted zones are more common than anyone admits.
Mapping WAFs across an estate is step one of collapsing three security vendors into one.
See which security edges your market actually deploys, not which ones sponsor conferences.
Free and live now, in beta.
The toolkit automates the detection and benchmark data behind the assessments we already run, the tools are how we prove the data is good.
Every tool ships free with shareable reports; the business model is the advisory behind it, not your email address.
Available free are in build. Dates are windows, not promises, we ship when the detection is trustworthy.
Want the answer before the tool exists? A free assessment runs the same analysis, human-graded, usually within 24 hours, and puts you on the early-access list for WAF Detector.
WAF Detector in context.
The research this tool automates.
More free CDN World tools
All part of the same toolkit — passive, non-intrusive, no signup.
WAF Detector questions,
answered straight.
When does WAF Detector launch?
It’s in development as part of the CDN World toolkit; the tools page has the early-access list.
Is this a security scanner?
No, and deliberately so. It sends only ordinary, benign requests and identifies the protection layer from passive fingerprints. It never sends attack payloads, probes for vulnerabilities, or does anything a production site would register as hostile.
Which products can it identify?
The launch library targets the WAFs and BOT MGMT edges we meet most in assessments, the major CDN-bundled WAFs and standalone cloud products, and it will grow the way our CDN signature library did.
Can a WAF hide from it?
Some deployments mask well, and the report says so honestly: a low-confidence result with the evidence shown beats a confident guess.
Why does a CDN advisory build a WAF tool?
Because on modern stacks the WAF and CDN are one buying decision, you can’t advise on delivery without seeing the security layer in front of it.
I need this answered today.
A security-focused assessment covers WAF identification and posture, human-graded.
All product names, logos and brands referenced in tool reports are the property of their respective owners and are used for identification purposes only. CDN World tools perform passive, non-intrusive analysis. Tool capabilities and launch timing described on this page are plans, not commitments, and may change.
