Bot & Crawler Detection

How automated traffic is categorized and separated from real human visitors.

Bot & Crawler Detection

Automated crawlers, SEO spiders, AI scrapers, and uptime checkers often pollute standard analytics data. VeloStats filters and categorizes this traffic server-side.

Categorization Engine

Every incoming request passes through an autonomous inspection pipeline:

  1. User-Agent Fingerprinting: Known search spiders (Googlebot, Bingbot), social crawlers (Twitterbot, LinkedInBot, WhatsApp), and AI crawlers (GPTBot, ClaudeBot, Perplexity) are detected and classified.
  2. Datacenter ASN Matching: IP addresses originating from major hosting providers (AWS, Hetzner, DigitalOcean, OVH) are flagged using local MaxMind GeoLite2 ASN databases.
  3. Behavioral Traps & Diagnostics: Headless Chrome, webdriver flags, and impossible interaction timings trigger suspicious bot classifications.

Verdict Types

Category Description Counted in Humans?
search_engine Legitimate indexing crawlers (Google, Bing). No
ai_crawler LLM scrapers (OpenAI, Anthropic, Common Crawl). No
social_media Link-preview generators (Slack, Discord, Apple iMessage). No
datacenter Server-originating requests without human interaction. No
human_verified Verified real human session (passed heartbeat checks). Yes