fivebar

Bots

Copy page
View Markdown
Open with
Connect MCP
Cursor VS Code

fivebar keeps bots out of your figures, and the Bots page shows what they were.

Crawlers, link previews, uptime monitors and scripts load pages too, and counted as people they would swell your figures. fivebar tells them apart as they arrive, with nothing to set up, and the Bots page is where to look when a visit of your own goes missing.

Only bots that run your pages’ JavaScript, or send the script’s counts themselves, reach fivebar at all. Most crawlers don’t, Googlebot’s everyday crawling and the AI crawlers among them, so they never show: see Bots that never show.

The Bots page

Open it from the Overview, Speed, Errors and Bots switch under the site’s name. It keeps the dashboard’s dates and filters, and shows:

Click any row to narrow the page to it. A reason or a bot narrows the Bots page alone, so it stays behind when you switch pages. Narrowed to one, the share is still of every pageview. Under a filter by a page, a source, a country, a network, a browser or an operating system, the page counts the bots that match. Filtered by anything else, such as a referrer, a city, a device or a goal, it has nothing to show.

A bot is never a visitor or a visit, so the page counts pageviews alone. A bot’s pageview answered with an error, such as a 404, isn’t counted at all, here or on the Errors page.

Bots are left out of everything else: the dashboard’s figures and panes, who is on the site now, email reports and the stats API. An app connected over MCP reads this page’s figures with get_site_bots, and no other tool’s figures count a bot.

What counts as a bot

fivebar takes a visit for a bot’s the same way on every site, with no setting to change it, and gives it one of these reasons:

Known bots

The Bot pane names the bots fivebar knows, from a list of its own. The crawlers: Google, Bing, Apple, Yandex, Baidu, DuckDuckGo, Petal Search, Yahoo, OpenAI, Anthropic, Perplexity, Meta, Common Crawl, Ahrefs, Semrush, Majestic and Moz. The link previews: Facebook, WhatsApp, Slack, Telegram and Discord. The monitors: Lighthouse and Pingdom. The programs: curl, Wget, Python requests, axios, OkHttp, Java, Go and libwww-perl.

A bot is named by what its user agent says, which anyone can copy, so a name is a claim, not proof. Any other bot has no name, and isn’t in the Bot pane.

Hosting networks

A visit from a network classed as hosting is a bot’s whatever its user agent says, since most bots run on servers and few people browse from one. That’s 8,959 networks, from ipverse’s as-metadata, the list a site’s settings name networks from. Among them are Amazon Web Services (AS16509), Google Cloud (AS396982), Microsoft Azure (AS8075), DigitalOcean (AS14061), Hetzner (AS24940) and OVHcloud (AS16276). The list classes each network from several signals of its own, and says it isn’t always right.

Some networks classed as hosting carry people too, so a visit from one is taken for a bot’s by its user agent alone:

Most VPNs and proxy services run on hosting networks, so a person browsing through one is taken for a bot, as is a check you make from a cloud server. To see which network you’re on, look under Excluded traffic in a site’s settings.

Behind a proxy

Through a proxy that passes on who the visitor is but not their network, fivebar can’t tell a hosting network from any other. Bots are then told apart by their user agent alone, so a visit through a VPN or from a cloud server is counted as a person’s. A proxy that passes the network on gets the same checks as a visit straight from a browser.

Bots that never show

A bot reaches fivebar only by running the script, as a browser does, or by sending its counts as the script would. Most crawlers, the AI ones among them, read a page’s HTML without running its scripts, so however often they come, they never show. An empty Bots page means no bot ran the script, not that none came: your server’s own logs see every request.

Googlebot reads most pages that way too. It shows only when Google renders a page, running its scripts as a browser would, and the renderer sends the script’s count. So the Bots page is no measure of how often Google, or any search engine or AI company, reads your site.

A bot that fits none of the reasons above is counted as a person, and so is an automated browser that hides what it is, as some scrapers do. Leave one out by its address, or by its network if the network is its own: see Excluding traffic. Traffic a site excludes is left out before anything else, so it’s never on the Bots page either.

What is kept

For each pageview taken for a bot, counted by the hour: why it was taken for one, which known bot it said it was, the page, where it said it came from, its country and network, and the browser and operating system its user agent names. Nothing else is kept: not its speed, time on the page, scroll depth, events or clicks, nor its user agent, its IP address or a visitor code made from them, so one bot is never told from another. See Privacy.