Verified with founders on IndieHackers

Your traffic numbers are wrong twice over.

Crawlers and click farms inflate what your analytics shows. Ad blockers hide real people from it. Both happen at once, so the total looks about right and every decision underneath it is off.

Setup takes about five minutes and needs no changes to your pages. Finish it and $100 lands in your wallet. 30 day money back guarantee.

12d 08h 24m 99 of 100 places left. Ends 30 September and does not come back. Claim it
The same 10,000 visits, read two ways
What a JavaScript tag records 7,100 (wrong twice)
Counts crawlers as people. Loses everyone who blocks the script, so they never existed as far as it is concerned.
What your server actually saw 10,000
Every visit, separated by what it actually was.
Engaged people Script blocked, still real Rendered, did nothing Scrapers and automation
The problem

Two errors, pointing opposite ways.

Analytics that runs in the browser overcounts, because a headless browser executes JavaScript exactly like a person does. And it undercounts, because a fifth to a third of real people block the script entirely.

Either error alone would be survivable. Together they cancel out just enough to look plausible, which is why the number goes unquestioned for years. The total is roughly right and the composition is completely wrong.

“My top cities were Prineville, Boardman and Council Bluffs. Those aren't cities. They're datacenter towns. Once you see it you can't unsee it.”

Indie founder, on discovering what his analytics was counting. Read the thread

Search Console disagrees too

It undercounts in the other direction, hiding low volume queries behind a privacy threshold. Two tools, two wrong numbers, neither of them the truth. Your server log is the only place a request cannot hide.

One agent is not one visitor

A person browsing is about four requests. An AI agent doing the same task is closer to four hundred. Any dashboard leading with request counts shows a single agent outweighing a hundred real people, and the chart just looks like growth.

Bot filters pass click farms

Real browsers, real residential addresses, plausible referrers, and nobody home. By every measure a bot filter takes, they are browsers. Telling them apart needs behaviour, not identity.

A bug magnified: what crawlers look like once you can see them
How it works

Read the server, not the browser.

Your server or edge tells us about each request, and we classify it. That part is unblockable, because it never touches the visitor's browser. An optional snippet adds behaviour, which is the only thing that separates a person who read the page from a browser that rendered it and left.

If the snippet is blocked, the visit is still counted. You lose the behavioural detail, never the visitor. That is the whole difference from a JavaScript tag, where a blocked script means the visit never happened.

Every verdict decomposes into the individual signals that produced it. The classification engine is open source so anyone can audit the method.

Evidence · session detail app.clickbaton.com/entities
Consumer network, which is where real people are
Browser hints a modern Chromium build sends
No behavioural data: snippet blocked, still counted
Pointer travelled in a mathematically straight line
VERDICT Zombie Traffic · 90% confident
Active Human
Moved, scrolled, clicked, or completed something real in your product.
Human (Privacy Mode)
A real person whose script was blocked. Counted anyway, from the server log.
Zombie Traffic
A real browser that rendered the page and did nothing at all. Where click farms live.
Utility Crawler
Verified search and AI crawlers. Excluded from your conversion rate.
Rogue Scraper
Automation, spoofed identities, datacenter tooling.
Two more axes

Tier says what it is. This says what it is doing to you.

A verified search crawler and a competitor's price monitor land in the same tier. They are the same kind of thing and they deserve opposite decisions, so we read two more properties off every agent.

Function is what kind of thing it is: search engine, AI crawler, AI assistant, AI search, SEO tool, social media, and the rest of the taxonomy. Intent is what it is doing to you, and it is never declared. It is worked out from what the agent actually did on your site: which paths it went to, how evenly spaced the requests were, whether it read robots.txt first, whether real people ever arrived from that surface afterwards.

The same crawler genuinely behaves differently on different sites, so intent is measured per site rather than stamped globally. Googlebot indexing your articles and a scraper copying them can be the same tier. The doing is the difference, and the doing is what we measure.

Agents · what it is doing app.clickbaton.com/agents
AgentWhat it isWhat it is doing
Googlebot Search engine Indexes and cites you
PerplexityBot AI search Indexes and cites you
GPTBot AI crawler Collects for training
Claude User AI assistant Fetching for a person right now
SemrushBot SEO tool Takes without citing
Facebook Social media Building a link preview
Setup

Works with what you already run.

Edge middleware, a log agent, or two lines in your application. No DNS change, no proxy in front of your site, nothing that can take you down.

Vercel
Cloudflare
Nginx
Apache
ISPmanager
cPanel
Plesk
LiteSpeed
Caddy
IIS
AWS ALB
Netlify
WordPress
Laravel
Next.js
Django
Express
Rails
Click fraud

Stop paying for clicks that were never people.

Put a protected link between your advert and your landing page. A real person sails through in about 40 milliseconds. A rented server gets stopped, with the reason attached, and you get a timestamped record of every click that was turned away and exactly which check it failed.

That record is the point. Telling an ad network your traffic was fake is an accusation. Showing them four hundred clicks that arrived from rented servers with no browser headers is evidence, and evidence is what gets a refund.

It fails open: if the check times out or we have a bad day, the visitor goes through. And the link runs on our domain, so if we go down your site keeps serving and only the link stops.

Protected link · click log app.clickbaton.com/link_detail
clickbaton.com/l/9fK2xQ · consumer ISP · Firefox
user agent: browser-shaped
network: residential
Through42ms
clickbaton.com/l/9fK2xQ · 203.0.113.44 · no headers
user agent: browser-shaped
network: rented server, not a consumer ISP
Blocked
clickbaton.com/l/9fK2xQ · residential · 0s session
network: residential
pointer travelled in a straight line, zero dwell
Blocked

No click limits, ever

Available on a plan or not. We will not meter this, because metering it would mean earning more from the fraudulent clicks it exists to stop.

What it saved you, in money

Tell us what a click costs and we show what blocking them kept in your budget. Leave it blank and we show the blocks with no figure rather than inventing one.

Blocking rules

Rules we refuse to write.

Most tools will hand you a block button and let you find out what it cost you. We think a rule that turns away paying visitors silently is worse than no rule at all, because the people it blocks do not complain. They see an error and go somewhere else, and you see a traffic dip with nothing attached to it.

So every rule is checked against your own traffic first. If the pattern would also have blocked real people, we say how many before you can add it. If the number is large, we refuse to generate the rule at all. There are networks we will not help you block whoever asks: mobile carriers, consumer ISPs, the ranges that feed your search traffic. A tool that lets you lock out four thousand customers with one comfortable click is worse than no tool.

And we never do the blocking ourselves. Everything here produces configuration for infrastructure you already run, and you review it before it goes anywhere near your server. Every rule expires, because a permanent block is a decision about a network that may belong to somebody completely different next year.

Blocking rules · guard check app.clickbaton.com/waf
block AS7922 · Comcast
user agent: browser-shaped
4,589 real people match this network on your site
4,589 real people matched this pattern
in the last 30 days on your own site
Refused
We will not generate this rule. Narrow it to the specific addresses the bad traffic came from, or use the evidence page to see exactly which sessions prompted the suggestion.
Costs & attribution

What machines take, and what they send back.

A dashboard that only totals bandwidth talks you into blocking the crawler that feeds you. So every cost figure sits beside its counterweight: what came back through that same agent, in people and in confirmed conversions.

Googlebot costs cents and sends thousands. A scraper costs the same cents and sends nothing. Same byte count, opposite decisions. Only the return leg tells you which is which.

Attribution lags honestly: content indexed today can surface in an answer engine months later, so AI crawlers get judged over quarters, not fortnights. The numbers say when they are estimates, and the method is on the page.

Cost of machine traffic app.clickbaton.com/costs
what it took $0.13
people returned 16,503
Keep. Costs about 13 cents to serve, and thousands of real people arrived through it. A one-sided dashboard would have told you to block your own feed.
Campaign audit

Backtest the campaign you already doubt.

You know which campaign you suspect. Paste its dates and source into the audit and watch the system agree with you or surprise you, for reasons you can check: how many of those clicks were real people, how many did anything, and which named signal flagged the rest.

A verdict is an accusation; a verdict with named signals is evidence. The audit never reports a number without the reasons underneath it, because the output is meant to be shown to whoever sold you the traffic.

Campaign audit app.clickbaton.com/campaigns
483 clicks · utm_source=bing · 30 days
183 real people 87 zombies 213 machines
62% never moved the pointer
requests spaced at near-identical intervals
21% skipped the browser check entirely
True conversion rate

The only number a hostile client cannot fake.

Your own server tells us when somebody signs up, buys, or finishes anything real, signed with a key that never touches a browser. That one assertion overrides every heuristic we run. A visitor running every privacy tool on earth looks like a bot, until your server says they created an account.

Then the arithmetic fixes itself. The naive rate divides by everyone, machines included. The true rate divides by people. The gap between those two numbers is the size of the lie your old dashboard was telling you.

Conversions app.clickbaton.com/conversions
✓ signed event: signup_completed verified server-side
naive rate · 2.1% true rate · 5.8%
denominator: 3,100 human sessions, not 8,600 total
Funnels

Your conversion rate is wrong. Here are both versions.

Bots reach checkout now. They click email links, submit forms and traverse four stages, and every conventional funnel folds them into the conversion rate. That is how somebody concludes their checkout is broken when in fact half of what reached it was never a person.

Both numbers are shown side by side, always. The inflated one is what you have been looking at elsewhere, and hiding it would make this look like a different tool with worse figures rather than the same figures told honestly. The gap between the two is the finding.

Stages must happen in order to count, visits are stitched across days, and the loose "ever visited" number other tools would show sits beside the ordered one, because the gap between them is how much every other tool was overstating.

Funnels · signup flow app.clickbaton.com/funnels
What other tools show 8.6% 3,100 of 36,000 visits
Counting only real people 5.2% 260 of 5,000 people
Landing page 100%
Pricing page 48%
Signup form 22%
Confirmed 11%
The 3.4 point gap is the size of the lie. The visit-based number is diluted by 31,000 sessions that were never going to convert. Your checkout is not broken.
Alerts

Arrive where you already are.

A notification in an app you open twice a week is a record of something you missed. So alerts go to Slack, Discord, Teams, Zapier or your own signed endpoint, with thresholds you set: machine share, traffic jumps against the baseline you pick, funnel leaks, or a site that stopped reporting entirely.

A failing endpoint is shown as failing, loudly. The worst version of this feature is one that quietly stops delivering while you believe you are covered. Ours pauses and tells you why.

#alerts · Slack hooks.slack.com/services/…
#alerts
roipad.com: machines were 71% of yesterday's traffic 4,100 sessions, 2,911 of them scrapers and crawlers. Your threshold is 60%. bot_surge · via integrations · 08:00
New on roipad.com: Bytespider 938 requests from something that has not appeared here in two months. new_agent · 08:00
Nothing has arrived from staging.roipad.com for 9 hours Usually a rotated key or an agent that stopped. ingest_silent · 08:01
The duration lens

Split your traffic by how long anything stayed.

The click farm signature is a shape: everything plausible, nothing home, and a session window under one second. One chip isolates every sub second visit on your site. A slider up to a minute isolates the readers. Zombies that lingered half a minute and machines that vanished in under a second were always different populations wearing the same tier. Now they are two clicks apart.

Evidence · sessions app.clickbaton.com/entities
Lasted ≥ 30s
412s · 6 pages · scrolled, clicked
1685s · 11 pages · returning visitor
0s · 1 page · single request
0s · 1 page · single request
0s · 1 page · single request
What it costs

Start free. Upgrade when it is paying for itself.

Start here
Free
$0/month
$100 signup credit if you qualify
  • 3 day trial of every feature, open to everyone
  • Full traffic truth, one site
  • No card required to start
Starter
$15/month
  • For one site you want the truth about.
  • No traffic limit on any plan
  • Everything the tier below has, plus more
Growth
$39/month
  • Campaign audits, protected links, alerts.
  • No traffic limit on any plan
  • Everything the tier below has, plus more
Scale
$119/month
  • Everything, for a portfolio of sites.
  • No traffic limit on any plan
  • Everything the tier below has, plus more

No plan has a traffic limit. Bot traffic is the thing you are paying us to find, so billing you more for having more of it would put us on the wrong side of your own interests. Every other tool in this category meters exactly the traffic it promises to eliminate.

Full comparison
Privacy

We measure behaviour, not people.

Your traffic is a puzzle with thousands of pieces. The picture only needs how each piece moved and when. It never needs whose piece it was, so that is the part we never keep.

Visitor addresses are hashed with a salt that changes every night, so the same person looks different tomorrow. Nobody can follow them through the data, including us. Raw logs are classified and discarded in the same pass, never stored.

The behaviour snippet measures pointer movement, scroll and typing rhythm as timing and geometry only. It cannot tell an A from a Z. No canvas fingerprinting, no device identity, and by default no cookie, which is why your visitors need no banner on our account.

The picture assembles. The box the pieces came in is thrown away.

A puzzle: every visitor is a piece, and the picture never needs whose it was

Find out what your traffic actually is.

Five minutes to set up. Nothing to install on your pages.

Get started