🚀 Experience the new and improved APIVoid! Check out what's new

Bot Detection Test

Test your browser for bot-like signals. This experimental tool analyzes your browser fingerprint and detects anomalies such as headless environments, spoofed user agents, browser tampering, and potential data leaks. Get an instant estimated risk score from 0 (likely human) to 100 (likely bot). Check out IP Reputation API and Email Verify API to enhance bot and abuse detection.

Collecting browser signals…

BOT DETECTION TEST FAQ

Have questions about this bot detection test? Find answers here

Learn how browser fingerprinting works, what signals are analyzed, and how the risk score is calculated to detect bots and headless browsers.

What is browser fingerprinting and how does it work?

Browser fingerprinting is a technique that collects various attributes exposed by your browser to create a unique identifier for your device. This includes data such as screen resolution, installed plugins, timezone, language settings, WebGL renderer details, user agent string, and many other signals. When combined, these attributes form a "fingerprint" that is often unique enough to distinguish one browser from another, even without cookies or login sessions. This test uses fingerprinting to assess whether a visitor appears to be a real human user or a potential automated bot.

How does this bot detection test identify bots?

The page collects dozens of browser signals and sends them to our server, where the analysis looks for inconsistencies commonly found in automated environments. It checks for known headless browser indicators (WebGL, canvas, screen dimensions, etc.), spoofed user agents, automation properties left by tools like Selenium or Puppeteer, cross-realm mismatches between the page, web workers and iframes, and missing feature APIs that real browsers always expose. Each suspicious signal triggers a rule that contributes points to a cumulative risk score from 0 to 100, where higher scores indicate a greater likelihood of bot activity. The result shows how many rules were triggered and which broad area they belong to (network and request, hardware and display, browser and engine, browser integrity); the individual rules and their weights are intentionally kept server-side so they cannot be trivially patched by bot authors.

Is this client-side bot detection script enough to block bots?

This script provides a solid first layer of defense focused on browser identification and fingerprinting, but effective bot protection typically requires a multi-layered approach. Browser fingerprinting can detect headless browsers, spoofed user agents, and automation tools, but sophisticated bots may evolve to bypass client-side checks alone. For comprehensive protection, we recommend combining browser fingerprinting with additional layers such as IP reputation analysis to identify known malicious and suspicious IP addresses, geolocation and proxy detection to flag suspicious traffic origins, email reputation checks to verify user identities during sign-ups, and user behavior analysis to detect non-human interaction patterns, multiple accounts and historical suspicious behaviors. Each layer catches threats that others might miss, and together they create a much stronger defense against automated abuse.

How accurate is bot detection and can it produce false positives?

Bot detection based on browser signals is inherently heuristic-based, which means false positives are possible in certain edge cases. For example, users with unusual browser configurations, privacy-focused extensions, or older browser versions may trigger some signals. Similarly, browsers running inside virtual machines or with strict privacy settings may appear slightly suspicious. The risk score is designed to be conservative: a real human user on a standard browser should consistently score 0.

What data points are collected during the test?

The test collects a wide range of browser-exposed attributes organized into several categories: screen properties (resolution, color depth, pixel ratio), time and locale settings, HTTP request headers (user agent, accept-language, client hints), navigator properties (platform, language, plugins, hardware concurrency, device memory), browser engine signals (engine type, version, and JavaScript engine characteristics), the same properties observed from a web worker and an iframe, WebRTC capabilities, WebGL and WebGPU renderer details, WebAssembly feature support, and much more.

What does it mean when my browser is marked as "tampered"?

A "tampered" browser means the test detected inconsistencies between what your browser claims to be and what it actually supports. For example, if your user agent says you are running Chrome but the browser lacks Chrome-specific features like the window.chrome object or other Chrome-specific properties, it suggests the user agent may have been spoofed or altered in some way.

Is my personal data stored or shared with third parties?

The signals collected by the page (browser properties, rendering hashes and request headers) are sent to our server to compute the risk score and are processed primarily in memory; they may be stored internally in an anonymized form to help improve the bot detection, and never shared with third-party. The technical fingerprint hashes shown on the page are derived values and do not contain PII. Your IP address is looked up through our own IP Reputation API to enrich the result with reputation, geolocation and anonymity data, and the lookup result is cached for a short time to avoid repeated queries. The only external network request made by the browser itself is to a public STUN server (for WebRTC IP detection).

Why does my browser appear as likely bot or risky?

A high risk score can result from several factors. Common causes include: using a browser with strict privacy settings that disable APIs like WebGL or Web Audio, running inside a virtual machine with limited device memory, having browser extensions that modify the user agent string or block JavaScript APIs, using an outdated browser that lacks modern features the test checks for, connecting from a hosting, proxy or VPN IP address, or accessing the page through an automated testing framework like Selenium. You can check the detection summary below the score to see which areas contributed to your result and how many rules were triggered in each. Please note that this is an experimental test.

Does this test perform IP address analysis?

Yes. Together with the browser signals, the server analyzes the IP address of the connection using our IP Reputation API. This adds geolocation, ISP and ASN details, anonymity detection (proxy, VPN, Tor, hosting and relay services), blacklist detections, and verification of search engine crawlers. Connections coming from anonymizing or hosting networks contribute to the risk score. The browser also connects to an external and public STUN server to perform a quick WebRTC analysis.

What does it mean that this bot detection is experimental?

The tool was created to test bot detection by primarily checking browser properties and other signals, and is intended for testing purposes only. While the detection methods used are based on well-established fingerprinting techniques, the specific thresholds, risk scoring weights, and signal combinations are continuously being refined. Browser vendors regularly update their APIs and behaviors, which can affect detection accuracy over time. The tool should be used as one data point among many in a comprehensive bot detection strategy, rather than as a definitive classification system. We encourage users to contact us and provide feedback to help improve detection accuracy.

Start using our API services in just a few minutes

Create your account, activate your free trial and make your first API call. No credit card and no commitment required.

Get started now