CPChris Portschellerinwebdecoy.hashnode.dev·13m ago · 11 min readInside a WordPress Bot Detection EngineThe WebDecoy WordPress plugin ships with zero configuration required. But underneath the "install, activate, done" experience is a multi-layer detection engine that scores every request across server-00
CPChris Portschellerinwebdecoy.hashnode.dev·3h ago · 13 min readBot Detection False Positives: How to Actually Test AccuracyThe fastest way to lose confidence in bot protection is not to miss a bot. It is to block a real customer. A missed scraper costs bandwidth or content. A blocked customer costs a sale, a support escal00
CPChris Portschellerinwebdecoy.hashnode.dev·3h ago · 12 min readAI Agent Authentication in 2026: Web Bot Auth, ARD & OAuthAI agent authentication is not one protocol. It is a stack. An agent may need to discover a tool, prove which workload is running, authenticate an HTTP request, show that a user delegated authority, a00
CPChris Portschellerinwebdecoy.hashnode.dev·3h ago · 11 min readBrowser Fingerprinting in 2026: What Still Works, What Doesn'tBrowser fingerprinting still works in 2026, but the useful techniques have shifted underneath everyone. Chrome's Privacy Sandbox has frozen or removed half the signals fingerprinting libraries depende00
CPChris Portschellerinwebdecoy.hashnode.dev·3h ago · 13 min readWhy CAPTCHAs Are Dead (And What Replaces Them in 2026)There's a pattern you can watch happen on any reasonably popular site once a quarter. A team ships a new sign-up flow. They add reCAPTCHA. The bots keep coming. They upgrade to reCAPTCHA v3 invisible.00