خوش آمدید♥

برای دریافت آخرین بروزرسانی‌های افزونه، استایل و ... نیازمند ثبت‌نام در انجمن می‌باشید تا با ما بروز بمانید!

ثبت نام!
  • هاست سان
  • با خرید اشتراک ویژه شما میتوانید جدیدترین آپدیت افزونه ها و قالب های زیبا و پرکاربرد زنفورو را دریافت کنید!

    هر ماه یک کد تخفیف 60 درصدی محصولات فروشگاه به کاربران منتخب بخش ویژه اهدا می‌شود

  • انجمن مجهز به سیستم تشخیص کاربران دارای چند حساب کاربری می‌باشد در صورت مشاهده حساب کاربری شما مسدود میگردد.
Advanced Traffic Statistics: Access Counter, Live Radar, WAF & AI Bot Defense

رسمی Advanced Traffic Statistics: Access Counter, Live Radar, WAF & AI Bot Defense 1.9.12

دسترسی دریافت را ندارید
پشتیبانی از نسخه های
  1. 2.3
نیاز به ویرایش مجوزهای گروه‌های کاربری
  1. هست
AdvancedTrafficStatistic.webp



Your forum isn't mainly visited by people anymore.


AI companies harvest community content at scale to train their models. Commercial crawlers hammer boards for SEO data. And a new generation of scrapers has appeared — headless browsers with perfect user-agents, valid client hints and JavaScript execution, indistinguishable from a real Chrome visitor by any traditional check.

Counting visitors is no longer enough. You need to know who is really on your board, and be able to do something about it.

That's what this add-on has become. Advanced Traffic Statistics started life as a simple "who's online" widget; today it's a complete Traffic Intelligence & Web Application Firewall that tracks visits, categorises bot traffic with surgical precision, and actively protects your server from resource-draining scrapers, hackers and AI crawlers.

🆕 NEW IN v1.9.12 — A radar that actually moves

📻 The Live Radar, rebuilt
The table is gone. Each access is a card with a coloured edge that tells you its classification at a glance — dark red for blocked, orange for suspicious, teal for verified crawlers, green for humans — with a matching background tint. On a long list you read the composition of your traffic by scrolling, without stopping to decode badges.

The horizontal scrollbar is gone for good. It came from the fixed-width action column, which no longer exists: the ban and trust buttons sit outside the flow, hidden at rest and revealed when you hover a row. On touch devices and narrow screens they are always visible, below the row content.

⏱️ Auto-refresh
The radar can reload its rows on a timer without refreshing the page. New rows slide in at the top with a green highlight that fades, and the tab counters recalculate themselves while keeping whatever filter you had selected. It is off by default and costs nothing until you enable it. When on, the refresh is skipped while the browser tab is in the background and while your pointer is over the list, so it never shifts a row from under your cursor.

🧬 Clusters show how they were already classified
Each unclassified cluster now carries a tag with the classification the add-on assigned it, plus the share of its addresses currently blocked. The overlap with the Datacenter panel becomes explicit instead of confusing: you can see at a glance which groups are already handled and concentrate on the ones that are not.

📦 PREVIOUSLY IN v1.9.11 — Counting what actually matters

⚠️ Your visitor count will go down, and that's the point

Until now every request was counted, including images fetched directly from outside your forum. If one of your attachments ranks on Google Images, thousands of people can download it without ever opening your board — and they were all counted as visitors.

On the development board this was not a small effect: a seasonal image was pulling 16,500 addresses a day straight from Google Images, while the thread containing it had 431 views. Three quarters of the reported "visitors" had never seen a single page.

From this version, a visitor is someone who loaded at least one real page. Resource downloads are counted separately and shown in their own panel. Your figures will drop, sometimes sharply — this is not a regression, it is the number you should have been seeing all along.

🎣 WordPress Trap
Your board is probed daily for /wp-login.php, /wp-content/plugins/ and similar paths. On a domain without WordPress those requests have no legitimate explanation — unlike a heuristic score, this is a certainty, so it can justify blocking outright with practically no false-positive risk. Enable it only if WordPress is not installed on your domain, and those requests are rejected with a 403 and the address banned temporarily. Media paths are deliberately excluded, because domains that previously ran WordPress still receive genuine traffic to old image links.

🧬 Unclassified traffic cluster
Bots that match none of your lists are grouped by their exact browser signature over 7 days. When hundreds of separate addresses present an identical string, that is one operator running a distributed pool. Each cluster carries the evidence to judge it: share of addresses on datacenter networks, countries, hosting providers, sample addresses with AbuseIPDB lookups and sample requested paths. Signatures already covered by your lists are filtered out automatically.

📤 Shared resources
A panel listing attachments downloaded from outside your forum — links pasted into messaging apps, images embedded elsewhere, search-engine image results. Requests from your own pages are excluded, so what remains is genuine external bandwidth consumption.

🔍 Contradictory browser signatures
Some scrapers announce two browsers at once — a user-agent declaring both Firefox and Chrome, or a Gecko build alongside AppleWebKit. No real browser can do this. These signatures now take a heavy trust penalty that hands them to the Junk Shield, with the reason shown in the radar.

📻 Live Radar, rebuilt
The radar splits into tabs — All, Bots, Humans, Unclassified — switching instantly with no page reload. The horizontal scrollbar is gone: the timestamp moved under the address, redundant columns hide per tab, and on narrow screens the table becomes stacked cards.

🩺 System tab
The configuration health check now has its own tab. It verifies nine dependencies against your live setup — missing databases, shields that cannot act, permissions that expose too much, a stalled cron — and every warning tells you what to do about it.

📦 ALSO IN THE 1.9 SERIES

🔎 Score reason codes
Every visitor starts at 100 trust points and loses some for each suspicious trait: missing user-agent (−90), suspicious URL (−80), incomplete browser signature (−60), outdated browser (−50), abnormal request rate (−50), missing Accept-Language (−40), datacenter IP (−30). The radar shows exactly which traits were detected and what each one cost. Penalties accumulate: a single one rarely matters, but a visitor falling to 20 or below is reclassified as a bot. This is why a datacenter IP alone still shows as human — plenty of legitimate users browse through VPNs and cloud networks.

🛡️ Shield Impact
For AI Shield, Junk Shield, Unknown Bots, Datacenter and WordPress Trap, a panel shows how much traffic matched each rule today. If a shield is active the number is what it blocked; if it is off — or you have no Pro licence — it is what it would have blocked.

🕵️ Intrusion Forensics
Every intrusion attempt is recorded and classified into six categories — vulnerability scan, credential attack, SQL injection, path traversal, XSS and code injection — with a 30-day activity chart, a breakdown by type, recent attempts with country and hosting provider, and a ranking of the paths being targeted most. That last one tells you whether you are caught in generic sweeps or whether someone is deliberately hunting for XenForo weaknesses. The detector is designed so that a discussion titled "how to write a SQL select" is never mistaken for an attack.

🧠 A daily report that interprets, not just reports

Each morning you get a security report written from your own data, and its value is in the reasoning. It tells you which probes are harmless because that software isn't installed here, which are attackers hunting for backdoors on already compromised sites, and which are after credentials in exposed configuration files. It flags anything aimed specifically at XenForo and closes with a verdict in plain language. It writes in your board's language automatically and lets you declare other software on your domain so a real attack is never mistaken for noise.

🛡️ Datacenter (ASN) Detection
Modern scrapers run headless browsers with perfect user-agents, but they almost always run on datacenter IPs while real visitors come from residential or mobile networks. The add-on identifies traffic from 110 known hosting and VPN networks including AWS, Google Cloud, Azure, DigitalOcean, Hetzner, OVH, Scaleway, LeaseWeb, Alibaba Cloud, Tencent Cloud, DataCamp and M247. A configurable trust penalty flags them; an optional Pro hard-block stops them with a 403. Verified crawlers passing Forward-Confirmed reverse DNS are always exempt, and logged-in members are never affected.

💓 A dashboard with a live pulse
The Overview carries a server heartbeat: an ECG trace reading your actual traffic. Its colour shifts from green to red as the bot share rises, its speed follows your volume, and the small figures walking along it are drawn from real data — teal robots for crawlers, amber bugs for datacenter traffic, red spiders for intrusion attempts, destroyed at the shield. It adds no database queries at all.

📊 Analytics-style dashboard in tabs
Overview, Security, Traffic, Charts & History and System switch instantly. Colour-coded KPI cards for online users, visitors, bots, blocked threats and monthly totals, each with a trend indicator comparing like-for-like periods. The GeoIP section shows a ranked country list with proportional bars.

🎨 Datacenter Intelligence panel (Pro)
KPI cards for flagged today, last 7 days and blocked today. A 30-day activity chart to spot the exact day a scraping campaign started. Provider identification on every IP. An identity column revealing the user-agent each bot was impersonating — when a dozen IPs all claim the same browser, you are looking at a distributed botnet. Top providers ranking and AbuseIPDB reputation lookup on every address.

☁️ Full Cloudflare & Reverse Proxy Support
Forums behind Cloudflare see visitors' real IPs instead of the proxy's, so all statistics, geolocation and detection work correctly. The CF-Connecting-IP header is trusted only when the connection genuinely originates from a verified Cloudflare range, preventing header spoofing. If your server already restores real IPs, the add-on detects this and stays out of the way.

🔒 Privacy controls
Blur IP addresses on screen — blurs the final part of each address with a frosted-glass effect, revealing it on hover. Protects screenshots and screen shares while lookups, bans and detection keep working.

IP retention control — choose how long IP records are kept, from 1 to 90 days. Retention affects only the IP log: your aggregated statistics live in a separate archive with no IP addresses, so you can keep IPs for a single day and still retain years of history.

🌍 GeoIP powered by DB-IP

The country database uses the freely-redistributable DB-IP Lite database (Creative Commons licensed). Country detection works out of the box on every hosting environment, with no server configuration or PECL extension required.

🚀 INSTALLATION & SETUP
  1. Install the add-on
Upload the package and install it from Admin CP → Add-ons as usual.
  1. Add the sidebar widget
Go to Admin CP → Appearance → Widgets → Add widget and choose "Advanced Statistics (Widget)". Select the widget position where you want it displayed (typically the forum sidebar) and save. Without this step the sidebar widget will not appear.
  1. Open the statistics page
The full report is reachable from the forum navigation under Members → Statistics, or directly at yourforum.com/statistiche/Basic.

Live demo: https://migratoria.it/statistiche/Basic
  1. Configure the options
All settings live in Admin CP → Options → Advanced Traffic Statistics: detection shields, datacenter detection, WordPress Trap, Cloudflare handling, privacy controls, IP retention, Live Radar auto-refresh, chart styling and the AI report.
  1. Set the permissions
In Admin CP → Groups & Permissions → User group permissions, under General Permissions:

View Full Statistics Report — grant to the user groups you want to give access to the statistics page.View Live Traffic Radar — ⚠ Grant this to staff only. The radar exposes visitor IP addresses and the classification and ban controls, so it should never be enabled for regular members.

  1. Check your configuration
Open the statistics page and look at the System tab. It verifies your live setup and tells you if anything is inconsistent — a missing database, a shield that can't act, a permission that exposes too much. It is the fastest way to confirm the install is doing what you think it is.

  1. Optional: full datacenter coverage
Out of the box, datacenter detection covers the major cloud providers. For full coverage including smaller hosts and VPN infrastructure, download the free DB-IP ASN Lite database in MMDB format from IP to ASN Lite Free Database Download, decompress it, rename it to dbip-asn-lite.mmdb and upload it via FTP to src/addons/Statistiche/_data/.

⚔️ ACTIVE DEFENSE SHIELDS

AI Shield: Blocks Large Language Model scrapers (ChatGPT, GPTBot, Claude, Perplexity, CommonCrawl) from training on your community's unique content.Junk Shield: Identifies and blocks aggressive commercial crawlers (Ahrefs, Semrush, MJ12), vulnerability scanners (SQLMap, Nmap) and script-kiddie tools (Python requests, Curl).Datacenter Shield: Detects and blocks headless scrapers hiding on cloud IPs even when they perfectly fake a human browser.WordPress Trap: Blocks scanners probing for WordPress paths on domains that don't run WordPress.Emergency Mode: A panic button to block all unknown bots instantly during a DDoS attempt or high-load anomaly.IP Whitelist (with CIDR support): Trusted IPs or entire network ranges that bypass all security checks.

Every shield reports its impact whether it is switched on or not, so you can see what each one is worth before you enable it.

🔬 LIVE TRAFFIC RADAR & AI FORENSICS

Live Traffic Radar: A real-time panel showing the latest accesses — IP, country, hosting provider badge, identity, target URI, hit volume and heuristic trust score, split into tabs for bots, humans and unclassified traffic. Presented as a colour-coded card flow with no horizontal scrolling, and an optional auto-refresh that updates the rows in place.Score reason codes: Every trust score is broken down into the exact signals that produced it, with their individual weights.1-Click IP Ban: Ban an attacker's IP permanently, integrated directly into XenForo's native core firewall (XF:IpMatch).1-Click Whitelist: Caught a legitimate service by mistake? One click marks the address as trusted and restores access immediately.Advanced Spoofing Detection (FCrDNS): Bots faking Googlebot are unmasked via full Forward-Confirmed reverse DNS. Requests claiming to be a Chromium browser without the client hints that browser always sends are flagged as an incomplete browser signature.AI Daily Report: A security report published in your forum each morning, written by Google Gemini from your own traffic.Global Live Threat Map: An animated interactive map visualising intercepted threats in real time.Emergency CSV Export: Export malicious IPs to forward to your host or firewall during an attack, with CSV-injection protection.

🎯 INTELLIGENT TRAFFIC CLASSIFICATION

Authorized Crawlers (Green): Essential traffic like Google, Bing and Yahoo is whitelisted.Social & Tech Bots (Allowed): WhatsApp, Telegram, Facebook and Cloudflare bots are recognised so link previews and services work perfectly.AI & LLM Scrapers (Purple): Identifies bots scraping data for AI training.Aggressive/Unknown Bots (Red): Unclassified traffic or known bad actors are flagged and can be blocked.

⚡ PERFORMANCE & PRIVACY

Ultra-Light Architecture: Heavy database tasks run in a daily background cron; the sidebar widget performs only lightning-fast cached queries, eliminating bottlenecks during peak hours.100% Local Assets — zero external requests: Chart libraries, the interactive map and every country flag are served from your own server. Nothing about your visitors leaves your infrastructure.Smart Glass Mode: Charts support transparency and blur effects that adapt to dark and light themes.Accessibility aware: All animations honour the operating system's "reduce motion" preference.Foolproof Protection: Manual classification buttons auto-disable when a generic browser is detected, preventing accidental bans of real users.

💎 PRO vs FREE

The free version is genuinely useful and will stay that way: statistics, demographics, trends, datacenter trust scoring, the System health check and the Shield Impact counters — so you can see what's hitting your board and exactly what you would be stopping.

But seeing and stopping are different things. A PRO Licence is what turns visibility into defence:

Enable Active Defense Shields (AI, Junk, Datacenter, WordPress Trap, Emergency)Access the Live Traffic Radar, score reason codes, Interactive Map and 1-Click IP BanFull Intrusion Forensics panel (attack classification, targeted paths, per-attempt detail)Full Datacenter Intelligence panel (provider identification, 30-day history, AbuseIPDB lookups)Unclassified traffic clusters and Shared resources panelsAnimated 7-day trend chart in the sidebar widgetUnlock blurred tech stats (Devices, OS, Browsers, Server Load)

Note: detection itself always runs, including on unlicensed installs, and free users see the live counters and activity charts — so every admin can tell that something is happening on their board. Addresses, targeted paths, provider rankings and detail tables require a licence and are never sent to the browser without one.

An honest word: no tool blocks everything, and anyone claiming otherwise is selling you something. Determined attackers on residential proxies remain hard, which is why running this alongside an edge layer such as Cloudflare is the setup I recommend. But for the traffic that actually reaches your server, Pro gives you the complete arsenal rather than just the binoculars.

Actively developed. The best features in this add-on came from users rather than from a roadmap — datacenter detection exists because someone described a scraping problem that couldn't be solved with the tools available at the time. Suggestions and bug reports are genuinely welcome in the discussion thread.

Demo Live: https://migratoria.it (Registration required to view the charts page)

Supports Quiz System PRO, XenForo, and Bob's Article Management System (AMS).

📜 Previous version highlights
  • 1772032270928_1.png
    1772032270928_1.png
    243.2 کیلوبایت · بازدیدها: 0
  • 1772032784213_2.png
    1772032784213_2.png
    187.6 کیلوبایت · بازدیدها: 0
  • 1772032830943_3.png
    1772032830943_3.png
    198.5 کیلوبایت · بازدیدها: 0
  • 1772032868124_4.png
    1772032868124_4.png
    152.4 کیلوبایت · بازدیدها: 0
  • 1772032934775_5.png
    1772032934775_5.png
    94.8 کیلوبایت · بازدیدها: 0
  • 1785535161324_6.png
    1785535161324_6.png
    164.4 کیلوبایت · بازدیدها: 0
  • 1785594527122_7.png
    1785594527122_7.png
    241.7 کیلوبایت · بازدیدها: 0
نویسنده
King
دریافت‌ها
0
بازدیدها
2
اولین انتشار
آخرین بروزرسانی
رتبه‌بندی
0.00 ستاره 0 رتبه‌بندی

فایل‌های بیشتری از King

فایل‌های مشابه
فرستنده فایل عنوان دسته دریافت‌ها آخرین بروزرسانی
Dariush رسمی Advanced search افزونه های رسمی 0
King رسمی Google Adsense Autoads (Advanced) افزونه های رسمی 0
King رسمی [XTR] Advanced Quote Box افزونه های رسمی 1
بالا پایین