For automation teams
Understand access.
- Which configurations can access a target?
- What characteristics make my client detectable?
- How do browsers, libraries and network stacks compare?
- Which configuration should I run?
In development · Pre-launch
Test access. Measure detection. Audit protection. Research the web automation landscape.
WhoScrapes is currently in development. No product is available yet.
Both sides of the connection
For automation teams
For website owners
The same benchmark can answer opposite questions depending on which side of the connection you operate.
The platform
Each product answers a different question, from either side of the connection. Use one, or use them together. None of them requires the others.
Two example paths. Examples only: start anywhere and stop wherever you have your answer.
Run
Run will be the execution layer of WhoScrapes: take a tested configuration and run it through a consistent execution environment.
A configuration is more than a library name. "Playwright" says very little about how a request actually looks on the wire. Run treats the whole stack as one versioned unit, so what you tested is what you execute.
Use a configuration discovered in Labs, one you've built yourself, or a known stack you simply want to execute consistently.
Run is execution infrastructure. It is designed to be used on its own, without Labs, Probe or Atlas.
Labs
Labs will be a controlled experimentation environment. It runs many complete configurations under the same conditions and records how each one behaves: the access outcome on one side, the protection outcome on the other.
For automation teams
Labs explores combinations of browser engines, HTTP stacks, runtime settings, network types, sessions and other configuration components to understand which configurations behave differently against a target.
For site owners
With proof of ownership or explicit authorization, Labs can invert the same experiment as synthetic automation testing: which classes of automation can still access my site?
requires Domain verification (DNS TXT record, HTTP verification file, or an account-level ownership workflow). Reports describe automation classes and protection coverage, not site-specific techniques.
Probe
Probe is being built as a benchmarking layer across the bot-protection ecosystem. Test your own browser, scraper, crawler or HTTP client against independent detection techniques and against real protection products wherever direct integration or controlled test environments are available.
The goal is not a single generic "bot score." Probe will show how the same client is classified across different protection systems, signal families and network-intelligence sources.
Product outcomes and independently observed signals are reported separately. A signal WhoScrapes observes is not presented as the reason a product made its decision unless the vendor exposes that information. No source code upload and no SDK required; you do not need WhoScrapes Run to use Probe.
Active protection testing is intended for domains you own or are authorized to test, confirmed through DNS TXT, an HTTP verification file, or an account-level domain ownership workflow.
Different anti-bot systems make different decisions about the same client. Probe is designed to test that difference directly: a standardized benchmark harness for the bot-protection ecosystem, with WhoScrapes' own detectors explaining and complementing the product outcomes.
Examples represent technologies WhoScrapes intends to research or integrate with. No affiliation, partnership or completed integration is implied. Names are trademarks of their respective owners.
A protection system is not a signal. Probe keeps the two apart: the product outcome says what happened, the detection layers help explain it.
| Protection ↓ / Layer → | TLS | Browser | IP | Behavior | Session |
|---|---|---|---|---|---|
| Cloudflare | |||||
| DataDome | |||||
| Akamai | |||||
| AWS |
Four ways a benchmark result can be produced, from strongest to most derived.
The actual protection product evaluates the request. This is the strongest result.
The client is benchmarked against a controlled or authorized environment running the real protection product. This matters for enterprise systems that cannot simply be called through an API. The product is real even when WhoScrapes has no access to its proprietary internal score.
Potential future coverage: Akamai Bot Manager, HUMAN / PerimeterX, F5 / Shape, Imperva, DataDome, Kasada, Radware, Netacea.
WhoScrapes implements an individual detector directly and measures it.
WhoScrapes reproduces a detection family described publicly by a commercial protection vendor.
Modeled results do not claim to reproduce a vendor's proprietary scoring model.
A detection result is only useful if you know what produced it. Probe is designed to label each result with its source.
Native and Controlled are real-product benchmarks.
A browser that passes one protection system may fail another. Probe is intended to make those differences measurable by running the same client against multiple independent protection environments under controlled conditions.
Detection is not limited to browser anti-bot products. Probe plans to compare independent IP and network-intelligence providers too, and the disagreement between them is itself a useful result.
Atlas
Atlas will be the research and intelligence layer of WhoScrapes. It catalogs both sides: what protection the web uses, what automation stacks exist, and how the two interact.
Cloudflare · Akamai · DataDome · HUMAN / PerimeterX · F5 / Shape · Imperva · AWS WAF Bot Control · Fastly · Fingerprint · Google reCAPTCHA · hCaptcha · GeeTest · Arkose Labs · Kasada · Radware · Netacea · Oracle WAF · Azure WAF · Fortinet · Coraza · OWASP CRS · BotD · CreepJS · JA4 · p0f · CrowdSec · IPinfo · MaxMind · Spur · IPQualityScore · GreyNoise · AbuseIPDB
Playwright · Puppeteer · Selenium · WebDriver BiDi · Chrome DevTools Protocol · Scrapy · curl · Python requests · httpx · Go net/http
Technologies Atlas may research, listed for illustration. Names are trademarks of their respective owners; no affiliation, partnership or endorsement is implied.
Atlas records how much is actually known, and says so.
Atlas describes what is publicly observable. It does not claim knowledge of proprietary internal algorithms or of customer-specific security configurations.
Atlas is not only "what protection does the web use?" It also asks what automation stacks exist, and how each class of automation interacts with each class of protection.
Each cell is a research question, not a result. CF Cloudflare · DD DataDome · AK Akamai · AWS AWS WAF.
| Automation ↓ / Protection → | CF | DD | AK | AWS |
|---|---|---|---|---|
| Playwright | ||||
| Puppeteer | ||||
| HTTP clients | ||||
| Browser clouds | ||||
| AI crawlers |
Atlas will track protection vendors, detection techniques, integrations and observed deployments. That research will help determine which products and signal families Probe should benchmark.
When a commercial system is impractical to integrate directly, Atlas research can support a modeled detector or identify opportunities for controlled benchmark environments.
Probe benchmarks will run against WhoScrapes-controlled, partner-provided or explicitly authorized environments, not unrelated third-party sites.
Inside Atlas
Understand the publicly observable automation and protection surface of a website: infrastructure, protection technologies, and how protection appears to be applied across the site, each with an evidence level.
Inspect observes. Probe tests.
Inspect is technology research. It reports what appears to be deployed, never site-specific techniques. When active testing is needed, verified site owners use Probe.
Why WhoScrapes
Most tools measure one side of the connection. WhoScrapes is designed to measure the interaction between them.
Move beyond PASS, BLOCKED, and generic bot scores. The goal is a per-layer explanation, readable from either side.
Anti-bot products do not classify every client the same way. Probe is intended to compare real protection systems, independent detectors and network-intelligence providers using the same automation configuration.
Understand both successful automation and successful protection, from the same measurements.
Repeat the same client and protection tests under the same conditions, and compare changes over time.
Atlas studies automation technology and protection technology with the same evidence standards.
Configurations, not labels
WhoScrapes describes automation as a complete, specific stack, and reports the access outcome and detection results for that exact stack.
Who it's for
WhoScrapes is about benchmarking, interoperability, observability and research into web automation and web protection.
About
WhoScrapes is an engineering and research platform for understanding the interaction between automated clients and web protection. Automation teams can measure access and detection. Site owners can measure protection coverage and exposure. Atlas researches the technologies used by both sides.
WhoScrapes is not a proxy service and not a CAPTCHA-solving product. Active testing of third-party sites is not the purpose of the defensive testing workflow; site-owner protection testing requires ownership or authorization.
Nothing on this page is available yet. Examples are illustrative, and we will publish real results only when they are real.
In development
We're building the first version of Run, Labs, Probe, and Atlas. Join the waitlist if you build web automation, operate protection infrastructure, or want to understand how the two interact.
We'll only email you about WhoScrapes early access. No spam.