In development · Pre-launch

Understand web automation
from both sides.

Test access. Measure detection. Audit protection. Research the web automation landscape.

01 Can automation access it? 02 What detects the automation? 03 What gets through your protection?

WhoScrapes is currently in development. No product is available yet.

Both sides of the connection

One platform. Two perspectives.

For automation teams

Understand access.

  • Which configurations can access a target?
  • What characteristics make my client detectable?
  • How do browsers, libraries and network stacks compare?
  • Which configuration should I run?

For website owners

Understand exposure.

  • Which types of automation can access my site?
  • What does my current protection detect?
  • Which client classes still get through?
  • Where are my protection gaps?
  • How does my protection stack compare with the wider web?

The same benchmark can answer opposite questions depending on which side of the connection you operate.

Automation teams ask: "What detects me?" Website owners ask: "What am I detecting?"

The platform

Four products. One measurement layer.

Each product answers a different question, from either side of the connection. Use one, or use them together. None of them requires the others.

Run Execute a complete, tested configuration consistently.
Labs Experiment with configurations and measure both access outcome and protection coverage.
Probe Benchmark your client across protection systems and detection layers, or test your own site's protection against controlled automation.
Atlas Research the automation and protection technologies used across the web.
Atlas / Inspect Observe which technologies appear to be deployed on a supplied site.
WHOSCRAPES
Atlas Automation + protection intelligence
Labs Compare configurations Test protection coverage
Probe Benchmark across protection systems Measure detection layers
Run Execute known configurations
Each product stands on its own. There is no required order.

Two example paths. Examples only: start anywhere and stop wherever you have your answer.

Automation team
  1. InspectInspect target
  2. AtlasResearch its stack
  3. ProbeProbe my client
  4. LabsCompare configurations
  5. RunRun the chosen one
Website owner
  1. InspectInspect my site
  2. AtlasCompare with the web
  3. ProbeProbe my protection
  4. LabsCoverage testing
  5. RepeatMonitor and re-test

Run

Run configurations that work.

Run will be the execution layer of WhoScrapes: take a tested configuration and run it through a consistent execution environment.

A configuration is more than a library name. "Playwright" says very little about how a request actually looks on the wire. Run treats the whole stack as one versioned unit, so what you tested is what you execute.

Use a configuration discovered in Labs, one you've built yourself, or a known stack you simply want to execute consistently.

Run is execution infrastructure. It is designed to be used on its own, without Labs, Probe or Atlas.

configuration =
  • engineBrowser or HTTP engine
  • versionExact engine and library versions
  • launchLaunch flags and runtime options
  • networkTLS, HTTP/2 and HTTP/3 stack
  • headersHeader order, values and Client Hints
  • fingerprintBrowser fingerprint and profile
  • egressProxy and network configuration
  • sessionCookies and persisted session state
  • navigationNavigation and pacing strategy
  • runtimeOther environment settings

Labs

Find out what works.

Labs will be a controlled experimentation environment. It runs many complete configurations under the same conditions and records how each one behaves: the access outcome on one side, the protection outcome on the other.

01 Target https://target.example/
02 10–100 configurations
03 Controlled benchmark Same target, same conditions, repeated runs
04 Outcomes Access and protection, per configuration

For automation teams

Configuration compatibility

Labs explores combinations of browser engines, HTTP stacks, runtime settings, network types, sessions and other configuration components to understand which configurations behave differently against a target.

  • Which configurations reach the intended content?
  • Which browser/library combinations behave differently?
  • Which configuration change affected the result?
  • Is the failure associated with networking, browser behavior, session state or another layer?
PlaywrightPuppeteerSeleniumChromiumFirefoxWebKitMobile browsersHTTP clientsTLS / network stacksProxy typesHeadersBrowser configurationsSession strategiesOther libraries & techniques

For site owners

Protection coverage

With proof of ownership or explicit authorization, Labs can invert the same experiment as synthetic automation testing: which classes of automation can still access my site?

Plain HTTP clientsBrowser automationDifferent browser enginesDatacenter networkingResidential networkingPersistent sessionsRotating sessionsTransport fingerprintsRuntime characteristics
labs · protection coverage Illustrative · mock data
Automation class
Basic HTTP clientBLOCKED
Default browser automationBLOCKED
Persistent browser sessionBLOCKED
Residential browser clientALLOWED
Rotating session clientALLOWED
Potential gaps
Network / identity correlationWEAK
Session continuity analysisWEAK
Browser automation detectionSTRONG
Datacenter reputationSTRONG

requires Domain verification (DNS TXT record, HTTP verification file, or an account-level ownership workflow). Reports describe automation classes and protection coverage, not site-specific techniques.

Probe

See what sees your bot.Or see what your protection misses.

Probe is being built as a benchmarking layer across the bot-protection ecosystem. Test your own browser, scraper, crawler or HTTP client against independent detection techniques and against real protection products wherever direct integration or controlled test environments are available.

The goal is not a single generic "bot score." Probe will show how the same client is classified across different protection systems, signal families and network-intelligence sources.

your stack Your client Scraper, crawler, browser, HTTP client or agent, unmodified
benchmark harness WhoScrapes Probe Protection systems, open detectors and WhoScrapes detectors evaluate the same session
result Comparison report Product outcomes, plus a per-layer diagnostic explanation
probe · client report Illustrative · not real data
Protection systems
Protection AnativePASS
Protection BcontrolledCHALLENGED
Protection CcontrolledBLOCKED
Protection DnativePASS
Protection EcontrolledUNKNOWN
Detection layers
TLS / transportimplementedPASS
HTTP/2 consistencyimplementedPASS
Browser automationmodeledDETECTED
CDP instrumentationimplementedDETECTED
Browser integritymodeledPASS
IP reputationimplementedDETECTED
Session behaviorimplementedPASS

Product outcomes and independently observed signals are reported separately. A signal WhoScrapes observes is not presented as the reason a product made its decision unless the vendor exposes that information. No source code upload and no SDK required; you do not need WhoScrapes Run to use Probe.

Benchmark across protection systems.

Different anti-bot systems make different decisions about the same client. Probe is designed to test that difference directly: a standardized benchmark harness for the bot-protection ecosystem, with WhoScrapes' own detectors explaining and complementing the product outcomes.

target coverage Planned · not live
  • Commercial bot managementPlanned
  • WAF / edge protectionPlanned
  • CAPTCHA & active challengesPlanned
  • Device / fraud intelligencePlanned
  • IP & network intelligencePlanned
  • Open-source detectorsPlanned
  • WhoScrapes atomic detectorsIn development
Your client
Real productsNative & controlled
Open detectorsPublic tools & rulesets
WhoScrapesImplemented & modeled
Comparison report

Example research and integration targets

Bot management & WAF
Cloudflare Bot Management · AWS WAF Bot Control · DataDome · Akamai Bot Manager · HUMAN / PerimeterX · F5 / Shape · Imperva · Vercel BotID · Kasada · Radware · Netacea
CAPTCHA & challenges
Google reCAPTCHA · hCaptcha · Arkose Labs
Device intelligence
Fingerprint
IP & network intelligence
MaxMind · IPinfo · Spur · IPQualityScore · GreyNoise · AbuseIPDB · CrowdSec · other reputation and proxy datasets
Open-source detectors
BotD · CreepJS · OWASP CRS · Coraza · JA4 · p0f

Examples represent technologies WhoScrapes intends to research or integrate with. No affiliation, partnership or completed integration is implied. Names are trademarks of their respective owners.

Which products react? Which signals fire?

A protection system is not a signal. Probe keeps the two apart: the product outcome says what happened, the detection layers help explain it.

Protection systems
CloudflareAkamaiDataDomeAWS WAF Bot ControlHUMANF5 / ShapeImpervaFingerprintreCAPTCHAhCaptchaArkoseKasada…
Detection layers
NetworkTLSHTTP/2HeadersBrowser runtimeAutomationDevice fingerprintBehaviorSessionIP reputationChallengesWAF
Conceptual only · not a claim about proprietary vendor implementations
Protection ↓ / Layer →TLSBrowserIPBehaviorSession
Cloudflare
DataDome
Akamai
AWS

How protection coverage will work.

Four ways a benchmark result can be produced, from strongest to most derived.

NativeReal product

The actual protection product evaluates the request. This is the strongest result.

  • Vendor API
  • Vendor SDK
  • A WhoScrapes-controlled hostname configured behind the product
  • A supported edge / WAF integration
Example format
Protection system A
SourceNATIVE
OutcomeCHALLENGED
ControlledReal product

The client is benchmarked against a controlled or authorized environment running the real protection product. This matters for enterprise systems that cannot simply be called through an API. The product is real even when WhoScrapes has no access to its proprietary internal score.

  • Operated by WhoScrapes
  • Provided by a benchmark partner
  • Explicitly authorized for benchmarking

Potential future coverage: Akamai Bot Manager, HUMAN / PerimeterX, F5 / Shape, Imperva, DataDome, Kasada, Radware, Netacea.

PASSCHALLENGEDBLOCKEDSOFT BLOCKUNKNOWN
Implemented

WhoScrapes implements an individual detector directly and measures it.

JA4 / TLSHTTP/2Header consistencyBrowser / runtime consistencyCDP instrumentationJavaScript integrityWebGL / Canvas / deviceBehavioral measurementsSession continuityIP / network classificationHoneypot behaviorWAF rules
Modeled

WhoScrapes reproduces a detection family described publicly by a commercial protection vendor.

Browser inconsistencyAutomated-browser signalsToken / session reuseSuspicious navigationEnvironment spoofingCoordinated activitySensor tamperingUnusual request signatures

Modeled results do not claim to reproduce a vendor's proprietary scoring model.

Signal families Probe is designed to cover

Transport & protocol

  • TLS fingerprints
  • HTTP/2 and HTTP/3 fingerprints
  • Request and header consistency
  • Crawler authentication

Browser & runtime

  • Browser fingerprinting
  • Browser environment consistency
  • Automation framework artifacts
  • CDP / browser instrumentation
  • JavaScript integrity
  • Canvas, WebGL, WebGPU
  • Fonts, audio, device characteristics

Behavior & session

  • Behavioral signals
  • Navigation patterns
  • Session continuity
  • Request velocity
  • Coordinated activity
  • Honeypot links

Challenges & rules

  • Active JavaScript challenges
  • Proof-of-work challenges
  • WAF rules

Network & reputation

  • IP reputation
  • VPN, proxy, datacenter detection
  • ASN / network reputation

Every result says where it came from.

A detection result is only useful if you know what produced it. Probe is designed to label each result with its source.

Native and Controlled are real-product benchmarks.

Native
The actual vendor product or API evaluated the request.
Controlled
A real protection product evaluated the client in a WhoScrapes-controlled or explicitly authorized benchmark environment.
Implemented
WhoScrapes implements and measures the detector itself.
Modeled
WhoScrapes implements a comparable signal family based on public vendor documentation and research.
Observed
The result comes from publicly observable behavior or research rather than direct access to the protection system.

One client. Many protection stacks.

A browser that passes one protection system may fail another. Probe is intended to make those differences measurable by running the same client against multiple independent protection environments under controlled conditions.

Your browser
  • Protection system A
  • Protection system B
  • Protection system C
  • Protection system D
  • IP intelligence provider A
  • IP intelligence provider B
  • WhoScrapes detector suite
Comparison report
probe · network classification Illustrative · not real data
Provider AResidential proxy
Provider BResidential
Provider CProxy
Provider DClear

Detection is not limited to browser anti-bot products. Probe plans to compare independent IP and network-intelligence providers too, and the disagreement between them is itself a useful result.

Atlas

Map the automation and protection landscape.

Atlas will be the research and intelligence layer of WhoScrapes. It catalogs both sides: what protection the web uses, what automation stacks exist, and how the two interact.

Protection intelligence

  • Anti-bot vendors
  • WAF providers
  • CAPTCHA and challenge systems
  • Browser fingerprinting
  • Fraud and device intelligence
  • IP intelligence
  • Open-source detection tools
  • Detection algorithms
  • Observed deployments

Automation intelligence

  • Browser automation libraries
  • HTTP client libraries
  • Crawling frameworks
  • Browser infrastructure platforms
  • Network stacks
  • Browser / runtime configurations
  • Crawler identities
  • Authenticated bots
  • AI agents and crawlers
  • Known automation signatures
  • Transport / client fingerprints

Example research subjects

Cloudflare · Akamai · DataDome · HUMAN / PerimeterX · F5 / Shape · Imperva · AWS WAF Bot Control · Fastly · Fingerprint · Google reCAPTCHA · hCaptcha · GeeTest · Arkose Labs · Kasada · Radware · Netacea · Oracle WAF · Azure WAF · Fortinet · Coraza · OWASP CRS · BotD · CreepJS · JA4 · p0f · CrowdSec · IPinfo · MaxMind · Spur · IPQualityScore · GreyNoise · AbuseIPDB

Playwright · Puppeteer · Selenium · WebDriver BiDi · Chrome DevTools Protocol · Scrapy · curl · Python requests · httpx · Go net/http

Technologies Atlas may research, listed for illustration. Names are trademarks of their respective owners; no affiliation, partnership or endorsement is implied.

Observed is not the same as inferred.

Atlas records how much is actually known, and says so.

Verified
Public vendor or customer documentation confirms it.
Observed
Distinct technical behavior or signatures were observed.
Inferred
Available evidence strongly suggests the technology or capability.
Unknown
Not enough evidence to say.

Atlas describes what is publicly observable. It does not claim knowledge of proprietary internal algorithms or of customer-specific security configurations.

The research value is in the relationship.

Atlas is not only "what protection does the web use?" It also asks what automation stacks exist, and how each class of automation interacts with each class of protection.

Each cell is a research question, not a result. CF Cloudflare · DD DataDome · AK Akamai · AWS AWS WAF.

Concept · no benchmark data
Automation ↓ / Protection →CFDDAKAWS
Playwright
Puppeteer
HTTP clients
Browser clouds
AI crawlers

Atlas researches the ecosystem. Probe benchmarks against it.

Atlas will track protection vendors, detection techniques, integrations and observed deployments. That research will help determine which products and signal families Probe should benchmark.

When a commercial system is impractical to integrate directly, Atlas research can support a modeled detector or identify opportunities for controlled benchmark environments.

Probe benchmarks will run against WhoScrapes-controlled, partner-provided or explicitly authorized environments, not unrelated third-party sites.

  1. AtlasResearch protections
  2. ProbeBenchmark clients
  3. AtlasRecord observed behavior

Inside Atlas

Inspect a website.

Understand the publicly observable automation and protection surface of a website: infrastructure, protection technologies, and how protection appears to be applied across the site, each with an evidence level.

Inspect observes. Probe tests.

Inspect is technology research. It reports what appears to be deployed, never site-specific techniques. When active testing is needed, verified site owners use Probe.

inspect example.com Concept · not a live service
Infrastructure
Edge / CDN · CloudflareHigh confidence
HTTP/3 advertisedObserved
Protection
Bot protection · DataDomeObserved
Client-side fingerprintingObserved
Device challengeObserved
Rate limiting · possibleInferred
Automation surface
Protection varies by site areaInferred
Known crawler handlingObserved
Crawler authenticationUnknown

Why WhoScrapes

Most tools look at one side.

Most tools measure one side of the connection. WhoScrapes is designed to measure the interaction between them.

Automation Can I access the site?
WhoScrapes Measures the interaction.
Protection Can I identify or stop the automation?

Transparent diagnostics

Move beyond PASS, BLOCKED, and generic bot scores. The goal is a per-layer explanation, readable from either side.

Typical result
BLOCKED
WhoScrapes result Illustrative
TransportPASS
Browser consistencyFAIL
Automation artifactsFAIL
IP reputationPASS
BehaviorPASS

Cross-vendor benchmarking

Anti-bot products do not classify every client the same way. Probe is intended to compare real protection systems, independent detectors and network-intelligence providers using the same automation configuration.

Access + exposure

Understand both successful automation and successful protection, from the same measurements.

Reproducible benchmarking

Repeat the same client and protection tests under the same conditions, and compare changes over time.

Neutral research

Atlas studies automation technology and protection technology with the same evidence standards.

Configurations, not labels

"Playwright" is not a configuration.

WhoScrapes describes automation as a complete, specific stack, and reports the access outcome and detection results for that exact stack.

Illustrative example · mock data · not a live benchmark
config
  • Playwright / Chromium 152
  • Linux
  • HTTP/2
  • Residential network
  • FR region
  • Persistent session
  • Standard browser profile
access outcome
Search targetPASS
Marketplace targetPASS
Retail targetCHALLENGE
detection
TLS consistencyPASS
HTTP/2 fingerprintPASS
Automation signalDETECTED
Browser integrityPASS
IP reputationPASS

Who it's for

Built for teams on both sides of web automation.

WhoScrapes is about benchmarking, interoperability, observability and research into web automation and web protection.

Automation

  • Scraping infrastructure companies
  • Browser automation platforms
  • Data providers
  • Search and indexing companies
  • AI agent developers
  • SEO and data intelligence platforms
  • Proxy and network providers
  • Crawler developers
  • Teams maintaining browser automation

Protection

  • Website owners
  • Ecommerce platforms
  • Marketplaces
  • Publishers
  • Security engineering teams
  • Bot-management vendors
  • WAF and security providers
  • Fraud and risk teams
  • Infrastructure and CDN teams
  • QA and resilience teams

About

An engineering and research platform.

WhoScrapes is an engineering and research platform for understanding the interaction between automated clients and web protection. Automation teams can measure access and detection. Site owners can measure protection coverage and exposure. Atlas researches the technologies used by both sides.

WhoScrapes is not a proxy service and not a CAPTCHA-solving product. Active testing of third-party sites is not the purpose of the defensive testing workflow; site-owner protection testing requires ownership or authorization.

Nothing on this page is available yet. Examples are illustrative, and we will publish real results only when they are real.

In development

WhoScrapes is being built now.

We're building the first version of Run, Labs, Probe, and Atlas. Join the waitlist if you build web automation, operate protection infrastructure, or want to understand how the two interact.

We'll only email you about WhoScrapes early access. No spam.

I work primarily on optional
Primary interest optional