TrackingSpamScore · Spam · paid

Find the bots in your Matomo data — and keep them out.

Spots bot traffic by how whole groups of visits behave, shows it per network and blocks it while tracking — server-side.

Latest v0.7.0

What it does for you
01

Catches bots with real browsers

Headless browsers that run JavaScript get past IP-range filters. TrackingSpamScore judges whole groups: sudden, uniform traffic from a hosting network that never interacts stands out, even when each single visit looks normal.

02

Clean numbers from now on

Block networks and IP ranges during tracking — one by one, several at once, or automatically for 7 days once a source reaches the blocking threshold. E-commerce orders always get through.

03

Every decision explained

Each spam source lists the evidence that flagged it, and the visitor log shows score and reasons per visit. Mark visits as bot or human and see precision and detection rate.

04

Built for busy instances

An hourly background analysis on grouped statistics and paged lists that load fast. Everything runs inside your Matomo — no extra JavaScript, no external service.

Click to enlarge

Pricing
Monthly
49 € per month
Buy now
Yearly Popular
490 € per year

save 17 % vs. monthly

Buy now
2 Years
784 € for 2 years

save 33 % vs. monthly

Buy now
No payment details needed — the trial license lands right in your account.
Frequently asked questions

No. It marks visits with a spam score that you can filter by segment, and blocking only affects new tracking requests. To remove spam that was already tracked, the network card gives you the segment for Matomo's GDPR tools.

Automatic blocking is off until you turn it on. It needs several corroborating signals, lasts 7 days and never applies to networks you allowed. A hosting network alone never becomes spam, and e-commerce orders are always tracked.

DB-IP IP to ASN Lite (free, no account, Matomo can update it automatically) or MaxMind GeoLite2-ASN (free with a MaxMind account). The admin page checks the database and explains how to set it up. Without one, only IP ranges are evaluated.

Each tracking request is checked against a cached block list and the network database — a quick lookup. The analysis runs once an hour in the background on grouped statistics.

TrackingSpamPrevention blocks fixed lists such as cloud IP ranges and organisation names. TrackingSpamScore learns from behaviour and also catches networks no list knows yet; it uses TrackingSpamPrevention's organisation list as one of its inputs. Both work together.

Yes. Export all rules as a CSV file and import it there. The import also accepts any CSV with the columns asn and rule, or a plain list of AS numbers, which are then blocked.

Install via the Feinwerk connector
  1. 01 Download the Feinwerk connector and unzip it into your Matomo's plugins/ directory, then activate it.
  2. 02 Open its settings and set the marketplace URL and your instance token.
  3. 03 Open the Feinwerk Plugins screen, find TrackingSpamScore, and click Install.
Download connector plugin
For the technically curious

TrackingSpamScore

TrackingSpamScore finds automated traffic in your Matomo data and keeps it out — including bots that run a real browser with JavaScript and slip past IP-range and datacenter lists. It does not judge single requests. It looks at groups of visits: a network, a network in one country, a device profile within a network, or an IP range. A hosting network whose visits arrive suddenly, all look the same and never interact is spam. A varied crowd from a residential internet provider is not.

Everything runs on your server from data Matomo already stores: no additional JavaScript, no fingerprinting, no external service.

Reports and views

Spam networks report

Visitors › Networks & spam — one row per network (autonomous system) with visits, spam visits, spam rate, highest spam score, share of visits without events, bounce rate and average time on site. It works for every date range and segment like any other Matomo report. Tags show at a glance whether a network is blocked, allowed or a hosting network. Each row opens its visits in the visitor log; super users tick several networks and block or allow them at once.

Spam protection admin page

Administration › System › Spam protection

  • Status: automatic blocking on or off, how many networks and IP ranges are blocked right now, the network database in use and the result of the last analysis.
  • Detected spam sources per website: score, visits, the evidence that flagged the source, when it was last seen and until when it is blocked. Filter by minimum score and by status (blocked / not blocked); tags show whether the network is blocked by a rule or automatically, or only its IP range. Select several sources and block or allow their networks together.
  • Network card: everything about one network — hosting or access network, its rule, its spam sources on all websites, its visits in the visitor log and the segment for deleting them with Matomo's GDPR tools.
  • Network rules: block or allow networks, several AS numbers at once, remove selected rules — and export all rules as CSV and import them again, also on another Matomo.
  • Accuracy: mark visits as bot or human in the visitor log; the page shows the precision and detection rate of your spam threshold.
  • Signal weights: turn each signal off (0) or strengthen it (up to 3).
  • Network database setup: if no usable network database is found, the page says why (missing, unreadable, damaged or still compressed, wrong type) and how to set one up.

Visitor log and segments

Visits with a spam score show it in the visitor log together with the reasons; super users mark them as bot or human right there. The segments spamScore (0–100) and spamAsn (network number) work in every report — for example "all visits without spam" or "only this network".

Blocking

  • Networks and IP ranges you block are not tracked on any website, from the next request on.
  • Automatic blocking (off by default): sources that reach the blocking threshold are blocked for 7 days; the block is extended while they keep sending spam.
  • Allowing a network always wins: it is never flagged or blocked, and its spam scores are cleared with the next analysis.
  • E-commerce orders are always tracked, even from blocked networks and IP ranges, so no revenue is lost.
  • Blocking stops new spam. Visits that were already tracked can be deleted with Matomo's GDPR tools, using the segment shown on the network card.

How the spam classification works

1. Groups of visits

Every hour TrackingSpamScore looks at the recent traffic of each website (by default the last 24 hours) and forms groups:

Group Example
Whole network all visits from one autonomous system
Network in one country visits from that network located in one country
Device profile in a network same browser version, operating system and screen size within one network
IP range IPv4 /24 or IPv6 /48 — used when Matomo's IP anonymisation masks at most one byte

The behaviour signals need a minimum number of visits per group (default 8).

2. Signals

Each signal is measured from 0 to 1 and compared with the website's own normal values, so it adapts to every site.

Primary signals can carry suspicion on their own:

Signal What it measures
Hosting network The network belongs to a hosting or cloud provider: a built-in list, the organisations blocked in Matomo's TrackingSpamPrevention and your own block rules.
Sudden traffic surge Visits in the window against the group's daily median of the last 28 days. It counts from twice the usual volume and is at full strength at six times. Networks that are normally absent count as sudden. Needs three days of history.
Uniform behaviour How little visit duration and number of actions vary within the group. People differ, scripts repeat.

Supporting signals only count together with others:

Signal What it measures
Repeated page loads The same page is loaded again and again within visits.
Unusual country A country that normally brings less than 1 % of the website's traffic suddenly surges.
No interactions No events, although the website's visitors usually trigger some (only if at least 5 % of its visits do).
No campaign traffic No campaign visits, although the website usually receives some (only if at least 5 % of its visits are campaign visits).
Outdated or automated client Typical bot screen sizes (800×600, 1024×768, 0×0, 1×1) or a browser more than two major versions behind the newest one seen.

Relief:

Signal Effect
Purchases E-commerce orders from the group compared with the website's average. At the average rate the score drops by 60 %; a single order among thousands of bot visits hardly changes it.

3. From signals to a score (0–100)

  • Each primary signal adds up to 50 points, each supporting signal up to 12 (all supporting signals together at most 35).
  • A hosting network alone scores at most 40 — company VPNs and cloud proxies are not spam just because of where they come from.
  • Corroboration: 80 or more needs two strong primary signals, or one strong primary signal plus two strong supporting signals. No single signal can turn a group into spam or get it blocked.
  • Purchases then lower the score by up to 60 %.
  • Your signal weights scale each signal (0 = off, 1 = default, up to 3).
  • Networks you block yourself count as 100.

Example: a hosting network suddenly sends twenty times its usual traffic, and all visits last 0–2 seconds with one page view and no events: hosting network + surge + uniform behaviour → 100. A residential provider with varied visits at its normal volume gets no score at all.

4. What the score is used for

  • Groups below 30 are ignored as noise.
  • Each visit gets the score of its strongest group. Scores only rise; allowing a network resets them. Visits with an e-commerce order are never marked.
  • Spam threshold (default 80): visits at or above it count as spam in the report, the accuracy check and the visitor log.
  • Blocking threshold (default 90, at least 80): with automatic blocking on, groups at or above it are blocked during tracking.

Requirements

  • Matomo 5 (5.0 or newer, below 6.0), PHP 8.1 or newer.

  • Matomo's scheduled tasks must run (cron with core:archive, or browser-triggered archiving) — the analysis runs every hour.

  • A network (ASN) database in Matomo's GeoIP directory, which you install and keep up to date yourself:

    • DB-IP IP to ASN Lite — free, no account, CC BY 4.0; Matomo's automatic geolocation updates can download it every month.
    • MaxMind GeoLite2-ASN — free with a MaxMind account.

    The database is not included with the plugin. Without one, only IP ranges are evaluated.

  • Recommended: GeoIp2 as location provider (countries).

Getting started

  1. Install and activate the plugin and set up the network database — the admin page guides you.
  2. Leave automatic blocking off for a few days and look at the spam networks report and the detected sources.
  3. Block obvious hosting networks yourself, several at once if you like.
  4. Mark some visits as bot or human in the visitor log and check precision and detection rate.
  5. Turn on automatic blocking once the accuracy looks right.

Settings

Administration › System › General settings › FeinwerkTrackingSpamScore

Setting Default Purpose
Block detected spam networks automatically off Blocks networks and IP ranges at or above the blocking threshold for 7 days. Your own rules always apply.
Spam threshold 80 Score (30–100) from which visits count as spam.
Blocking threshold 90 Score (80–100) needed for automatic blocking.
Analysis window 24 hours Recent traffic the hourly analysis looks at.
Minimum group size 8 Visits a group needs before it is evaluated.

Privacy

All signals come from data Matomo already stores: network and country from the IP address, visit duration, actions, events, referrer type, browser and device. No additional data is collected and nothing leaves your server. Spam that was already tracked is deleted with Matomo's GDPR tools.

License

Commercial plugin under the Feinwerk EULA.