See what bots and crawlers are doing to your WordPress site.
Salience reads your Kinsta access log through the official API and turns it into verified bot identities, crawl and error analysis, and alerts that name the addresses, paths and user agents involved, with no plugin, no agent and nothing installed on your site.
Any Kinsta plan, live in about five minutes. No plugin, no agent and no DNS or theme changes.
The Log Explorer page for demo-site.example once Kinsta is connected through Kinsta API log pull: the Website setup strip shows Logs Receiving, and the table fills with Googlebot requesting /blog/how-to-choose-a-host, status 200, Verified; GPTBot requesting /category/guides/, status 200, Verified; Googlebot (claimed) requesting /wp-login.php, status 200, Unverified; Bingbot requesting /?s=cheap+hosting, status 200, Crawl waste. Latest 15-minute pull: 6,214 requests.
WordPress sites attract a lot of automated traffic
Every WordPress site on the internet receives the same background hum of login attempts, plugin probes and content scraping. Most owners see none of it, because the only tools they have run inside the browser.
Reading analytics that count human sessions and show nothing at all about the automated traffic, which is frequently the larger share of what your site actually serves.
Installing yet another security plugin to get visibility, which adds load to the site you were trying to protect and still only sees what PHP happens to run for.
Opening the log viewer in MyKinsta when something has already gone wrong, scrolling raw lines, and finding the window you needed has aged out of retention.
Wondering whether Googlebot is wasting its time on /wp-admin, plugin-generated URLs and old archive pages, with no way to check.
See your WordPress traffic sorted into people, bots and crawlers
The access log arrives on a schedule and is classified on the way in: humans, verified crawlers, AI agents and suspicious automation, separated and counted.
The Salience dashboard for demo-site.example, last 24 hours. Website setup 5 of 6 completed. Traffic over time in fifteen-minute buckets, human and bot requests stacked. Bot identity evidence: 12.1K verified requests, 762 unverified claims, 2.7K with verification unknown. Total requests 34.2K, up 7.0% on the previous period. Unique IPs 15.3K, up 2.0%. Bot traffic 45.5%, down 1.9 points. AI crawlers 18.5%, down 8.0 points.
Data arrives every 15 minutes. This is a scheduled pull, not a stream, and the numbers on this page are honest about that.
It works with no plugin installed
No plugin, no agent, no mu-plugin, no theme edit and no DNS change. The connection is an API key and an environment ID, which means nothing about your WordPress install changes, nothing new can break it, and nothing needs updating when WordPress does.
Site Checks on demo-site.example: Checks need attention, 16 Pass, 5 Warn, 1 Fail, 0 Not applicable. Crawler access: robots.txt reliability Failing, AI crawler access Warning, llms.txt availability Warning, Search-crawler rate limits Pass, Googlebot access Pass, robots.txt fetch cadence Pass, Sitemap availability and fetches Pass.
Check that a crawler is who it says it is
Your access log records what each client claimed to be. Salience checks every claimed identity against the provider's own published address ranges, separating genuine Googlebot, Bingbot, GPTBot and ClaudeBot from the scrapers borrowing their names, and lists the impostors with the addresses responsible.
Bots and Crawlers on demo-site.example, last 24 hours: 15,541 bot requests, 12,233 verified, 655 failed verification, 2,653 other status. Served versus rejected: Googlebot 357 served, 34 rejected, Impersonators only, 0 verified · 34 unverified; Amazonbot 3,934 served, 16 rejected, The real bot, 16 verified · 0 unverified; Attack Path Probe 413 served, 104 rejected, Not verifiable, 0 verified · 104 unverified.
See where crawl budget goes on a WordPress site
Crawler time spent on /wp-admin, plugin-generated URL sprawl, redirect chains and 404 ghosts is time not spent on the pages you want indexed. Activity is broken down by section and URL pattern, so the waste is named rather than suspected.
Sitemap Coverage on demo-site.example: 31,041 Total Active URLs, 22,514 Recently Crawled, 7,912 Stale, 615 Never Crawled, 73% Coverage Rate. /category/guides/ first seen 23/01/2026, 135 recorded crawls, last crawled 15h ago by Bingbot, Crawled; /2026/09/how-to-choose-a-host/ first seen 29/04/2026, 1 recorded crawls, last crawled 22/03/2026 by Googlebot Smartphone, Stale; /feed/ first seen 25/02/2026, 2 recorded crawls, last crawled 25/02/2026 by Bingbot, Stale; /wp-sitemap.xml first seen 14/02/2026, 2 recorded crawls, last crawled 14/02/2026 by Googlebot, Stale.
How it works
Connect
Generate an API key in MyKinsta, add it to Salience with your site's environment ID, and you are done. Nothing is installed and nothing about your site changes.
We analyse
Each pulled line is classified against the crawler registry, verified against published provider ranges, grouped by section and compared with your own history, sitemap, robots.txt and Search Console data.
Get answers
Dashboards, alerts by email, Slack or webhook, plain-English querying, an API and a CLI. The first pull runs as soon as the connection is saved.
Specification
- Collection method
- A scheduled pull through the official Kinsta API
- Data freshness
- Every 15 minutes
- Typical setup time
- About 5 minutes
- Plan requirement
- Any Kinsta managed WordPress plan with API access enabled
- Permissions needed
- A Kinsta API key from MyKinsta, plus your site's environment ID
- Code or DNS changes
- None. Nothing installed on the site, no plugin, no DNS change
- Historical import
- Partial. Kinsta retains logs for up to four days; Salience pulls what remains
- Key limitation
- Data arrives on a 15-minute schedule rather than streaming, so detection lags real time accordingly. Only the access log is analysed.
Which of these is you?
WordPress site owners
I have no idea how much of my traffic is bots, or whether any of them are doing something I should worry about.
Automated traffic separated from human, verified against published address ranges, with probe patterns surfaced by name.
Threat intelligence
Agencies managing client sites
I look after a dozen Kinsta sites and I only hear about a problem when the client notices it first.
Every site in one organisation with its own baselines and alerting, so a change surfaces before the phone call.
Site reliability
SEO teams
Is Googlebot spending its time on my content, or on admin paths and plugin URLs nobody wants indexed?
Crawl activity by section and URL pattern, crawl waste, and error spikes caught against your baseline.
Search intelligence
Content and publishing teams
Which AI systems are reading our articles, and are the ones claiming to be GPTBot genuine?
AI crawler activity separated into training, AI-search indexing and user-triggered retrieval, with impostors flagged.
AI access intelligence
Isn't the MyKinsta log viewer enough?
For what it is, it is genuinely handy, and more than many managed hosts provide. MyKinsta gives you a log viewer with the raw access and error logs, and Kinsta APM for tracing slow PHP transactions. If you want to see what is happening right now, or debug a specific slow request, that is the right place and it costs nothing extra. The difference is not access to the data, since Salience reads the same log through Kinsta's own API. It is what happens to it: whether anything is remembered, verified, or watched.
View the raw access log
- MyKinsta and Kinsta APM
- Yes, in the log viewer
- Salience
- Yes, parsed and searchable
Retention
- MyKinsta and Kinsta APM
- Around four days
- Salience
- Retained per plan, months of baseline
Bot identity verified against published ranges
- MyKinsta and Kinsta APM
- User agent taken at face value
- Salience
- Checked against official ranges, 200+ identities
Search and AI crawler interpretation
- MyKinsta and Kinsta APM
- Out of scope
- Salience
- Crawl budget, index context, training versus retrieval
Alerting when something changes
- MyKinsta and Kinsta APM
- You open the viewer and look
- Salience
- 16 detectors, each naming a next step
PHP performance tracing
- MyKinsta and Kinsta APM
- Kinsta APM does this well
- Salience
- Not attempted: different question
Several sites in one view
- MyKinsta and Kinsta APM
- Per site, per environment
- Salience
- Every site in one organisation
When the native tooling is all you need
If you want to tail a log during an incident or find out why one PHP request was slow, MyKinsta and Kinsta APM are the right tools and Salience does not replace them. Salience is for the questions the log viewer cannot answer because it does not remember: what changed since last month, who those clients really were, and whether anyone should have been told.
Facts about the integration
No customer logos and no five-star quotes on this page. These are properties of the product you can check on the free tier in an afternoon.
Illustrative, not a customer incident
A WordPress site receives a steady background of POST requests to /wp-login.php and /xmlrpc.php: thousands a day, all rejected, entirely unremarkable. Then one address starts working through /wp-content/uploads/ instead, systematically, at a rate no human would produce. In the raw log viewer it is indistinguishable from the noise. Against a baseline it is a change worth an alert.
Everything included
One connection, one request stream. No per-feature setup and no second pipeline to maintain.
Verified bot and AI crawler identities
Claimed identities checked against official IP ranges where providers publish them; anything unverifiable is marked unverified rather than guessed at.
Traffic by WordPress section
Admin paths, uploads, plugin-generated URLs, archives and real content tracked as separate areas, so findings land with the section named.
Login and probe detection
/wp-login.php floods, /xmlrpc.php attempts, /.env and config fetches and plugin vulnerability scans, escalated if anything returned a 200.
Crawl budget and coverage
Which pages Googlebot actually reaches, which it never has, and how much of its time goes to paths nobody wants indexed.
Error and status monitoring
2xx through 5xx per path and section, with spike detection against your own baseline rather than a fixed threshold.
History from 30 days to four years
Kinsta keeps its logs for around four days; Salience keeps your history for months, so a baseline actually exists to compare against.
Sitemap and robots.txt context
Fetched and diffed daily, correlated with crawl activity, so a coverage change links back to the edit behind it.
Alerts by email, Slack and webhook
Dashboards, email and Slack alerts, webhooks, a public API, a CLI, an MCP server, CSV exports and shared read-only dashboards.
Recommendations to act on
Addresses to block, fake crawler user agents, 404 paths crawlers keep hitting and slow paths, scored from the last 30 days of alerts, with the sample user agent and paths behind each one.
Saved segments
Page groups you define by prefix, pattern or query string, with a one-click library of common groups, applied to all history and used in every report, alert and export.
Site checks every night
Twenty-one checks on crawler access, security hygiene and serving quality, each pass, warn or fail with the evidence, 30 days of history and an alert when a verdict changes.
Weekly report and daily digest
A weekly email report per site, a daily digest of lower-severity alerts, and email for anything above the severity you set.
Trust & data protection
Privacy and data protectionYou are the controller
We process only on your instructions. GDPR Art. 28 DPA on every account, nothing to sign.
UK data residency
AWS eu-west-2 (London). Encrypted in transit (TLS 1.2+) and at rest (AES-256).
Server-side collection
No browser tracking script and no client-side pixel.
No sale, no pooling
Your logs are never sold, never used for advertising, never shared between customers. DPA, sub-processor list and security overview available.
What is collected
- Timestamp, method, host and path
- Status code and response size
- Client address and user agent
What is never collected
- Kinsta's PHP error log
- Kinsta's cache-performance log
- Request and response bodies
Priced on requests, not seats, with websites included by plan, which suits agencies running many WordPress installs. Start on the free tier with 500,000 requests a month and upgrade when your traffic does.
Crawler intelligence from $19/mo.
Priced on requests, not seats. Unlimited users on every plan except Solo. Start on the free tier and upgrade when your traffic does. Free trial, no card needed.
- 500K requests/mo
- 1 site
- 30 days history
- Unlimited users
- Real-time analytics, bot and AI detection
- 20M requests/mo
- 5 sites (+5)
- 1 year history
- Unlimited users
- Real-time analytics with bot and AI-crawler verification
- 100M requests/mo
- 15 sites (+15)
- 2 years history
- Unlimited users
- AI allowance: ~600 answers or ~60 reports a month
- 500M requests/mo
- 50 sites, no ceiling
- 4 years history
- Unlimited users
- AI allowance: ~3,000 answers or ~300 reports a month
- 1B requests/mo
- Unlimited sites
- Custom history
- Unlimited users
- SSO / SAML and audit log
Common questions
Is this real-time?
No, and we would rather say so than fudge it. Kinsta's API is polled every 15 minutes, so detection lags real time by up to that much. For search, crawler and scraping questions that is entirely sufficient; if you need sub-minute detection, putting Cloudflare in front of the site and using the Cloudflare integration gives you streaming instead.
Do I need to install a plugin?
No. Nothing is installed on the site at all. No plugin, no mu-plugin, no agent, no theme edit and no DNS change. The connection is an API key and an environment ID, so there is nothing that can slow WordPress down or break during an update.
How long does setup take, and do I need a developer?
About five minutes, and no developer. Generate an API key in MyKinsta, paste it into Salience with your environment ID, and the first pull runs immediately. It is the simplest of our integrations.
How far back can I see?
From connection onwards, retained per your plan. On first connection Salience pulls whatever Kinsta still holds, which is up to about four days. That is Kinsta's retention, not ours. From that point your history accumulates in Salience well beyond what the log viewer keeps.
What does Salience get access to?
The access log for the environment you name, read-only. Not your database, not your files, not your WordPress admin, not deployments and not any other environment. The key can be revoked from MyKinsta at any moment.
Does this cover the error log or PHP performance?
No. Salience analyses the access log: the record of requests and what your site answered. Kinsta's PHP error log and cache-performance log are not ingested, and PHP transaction tracing is Kinsta APM's job rather than ours.
I manage several client sites. Does that work?
Yes, and it is a common setup. Each site connects with its own key and environment ID and appears separately in one organisation, with its own baselines and alerting. Pricing is on requests rather than per site, so a portfolio of small WordPress sites does not become expensive.
What happens to our data, and where is it stored?
You are the controller; Salience processes only on your instructions under a GDPR Art. 28 DPA that applies to every account. Data is stored encrypted in AWS eu-west-2 (London), never sold, never used for advertising and never pooled between customers.
Can we remove it later?
Revoke the API key in MyKinsta, or disconnect in Salience. The pull stops immediately, and since nothing was ever installed on the site there is nothing to uninstall.
Your logs already show what Google and the AI crawlers are doing.
Any Kinsta plan, live in about five minutes. No plugin, no agent and no DNS or theme changes.