Eleven of Loghound’s 26 rules carry 80 points or more. Eighty is the bot threshold, so each of these is a claim that this one piece of evidence is enough to call a visit a bot.
The bold name is the label the panel shows; the code below it is what a filter URL and the stored data carry. The other fifteen rules are on Rules that stack.
The page exposed a driver artefact: the webdriver flag, a chromedriver global, or a Puppeteer, Playwright or Selenium hook. Browsers do not have these; drivers do. A page cannot acquire them by accident.
It said it was a bot and it was telling the truth. Verdict bot, threat none. Honest crawlers explains why these are kept apart.
The User-Agent is neither a browser a person uses nor a declared crawler: an empty header, a bare Mozilla/5.0, WordPress/6.4.3, a home-made client. The browser list covers desktop, mobile, regional, in-app, text-mode, TV, console and feature-phone browsers, and it errs towards “browser”. A log format that does not record the User-Agent is never judged by it.
It declared itself a major search crawler and forward-confirmed reverse DNS did not back that up. This is impersonation, checked the way the search engines themselves document.
WebGL reported a software renderer (SwiftShader, llvmpipe, Mesa OffScreen or Microsoft Basic Render), which is what you get when there is no screen. Not 100, because a virtual machine or a remote desktop can land here too.
The time on page the beacon claimed is impossible against the moment its own token was issued, by more than five seconds. Within that margin the number is quietly corrected, because a busy browser can overshoot honestly. The lie is kept as evidence.
The browser engine lacks a feature that shipped in the version the User-Agent claims, or has one that shipped after it, with two versions of grace either way. iOS browsers are skipped. A spoofed User-Agent cannot change what the engine can do. Browser claim probes.
The visit asked for something no browser requests by accident: a sensitive file, a command injection, a JNDI lookup, a server-side fetch or cloud metadata address, a known exploit path, program code as a path, a scanner User-Agent, a crawler impersonation, or one of your attack patterns. Noisier patterns are shown on the Attacks view but are not a verdict alone.
Your site answered a request that matched an attack pattern with a 403 or a 406: its own defences refused it and the detector names it a probe. Sign-in requests do not count, because a person can be refused at a login form.
Five or more different addresses shared this exact header fingerprint within 24 hours, not on mobile networks, and it is not a crawler that passed its reverse DNS check. One client, many exits.
Your site refused every request this client made and served it nothing: no page, no redirect, not one byte of body. Sign-in challenges (401, 407) and rate limits (429) alone do not count.
Sec-CH-UA mismatch (75) and Platform mismatch (70) are weighted below 80, but a User-Agent its own client hints contradict always makes the verdict bot. They are on Rules that stack.