In the Sucuri WAF dashboard at waf.sucuri.net, not the WordPress plugin – the plugin scans for malware, the cloud firewall in front of your DNS does the blocking. Check the blocked user agent list and the bot filter settings.

  1. Confirm which Sucuri you have. The Sucuri WordPress plugin alone doesn’t block crawlers. If you don’t have the cloud WAF, the block is at another layer – re-run the check in Blaze AI Discovery to identify it.
  2. waf.sucuri.net → your site → Settings → Access Control. Review the blocked user agents list for AI crawler strings and remove them. If a specific crawler keeps getting challenged, add it to the allowed user agents list.
  3. Settings → Security. Aggressive bot filtering and advanced evasion detection can challenge legitimate verified crawlers. Relax these one notch if step 2 was clean, then re-test before relaxing further – these settings exist for a reason.
  4. Check the real-time logs. Sucuri’s audit trail shows blocked requests with the rule that fired – confirmation beats guessing.
  5. Verify from outside with the plugin’s outside-in check, since your own IP may be allowlisted in the WAF.
Start My Audit