In the Sucuri WAF dashboard at waf.sucuri.net, not the WordPress plugin – the plugin scans for malware, the cloud firewall in front of your DNS does the blocking. Check the blocked user agent list and the bot filter settings.
- Confirm which Sucuri you have. The Sucuri WordPress plugin alone doesn’t block crawlers. If you don’t have the cloud WAF, the block is at another layer – re-run the check in Blaze AI Discovery to identify it.
- waf.sucuri.net → your site → Settings → Access Control. Review the blocked user agents list for AI crawler strings and remove them. If a specific crawler keeps getting challenged, add it to the allowed user agents list.
- Settings → Security. Aggressive bot filtering and advanced evasion detection can challenge legitimate verified crawlers. Relax these one notch if step 2 was clean, then re-test before relaxing further – these settings exist for a reason.
- Check the real-time logs. Sucuri’s audit trail shows blocked requests with the rule that fired – confirmation beats guessing.
- Verify from outside with the plugin’s outside-in check, since your own IP may be allowlisted in the WAF.