96.3% anti-bot pass rate. $0 in proxies.
- 96.3%
- Pass rate, 26 of 27 live sites
- $0
- Spent on proxies. Own engine, no per-page fees
- ~2.2s
- Median latency (p50) across the run
How we measured it
What we ran, including the one site we did not clear.
27 real sites, 22 of them protected
Live production sites behind commercial anti-bot vendors (DataDome, Akamai, PerimeterX, Cloudflare, Amazon, Imperva) plus in-house-protected directory and social sites. The remaining 5 rows are unprotected controls (example.com, the toscrape sandboxes, Wikipedia, Hacker News) that catch a broken test setup. All 27 count toward the headline; the controls all passed.
Paced like a real client
Requests are paced to behave like a real client. The free-tier rate limiter caps at 10 requests a minute by design. Reproduce with
--concurrency 1 --delay 4000.Block detection
A site counts as passed only when the response clears both an HTTP-status check and a content-fingerprint check for known block and challenge pages.
Dated and reproducible
Run on 2026-06-23. The script and the raw per-site rows are published, so anyone can re-run it.
Results by anti-bot vendor
The pass rate against each vendor, from the raw run.
| Vendor | Pass rate | Sites |
|---|---|---|
| DataDome | 4/4 | Vinted · SeLoger · Footlocker · Leboncoin |
| Akamai | 4/4 | Nike · Best Buy · Kayak · Etsy |
| PerimeterX | 3/3 | Zillow · Walmart · Ticketmaster |
| Cloudflare | 5/5 | G2 · Indeed · Glassdoor · Patreon · Crunchbase |
| Amazon | 1/1 | Amazon product page |
| Imperva | 1/1 | Target |
| In-house / other | 3/4, one failure | Yelp · Yellow Pages · Instagram · X. Includes the one failure below |
| No vendor (controls) | 5/5 | example.com · books.toscrape · quotes.toscrape · Wikipedia · Hacker News |
The rows above sum to the headline: 22 sites behind a commercial anti-bot vendor plus 5 unprotected controls is 27 sites, 26 of which passed. Controls are listed so you can check the arithmetic. Every row comes from bench-clean.json.
The one we did not clear: yellowpages.com
Reproduce it
The benchmark script is scripts/benchmark-antibot.mjs, published here verbatim. It targets a live deployment, walks the site list and writes the raw per-site rows (URL, vendor, status, latency, pass or fail) this page reports on. The exact output of the 2026-06-23 run is at /bench-clean.json so you can diff your run against ours.
node scripts/benchmark-antibot.mjs --concurrency 1 --delay 4000
# Expected output shape:
# { "overall": 96.3, "passed": 26, "total": 27, "p50Ms": 2171,
# "rows": [ { "url": "...", "vendor": "datadome", "pass": true, "ms": 2255, "status": 200 }, ... ] }The free-tier rate limiter caps at 10 requests a minute by design, so pace the run with --concurrency 1 --delay 4000. A faster run gets 429 responses from the limiter. Those are rate limits on your key and say nothing about the sites.
Run history
One run so far. This page gets a new row every time the benchmark is re-run against a deployed build.
| Date | Score | Commit |
|---|---|---|
| 2026-06-23 | 96.3% (26/27) | 06d7e53 |
What this doesn't prove
- Small sample
- n=27. Enough to say something about the major anti-bot vendors. Too few to promise a percentage on a site we have never tested.
- No residential-proxy targets
- The suite has no sites that need a residential IP to reach at all (for example Mercado Libre). Those need a paid proxy provider, and this run measured the free-tier engine alone.
- Benchmark ≠ SLA
- A point-in-time measurement. It is no uptime or success-rate guarantee. Sites change their defenses, and a pass today does not promise a pass on every future request.
- Our own run, unaudited
- We ran this against our own deployment, and no third party checked it. The script is published so you can re-run it yourself.
Run the hard sites yourself
Paste a protected URL into the playground and see how it was fetched. Create a key, or let your agent mint its own. No card and no sales call.