Suspected bots causing 404 errors

You might have received the following notice in your Really Simple Security Dashboard about suspected bots triggering large numbers of “404 Not Found” errors on your site:

If your error logs are filling up with 404 errors and you cannot trace them to real users, you are almost certainly dealing with automated bot traffic. Bots scan WordPress sites constantly, looking for accessible configuration files, outdated plugins, or login pages to attack. 

Most of this traffic is harmless to your site’s day-to-day operations, but it inflates your error logs, wastes server resources, and is an open sign that your site is being scanned for vulnerabilities. Here is how to identify what is happening and what to do about it. 

Why does Really Simple Security detect excessive amounts of 404 pages being triggered?

When a legitimate visitor browses a website, they typically follow links provided on the site or through search engines. While legitimate users could definitely encounter an occasional “404 Not Found” error due to visiting an outdated or incorrect link, they are unlikely to run into excessive amounts of 404 pages, especially within a short timeframe (e.g. 2-10 seconds).

On the contrary, bots and automated scanning tools tend to generate high volumes of 404 errors when they scan websites for vulnerabilities. These tools work by trying to access several pages and files on a site, including pages that do not exist on the website, whereby each failed attempt would generate a 404 Not Found error. This is done in an attempt to discover vulnerabilities in the site’s security which can potentially be exploited.

This is why Really Simple Security detects excessive amounts of 404 pages being triggered, as it is a good indication that a malicious actor is looking for vulnerable parts of your website. Ideally, we would stop those bots from searching our sites, saving some server resources for legitimate users as well.

How to block users that trigger excessive amounts of 404 pages on a site?

The “404 Blocking” firewall rule in Really Simple Security Pro (Security -> Settings -> Firewall) pro-actively blocks IP addresses that exceed the acceptable amount of 404 Not Found pages within a certain timeframe.

The Threshold setting determines the acceptable amount of 404 errors (for example: 10 errors) that can be triggered within a certain timeframe (for example: 10 seconds). If this amount of 404 pages is exceeded, the offending IP address will be blocked for the duration as selected under Lockout Duration.

If you are concerned about locking out legitimate visitors (who trigger large amounts of 404 errors by accident), you can additionally enable the “Trigger Captcha on Lockout” setting. This allows legitimate users who have accidentally been blocked to unblock their IP address by completing a CAPTCHA.

Really Simple SSL Pro - Firewall 404 Blocking Configuration

Really Simple Security blocks malicious bot traffic

The Really Simple Security firewall identifies and blocks suspicious requests automatically — including the bot scans that generate these error log 404s

Simple and Performant Security.


Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate generation.