The problem
More than half of web traffic is now automated (Cloudflare, 2026), and the name in a user-agent string is just text anyone can type. On a brand-new test store linked from nowhere, 14 visits in its first 11 hours claimed to be Googlebot, GPTBot, or ChatGPT and failed their operator's own IP check. Real Googlebot didn't show up in that window.
What Frenemy does
- Names every visitor and checks its claim: wherever Frenemy sees the visitor's real IP (out of the box on Cloudflare, including Shopify stores on their own Cloudflare), a crawler's identity is verified against its operator's own records (published IP ranges or reverse DNS), then marked verified, claimed, or impostor.
- Friend, foe, or frenemy: search crawlers that rank you, assistants fetching for a real customer, training scrapers that take and may give nothing back, and impostors wearing someone else's name.
- A per-crawler ledger: how much each crawler reads (measured bytes on Cloudflare installs; dollars are an estimate at a rate you set) versus the visitors it sends back.
- Rehearse before you block: stage rules in a dry run that shows exactly what would have been blocked, before anything is. Search engines stay off the block list unless you explicitly opt in.
Built to do no harm
Classification runs in-process at the edge in microseconds with zero network calls, and if Frenemy ever fails, your site fails open. Raw IPs are never stored.
Try it
Store owners: a free, no-signup check shows whether AI shopping agents can reach your store (frenemy.dev/store-check). Everyone: a 14-day trial, no card. Plans from $4.99/month per site.


