Back in May, we launched the bot protection tool in MyKinsta to everyone, giving you control over how automated traffic is handled on your site.
Since then, one feedback has come up again and again: knowing how much traffic was being challenged or blocked is useful, but customers want to know what that traffic actually was and where it went once bot protection made a decision about it.
This release is our answer to that. Bot protection’s analytics have been rebuilt to trace every request from classification to outcome, and to make that view available in more places than just the bot protection page itself.
A bot protection widget, right on your site’s dashboard
You no longer need to go looking for your traffic protection numbers. A new bot protection widget now lives in the right-hand column of Sites > sitename > Info, showing a quick breakdown of allowed, challenged, and blocked requests over the last 24 hours at a glance.

It’s a small addition, but it means you can catch a spike in blocked or challenged traffic the moment you land on a site, without navigating anywhere else.
Follow traffic from classification to outcome
The biggest change is to the Request breakdown section on Sites > sitename > Bot protection.
Previously, this page showed a bar chart for how traffic was classified, and another for how bot protection acted on it. Figuring out how the two connected meant doing the math yourself.
Now, a Sankey diagram connects them directly, covering the last 24 hours of traffic. You can see, at a glance, how much of your Likely bots traffic was challenged versus how much of your Malicious traffic was blocked outright, without cross-referencing two charts.

Three new traffic types in the breakdown
We’ve also added three new categories to the breakdown:
- Malicious traffic: the attack, DDoS, and abuse traffic Kinsta has always blocked by default, even before bot protection existed, are now visible in your analytics for the first time.
- Custom rules: traffic affected by exceptions you’ve added in Always Allow, or by any custom WAF rules our Support team has configured for your site.
- WP automations: traffic allowed through because you’ve enabled Allow typical WordPress automations.

Between these additions and the existing categories, you now get a complete picture of everything hitting your site, not just the categories bot protection actively controls.
Find out exactly what’s generating any type of traffic
New Top traffic tables now appear on both Sites > sitename > Bot protection and Sites > sitename > Analytics > Bot traffic, showing the most common paths, user agents, countries, and IPs behind your site’s traffic.

On the bot protection page, this table always reflects the last 24 hours, matching the rest of that page. On the Analytics > Bot traffic page, it follows whatever date range you’ve selected, so you can pull up Top traffic for the past 7, 30, or 90 days, not just the day before.
Use the dropdown above the table to filter by traffic type. For example, switch to Malicious traffic to see exactly which paths are being targeted, or to AI crawlers to see which bots are generating the most requests.

If you’ve ever wanted to know exactly what /wp-login.php or /xmlrpc.php traffic looks like on your site before deciding whether to tighten your protection level, this is where you’ll find it.
Filter the Requests chart by traffic type
Over on Sites > sitename > Analytics > Bot traffic, the Requests chart now includes a traffic type selector. Instead of viewing all traffic types stacked together, you can isolate just the ones you care about.

All traffic types are selected by default, so nothing changes unless you want it to.
Try it out
Bot protection remains a Beta feature, and this analytics refresh is very much part of that ongoing work. We’d love to know whether the new flow chart and Top traffic tables make it easier to understand your site’s traffic.
Let us know what you find, and check our documentation for a full walkthrough of every chart on the page.