Stop needing to be perfect
Hardening only holds if you never miss. Counterprompt works on the bots that get through anyway.
New: deception built for AI attack agents
Attack bots believe whatever your site tells them. Counterprompt catches them on bait, then feeds them instructions that end the attack. Your visitors never notice.
Free WordPress plugin at launch. No credit card. No model to run.
Five moves, one deterministic engine. Turn it on and it works.
Hidden links and robots.txt entries point at decoy paths. People never see them and polite crawlers skip them, so anything that asks is a bot.
GET /wp-content/backup-2019/ IP flagged for 24h
Notices placed where only a model reads them say the host is a staging mirror stuffed with synthetic data. Agents that follow their scope rules stand down.
Agent: target out of scope. Standing down.
For flagged IPs, version fingerprints disappear and user enumeration comes back empty. The agent loses the details it needs to pick an exploit.
GET /wp-json/wp/v2/users 200 OK []
A maze of plausible pages that only link to more maze. Every step costs the attacker tokens, and your server barely notices.
/archive/2019/q3/7/b/c/d/ step 412
The operator receives findings built on synthetic data and dead ends. Pro shows you exactly who took the bait and what they tried.
Report: 0 exploitable findings. Engagement closed.
Hardening only holds if you never miss. Counterprompt works on the bots that get through anyway.
AI agents act on whatever lands in their context window. We give them something worth acting on.
No blocking, no counterattacks, no calls home and nothing taken from the bot. Visitors never notice.
Join the waitlist now and lock in founding member pricing.
$0/forever
The full defense engine for one WordPress site or a hundred.
Founding price
$19/site/mo
Everything in Core, plus the tools to stay ahead.
Running more than WordPress? Counterprompt Edge puts the same defense at the Cloudflare edge, in front of any stack. Contact us
WordPress at launch. More platforms on the way.
| Capability | Typical WAF | Counterprompt |
|---|---|---|
| Stops known exploit signatures | ✓ | – |
| Wastes the attacker’s time and budget | – | ✓ |
| Corrupts the attacker’s findings | – | ✓ |
| Works when you’ve missed a bug | – | ✓ |
| Needs no rule tuning | – | ✓ |
Join the free waitlist and lock in Pro at $19/mo for your first year.
One email when it ships. Unsubscribe anytime.