Seatext library / BotRefund evidence
Can BotRefund Detect Headless Browsers in Real Time?
Yes. BotRefund evaluates each request as it arrives, running over 100 independent checks — including tests for headless frameworks like Playwright and Puppeteer — and feeds the combined evidence into an AI model that...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Yes, BotRefund can detect headless browsers in real-time and block them before they access your site. As soon as a visitor lands on a protected page, the system runs over 100 independent checks in the browser and returns a verdict within milliseconds. This allows you to block, challenge, or log headless traffic before the visitor sees any content.
How real-time headless detection works
When a visitor hits a page protected by BotRefund, a script runs immediately in the browser. That script executes a set of checks — over 100 of them — that probe the JavaScript environment, rendering behavior, input timing, hardware fingerprints, and network context. Several checks target artifacts left by headless automation frameworks. For example, the Playwright Init Scripts check looks for mismatches in browser APIs that automation tools patch or hide. The Clean Context Iframe check verifies whether the browsing context behaves like a genuine user session. The Scrollbar Width Leak check captures timing and movement patterns that scripts struggle to replicate. Each check produces one independent piece of evidence, not a final verdict.
Headless browsers often have subtle differences from regular browsers. They may expose APIs that normal browsers hide, or they may miss properties that real browsers include. The scrollbar width test works because headless browsers sometimes render scrollbars differently or omit them entirely. The context iframe test finds inconsistencies when automation tools try to mask their presence. These checks are effective because they rely on low-level browser behavior that is hard to fake.
From signals to a verdict in milliseconds
All 100+ signals stream into BotRefund's prediction AI as the session unfolds. The model weighs the complete pattern across browser, network, device, and behavior dimensions instead of trusting any single rule. A lone anomaly — such as a missing permission or an unusual scrollbar width — is kept as evidence and cross-checked against the other signals. Only when multiple independent indicators align does the system classify the visit as automated. This corroboration approach drives the reported 99% detection confidence.
The AI model uses machine learning trained on millions of human and bot sessions. It learns to recognize patterns that are common in headless traffic but rare in real users. For example, headless browsers often have identical screen resolutions, consistent user-agent strings, and no typical mouse jitter. The model sees these patterns and flags the session as automated.
What the system actually blocks
BotRefund distinguishes between detection and enforcement. The real-time engine identifies headless browsers, scrapers, click-farm traffic, and other automated visitors. Customers can then choose to block, challenge (CAPTCHA, proof-of-work), throttle, or simply log and report those sessions. The same evidence package — click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning — is formatted into refund-ready reports that Google and Meta reviewers accept.
Practical scenarios include a competitor using a Puppeteer script to scrape your pricing page every hour. BotRefund detects the headless browser on the first request and blocks it. Or a click farm running headless Chrome instances to click on ads. The system catches the automated behavior and prevents the clicks from being counted as legitimate.
Why a single check is never enough
Privacy extensions, VPNs, corporate proxies, and uncommon devices can each produce one odd signal that looks bot-like in isolation. BotRefund's architecture treats every signal as "evidence, not a verdict." The AI only flags a session when the cluster of independent checks tells a consistent automation story. This reduces false positives that would otherwise block real customers on restrictive networks or privacy-hardened browsers.
For example, a user behind a corporate VPN might have a mismatched IP and location. That alone would not trigger a bot verdict. The AI waits for additional signals like missing screen orientation or unnatural mouse movement before classifying the session as automated.
Limitations and edge cases
- Sophisticated residential botnets that run on real devices with real browsers can mimic human behavior closely enough to evade some client-side checks. BotRefund mitigates this by adding network reputation, hardware consistency, and behavioral biometrics, but no system catches 100% of advanced threats.
- First-page latency: the client-side script must load and execute. On extremely slow connections or when a visitor closes the tab instantly, the full signal set may not be collected.
- Non-browser traffic: API abuse, mobile app fraud, and server-to-server click spam fall outside the browser fingerprinting scope and require separate server-side controls.
- Headless browsers using stealth plugins: Some automation tools use stealth plugins to hide their presence. BotRefund's multiple checks still catch inconsistencies because stealth plugins cannot fix every low-level browser difference.
Key facts
| Capability | Detail | Source |
|---|---|---|
| Independent checks per session | 106+ documented checks including Playwright Init Scripts, Clean Context Iframe, Scrollbar Width Leak, and behavioral biometrics | S1, S3, S4 |
| Detection confidence | 99% accuracy reported across browser, network, device, and behavior signals | S1, S2 |
| Real-time evaluation | Client-side script runs on page load; AI verdict returned before full page render | S2 |
| Refund-ready reporting | Click IDs, campaign data, timestamps, session recordings, signal-by-signal reasoning in Google/Meta format | S2 |
| Client recovery rate | 83% of 2,500+ audited brands recovered funds from Google and Meta | S2 |
| False-positive mitigation | Each signal kept as evidence; verdict requires cross-checked corroboration | S1, S3, S4 |
Frequently asked questions
Does BotRefund block headless browsers automatically, or do I configure the response?
You choose the enforcement action: block, challenge, throttle, or log-only. The detection verdict is real-time; the response policy is configurable per campaign or site section.
Can it detect Puppeteer, Selenium, and Playwright equally well?
Yes. The check library includes framework-specific traps (e.g., Playwright Init Scripts) plus generic automation artifacts (Clean Context Iframe, navigator.webdriver, permission inconsistencies) that cover all major headless drivers.
What if a real user triggers one of the headless checks?
A single triggered check is not a verdict. The AI requires multiple independent signals to align before classifying a session as bot traffic. Privacy tools and unusual setups rarely produce a full cluster of automation indicators.
How fast is the verdict returned?
The client-side script executes in parallel with page load. The AI evaluation completes in milliseconds, so enforcement (block/challenge) can happen before the visitor sees content.
Does the script affect Core Web Vitals or page speed?
The script is designed to be non-blocking and runs asynchronously. Exact performance impact depends on your page composition; BotRefund provides a free audit so you can measure it on your own site.
Can I use BotRefund alongside Cloudflare or a WAF?
Yes. BotRefund operates at the marketing/analytics layer, preserving attribution and producing refund evidence. Edge WAFs handle DDoS and infrastructure threats; the two layers complement each other.
How does BotRefund's detection differ from simple user-agent checks?
User-agent checks are easy to spoof. BotRefund uses multiple behavioral and browser-level tests that are harder to fake. A headless browser can change its user agent, but it cannot easily fix all the inconsistencies in APIs, rendering, and behavior that the 100+ checks detect.
What does the free bot audit include?
The audit installs the detection script in shadow mode, collects a sample of your traffic, and returns a report showing bot percentage, signal breakdown, and estimated ad-spend waste — with no commitment to purchase.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.