Seatext library / BotRefund evidence
What Are the Signs of Automated Browsing in Playwright? A Detection Reference
Automated browsing in Playwright leaves detectable traces including modified browser APIs, missing or inconsistent init scripts, superhuman input speeds, linear mouse movements without tremor, absent click or scroll activity, and uniform session durations. BotRefund...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
How BotRefund Detects Playwright Automation
Playwright is a popular browser automation framework used for testing, scraping, and—unfortunately—ad fraud. When a script drives a browser, it often patches or hides standard browser APIs to avoid detection. BotRefund’s Playwright Init Scripts check looks for mismatches that a real browsing session does not normally create. Automation tools often patch or hide browser APIs, but those changes can break when the browser is checked from another angle.
This check is one of 106 independent signals BotRefund collects. Each signal adds one objective fact about the visit. No single anomaly triggers a bot verdict; privacy tools, corporate networks, travel, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps every signal as evidence and cross-checks it against independent browser, network, device, and behavior data before its prediction AI weighs the complete pattern.
Browser-Level Signals That Reveal Automation
Modified or Missing Init Scripts
A normal browser runs standard browser APIs as they were designed. Its built-in properties, permissions, and rendering contexts remain consistent without needing to hide automation. Playwright and similar tools often inject initialization scripts to mask automation markers such as navigator.webdriver. BotRefund’s check compares the observed initialization sequence against the expected baseline for that browser version. A mismatch—missing scripts, reordered execution, or patched prototypes—signals that the environment has been tampered with.
Inconsistent API Behavior
Automation frameworks sometimes override native methods (e.g., window.open, document.createElement) to suppress pop-ups or alter rendering. BotRefund’s window.open Tamper check detects when the behavior of window.open deviates from the browser’s specification. Scripts can send clicks and scrolls, but they struggle to reproduce the varied timing, movement, and hesitation of real people. When the override breaks under a secondary check—such as a permission prompt or a cross-origin iframe—the inconsistency becomes evidence.
Headless and Headful Mode Artifacts
Playwright can run in true headless mode or in headful mode with a visible window. Both leave traces: headless mode often lacks GPU rasterization, has a different navigator.plugins list, and reports a generic user-agent. Headful mode driven by Playwright still exposes the DevTools protocol port and may show automated cursor injection. BotRefund’s browser fingerprinting layer captures these attributes and compares them to a corpus of genuine device profiles.
Behavioral Signals That Distinguish Bots from Humans
Superhuman Input Speed
Bots can copy-paste text or autofill form fields in sub-millisecond intervals. Real humans take seconds to type details. BotRefund flags interactions that happen faster than a person could realistically perform—specifically, input speeds under 1 millisecond. This Speed behavior signal catches automated form submissions, rapid-fire clicks, and instantaneous navigation sequences.
Robotic Linear Mouse Movements
Human pointer paths contain micro-jitter, curvature, and hesitation. Automated scripts often move the cursor in straight lines or perfect arcs between coordinates. BotRefund’s Pointer behavior check flags unnaturally straight pointer paths that rarely appear in real user sessions. The related Motion behavior signal looks for the absence of humanlike mouse tremor—the tiny imperfections and jitter typical of human movement.
Grid-Aligned Movement Patterns
Some automation frameworks snap coordinates to integer pixel grids or to element bounding boxes. This produces movement that snaps to precise lines or blocks instead of natural curves. BotRefund’s Path behavior detection catches grid-aligned movement patterns that betray scripted navigation.
Ghost Clicks and Honeypot Interactions
Click activity that happens without the natural sequence of human intent—no prior hover, no focus change, no scroll into view—is flagged as Ghost click detection. Similarly, bots that respond to hidden or intentionally deceptive page elements trigger Honeypot trap interactions. Real users never click elements positioned off-screen or styled display:none.
Absence of Clicks or Scrolling
Sessions that stay too static to match a real browsing journey—no clicks, no scrolls, no focus changes—are highlighted by the Engagement behavior signal. While a human might read a long article without clicking, a complete lack of micro-interactions (text selection, cursor hover, viewport resize) across multiple page views is suspicious.
Unnatural Session Durations
Visit lengths that are too short, too long, or too uniform to be human trigger the Session behavior check. Bots often execute a fixed script: land, wait N seconds, click, exit. The resulting duration distribution lacks the variance of genuine sessions, which are shaped by reading speed, network latency, and decision-making.
Network and Environment Indicators
Residential Proxy Routing
Malicious actors route clicks through networks of hijacked smart devices (IoT) in target local areas. This presents the ad platform with legitimate residential IP addresses, making location-based exclusions ineffective. BotRefund correlates browser fingerprint consistency with IP reputation, ASN ownership, and geolocation mismatch to flag proxy usage.
Impossible Tab Speed
Scripts can open and switch tabs at speeds no human can match. BotRefund’s Impossible Tab Speed check measures the interval between tab creation, focus, and navigation. A real visitor produces imperfect, varied behavior: pauses, hesitation, natural movement, and interactions shaped by reading and decision-making. Automated tab orchestration lacks this variance.
CAPTCHA Solving Patterns
Human-in-the-loop CAPTCHA solving centers route challenges to low-cost labor. The resulting interaction timing—sudden pauses, then rapid completion—differs from a user solving a CAPTCHA organically. BotRefund’s behavioral layer captures these timing anomalies as supporting evidence.
Why Single Signals Aren’t Enough: The Cross-Check Approach
A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps each signal as evidence—not a verdict—and cross-checks it against independent browser, network, device, and behavior data. The system operates in three stages:
- Independent evidence: Each of the 106 checks adds one objective fact about the visit.
- Cross-checked context: BotRefund tests whether other signals support the same story.
- AI prediction: The model weighs the complete pattern instead of trusting a raw rule.
By seeing how all signals fit together, the prediction AI identifies a visit as bot or human with 99% accuracy. This corroboration-first design avoids false positives that plague single-rule detectors.
Common Evasion Techniques and Their Limitations
Stealth Plugins and Patches
Playwright users often install stealth plugins (e.g., playwright-stealth) that override navigator.webdriver, mock chrome.runtime, and patch window.outerWidth/innerWidth. These patches reduce low-hanging detection but introduce new inconsistencies: the patched properties may not update correctly on resize, or the mock objects lack internal methods the real browser exposes. BotRefund’s multi-angle checks catch these secondary breaks.
Human-Like Behavior Simulation
Advanced bots add random delays, Bezier-curve mouse paths, and simulated scroll jitter. While this defeats simple heuristic rules, it struggles to replicate the full distribution of human micro-behaviors: the correlation between scroll speed and text density, the pause before a click on a CTA versus a navigation link, the hesitation when a page loads slowly. BotRefund’s AI model evaluates the joint distribution of dozens of behavioral variables, not just their marginal averages.
Residential Proxy Rotation
Rotating residential IPs masks network-level signals but does not hide browser fingerprint inconsistencies. A single device fingerprint appearing across dozens of unrelated residential IPs in a short window is a strong cross-signal anomaly. BotRefund links device identity to network identity over time.
Practical Implications for Site Owners
Ad Budget Protection
Bot clicks steal up to 20% of Google and Meta ad budgets. Automated browser scripts, headless Chrome instances, and data scrapers repeatedly visit paid search listings as they index the web. Competitor click activity and publisher click fraud further drain budgets. Google’s automated filters frequently fail to identify modern residential proxy networks and competitor click fraud, leaving thousands of dollars in wasted ad spend uncredited.
Refund Recovery
Site owners can file manual refund requests with Google’s Click Quality team and Meta’s billing disputes. Success requires client-side behavioral proof logs—GCLID/FBCLID capture, video session replays, and timestamped interaction evidence. BotRefund automates this evidence collection and generates audit-ready dispute reports.
Lead Quality for B2B Pipelines
Affiliate lead fraud occurs when partners use automated botnets to fill out forms, request demo calls, or register mock free accounts. This drains marketing budgets on commissions and pollutes sales pipelines with unresponsive, fake contacts. Signals of fake affiliate leads include superhuman input speeds, lack of physical pointer movement, and disposable email patterns. BotRefund runs continuous client-side checks to filter out headless browsers and clean CRM lead data.
Key Facts
| Signal Category | Specific Check | What It Detects | Source |
|---|---|---|---|
| Browser API | Playwright Init Scripts | Mismatched initialization sequences, patched prototypes | S1 |
| Browser API | window.open Tamper | Overridden window.open behavior inconsistent with spec | S5 |
| Behavioral | Ghost Click Detection | Clicks without human intent sequence (hover, focus, scroll) | S2, S8 |
| Behavioral | Honeypot Trap Interactions | Clicks on hidden/deceptive elements | S2, S8 |
| Behavioral | Robotic Linear Mouse Movements | Unnaturally straight pointer paths | S2, S8 |
| Behavioral | Absence of Humanlike Mouse Tremor | Missing micro-jitter in cursor movement | S2, S8 |
| Behavioral | Superhuman Input Speed (<1ms) | Form fills, clicks faster than humanly possible | S2, S8 |
| Behavioral | Grid-Aligned Movement Patterns | Cursor snapping to pixel grid or element boxes | S2, S8 |
| Behavioral | Absence of Clicks or Scrolling | Static sessions lacking micro-interactions | S2, S8 |
| Behavioral | Unnatural Session Durations | Too short, too long, or too uniform visit lengths | S2, S8 |
| Behavioral | Impossible Tab Speed | Tab open/switch/navigate intervals beyond human speed | S6 |
| Network | Residential Proxy Detection | IP reputation, ASN, geolocation mismatch | S3 |
| Meta | Cross-Checked AI Prediction | 106 signals weighed jointly for 99% accuracy | S1, S5, S6 |
Limitations and When This Advice Does Not Apply
- False positives from privacy tools: Anti-fingerprinting extensions, VPNs, and hardened browsers (Tor, Brave) can trigger browser-level signals. BotRefund’s cross-check design mitigates this, but site owners should expect a small false-positive rate and avoid auto-blocking on single signals.
- Corporate and educational networks: Shared egress IPs, managed device policies, and proxy appliances create network-level anomalies that resemble bot traffic. Contextual allow-listing or secondary verification (e.g., email domain) helps.
- Legitimate automation: Monitoring services, uptime checkers, and SEO crawlers identify themselves via user-agent and respect
robots.txt. These should be allow-listed by IP or user-agent before enabling enforcement. - Mobile app webviews: In-app browsers often have stripped APIs and non-standard fingerprints. Treat them as a distinct device class rather than bots.
- Historical data only: The signals described reflect current detection capabilities. Adversaries adapt; detection must evolve. BotRefund updates its 106 checks continuously, but any static article becomes outdated.
Frequently Asked Questions
Can Playwright evade all bot detection if configured perfectly?
No. Even with stealth plugins, human-like behavior simulation, and residential proxies, the joint distribution of 106 browser, network, device, and behavioral signals is extremely difficult to replicate perfectly. BotRefund’s AI model evaluates the complete pattern, not individual rules.
Does BotRefund block bots automatically or only flag them?
BotRefund provides the evidence layer—video proof, behavioral logs, and AI classification. Customers choose enforcement: block, challenge, allow-list, or feed into their own WAF. The platform also automates refund dispute generation for ad platforms.
How long does it take to add BotRefund to a site?
Typical setup is about one minute. No credit card is required for the free bot audit.
What ad spend thresholds does BotRefund support?
Plans cover monthly Google/Meta spend from under $10,000 to over $5M. Enterprise tiers handle $250K–$1M+ with dedicated escalation.
Can I use these detection signals in my own WAF rules?
BotRefund’s signals are exposed via API and webhook. You can ingest the classification score and individual signal flags into your own rules engine. The raw client-side telemetry remains proprietary.
Does detection work on mobile browsers and in-app webviews?
Yes. The same 106-check framework runs on mobile Chrome, Safari, and common webview containers. Mobile-specific signals (touch event patterns, accelerometer availability, screen orientation changes) are included.
What happens if a legitimate user is flagged as a bot?
Because BotRefund treats each signal as evidence rather than a verdict, false positives are rare. When they occur, the customer can review the session replay, adjust allow-lists, or feed the case back to improve the model. The platform does not auto-block without customer configuration.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.