vadixbot

Bot User-Agent: vadixbot

🤖 Overview

Vadixbot is a legitimate web crawler operated by Vadix Ltd., a UK-based cybersecurity company specializing in automated web application vulnerability scanning. According to Vadix’s official documentation (vadix.io/crawler), the bot is designed to systematically crawl public-facing web applications to identify security flaws such as SQL injection, cross-site scripting (XSS), and misconfigurations, feeding results into the Vadix Security Scanner platform.

🌐 Technical Behavior

Vadixbot performs both shallow and deep crawls by following links recursively, typically issuing between 10 and 30 requests per second per target, depending on server response times. It uses HTTPS as the default protocol and respects Cache-Control headers to avoid redundant crawling. IP ranges are assigned from Vadix’s autonomous system (AS 207813 as per BGP records) and are listed on their official IP whitelist page (vadix.io/ip-ranges). The crawler always identifies itself in the User-Agent header and includes a From header containing an abuse contact email.

📋 robots.txt Compliance

Vadixbot fully respects the robots.txt standard, as confirmed in Vadix’s publicly posted compliance statement (vadix.io/robots). If a Disallow directive is encountered, the crawler immediately stops accessing those paths and logs the exclusion for the scanning session. Documented evidence from third-party tests (e.g., security.stackexchange.com/q/45012) shows no violations.

🔍 Detection Indicators

The primary User-Agent string is Vadixbot/1.0 (also Vadixbot/1.1 for newer versions). Behavioral fingerprints include a consistent request pattern with a fixed inter‑request delay of 200–500 ms, and a Via header containing Vadix-Proxy. The bot also sends a X-Vadix-Scan-ID header for traceability.

📊 Data Usage

Collected data—URLs, response codes, page content, and detected vulnerabilities—is used exclusively for generating security assessment reports within the Vadix platform. No content is stored for AI training or search indexing; it is processed in‑memory and discarded after the scan completes.

⚙️ Rate Limiting Policy

Although legitimate, Vadixbot can be aggressive during deep scans; therefore, threshold-based rate limiting (e.g., >50 req/s) is recommended to prevent resource exhaustion while still allowing the scanner to complete its security assessment within acceptable timeframes.

🛡️

Stop Bots. Save Bandwidth. Protect Revenue.

Boteraser automatically detects and blocks unwanted bots — protecting your site from scrapers, DDoS bursts, and credential stuffing attacks without slowing down real visitors.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.