react-bot-detection
@tsdevstack/react-bot-detection is a React library for client-side bot detection using behavioral analysis and honeypot fields. Zero dependencies beyond React, SSR-safe, fully typed.
Quick start
Exports
Detection methods
Behavioral analysis (useBotDetection)
Tracks mouse movements, typing patterns, focus events, and time on form. Scores each signal:
Threshold: Score >= 50 is classified as a bot.
Honeypot (useHoneypot)
Hidden fields invisible to humans but visible to bots that parse HTML. When filled, adds +100 to score.
BotProtectedForm props
Best practices
- Always validate server-side — client-side detection can be bypassed. Send the
botScoreto your backend and verify there. - Don't reveal detection — silently accept bot submissions but don't process them. This prevents bots from learning your detection methods.
- Combine with rate limiting — bot detection is one layer. Also use IP-based rate limiting and email verification.
- Use the debug panel in development:
showDebugPanel={process.env.NODE_ENV === 'development'}