website security, bot attacks, managed hosting, AI analysis, custom defense, Cloudflare protection

Ask Freelock: Why Is My Site Still Getting Hammered by Bots — Even on a Major Hosting Platform?

By John Locke on April 15, 2026

We recently heard from a former client who had moved their site to a major managed hosting platform, hoping for more stability and better protection. Instead, they found themselves dealing with relentless bot attacks — slowdowns, outages, and a growing bill for security add-ons that weren't solving the problem.

Their question: Can you recommend an independent expert who can help?

Our answer: we think that's us. Here's why — and what we've learned over three years of fighting these battles.

The problem with "set it and forget it" hosting

Platforms like Pantheon offer a lot of value — solid infrastructure, easy deployments, a reliable foundation. But when it comes to targeted, evolving bot attacks, infrastructure alone isn't enough. Large hosting platforms protect everyone the same way. They can't dedicate time to studying your site's specific attack pattern and crafting a response tailored to it. We can.

What about Cloudflare?

Cloudflare is a tool we're familiar with — some of our clients use it, and it genuinely does add a useful layer of protection. But it's not a silver bullet. When attacks evolve, Cloudflare's rules need to evolve too, and that requires someone actively watching, analyzing, and updating those rules. Without hands-on attention, even Cloudflare-protected sites can get overwhelmed. The tool is only as good as the person tuning it.

What we actually do

When a site we manage starts showing signs of a bot attack, we dig into the traffic logs. Over the past couple of years, we've been feeding those logs into AI tools that help us spot patterns — the tell-tale signatures of bots trying to scrape content, hammer databases, or overwhelm servers. Every attack is a little different, which means every defense has to be a little different too.

We put protections in place, and they typically hold well for several months. When the attacks evolve — and they always do — we're back at it, usually resolving the issue within a few hours. Across the sites we've been actively defending, including sites with large content databases that are particularly attractive to scrapers, we've been able to keep our clients operational when others couldn't.

We provide active, hands-on management across 50+ sites, so we also benefit from pattern recognition across a broad portfolio — when we see something new on one site, we're better prepared when it shows up on another.

What this means for you

If your site has a large library of resources, a database-driven directory, or any kind of content that's valuable enough for someone to want to copy — you're a target. Not because you did anything wrong, but because what you've built is worth stealing.

The question isn't whether you'll face bot attacks. It's whether you have someone in your corner who will notice quickly, respond personally, and stick with you as the threat evolves.

That's what we do.

If you're worried about your site's resilience — or you've already been hit and aren't sure what to do next — we'd love to talk.

Add new comment

The content of this field is kept private and will not be shown publicly.

Filtered HTML

  • Web page addresses and email addresses turn into links automatically.
  • Allowed HTML tags: <a href hreflang> <em> <strong> <blockquote cite> <cite> <code> <ul type> <ol start type> <li> <dl> <dt> <dd> <h1> <h2 id> <h3 id> <h4 id> <h5 id> <p> <br> <img src alt height width>
  • Lines and paragraphs break automatically.

Drupal Canvas — Block HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href> <p> <br> <ul> <ol> <li>

Drupal Canvas — Inline HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href>

About the Author

Profile picture for user John Locke

John Locke is the lead developer and founder of Freelock, LLC. In addition to being a proficient web developer, he is an experienced technical writer, network administrator, and all around problem solver. He has worked with computers since 1984, and currently advises small businesses on open source software.