← Bot Directory/wbsearchbot
Bot directory / search-engine

wbsearchbot: Robots.txt & Crawl Policy Reference

Technical reference for the historical wbsearchbot registry label, noting that the Warebay domain has been repurposed to an e-commerce store.

AI Summary: The registry describes wbsearchbot as the Warebay search engine crawler, but the historical documentation URL returns a 404 error. The warebay.com domain has been repurposed and currently hosts a furniture e-commerce store. No current operator, exact User-Agent, IP list, or robots policy exists for this crawler. Treat the token as an obsolete historical label rather than an authenticated active crawler.

Role and policy boundary

The registry describes this entry as the Warebay search web crawler bot. It does not record an exact User-Agent string, though the slug implies wbsearchbot.

During headless-browser review, the referenced documentation URL (http://www.warebay.com/bot.html) returned a 404 "Page not found" error. The root domain warebay.com now hosts an e-commerce store selling furniture and home goods ("WareBay"). It no longer operates as a search engine and does not publish a search-crawler specification or webmaster guidelines.

This profile therefore uses legacy-label and records the User-Agent as Not publicly documented. A matching request is no longer an authentic Warebay search crawler; it could be a legacy deployment, a third-party scraper, a test client, or a spoofed header. Do not infer that an active Warebay search crawler still exists, that it obeys robots.txt, or that the token establishes permission for AI input, model training, or data retention.

Because the service is discontinued and the domain repurposed, do not publish an assumed wbsearchbot robots group as if it came from the operator. If logs establish a current, attributable token and you decide to exclude it, use the exact observed value in a deliberate site-owner rule:

configuration / code
User-agent: CONFIRMED-OBSERVED-WBSEARCHBOT
Disallow: /

For selective access after confirmation:

configuration / code
User-agent: CONFIRMED-OBSERVED-WBSEARCHBOT
Allow: /public/
Allow: /docs/
Disallow: /admin/
Disallow: /account/
Disallow: /private/
Disallow: /licensed/
Disallow: /api/

These are explanatory site-owner controls, not recovered Warebay instructions. Robots.txt is advisory and cannot secure private or licensed content; use authentication, authorization, signed URLs, data minimization, and origin controls.

Layered verification

Start with raw access logs and preserve the complete User-Agent, source IP, ASN, reverse-DNS result, HTTP method, requested path, response status, response size, redirect chain, timestamp, concurrency, and request rate. Because the original search engine is defunct, no current source publishes an IP range, reverse-DNS procedure, Crawl-delay, rate guidance, removal address, or verification workflow.

Do not treat the warebay.com URL in a header as proof of operator ownership. A client can copy any URL, and the referenced domain has pivoted entirely to e-commerce. Check source IP and DNS evidence independently.

Compare observed behavior with a search-indexing hypothesis without turning it into attribution. Public HTML, metadata, feeds, sitemaps, and ordinary assets may be requested by many tools. Private endpoints, licensed content, account routes, APIs, high concurrency, repeated retries, or unexpected bulk downloads establish impact and load risk, not Warebay attribution or downstream use.

Evaluate /robots.txt only after the actual observed token is known. Confirm that it is served by the intended host, returns a successful text response, and contains the exact group you intend to publish. An absent operator source and a repurposed domain are not evidence of robots compliance. If no exact group exists, a global rule may affect unrelated clients and should be adopted only as an explicit site-wide decision.

Page-level directives can express indexing preferences:

configuration / code
<meta name="robots" content="noindex, nofollow">
configuration / code
X-Robots-Tag: noindex, nofollow

These signals do not authenticate an undocumented crawler or secure private paths. Enforce sensitive boundaries in the application and at the origin. If your policy distinguishes search indexing, AI input, reference use, and model training, document each purpose separately rather than inferring permission from a discontinued registry label.

WAF and Nginx remediation examples

When the source is unverified, use report-only logging and a narrow observation. Avoid broad warebay, search, or browser rules that can affect unrelated clients:

configuration / code
{
  "description": "Observe unverified wbsearchbot candidates",
  "expression": "lower(http.user_agent) contains \"wbsearchbot\"",
  "action": "log"
}

After independent verification and a policy decision, scope enforcement to sensitive routes and preserve evidence for the rule:

configuration / code
map $http_user_agent $block_confirmed_warebay_private {
    default 0;
    # Add only a complete, independently verified token here.
    # ~*Exact-Observed-Token 1;
}

server {
    location ~ ^/(admin|account|private|licensed|internal|api)/ {
        if ($block_confirmed_warebay_private) { return 403; }
        try_files $uri $uri/ =404;
    }
}

A User-Agent match is easy to spoof, and the registry token points to a repurposed domain. Do not invent an IP allowlist, reverse-DNS suffix, rate, training policy, or permanent trust exception. Use per-client rate limits, concurrency ceilings, timeouts, response-size controls, caching, and anomaly detection at the edge or origin. Start in report-only mode, review false positives, and restrict only after evidence supports the action.

Test public pages, feeds, sitemaps, structured data, licensed assets, account routes, APIs, 429 behavior, response-size limits, and approved integrations separately. Pair WAF controls with authentication and application authorization instead of using robots.txt as an access-control mechanism.

Review checklist

Search logs for the exact wbsearchbot substring and preserve the complete header, source IP, ASN, PTR result, forward lookup, path, method, response size, status, timing, rate, concurrency, and redirects. Treat the URL in the header as an unverified string, not a support channel.

Re-check the Warebay domain, robots.txt, and the crawler registry. In this review, the historical documentation was offline and the domain had pivoted to e-commerce. Keep this profile at legacy-label permanently unless the search engine brand is verifiably resurrected by a new operator.

Decide whether your objective is to preserve public discovery, reduce crawl load, limit extraction, protect licensed material, or prevent private access. Publish exact robots rules only after the token is known; enforce private routes with authentication and origin controls.

Review search indexing, AI input, reference use, and model-training decisions separately. Neither the registry description nor a header containing an obsolete URL establishes downstream permission or use. Do not claim successful blocking or verification from configuration alone; validate later logs.

Record the date and reason for the legacy-label classification so future evidence can be compared without silently upgrading an unsupported historical label. If a new deployment identifies itself differently, create a separate evidence trail.

References

  1. Crawler User Agents community registry — registry context for the wbsearchbot label; it does not authenticate current infrastructure.
  2. WareBay domain — registry-linked domain; headless-browser review on 2026-08-25 confirmed the domain now hosts a furniture e-commerce store and the crawler documentation is a 404.
  3. Google Robots.txt Introduction — general explanation of crawler directives and their limitations.
  4. RFC 9309 — Robots Exclusion Protocol standard; it does not authenticate a User-Agent.

Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.