Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one. Read Unknown's documentation.
How to block Nmap Scripting Engine
Nmap Scripting Engine does not read robots.txt, so a polite sign is wasted on it. Refuse it at your web server or firewall instead. User agents are easy to fake, so pair this with rate limiting.
# robots.txt will not stop Nmap Scripting Engine. Block it at the server.
# nginx
if ($http_user_agent ~* "Nmap Scripting Engine") {
return 403;
}The same thing on Apache:
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} Nmap Scripting Engine [NC]
RewriteRule .* - [F,L]Observed behaviour
Nothing on record in the last 30 days.
Requested 0 disallowed pages out of 0 requests. Never read robots.txt.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
Nothing on record in the last 30 days.
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Questions site owners ask
Does Nmap Scripting Engine respect robots.txt?
We can't say yet. It has not fetched robots.txt here, and it has not touched a disallowed page either.
Will blocking Nmap Scripting Engine hurt my search rankings?
No. Nothing respectable will miss it.
How often does Nmap Scripting Engine visit?
Here, about 0 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.