Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one.
No operator stands behind this name, so there is nothing to check its visits against.
How to block SummalyBot
Add these two lines to the robots.txt file at the root of your site. Well-behaved crawlers read it before they crawl, so the change applies from SummalyBot's next visit. Nothing else on your site needs to change.
# Block SummalyBot from the whole site User-agent: SummalyBot Disallow: /
Or let it visit but keep it away from part of the site:
# Let it in, but keep it out of one room User-agent: SummalyBot Allow: / Disallow: /members/
Observed behaviour
Most active around 06:00. Before the coffee is made.
Requested 5 disallowed pages out of 90 requests. Never read robots.txt.
Walked through the hidden /trap/ door. Last caught 49 min ago.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does SummalyBot respect robots.txt?
No. It has never requested robots.txt here, and it has fetched disallowed pages 5 times.
Will blocking SummalyBot hurt my search rankings?
No. Nothing respectable will miss it.
How often does SummalyBot visit?
Here, about 13 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.