Skip to content
Shield · Analytics

Shield

Analytics

Every widget has a Metrics tab in the console with verification volumes, humanity score trends and failure counts. It is built entirely from hourly aggregates.

On this page4 sections

Shield analytics with verifications and humanity score distribution

Available metrics#

Open Shield → your widget → Metrics and select a range (24 hours, 7 days, or 30 days):

Metric What it tells you
Verifications Successful siteverify calls: traffic your server accepted a token for
Challenges issued How many verification attempts started (the widget’s raw traffic)
Average humanity score Score trend over time. A sudden drop is an early warning of a bot campaign
Solve rate Challenges solved ÷ issued. Low rates suggest clients abandoning or failing the challenge
Interactive shown How often managed mode escalated to the “I am human” confirmation
Failed / replayed Rejected siteverify calls, including replay attempts. This is your token-abuse signal
Tarpit challenges Escalated-difficulty challenges served to repeat offenders. Shows how hard the tarpit is working
Shadow would-fail / would-escalate For widgets in shadow (report-only) mode: what strict enforcement would have rejected or escalated. This is your trial scorecard

Reading the data#

  • Average score falling while volume rises: this usually means automated traffic has arrived. Check the interactive-shown count; in managed mode it should rise with it.
  • Replays above zero: something is resubmitting used tokens, typically a naive bot re-posting a captured form. Shield rejects these automatically.
  • Issued far exceeding verifications: this is normal. Every page load with a widget issues a challenge, but only submitted forms reach siteverify.

Data retention and privacy#

All analytics are hourly aggregate counters per widget. Shield does not store visitor IP addresses, fingerprints, cookies, or any per-visitor records. The signals used for scoring are processed in memory during the request and discarded. There is no per-visitor drill-down because there is no per-visitor data.

This is what makes Shield GDPR/CCPA-friendly by default: there’s nothing to consent to, export, or delete.

Next steps