01 · Operator
Who operates RootEvidence
- Company
- Root Evidence, Inc.
- Type
- Monitoring bot
- Official docs
- rootevidence.com
02 · Behavior
What RootEvidence does
Root Evidence sells a platform that scans external assets for vulnerabilities every 24 hours. It also maps the external attack surface of its customers. The RootEvidence user agent is attributed to this scanning by bot databases.
03 · Impact
Why RootEvidence matters for your site
If you allow it
- Scans may be run by your own security vendor
- Light requests
If you block it
- No search or traffic benefit
- Probes for vulnerabilities
04 · Allow
How to allow RootEvidence
robots.txt
User-agent: RootEvidence
Allow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "RootEvidence")
Action: Skip › All Super Bot Fight Mode rules
# Also check Security › Bots: "Block AI bots" can block it regardless of robots.txt.
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: RootEvidence
Allow: /
nginx
# nginx serves every user agent by default.
# Make sure no rule like this blocks it:
# if ($http_user_agent ~* "RootEvidence") { return 403; }
Apache
# Apache serves every user agent by default.
# Make sure .htaccess has no rule like this:
# RewriteCond %{HTTP_USER_AGENT} RootEvidence [NC]
# RewriteRule .* - [F,L]
05 · Block
How to block RootEvidence
Start with robots.txt. If RootEvidence keeps showing up in your logs, block it at your CDN or web server.
robots.txt
User-agent: RootEvidence
Disallow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "RootEvidence")
Action: Block
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: RootEvidence
Disallow: /
nginx
# In your server { } block:
if ($http_user_agent ~* "RootEvidence") {
return 403;
}
Apache
# .htaccess
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} RootEvidence [NC]
RewriteRule .* - [F,L]
</IfModule>
06 · User agents
User agents we see for RootEvidence
The user agent published by the operator:
RootEvidence/1.0
07 · Verification
Is it really RootEvidence?
RootEvidence’s operator publishes no IP ranges or hostnames, so requests cannot be verified. Treat the user agent as a claim, and watch your logs for unusual request rates.
FAQ
Questions about RootEvidence
What is the RootEvidence user agent?
It is attributed to Root Evidence, Inc., which runs external vulnerability scans for its customers.
Should I block RootEvidence?
Block it unless your organization uses Root Evidence. It brings no search traffic.
Last reviewed Oct 8, 2026