01 · Operator
Who operates MerchantSecurityScanner
- Company
- Stripe
- Type
- Monitoring bot
- Official docs
- support.stripe.com
02 · Behavior
What MerchantSecurityScanner does
Stripe scans merchant websites to catch problems before they put Stripe users at risk. Examples are exposed admin panels or unprotected API keys. Stripe states the scanner does not exploit vulnerabilities or guess passwords. It is designed not to overload websites.
03 · Impact
Why MerchantSecurityScanner matters for your site
If you allow it
- Finds security issues before attackers do
- Operated by your payment provider
- Designed to avoid overloading servers
If you block it
- Probes paths like admin panels, which can trigger security alerts
- Brings no traffic or visibility
- No benefit if you do not use Stripe
04 · Allow
How to allow MerchantSecurityScanner
robots.txt
User-agent: MerchantSecurityScanner
Allow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "MerchantSecurityScanner")
Action: Skip › All Super Bot Fight Mode rules
# Also check Security › Bots: "Block AI bots" can block it regardless of robots.txt.
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: MerchantSecurityScanner
Allow: /
nginx
# nginx serves every user agent by default.
# Make sure no rule like this blocks it:
# if ($http_user_agent ~* "MerchantSecurityScanner") { return 403; }
Apache
# Apache serves every user agent by default.
# Make sure .htaccess has no rule like this:
# RewriteCond %{HTTP_USER_AGENT} MerchantSecurityScanner [NC]
# RewriteRule .* - [F,L]
05 · Block
How to block MerchantSecurityScanner
Start with robots.txt. If MerchantSecurityScanner keeps showing up in your logs, block it at your CDN or web server.
robots.txt
User-agent: MerchantSecurityScanner
Disallow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "MerchantSecurityScanner")
Action: Block
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: MerchantSecurityScanner
Disallow: /
nginx
# In your server { } block:
if ($http_user_agent ~* "MerchantSecurityScanner") {
return 403;
}
Apache
# .htaccess
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} MerchantSecurityScanner [NC]
RewriteRule .* - [F,L]
</IfModule>
06 · User agents
User agents we see for MerchantSecurityScanner
| User agent | Share | Last seen | Status |
|---|---|---|---|
MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner) |
100% | Unverified |
07 · Verification
Is it really MerchantSecurityScanner?
MerchantSecurityScanner’s operator publishes no IP ranges or hostnames, so requests cannot be verified. Treat the user agent as a claim, and watch your logs for unusual request rates.
FAQ
Questions about MerchantSecurityScanner
Why is Stripe scanning my website?
Stripe scans websites of its users for common vulnerabilities, such as exposed admin panels or API keys. It wants to catch problems before they endanger Stripe users.
Does MerchantSecurityScanner try to hack my site?
No. Stripe states its scanners never try to exploit vulnerabilities and do not guess passwords.
How do I opt out of Stripe's security scans?
Contact Stripe Support via the Dashboard chat, or email mss-optout@stripe.com with your account ID.
Last reviewed Oct 8, 2026