Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: bot detection is enforced by the website, not switched off by a Selenium option. Do not build new automation around PhantomJS: its project says development is suspended, and Selenium removed native PhantomJS support because its WebDriver implementation was no longer actively developed. For authorized testing, migrate to a maintained Chrome or Firefox browser in headless mode, keep browser and driver versions compatible, identify your automation honestly, respect the site’s rules, and use an official API or obtain permission when access is challenged.

What bot detection actually is

A site decides whether a request looks like an ordinary visitor, an approved crawler, an automated test, or abusive traffic. It can combine many signals rather than checking one Selenium flag. Cloudflare, for example, documents heuristics, JavaScript detections, machine learning and behavioral analysis; its products can also analyze request patterns by ASN and JA4 fingerprint. That is one vendor’s implementation, not a universal description of every site.

Signals may include request headers, cookies and session history, browser and JavaScript behavior, navigation timing, TLS or network fingerprints, login state, traffic volume, and whether the client follows published crawler instructions. A delay, a different User-Agent, a proxy, or headless mode can change one signal without making the workflow invisible, permitted, or reliable.

Why PhantomJS should not be the foundation of a new scraper

Its development is suspended

The PhantomJS project homepage states: “Important: PhantomJS development is suspended until further notice.” PhantomJS was a JavaScript-scriptable headless browser that historically supported page automation, screenshots, headless testing and network monitoring, but its engine and WebDriver stack are now legacy technology.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Selenium moved away from native support

Selenium’s JavaScript WebDriver change notes say native PhantomJS support was removed because PhantomJS’s WebDriver implementation was no longer under active development. The same guidance points PhantomJS users toward Chrome or Firefox in headless mode. This is Selenium-specific historical guidance; language bindings do not necessarily expose identical APIs or removal timelines.

That does not mean an old PhantomJS script will instantly stop running. It means you inherit unmaintained browser behavior, increasing incompatibility with modern JavaScript, TLS, web APIs and site defenses. Treat it as a migration project, not as a bot-detection workaround.

First decide whether the access is allowed

Technical success is not proof of authorization. Before changing a scraper, check the target site’s terms, robots.txt and crawl directives, published API or developer documentation, authentication requirements and rate limits. The sources do not determine the lawfulness of scraping in any particular country or for any particular site.

  • Your own application: configure the test or staging environment to recognize expected automated traffic. Review challenge rules, allowlisted test networks and API routes.
  • An external site: confirm that automated access is permitted, use the documented API when one exists, and contact the operator if a challenge or block appears.
  • Security research: obtain written authorization, define the permitted paths and rate, and keep records of the test window.

Cloudflare’s verified-bot documentation describes a verified bot as one that is transparent about who it is and what it does, does not abuse the access that honesty earns, obeys robots.txt and crawl directives, and maintains reasonable request rates. That is a useful operating principle even when the target does not use Cloudflare.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Migrate an authorized Selenium workflow to a maintained browser

Use Selenium Manager instead of pinning a random driver

Selenium Manager is Selenium’s official driver manager. It has shipped with Selenium releases since version 4.6 and can discover, download and cache browser drivers and, where supported, browser releases. Install a current Selenium package, install a supported Chrome or Firefox build, and let Selenium Manager resolve the matching driver unless your environment requires an explicitly managed binary.

Python example: headless Chrome with an honest identity

This example is for testing a site you control or are authorized to automate. It does not attempt to evade a challenge.

from selenium import webdriver
from selenium.webdriver.chrome.options import Options

options = Options()
options.add_argument("--headless=new")
options.add_argument("--window-size=1440,1000")
options.add_argument("--user-agent=ItechGuidesAuthorizedTest/1.0 (+https://example.com/automation-contact)")

driver = webdriver.Chrome(options=options)  # Selenium Manager supplies the driver
try:
    driver.get("https://example.com")
    print(driver.title)
    driver.save_screenshot("example.png")
finally:
    driver.quit()

Replace the example identity with a truthful contact URL that your team controls. Do not claim to be a verified crawler, search engine or another organization.

Python example: headless Firefox

from selenium import webdriver
from selenium.webdriver.firefox.options import Options

options = Options()
options.add_argument("-headless")
options.set_preference("general.useragent.override", "ItechGuidesAuthorizedTest/1.0 (+https://example.com/automation-contact)")

driver = webdriver.Firefox(options=options)
try:
    driver.get("https://example.com")
    print(driver.current_url)
finally:
    driver.quit()

Use the browser that matches the compatibility matrix for your application. The available evidence does not establish a universal Chrome-versus-Firefox detection or performance winner.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

JavaScript example with Selenium

const { Builder } = require('selenium-webdriver');
const chrome = require('selenium-webdriver/chrome');

(async function () {
  const options = new chrome.Options()
    .addArguments('--headless=new', '--window-size=1440,1000')
    .addArguments('--user-agent=ItechGuidesAuthorizedTest/1.0 (+https://example.com/automation-contact)');
  const driver = await new Builder().forBrowser('chrome').setChromeOptions(options).build();
  try {
    await driver.get('https://example.com');
    console.log(await driver.getTitle());
  } finally {
    await driver.quit();
  }
}());

Keep automation detectable, controlled and polite

Identify the client accurately

Use a stable product name and contact address in your user agent or documentation. Keep an audit trail of the account, purpose, target paths, timestamps and response codes. Honest identity helps an operator distinguish an approved test from abusive traffic; it is not a bypass technique.

Control request rate and concurrency

Use the lowest request rate that meets the test objective. Add bounded backoff for transient 429 or 503 responses, cap concurrency, cache responses where permitted, and stop when the site signals that access is not allowed. Do not rotate identities or networks to continue after a block.

Prefer APIs and test endpoints

When an API exists, it normally gives the site a clearer way to authenticate, meter and authorize access. For your own application, expose a test endpoint or staging host instead of repeatedly driving production pages. Cloudflare’s scraping guidance specifically advises excluding API calls from a challenge rule when those API paths should not receive challenges; configure that rule only for routes you control and intend to expose.

What to do when a challenge appears

  1. Record the response safely. Capture the URL, status code, timestamp, request ID and a redacted screenshot or HTML sample. Never log passwords, session cookies or tokens.
  2. Check permission and documentation. Look for an API, crawler policy, authentication flow or contact channel. A challenge on an external site is a policy decision, not an invitation to defeat it.
  3. Validate your test configuration. If this is your site, check that the staging hostname, CI network, service account and expected API paths are covered by the intended allowlist or challenge rule.
  4. Ask the operator. Provide your truthful client identity, purpose, source addresses, request rate and dates. Request an allowlist, test window or API credential rather than trying to disguise the client.
  5. Stop if access is denied. Do not solve CAPTCHAs, spoof fingerprints or cycle proxies to turn a refusal into permission.

Common fixes that do not solve bot detection

Change What it can help with Why it is not a universal solution
Headless Chrome or Firefox Runs a current browser without a visible window and improves compatibility over PhantomJS. Headless execution remains one signal among many and can still be challenged.
Longer delays Prevents an accidental burst against your own service and can make tests less load-heavy. It does not grant permission or defeat JavaScript, fingerprint or session analysis.
Changing User-Agent Lets you identify an authorized client accurately. Misrepresenting a browser or crawler is not authorization and other signals remain.
Proxies or rotating IPs May be relevant to an approved distributed test designed with the operator. Using them to evade a block can violate policy and does not remove browser or behavior signals.
CAPTCHA solving or fingerprint spoofing Not a recommended remedy. It attempts to defeat a security control rather than establish authorization.

Troubleshooting Selenium migrations

“Driver executable not found” or a version mismatch

Upgrade Selenium, verify that the browser is installed and reachable in the execution environment, and allow Selenium Manager to resolve the driver. In a locked-down CI image, provide a tested browser-driver pair through your normal image or package process. Do not mix a newly updated browser with an old cached driver.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The page is blank or never finishes loading

Check DNS, outbound firewall rules, proxy configuration, certificates, JavaScript errors and the page’s own timeout behavior. Wait for a page-specific selector rather than assuming that a fixed sleep means the page is ready. Compare a permitted manual browser session with the test browser and inspect the response status without retrying aggressively.

A challenge page loops

Confirm that automation is allowed and that your test configuration is correct. A loop can result from a site policy, a missing cookie or JavaScript capability, an account restriction, clock skew, network reputation or an intentional block. Contact the operator or use the documented API; changing one header is not a dependable fix.

CI works locally but fails in production

Compare browser versions, operating-system libraries, timezone, geolocation, DNS, egress addresses, proxy settings and secrets. Keep these differences explicit in the test matrix. If the production network is not authorized, do not make it look like a local browser; request access or move the test to an approved environment.

PhantomJS code uses obsolete APIs

Rewrite the workflow around Selenium’s current WebDriver APIs, replace PhantomJS-specific command-line flags and screenshot behavior, and add waits for actual application conditions. Run a small authorized test suite in Chrome and Firefox before scaling it. Expect differences in JavaScript execution and rendering; do not treat a passing PhantomJS result as evidence that a modern browser or target site will behave the same way.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reliability, performance and operating cost

  • Browser lifecycle: create and close drivers predictably, isolate profiles between tests when state matters, and collect logs only with sensitive values redacted.
  • Version policy: update browser and Selenium dependencies on a schedule, then test before broad rollout. Selenium Manager reduces driver-maintenance work but does not replace compatibility testing.
  • Load control: measure page-load time, challenge rate, error classes and successful authorized transactions. Never optimize by increasing concurrency until the site operator agrees.
  • Recovery: use finite retries with exponential backoff for transient infrastructure failures; do not retry policy denials, CAPTCHAs or explicit blocks.
  • Data minimization: collect only the pages and fields required for the stated purpose, and protect cookies, credentials and screenshots.

Or skip the browser setup

ScreenshotNeo provides a website screenshot API and MCP server. One request returns a PNG, JPEG, WebP or PDF. Before capture it can accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed as clean shots, and response headers identify the page verdict and whether it was billed.

For a single authorized page, use the documented API at https://screenshotneo.com/docs/:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also supports full-page and element captures, device presets and arbitrary viewports, retina scale, dark mode, PDFs with paper and margin controls, HTML/CSS-to-image, custom CSS and JavaScript, clicks, selector waits, delays, network-idle waits, request and resource blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, usage data and an OpenAPI specification. It includes an MCP server with take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

Every feature is on every plan: Free includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Other plans are Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000 and Business $249 for 1,000,000; yearly billing gives two months free.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you need authorized screenshots without maintaining a browser and driver, sign up for the free 1,000-screenshot plan with no card.

FAQ

Can Selenium be made undetectable?

No reliable, universal setting does that. Detection combines site-specific signals, and attempting to evade a block is not the same as receiving permission.

Should I keep PhantomJS for an old test suite?

Only as a temporary legacy reference while you migrate. Its development is suspended and Selenium’s documented direction is maintained Chrome or Firefox in headless mode.

Does a challenge prove that scraping is illegal?

No. It proves that the site or its provider applied a control. The legal and contractual position depends on the target, jurisdiction, authorization and purpose; ask the operator or use an official API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.