Most unwanted traffic is not sophisticated: scripts probe for .env files, .git directories and admin panels you do not run. Matching those paths at the edge is cheap and rarely blocks a real user.
User-agent strings are trivial to fake. Requests for paths your site never serves are a more reliable signal.
location ~* ^/(\.env|\.git|wp-login\.php|phpmyadmin) {
return 444;
}Nginx 444 closes the connection without a response, which costs the scanner time and gives no information. Use 403 while testing so you can see what matches.
Open the Bot & scanner blocking generator
Not if you only match paths that do not exist on your site. Avoid blocking by broad user-agent patterns.