Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Blockary – Access Firewall

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Blockary – Access Firewall

By Michael
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Blockary blocks visitors by country and stops password guessing on the login page.

The country rule works as a block list or as an allow list. You pick the countries on the settings page. The plugin reads the country from the Cloudflare header or from a local copy of the free “IP to Country Lite” database from DB-IP. Visitors from the whitelist and from private networks always pass. Logged-in users pass by default. You can turn that off on the settings page. Administrators always pass.

The login protection counts failed logins per address and per username. An address that reaches the limit gets a temporary ban. The ban time grows with each ban, and a permanent ban follows after a number of temporary bans. The plugin can also lock a username, show the same error for a wrong username and a wrong password, hide usernames from visitors, and turn off XML-RPC.

The plugin loads as the first plugin. It decides a request without a login cookie before WordPress loads the other plugins. It decides a request with a login cookie as soon as WordPress can read that cookie. Blocked requests do not reach the theme. A log on the settings page shows the blocked requests, the failed logins, and the bans.

Load order

The plugin keeps itself first in the list of active plugins. WordPress then loads it before the other plugins, so a blocked request costs less and stays invisible to the other plugins. The plugin changes only the order of that list in the database. It writes no file for this and you do not have to set anything up.

Optional: the loader file

A loader file in the folder wp-content/mu-plugins is only useful when another plugin moves itself in front of Blockary. The plugin does not write that file itself. You download it on the settings page and copy it into the folder by hand, for example with SFTP. The settings page shows the exact path. The loader runs the decision only while the plugin is active. Without the plugin it does nothing. When you delete the plugin, delete the loader file too. When the settings page shows “Outdated” for the load order, download the file again and replace the copy.

Recovery

If a rule locks you out, add this line to wp-config.php:

define( 'BLOCKARY_DISABLE', true );

The plugin then blocks nothing until you remove the line.

External services

The plugin downloads the country database “IP to Country Lite” from DB-IP when you select the local database as the country source. The download runs once after you select that source and then once a month through WP-Cron. You can also start it on the settings page.

The request goes to https://download.db-ip.com/free/. The request carries only the name of the database file for the current month. It carries no data about your site or your visitors. The database is licensed under CC BY 4.0. The settings page shows the attribution link that the license requires.

Terms and privacy policy of DB-IP: https://db-ip.com/about and https://db-ip.com/privacy.php

The plugin sends no other request to an external service.

Installation

  1. Upload the folder blockary to wp-content/plugins, or install the plugin from Plugins > Add New.
  2. Activate the plugin.
  3. Open Settings > Blockary.
  4. Add your own address to the IP whitelist.
  5. Pick the country mode and the countries.
  6. If your site runs behind Cloudflare or another proxy, add the proxy to the trusted proxies. Without that entry the plugin sees the proxy address for every visitor.

FAQ

Where does the country data come from?

The plugin reads the country from the Cloudflare header CF-IPCountry when the site runs behind Cloudflare. Without Cloudflare the plugin downloads the free “IP to Country Lite” database from DB-IP into wp-content/uploads/blockary and refreshes it once a month. See the section “External services”.

Does the plugin send data about my visitors?

No. The country lookup runs on your server. The plugin sends no visitor data to any service.

What does the plugin write outside its own folder?

The plugin writes only the country database into wp-content/uploads/blockary. It removes that folder and its settings, bans, and log on uninstall. In the database, the plugin moves itself to the first position in the list of active plugins. The optional loader file in wp-content/mu-plugins is a file that you copy by hand. The plugin never writes or deletes it.

I locked myself out. What now?

Add define( 'BLOCKARY_DISABLE', true ); to wp-config.php. The plugin then blocks nothing. Fix the rule on the settings page and remove the line again.

Does the firewall apply to logged-in users?

Not by default. A visitor with a valid login cookie passes the country rule and the bans. If your site has open registration, turn off the setting “Do not apply the firewall to logged-in users”. The country rule and the bans then also apply to logged-in users. Administrators always pass, so that you cannot lock yourself out of the settings page.

My code uses the filter blockary_should_block. What changed in version 1.1.0?

The plugin now decides a request without a login cookie before WordPress loads the other plugins. A callback in a normal plugin is not registered at that moment. Put the callback into a must-use plugin (a file in wp-content/mu-plugins).

Does the plugin work with a caching plugin?

Yes. The plugin decides before WordPress loads the other plugins. A page cache that serves files before WordPress starts, for example a web server cache, can serve a cached page to a blocked visitor.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Blockary – Access Firewall” is open source software. The following people have contributed to this plugin.

Contributors
  • Michael

Translate “Blockary – Access Firewall” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.0

  • The plugin keeps itself first in the list of active plugins. The firewall decides a request without a login cookie before WordPress loads the other plugins. The loader file is no longer needed for that.
  • New setting “Do not apply the firewall to logged-in users”. It is on by default, which is the behavior of version 1.0.0. When it is off, the country rule and the bans also apply to logged-in users. Administrators always pass.

1.0.0

  • First version. Country rule with block list and allow list, login protection with bans, username lock, hidden usernames, XML-RPC switch, and a log.

Meta

  • Version 1.1.0
  • Last updated 5 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.4 or higher
  • Tested up to 7.1.2
  • PHP version 8.1 or higher
  • Tags
    Brute Forcecountry blockfirewalllogin protectionsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Michael

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry