Title: Blockary &#8211; Access Firewall
Author: Michael
Published: <strong>October 5, 2026</strong>
Last modified: October 6, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/blockary.svg)

# Blockary – Access Firewall

 By [Michael](https://profiles.wordpress.org/migaweb/)

[Download](https://downloads.wordpress.org/plugin/blockary.1.1.0.zip)

 * [Details](https://wordpress.org/plugins/blockary/#description)
 * [Reviews](https://wordpress.org/plugins/blockary/#reviews)
 *  [Installation](https://wordpress.org/plugins/blockary/#installation)
 * [Development](https://wordpress.org/plugins/blockary/#developers)

 [Support](https://wordpress.org/support/plugin/blockary/)

## Description

Blockary blocks visitors by country and stops password guessing on the login page.

The country rule works as a block list or as an allow list. You pick the countries
on the settings page. The plugin reads the country from the Cloudflare header or
from a local copy of the free “IP to Country Lite” database from DB-IP. Visitors
from the whitelist and from private networks always pass. Logged-in users pass by
default. You can turn that off on the settings page. Administrators always pass.

The login protection counts failed logins per address and per username. An address
that reaches the limit gets a temporary ban. The ban time grows with each ban, and
a permanent ban follows after a number of temporary bans. The plugin can also lock
a username, show the same error for a wrong username and a wrong password, hide 
usernames from visitors, and turn off XML-RPC.

The plugin loads as the first plugin. It decides a request without a login cookie
before WordPress loads the other plugins. It decides a request with a login cookie
as soon as WordPress can read that cookie. Blocked requests do not reach the theme.
A log on the settings page shows the blocked requests, the failed logins, and the
bans.

#### Load order

The plugin keeps itself first in the list of active plugins. WordPress then loads
it before the other plugins, so a blocked request costs less and stays invisible
to the other plugins. The plugin changes only the order of that list in the database.
It writes no file for this and you do not have to set anything up.

#### Optional: the loader file

A loader file in the folder `wp-content/mu-plugins` is only useful when another 
plugin moves itself in front of Blockary. The plugin does not write that file itself.
You download it on the settings page and copy it into the folder by hand, for example
with SFTP. The settings page shows the exact path. The loader runs the decision 
only while the plugin is active. Without the plugin it does nothing. When you delete
the plugin, delete the loader file too. When the settings page shows “Outdated” 
for the load order, download the file again and replace the copy.

#### Recovery

If a rule locks you out, add this line to `wp-config.php`:

    ```
    define( 'BLOCKARY_DISABLE', true );
    ```

The plugin then blocks nothing until you remove the line.

### External services

The plugin downloads the country database “IP to Country Lite” from DB-IP when you
select the local database as the country source. The download runs once after you
select that source and then once a month through WP-Cron. You can also start it 
on the settings page.

The request goes to `https://download.db-ip.com/free/`. The request carries only
the name of the database file for the current month. It carries no data about your
site or your visitors. The database is licensed under CC BY 4.0. The settings page
shows the attribution link that the license requires.

Terms and privacy policy of DB-IP: https://db-ip.com/about and https://db-ip.com/
privacy.php

The plugin sends no other request to an external service.

## Installation

 1. Upload the folder `blockary` to `wp-content/plugins`, or install the plugin from
    Plugins > Add New.
 2. Activate the plugin.
 3. Open Settings > Blockary.
 4. Add your own address to the IP whitelist.
 5. Pick the country mode and the countries.
 6. If your site runs behind Cloudflare or another proxy, add the proxy to the trusted
    proxies. Without that entry the plugin sees the proxy address for every visitor.

## FAQ

### Where does the country data come from?

The plugin reads the country from the Cloudflare header `CF-IPCountry` when the 
site runs behind Cloudflare. Without Cloudflare the plugin downloads the free “IP
to Country Lite” database from DB-IP into `wp-content/uploads/blockary` and refreshes
it once a month. See the section “External services”.

### Does the plugin send data about my visitors?

No. The country lookup runs on your server. The plugin sends no visitor data to 
any service.

### What does the plugin write outside its own folder?

The plugin writes only the country database into `wp-content/uploads/blockary`. 
It removes that folder and its settings, bans, and log on uninstall. In the database,
the plugin moves itself to the first position in the list of active plugins. The
optional loader file in `wp-content/mu-plugins` is a file that you copy by hand.
The plugin never writes or deletes it.

### I locked myself out. What now?

Add `define( 'BLOCKARY_DISABLE', true );` to `wp-config.php`. The plugin then blocks
nothing. Fix the rule on the settings page and remove the line again.

### Does the firewall apply to logged-in users?

Not by default. A visitor with a valid login cookie passes the country rule and 
the bans. If your site has open registration, turn off the setting “Do not apply
the firewall to logged-in users”. The country rule and the bans then also apply 
to logged-in users. Administrators always pass, so that you cannot lock yourself
out of the settings page.

### My code uses the filter blockary_should_block. What changed in version 1.1.0?

The plugin now decides a request without a login cookie before WordPress loads the
other plugins. A callback in a normal plugin is not registered at that moment. Put
the callback into a must-use plugin (a file in `wp-content/mu-plugins`).

### Does the plugin work with a caching plugin?

Yes. The plugin decides before WordPress loads the other plugins. A page cache that
serves files before WordPress starts, for example a web server cache, can serve 
a cached page to a blocked visitor.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Blockary – Access Firewall” is open source software. The following people have 
contributed to this plugin.

Contributors

 *   [ Michael ](https://profiles.wordpress.org/migaweb/)

[Translate “Blockary – Access Firewall” into your language.](https://translate.wordpress.org/projects/wp-plugins/blockary)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/blockary/), check out
the [SVN repository](https://plugins.svn.wordpress.org/blockary/), or subscribe 
to the [development log](https://plugins.trac.wordpress.org/log/blockary/) by [RSS](https://plugins.trac.wordpress.org/log/blockary/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.0

 * The plugin keeps itself first in the list of active plugins. The firewall decides
   a request without a login cookie before WordPress loads the other plugins. The
   loader file is no longer needed for that.
 * New setting “Do not apply the firewall to logged-in users”. It is on by default,
   which is the behavior of version 1.0.0. When it is off, the country rule and 
   the bans also apply to logged-in users. Administrators always pass.

#### 1.0.0

 * First version. Country rule with block list and allow list, login protection 
   with bans, username lock, hidden usernames, XML-RPC switch, and a log.

## Meta

 *  Version **1.1.0**
 *  Last updated **11 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [Brute Force](https://wordpress.org/plugins/tags/brute-force/)[country block](https://wordpress.org/plugins/tags/country-block/)
   [firewall](https://wordpress.org/plugins/tags/firewall/)[login protection](https://wordpress.org/plugins/tags/login-protection/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/blockary/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/blockary/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/blockary/reviews/)

## Contributors

 *   [ Michael ](https://profiles.wordpress.org/migaweb/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/blockary/)