Deerwood Country Access

Description

Deerwood Country Access makes geographic access control easy to manage from WordPress.

Choose which countries may access your site, detect and rate-limit repeat offenders, and optionally connect Cloudflare with a one-click OAuth authorization so unwanted traffic can be stopped at the edge before it reaches WordPress.

New installations are preconfigured for “Allow selected countries only” with Canada and the United States selected. Protection remains OFF until an administrator enables it.

Highlights

  • Allow selected countries only, or block selected countries.
  • Canada + United States preselected for new installations.
  • Cloudflare CF-IPCountry detection when available.
  • Optional cached IP geolocation fallback when Cloudflare country headers are unavailable; this external lookup is OFF by default.
  • Smart rate limiting for blocked traffic and common malicious probe paths.
  • Local blocked-request logging with configurable retention.
  • Repeat-offender reporting and one-click Cloudflare edge blocking.
  • One-click Cloudflare OAuth connection; site owners do not create or paste API tokens.
  • A single managed Cloudflare custom WAF rule for both geographic access and repeat offenders.
  • Country rule changes update the existing Cloudflare rule instead of creating new rules.
  • Administrator country/IP anti-lockout protections.
  • Trusted IP exceptions.
  • Optional 30-minute administrator safety window when an edge rule changes.
  • Cloudflare-verified search engines and trusted bots such as Googlebot and Bingbot can be allowed through.
  • Optional protection for the frontend, login, wp-admin, XML-RPC, and REST API.
  • Cloudflare connection testing, diagnostics, safe disconnect, and stale-connection recovery.

Country Access is focused on geographic and IP access control. It does not replace a complete WordPress malware scanner or security suite.

Important safety notice

Country Access can restrict access to your website at both the WordPress and Cloudflare edge levels. Incorrect country, IP, or Cloudflare rule settings can prevent you or other legitimate visitors from reaching the site.

Before enabling or changing protection, confirm that your own country is allowed and consider using the administrator safety window and trusted IP features. If you intentionally block your current country, make sure you have another recovery method available.

Country Access includes safeguards intended to reduce accidental lockouts, but no safeguard can guarantee access under every hosting, proxy, network, Cloudflare, or configuration scenario. Site administrators are responsible for reviewing and testing their access rules and maintaining appropriate backups and recovery access.

Country Access is provided without warranty, to the extent permitted by applicable law. Deerwood Media and the plugin contributors are not responsible for website downtime, lost traffic, lost revenue, data loss, third-party service behavior, or other damages resulting from the installation, configuration, use, or inability to use the plugin.

This notice does not replace or limit the terms of the GPL license.

External services

Country Access can communicate with external services. These integrations are documented here so site owners know when data leaves the WordPress installation.

Cloudflare

Cloudflare integration is optional and begins only after an administrator explicitly clicks the Cloudflare authorization control and approves the requested permissions.

Country Access uses Cloudflare for country information supplied in request headers and, when authorized, to identify the site’s Cloudflare zone and create/update/remove the plugin’s managed WAF protection rule. OAuth tokens and Cloudflare zone/account identifiers are stored in the WordPress database.

Cloudflare:
https://www.cloudflare.com/

Cloudflare Privacy Policy:
https://www.cloudflare.com/privacypolicy/

Cloudflare Terms:
https://www.cloudflare.com/website-terms/

Country Access is an independent plugin and is not affiliated with or endorsed by Cloudflare, Inc.

Country Access OAuth relay

To provide the one-click Cloudflare connection, Country Access sends the administrator through the publisher-operated OAuth relay at:

https://auth.deerwoodmedia.com/

During an OAuth connection, the relay receives OAuth/PKCE transaction data, the WordPress return URL, and the site’s hostname so it can complete the Cloudflare authorization flow and return the administrator to the correct WordPress site. The relay is used only when an administrator explicitly starts Cloudflare authorization.

The relay is operated by Deerwood Media:
https://deerwoodmedia.com/

IPWhois / ipwho.is geolocation fallback

When an administrator explicitly enables the geolocation fallback and Cloudflare does not provide a usable country code, Deerwood Country Access sends the visitor IP address to the IPWhois ipwho.is service to determine a country code. Results are cached in WordPress for seven days to reduce repeat requests.

IPWhois:
https://ipwhois.io/

IPWhois Privacy Policy:
https://ipwhois.io/privacy

IPWhois Terms of Service:
https://ipwhois.io/terms

Site owners should review the external-service policies and their own privacy obligations before enabling features that process visitor IP addresses.

Privacy

Country Access can store security-event information, including visitor IP addresses, in the local WordPress database when logging is enabled. Exact IP addresses are required for repeat-offender detection, local rate limiting, trusted-IP handling, and optional Cloudflare edge blocking.

Detailed logs are automatically removed according to the configured retention period. The default retention period is 30 days.

When the administrator explicitly enables fallback geolocation and Cloudflare does not provide a country code, the visitor IP address is sent to IPWhois to determine the country. Results are cached locally for seven days.

When an administrator explicitly connects Cloudflare, Country Access stores the resulting OAuth credentials and Cloudflare zone/account identifiers in the WordPress database so it can manage the Country Access edge-protection rule.

Country Access 1.0 does not send blocked-request logs or repeat-offender telemetry to a central Country Access threat database.

Screenshots

Installation

  1. Install and activate Country Access.
  2. Open Settings > Country Access.
  3. Review the preselected Canada + United States allow-only profile and make sure your own country is allowed.
  4. Review the administrator safety window and trusted IP options before enabling protection.
  5. Turn Country Access ON only when you are ready to enforce the policy.
  6. Optional: click Connect Cloudflare to move supported country and repeat-offender blocking to Cloudflare’s edge.
  7. After changing country or Cloudflare settings, test the site before ending your administrator session so you do not accidentally lock yourself out.

Cloudflare is optional. No Cloudflare API token is required for the normal OAuth connection.

FAQ

Do I need Cloudflare?

No. Deerwood Country Access works without Cloudflare. Its optional IPWhois geolocation fallback can be enabled by the administrator when a Cloudflare country header is unavailable. The external fallback is OFF by default.

Connecting Cloudflare allows Country Access to maintain an edge WAF rule so supported unwanted traffic can be blocked before it reaches your web server.

Does protection turn on immediately after activation?

No. New installations start with Canada and the United States selected in Allow Only mode, but Country Access remains OFF until an administrator enables it.

Does Country Access use one Cloudflare rule per IP or country?

No. Country Access maintains a single custom WAF rule named Country Access: Protection. Geographic restrictions and managed repeat-offender IPs are combined into that rule and updated in place.

Country Access does not intentionally modify or delete unrelated Cloudflare rules.

What happens if the Cloudflare custom-rule limit is reached?

Country Access leaves unrelated Cloudflare rules untouched. Local WordPress protection continues to operate and the administrator is shown the Cloudflare error.

Can Country Access accidentally block the administrator?

Country Access includes multiple safeguards. It checks the administrator’s current country before syncing risky geographic settings, supports trusted IPs, and can temporarily exempt the current administrator IP for 30 minutes while an edge rule is changed.

What about Googlebot and other search engines?

The Cloudflare settings include Allow verified search engines and trusted bots, enabled by default. When enabled, Country Access uses Cloudflare’s verified cf.client.bot signal so known good crawlers such as Googlebot and Bingbot can bypass the Country Access edge rule.

Country Access does not trust a visitor simply because its User-Agent says “Googlebot”.

Does rate limiting apply to all visitors?

No. The built-in rate limiter focuses on country-blocked traffic and suspicious probe paths. High-risk requests such as .env, .git, wp-config, and phpMyAdmin probes receive higher weights.

Why can the WordPress activity log be quiet after Cloudflare protection is enabled?

Traffic blocked at Cloudflare’s edge never reaches WordPress, so Country Access cannot record those requests in its local WordPress log. This is expected and reduces load on the origin server.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Deerwood Country Access” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.11

  • Fixed Cloudflare OAuth authorization to request offline_access so Cloudflare issues a refresh token.
  • Added automatic OAuth access-token renewal using the stored refresh token, including rotated refresh-token handling.
  • Added one automatic refresh-and-retry when Cloudflare unexpectedly returns HTTP 401.
  • Improved Cloudflare rule-status handling so API/authentication failures are not incorrectly reported as a missing managed rule.
  • Narrowed the verified-bot edge exception to Cloudflare-verified Google and Bing crawlers.
  • Added a warning when edge sync is enabled but the current request appears to bypass Cloudflare.
  • Added WordPress-layer direct-origin bypass protection when Cloudflare edge sync is active.
  • Added PHP CLI safety bypass so maintenance scripts that bootstrap WordPress are not blocked by Country Access.
  • Verified the full OAuth lifecycle in production testing: authorization, refresh-token issuance, forced access-token expiry, automatic renewal, and continued Cloudflare API access.

1.0.10

  • Added automatic WordPress-layer origin bypass protection when Country Access and Cloudflare country sync are enabled.
  • Requests that reach WordPress without Cloudflare request markers are blocked with HTTP 403 instead of bypassing the configured edge policy.
  • Logged-in administrators, trusted IPs, the detected origin server IP, WP-CLI, and WordPress cron retain their existing safety bypasses.
  • This portable WordPress safeguard complements, but does not replace, server/firewall origin lockdown.

1.0.9

  • Fixed Cloudflare OAuth renewal so a known-expired access token is never reused after refresh fails.
  • Added one automatic refresh-and-retry when Cloudflare unexpectedly returns HTTP 401.
  • Improved Cloudflare rule status so authentication/API failures display as unable to verify instead of incorrectly reporting the managed rule as missing.
  • Narrowed the verified-bot edge exception to Cloudflare-verified Google and Bing crawlers; other verified crawlers now follow the configured country policy.
  • Added an administrator warning when Cloudflare edge sync is enabled but the current request appears to be bypassing Cloudflare.

1.0.8

  • Updated internal prefixes for WordPress.org directory compatibility and collision avoidance.
  • Preserved existing settings and Cloudflare connection data during the prefix migration.

1.0.7

  • Added automatic protection for the WordPress origin server’s public IP when it can be safely detected.
  • The origin server IP now bypasses local Country Access blocking and rate limiting.
  • Cloudflare geographic, repeat-offender, and manual blacklist protection will not block the detected origin server IP.
  • The diagnostics panel shows the detected WordPress server IP as Protected.

1.0.6

  • Added an unsaved-settings safeguard to the Country Access admin screen.
  • A sticky Save Changes reminder appears after settings are modified.
  • Leaving or refreshing the page with unsaved changes now triggers a warning.
  • Saving clears the warning normally.

1.0.5

  • Added a manual IP blacklist alongside the existing whitelist.
  • Blacklisted IPs are blocked locally even when their country is otherwise allowed.
  • When Cloudflare sync is active, manual blacklist IPs are folded into the existing single Country Access: Protection rule.
  • Whitelisted IPs take priority over manual blacklist and managed repeat-offender IPs.
  • Explicit manual blacklist entries remain blocked even when verified-bot bypass is enabled.

1.0.4

  • Corrected the View rules in Cloudflare link to Cloudflare’s current zone Security Rules route (/security/security-rules).

1.0.3

  • Fixed the View rules in Cloudflare link to open the zone Security page used by Cloudflare’s current dashboard.
  • The link now targets /security/ instead of the obsolete /security/rules path.

1.0.2

  • Fixed the master ON/OFF control after the 1.0.1 settings-save safeguard.
  • Normal Save Settings actions continue to preserve the master protection state.
  • The dedicated master switch can now explicitly change the enabled state without the settings sanitizer reverting it.
  • Corrected two remaining admin links to the Deerwood Country Access settings slug.

1.0.1

  • Fixed a settings-save bug where saving the main settings form could turn off the master Country Access protection switch and remove the managed Cloudflare rule.
  • The master protection state is now preserved when saving unrelated settings.

1.0.0

  • Initial public release.
  • WordPress.org compliance pass: text domain, prepared custom-table queries, escaping, sanitization, nonces/OAuth state documentation, and redirect safety.
  • Country allow-only and block-selected modes.
  • Cloudflare-aware country detection with cached IP geolocation fallback.
  • Smart rate limiting and repeat-offender reporting.
  • One-click Cloudflare OAuth authorization.
  • Single managed Cloudflare WAF rule combining geographic and repeat-offender protection.
  • One-click offender edge blocking and removal.
  • Administrator anti-lockout and trusted-IP safeguards.
  • Verified Cloudflare bot/search-engine bypass option.
  • Safe Cloudflare disconnect, reconnect, and stale OAuth recovery.
  • Cloudflare API burst protection and graceful HTTP 429 handling.
  • Local security logging with configurable retention.