Title: Deerwood Country Access
Author: DeerwoodMedia
Published: <strong>September 30, 2026</strong>
Last modified: September 30, 2026

---

Search plugins

![](https://ps.w.org/deerwood-country-access/assets/icon-256x256.png?rev=3721785)

# Deerwood Country Access

 By [DeerwoodMedia](https://profiles.wordpress.org/williamqlee/)

[Download](https://downloads.wordpress.org/plugin/deerwood-country-access.1.0.11.zip)

 * [Details](https://wordpress.org/plugins/deerwood-country-access/#description)
 * [Reviews](https://wordpress.org/plugins/deerwood-country-access/#reviews)
 *  [Installation](https://wordpress.org/plugins/deerwood-country-access/#installation)
 * [Development](https://wordpress.org/plugins/deerwood-country-access/#developers)

 [Support](https://wordpress.org/support/plugin/deerwood-country-access/)

## Description

Deerwood Country Access makes geographic access control easy to manage from WordPress.

Choose which countries may access your site, detect and rate-limit repeat offenders,
and optionally connect Cloudflare with a one-click OAuth authorization so unwanted
traffic can be stopped at the edge before it reaches WordPress.

New installations are preconfigured for “Allow selected countries only” with Canada
and the United States selected. Protection remains OFF until an administrator enables
it.

#### Highlights

 * Allow selected countries only, or block selected countries.
 * Canada + United States preselected for new installations.
 * Cloudflare `CF-IPCountry` detection when available.
 * Optional cached IP geolocation fallback when Cloudflare country headers are unavailable;
   this external lookup is OFF by default.
 * Smart rate limiting for blocked traffic and common malicious probe paths.
 * Local blocked-request logging with configurable retention.
 * Repeat-offender reporting and one-click Cloudflare edge blocking.
 * One-click Cloudflare OAuth connection; site owners do not create or paste API
   tokens.
 * A single managed Cloudflare custom WAF rule for both geographic access and repeat
   offenders.
 * Country rule changes update the existing Cloudflare rule instead of creating 
   new rules.
 * Administrator country/IP anti-lockout protections.
 * Trusted IP exceptions.
 * Optional 30-minute administrator safety window when an edge rule changes.
 * Cloudflare-verified search engines and trusted bots such as Googlebot and Bingbot
   can be allowed through.
 * Optional protection for the frontend, login, wp-admin, XML-RPC, and REST API.
 * Cloudflare connection testing, diagnostics, safe disconnect, and stale-connection
   recovery.

Country Access is focused on geographic and IP access control. It does not replace
a complete WordPress malware scanner or security suite.

### Important safety notice

Country Access can restrict access to your website at both the WordPress and Cloudflare
edge levels. Incorrect country, IP, or Cloudflare rule settings can prevent you 
or other legitimate visitors from reaching the site.

Before enabling or changing protection, confirm that your own country is allowed
and consider using the administrator safety window and trusted IP features. If you
intentionally block your current country, make sure you have another recovery method
available.

Country Access includes safeguards intended to reduce accidental lockouts, but no
safeguard can guarantee access under every hosting, proxy, network, Cloudflare, 
or configuration scenario. Site administrators are responsible for reviewing and
testing their access rules and maintaining appropriate backups and recovery access.

Country Access is provided without warranty, to the extent permitted by applicable
law. Deerwood Media and the plugin contributors are not responsible for website 
downtime, lost traffic, lost revenue, data loss, third-party service behavior, or
other damages resulting from the installation, configuration, use, or inability 
to use the plugin.

This notice does not replace or limit the terms of the GPL license.

### External services

Country Access can communicate with external services. These integrations are documented
here so site owners know when data leaves the WordPress installation.

#### Cloudflare

Cloudflare integration is optional and begins only after an administrator explicitly
clicks the Cloudflare authorization control and approves the requested permissions.

Country Access uses Cloudflare for country information supplied in request headers
and, when authorized, to identify the site’s Cloudflare zone and create/update/remove
the plugin’s managed WAF protection rule. OAuth tokens and Cloudflare zone/account
identifiers are stored in the WordPress database.

Cloudflare:
 https://www.cloudflare.com/

Cloudflare Privacy Policy:
 https://www.cloudflare.com/privacypolicy/

Cloudflare Terms:
 https://www.cloudflare.com/website-terms/

Country Access is an independent plugin and is not affiliated with or endorsed by
Cloudflare, Inc.

#### Country Access OAuth relay

To provide the one-click Cloudflare connection, Country Access sends the administrator
through the publisher-operated OAuth relay at:

https://auth.deerwoodmedia.com/

During an OAuth connection, the relay receives OAuth/PKCE transaction data, the 
WordPress return URL, and the site’s hostname so it can complete the Cloudflare 
authorization flow and return the administrator to the correct WordPress site. The
relay is used only when an administrator explicitly starts Cloudflare authorization.

The relay is operated by Deerwood Media:
 https://deerwoodmedia.com/

#### IPWhois / ipwho.is geolocation fallback

When an administrator explicitly enables the geolocation fallback and Cloudflare
does not provide a usable country code, Deerwood Country Access sends the visitor
IP address to the IPWhois `ipwho.is` service to determine a country code. Results
are cached in WordPress for seven days to reduce repeat requests.

IPWhois:
 https://ipwhois.io/

IPWhois Privacy Policy:
 https://ipwhois.io/privacy

IPWhois Terms of Service:
 https://ipwhois.io/terms

Site owners should review the external-service policies and their own privacy obligations
before enabling features that process visitor IP addresses.

### Privacy

Country Access can store security-event information, including visitor IP addresses,
in the local WordPress database when logging is enabled. Exact IP addresses are 
required for repeat-offender detection, local rate limiting, trusted-IP handling,
and optional Cloudflare edge blocking.

Detailed logs are automatically removed according to the configured retention period.
The default retention period is 30 days.

When the administrator explicitly enables fallback geolocation and Cloudflare does
not provide a country code, the visitor IP address is sent to IPWhois to determine
the country. Results are cached locally for seven days.

When an administrator explicitly connects Cloudflare, Country Access stores the 
resulting OAuth credentials and Cloudflare zone/account identifiers in the WordPress
database so it can manage the Country Access edge-protection rule.

Country Access 1.0 does not send blocked-request logs or repeat-offender telemetry
to a central Country Access threat database.

## Screenshots

[⌊Country Access protection status, Cloudflare connection, country detection, and
connection diagnostics.⌉⌊Country Access protection status, Cloudflare connection,
country detection, and connection diagnostics.⌉[

Country Access protection status, Cloudflare connection, country detection, and 
connection diagnostics.

[⌊Search and select the countries allowed or blocked by your access policy.⌉⌊Search
and select the countries allowed or blocked by your access policy.⌉[

Search and select the countries allowed or blocked by your access policy.

[⌊Smart rate limiting, Cloudflare country synchronization, administrator safety 
controls, and verified search-engine protection.⌉⌊Smart rate limiting, Cloudflare
country synchronization, administrator safety controls, and verified search-engine
protection.⌉[

Smart rate limiting, Cloudflare country synchronization, administrator safety controls,
and verified search-engine protection.

[⌊Cloudflare Edge Protection showing the managed Country Access WAF rule and security
IP logging status.⌉⌊Cloudflare Edge Protection showing the managed Country Access
WAF rule and security IP logging status.⌉[

Cloudflare Edge Protection showing the managed Country Access WAF rule and security
IP logging status.

[⌊Blocked request activity showing recent blocks, countries, reasons, protected 
areas, and detection methods.⌉⌊Blocked request activity showing recent blocks, countries,
reasons, protected areas, and detection methods.⌉[

Blocked request activity showing recent blocks, countries, reasons, protected areas,
and detection methods.

## Installation

 1. Install and activate Country Access.
 2. Open **Settings > Country Access**.
 3. Review the preselected Canada + United States allow-only profile and make sure 
    your own country is allowed.
 4. Review the administrator safety window and trusted IP options before enabling protection.
 5. Turn Country Access ON only when you are ready to enforce the policy.
 6. Optional: click **Connect Cloudflare** to move supported country and repeat-offender
    blocking to Cloudflare’s edge.
 7. After changing country or Cloudflare settings, test the site before ending your
    administrator session so you do not accidentally lock yourself out.

Cloudflare is optional. No Cloudflare API token is required for the normal OAuth
connection.

## FAQ

### Do I need Cloudflare?

No. Deerwood Country Access works without Cloudflare. Its optional IPWhois geolocation
fallback can be enabled by the administrator when a Cloudflare country header is
unavailable. The external fallback is OFF by default.

Connecting Cloudflare allows Country Access to maintain an edge WAF rule so supported
unwanted traffic can be blocked before it reaches your web server.

### Does protection turn on immediately after activation?

No. New installations start with Canada and the United States selected in Allow 
Only mode, but Country Access remains OFF until an administrator enables it.

### Does Country Access use one Cloudflare rule per IP or country?

No. Country Access maintains a single custom WAF rule named **Country Access: Protection**.
Geographic restrictions and managed repeat-offender IPs are combined into that rule
and updated in place.

Country Access does not intentionally modify or delete unrelated Cloudflare rules.

### What happens if the Cloudflare custom-rule limit is reached?

Country Access leaves unrelated Cloudflare rules untouched. Local WordPress protection
continues to operate and the administrator is shown the Cloudflare error.

### Can Country Access accidentally block the administrator?

Country Access includes multiple safeguards. It checks the administrator’s current
country before syncing risky geographic settings, supports trusted IPs, and can 
temporarily exempt the current administrator IP for 30 minutes while an edge rule
is changed.

### What about Googlebot and other search engines?

The Cloudflare settings include **Allow verified search engines and trusted bots**,
enabled by default. When enabled, Country Access uses Cloudflare’s verified `cf.
client.bot` signal so known good crawlers such as Googlebot and Bingbot can bypass
the Country Access edge rule.

Country Access does not trust a visitor simply because its User-Agent says “Googlebot”.

### Does rate limiting apply to all visitors?

No. The built-in rate limiter focuses on country-blocked traffic and suspicious 
probe paths. High-risk requests such as `.env`, `.git`, `wp-config`, and phpMyAdmin
probes receive higher weights.

### Why can the WordPress activity log be quiet after Cloudflare protection is enabled?

Traffic blocked at Cloudflare’s edge never reaches WordPress, so Country Access 
cannot record those requests in its local WordPress log. This is expected and reduces
load on the origin server.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Deerwood Country Access” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ DeerwoodMedia ](https://profiles.wordpress.org/williamqlee/)

[Translate “Deerwood Country Access” into your language.](https://translate.wordpress.org/projects/wp-plugins/deerwood-country-access)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/deerwood-country-access/),
check out the [SVN repository](https://plugins.svn.wordpress.org/deerwood-country-access/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/deerwood-country-access/)
by [RSS](https://plugins.trac.wordpress.org/log/deerwood-country-access/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.11

 * Fixed Cloudflare OAuth authorization to request offline_access so Cloudflare 
   issues a refresh token.
 * Added automatic OAuth access-token renewal using the stored refresh token, including
   rotated refresh-token handling.
 * Added one automatic refresh-and-retry when Cloudflare unexpectedly returns HTTP
   401.
 * Improved Cloudflare rule-status handling so API/authentication failures are not
   incorrectly reported as a missing managed rule.
 * Narrowed the verified-bot edge exception to Cloudflare-verified Google and Bing
   crawlers.
 * Added a warning when edge sync is enabled but the current request appears to 
   bypass Cloudflare.
 * Added WordPress-layer direct-origin bypass protection when Cloudflare edge sync
   is active.
 * Added PHP CLI safety bypass so maintenance scripts that bootstrap WordPress are
   not blocked by Country Access.
 * Verified the full OAuth lifecycle in production testing: authorization, refresh-
   token issuance, forced access-token expiry, automatic renewal, and continued 
   Cloudflare API access.

#### 1.0.10

 * Added automatic WordPress-layer origin bypass protection when Country Access 
   and Cloudflare country sync are enabled.
 * Requests that reach WordPress without Cloudflare request markers are blocked 
   with HTTP 403 instead of bypassing the configured edge policy.
 * Logged-in administrators, trusted IPs, the detected origin server IP, WP-CLI,
   and WordPress cron retain their existing safety bypasses.
 * This portable WordPress safeguard complements, but does not replace, server/firewall
   origin lockdown.

#### 1.0.9

 * Fixed Cloudflare OAuth renewal so a known-expired access token is never reused
   after refresh fails.
 * Added one automatic refresh-and-retry when Cloudflare unexpectedly returns HTTP
   401.
 * Improved Cloudflare rule status so authentication/API failures display as unable
   to verify instead of incorrectly reporting the managed rule as missing.
 * Narrowed the verified-bot edge exception to Cloudflare-verified Google and Bing
   crawlers; other verified crawlers now follow the configured country policy.
 * Added an administrator warning when Cloudflare edge sync is enabled but the current
   request appears to be bypassing Cloudflare.

#### 1.0.8

 * Updated internal prefixes for WordPress.org directory compatibility and collision
   avoidance.
 * Preserved existing settings and Cloudflare connection data during the prefix 
   migration.

#### 1.0.7

 * Added automatic protection for the WordPress origin server’s public IP when it
   can be safely detected.
 * The origin server IP now bypasses local Country Access blocking and rate limiting.
 * Cloudflare geographic, repeat-offender, and manual blacklist protection will 
   not block the detected origin server IP.
 * The diagnostics panel shows the detected WordPress server IP as Protected.

#### 1.0.6

 * Added an unsaved-settings safeguard to the Country Access admin screen.
 * A sticky Save Changes reminder appears after settings are modified.
 * Leaving or refreshing the page with unsaved changes now triggers a warning.
 * Saving clears the warning normally.

#### 1.0.5

 * Added a manual IP blacklist alongside the existing whitelist.
 * Blacklisted IPs are blocked locally even when their country is otherwise allowed.
 * When Cloudflare sync is active, manual blacklist IPs are folded into the existing
   single Country Access: Protection rule.
 * Whitelisted IPs take priority over manual blacklist and managed repeat-offender
   IPs.
 * Explicit manual blacklist entries remain blocked even when verified-bot bypass
   is enabled.

#### 1.0.4

 * Corrected the View rules in Cloudflare link to Cloudflare’s current zone Security
   Rules route (/security/security-rules).

#### 1.0.3

 * Fixed the View rules in Cloudflare link to open the zone Security page used by
   Cloudflare’s current dashboard.
 * The link now targets /security/ instead of the obsolete /security/rules path.

#### 1.0.2

 * Fixed the master ON/OFF control after the 1.0.1 settings-save safeguard.
 * Normal Save Settings actions continue to preserve the master protection state.
 * The dedicated master switch can now explicitly change the enabled state without
   the settings sanitizer reverting it.
 * Corrected two remaining admin links to the Deerwood Country Access settings slug.

#### 1.0.1

 * Fixed a settings-save bug where saving the main settings form could turn off 
   the master Country Access protection switch and remove the managed Cloudflare
   rule.
 * The master protection state is now preserved when saving unrelated settings.

#### 1.0.0

 * Initial public release.
 * WordPress.org compliance pass: text domain, prepared custom-table queries, escaping,
   sanitization, nonces/OAuth state documentation, and redirect safety.
 * Country allow-only and block-selected modes.
 * Cloudflare-aware country detection with cached IP geolocation fallback.
 * Smart rate limiting and repeat-offender reporting.
 * One-click Cloudflare OAuth authorization.
 * Single managed Cloudflare WAF rule combining geographic and repeat-offender protection.
 * One-click offender edge blocking and removal.
 * Administrator anti-lockout and trusted-IP safeguards.
 * Verified Cloudflare bot/search-engine bypass option.
 * Safe Cloudflare disconnect, reconnect, and stale OAuth recovery.
 * Cloudflare API burst protection and graceful HTTP 429 handling.
 * Local security logging with configurable retention.

## Meta

 *  Version **1.0.11**
 *  Last updated **22 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [cloudflare](https://wordpress.org/plugins/tags/cloudflare/)[country blocking](https://wordpress.org/plugins/tags/country-blocking/)
   [firewall](https://wordpress.org/plugins/tags/firewall/)[geoblock](https://wordpress.org/plugins/tags/geoblock/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/deerwood-country-access/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/deerwood-country-access/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/deerwood-country-access/reviews/)

## Contributors

 *   [ DeerwoodMedia ](https://profiles.wordpress.org/williamqlee/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/deerwood-country-access/)