IP Location Block

Description

IP Location Block is a WordPress geo blocking plugin for blocking or allowing visitors by country, US state or equivalent region, IP address, CIDR range, or ASN.

Simple view covers common rules. Advanced view adds login, registration, comment, XML-RPC, bot, response, logging, privacy, provider, and diagnostic controls.

For the recommended setup, connect the IP Location Block Cloud provider for premium, frequently updated data, better country accuracy, ASN data, and state or region precision.

WordPress geo blocking by country, state, or region

Use a blocklist to deny selected locations or an allowlist to limit access. Regional rules use the administrative area returned for a country, such as a state, province, prefecture, territory, or region. This supports regional availability, service areas, store access, and site policies. Country rules remain active when precision is unavailable.

Key features

  • Block or allow visitors by country and state or equivalent region.
  • Add priority rules for IP addresses, IPv4 or IPv6 CIDR ranges, and ASNs.
  • Protect public pages, login, registration, comments, XML-RPC, and selected wp-admin requests.
  • Configure blocked responses and control failed logins or unwanted bots.
  • Search IPs and review validation logs, statistics, and diagnostics.
  • Use frequently updated data from the IP Location Block Cloud provider with country-level fallbacks.
  • Encrypt stored IP addresses, with optional anonymization.

IP Location Block Cloud provider

  • Better accuracy: Premium geolocation databases are updated frequently for more reliable country results.
  • Regional precision: Add state, province, prefecture, territory, or equivalent regional rules.
  • Broader data: Use IPv4, IPv6, and ASN information through one managed provider.

Legacy local and third-party providers remain supported for existing installations and country-level fallback rules. Regional precision requires the IP Location Block Cloud provider.

External services and privacy

  • IP Location Block Cloud provider: Selecting this provider sends the visitor IP and configured credential to IP Location Block for lookup. Review its privacy policy and terms.
  • IP2Location LITE: For compatibility with this provider, the plugin downloads country databases on activation and scheduled updates. Review its terms and privacy policy.
  • MaxMind GeoLite2: For compatibility with this provider, the plugin uses your license key to download databases. Review its license and privacy policy.
  • Other remote providers: Selecting IPInfoDB, IPinfo.io, ipapi, or ipstack sends the visitor IP and configured credential to that service for lookup. No remote provider is selected automatically.

Other remote provider policies: IPInfoDB privacy and service agreement; IPinfo.io privacy and terms; ipapi privacy and terms; ipstack privacy and terms.

The administrator chooses the providers and is responsible for any required consent or disclosure.

Documentation, support, and credits

Use the documentation, troubleshooting guide, support forum, or GitHub.

Independently maintained, IP Location Block is based on IP Geo Block by tokkonopapa. It uses IP2Location LITE and GeoLite2 data under their licenses.

Screenshots

Installation

  1. Open Plugins > Add New Plugin, search for IP Location Block, install it, and activate it.
  2. Open Settings > IP Location Block.
  3. In Simple view, choose whether to block or allow locations and where protection applies.
  4. Connect the IP Location Block Cloud provider for the recommended accuracy, ASN data, and regional precision.
  5. Verify representative IPs in Search, save the rules, and use Advanced view when you need more control.

See the getting started guide for a complete walkthrough.

FAQ

Can I block visitors from specific US states?

Yes. Connect the IP Location Block Cloud provider, add a United States rule, then select states under Regional rules. Other countries use their equivalent administrative areas. See state or region rules.

What does the IP Location Block Cloud provider add?

It uses premium, frequently updated geolocation data for better country accuracy, ASN information, and state or region precision.

Which parts of WordPress can the plugin protect?

Public pages, login, registration, comments, XML-RPC, and selected wp-admin requests. Advanced view controls each target.

Does it work with page caches, CDNs, and reverse proxies?

Yes, when configured correctly. Page caches may respond before WordPress runs, while a CDN or proxy can hide the visitor IP. Review the page-cache guide and test Search.

What if I block myself from wp-admin?

Bookmark the private emergency link before enforcing admin rules. If blocked, follow the admin access steps.

Can I migrate settings from IP Geo Block?

Yes. When old settings are detected, Plugin settings offers a migration preview before saving them.

Reviews

July 6, 2026 1 reply
Good so far. Just needs to stop reminding me on every single page to leave a review and will be great. Thank you.
September 2, 2025
This plugin is a lifesaver for managing access by location. Setup was quick and straightforward, and it’s been working perfectly right out of the box. Since installing it, I’ve noticed a significant decrease in suspicious login attempts. If you want an easy, reliable way to block visitors from certain countries, this is an excellent choice. A practical and well-built plugin!
June 13, 2025
S’ha de ficar com a “mu” a les opcions per a tallar el trànsit que no es vol.Si el teu target de clients està al Chunguetistan, pots fer una white list de chunguetistan, la teva IP de gestió i la IP del servidor. D’aquesta manera evites els centenars d’atacs continuats que rebia des de EEUU, Alemanya, Irlanda, França, … i ara gràcies a aquest plugin només rebo visites dels meus clients, que estan a Chunguetistan. 0 bots o crawlers, només visites reals i ventes!gràcies!
June 3, 2025 1 reply
It doesn’t seem to work. Under Settings, in the Matching Rule, Whitelist is selected and it says ‘A request from which the country code or IP address is NOT in the whitelist will be blocked.’ I’ve added my state US:State:Colorado. When spam is submitted, I looked-up their IP address and saw they were from Florida. In the Blacklist matching rule, I added US:State:Florida, and I still get spam from Florida.
March 5, 2025
This plugin does exactly what I needed—blocks traffic from specific countries without any hassle. Super easy to set up, and it works flawlessly. I’ve seen a big drop in unwanted login attempts since installing it. If you’re looking for a simple and effective way to control access by location, this is the one to go for. Huge thanks to the developer, Darko G., for creating such a useful plugin! I am From India, Tamilnadu.
Read all 34 reviews

Contributors & Developers

“IP Location Block” is open source software. The following people have contributed to this plugin.

Contributors

“IP Location Block” has been translated into 2 locales. Thank you to the translators for their contributions.

Translate “IP Location Block” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.4.0

Release Date – 24 Aug 2026

  • Redesigned the admin with Simple and Advanced views, provider setup, statistics, logs, search, and diagnostics.
  • Added searchable state or region rules and a modern bot-rule builder.
  • Prioritized the IP Location Block provider for regional rules while retaining country fallbacks.
  • Rebuilt internals with PSR-4 and scoped dependencies, plus broad provider, cache, database, filesystem, and interface fixes.
  • Requires PHP 8.1 and WordPress 6.5 or newer. The redesigned admin requires WordPress 6.6.

Older release history is available in changelog.txt included with the plugin.