{"id":334258,"date":"2026-07-27T08:06:13","date_gmt":"2026-07-27T08:06:13","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ip-and-country-block\/"},"modified":"2026-07-27T10:03:54","modified_gmt":"2026-07-27T10:03:54","slug":"ip-and-country-block","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ip-and-country-block\/","author":15148322,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.0.2","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"OWS IP & Country Block","header_author":"abunawim","header_description":"Block users based on their IP addresses and countries to enhance website security and control access.","assets_banners_color":"092b46","last_updated":"2026-07-27 10:03:54","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/github.com\/abunawim","header_plugin_uri":"https:\/\/github.com\/abunawim\/ip-and-country-block","header_author_uri":"https:\/\/github.com\/abunawim","rating":0,"author_block_rating":0,"active_installs":0,"downloads":27,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.0":{"tag":"1.1.0","author":"abunawim","date":"2026-07-27 10:03:54"}},"upgrade_notice":{"1.1.0":"<p>Important security fix: IP detection no longer trusts spoofable client headers by default. If your site is behind Cloudflare or another reverse proxy, set the new &quot;Trusted Proxy Header&quot; option after upgrading or IP-based blocking may use the proxy&#039;s IP instead of the visitor&#039;s.<\/p>","1.0.0":"<p>Initial release of IP and Country Block plugin.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3624139,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3624139,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3624139,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3624139,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Main settings page showing IP and country blocking options","2":"IP address blocking configuration with whitelist support","3":"Country selection interface for blocking specific nations","4":"Custom block message configuration"}},"plugin_section":[],"plugin_tags":[1912,172575,1174,1192,600],"plugin_category":[54],"plugin_contributors":[273430],"plugin_business_model":[],"class_list":["post-334258","plugin","type-plugin","status-publish","hentry","plugin_tags-access-control","plugin_tags-country-blocking","plugin_tags-firewall","plugin_tags-ip-blocking","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-abunawim","plugin_committers-abunawim"],"banners":{"banner":"https:\/\/ps.w.org\/ip-and-country-block\/assets\/banner-772x250.png?rev=3624139","banner_2x":"https:\/\/ps.w.org\/ip-and-country-block\/assets\/banner-1544x500.png?rev=3624139","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ip-and-country-block\/assets\/icon-128x128.png?rev=3624139","icon_2x":"https:\/\/ps.w.org\/ip-and-country-block\/assets\/icon-256x256.png?rev=3624139","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>OWS IP &amp; Country Block is a powerful WordPress plugin that allows you to block users based on their IP addresses and countries. This plugin helps enhance your website security by preventing access from unwanted sources.<\/p>\n\n<p><strong>Key Features:<\/strong><\/p>\n\n<ul>\n<li><strong>IP Address Blocking<\/strong>: Block specific IP addresses or IP ranges using CIDR notation<\/li>\n<li><strong>Country-based Blocking<\/strong>: Block entire countries from accessing your website<\/li>\n<li><strong>IP Whitelist<\/strong>: Create a whitelist of IP addresses that should never be blocked<\/li>\n<li><strong>Customizable Block Message<\/strong>: Set a custom message to display to blocked users<\/li>\n<li><strong>Access Logging<\/strong>: Keep track of blocked access attempts with detailed logs<\/li>\n<li><strong>Easy Administration<\/strong>: Simple and intuitive admin interface<\/li>\n<li><strong>Performance Optimized<\/strong>: Lightweight and fast with minimal impact on site performance<\/li>\n<\/ul>\n\n<p><strong>Use Cases:<\/strong><\/p>\n\n<ul>\n<li>Prevent spam and malicious attacks from specific countries<\/li>\n<li>Block competitors from accessing your content<\/li>\n<li>Comply with legal requirements for geo-blocking<\/li>\n<li>Enhance security by blocking known malicious IP ranges<\/li>\n<li>Control access during maintenance or testing<\/li>\n<\/ul>\n\n<p><strong>Security Features:<\/strong><\/p>\n\n<ul>\n<li>All user inputs are properly sanitized and validated<\/li>\n<li>Uses WordPress nonces for form security<\/li>\n<li>Follows WordPress coding standards and best practices<\/li>\n<li>Compatible with caching plugins and CDNs<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to ip-api.com to determine the country of a visitor's IP address. This lookup only occurs when country blocking is enabled and the visitor's country is not already cached.<\/p>\n\n<ul>\n<li><strong>Data sent:<\/strong> The visitor's IP address.<\/li>\n<li><strong>When:<\/strong> On each frontend page load when country blocking is active and no cached result exists for that IP.<\/li>\n<li><strong>Service provider:<\/strong> ip-api.com<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/ip-api.com\/docs\/legal<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/ip-api.com\/docs\/legal<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<p>This plugin stores IP addresses and country information for blocked access attempts in your WordPress database. This data is used solely for security purposes and is not shared with third parties. The plugin may make requests to free GeoIP services to determine visitor countries.<\/p>\n\n<h3>Support<\/h3>\n\n<p>For support, feature requests, or bug reports, please visit the plugin's GitHub repository or contact the developer.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>This plugin uses the IP-API service for country detection. Special thanks to the WordPress community for their coding standards and best practices.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/ip-and-country-block<\/code> directory, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress<\/li>\n<li>Use the Settings-&gt;IP &amp; Country Block screen to configure the plugin<\/li>\n<li>Add IP addresses or select countries you want to block<\/li>\n<li>Enable the blocking features and save your settings<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20block%20an%20entire%20country%3F\"><h3>How do I block an entire country?<\/h3><\/dt>\n<dd><p>Go to Settings -&gt; IP &amp; Country Block, enable \"Country Blocking\", select the countries you want to block from the dropdown list, and save your settings.<\/p><\/dd>\n<dt id=\"can%20i%20block%20ip%20ranges%3F\"><h3>Can I block IP ranges?<\/h3><\/dt>\n<dd><p>Yes, you can block IP ranges using CIDR notation. For example, to block the range 192.168.1.0 to 192.168.1.255, enter \"192.168.1.0\/24\".<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20slow%20down%20my%20website%3F\"><h3>Will this plugin slow down my website?<\/h3><\/dt>\n<dd><p>No, the plugin is designed to be lightweight and efficient. It only performs checks on the frontend and uses caching to minimize database queries for country lookups.<\/p><\/dd>\n<dt id=\"can%20i%20whitelist%20certain%20ip%20addresses%3F\"><h3>Can I whitelist certain IP addresses?<\/h3><\/dt>\n<dd><p>Yes, you can add IP addresses to the whitelist that will never be blocked, even if they match other blocking rules.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20cdns%20like%20cloudflare%3F\"><h3>Does this work with CDNs like Cloudflare?<\/h3><\/dt>\n<dd><p>Yes. If your site is behind Cloudflare or another reverse proxy\/CDN, go to the plugin settings and choose the matching option under \"Trusted Proxy Header\" so the plugin reads the visitor's real IP from the header your proxy sets. This is not enabled by default, because trusting these headers on a site that is <em>not<\/em> actually behind that proxy would let visitors fake their IP address and bypass blocking.<\/p><\/dd>\n<dt id=\"why%20isn%27t%20ip%20blocking%20working%20behind%20my%20cdn%3F\"><h3>Why isn't IP blocking working behind my CDN?<\/h3><\/dt>\n<dd><p>By default the plugin only trusts your web server's own connection info (REMOTE_ADDR), which is safe but on CDN\/proxied sites is the proxy's IP, not the visitor's. Go to Settings -&gt; IP &amp; Country Block and set \"Trusted Proxy Header\" to match your CDN\/proxy (for example, Cloudflare) so the real visitor IP is used.<\/p><\/dd>\n<dt id=\"can%20i%20see%20who%20has%20been%20blocked%3F\"><h3>Can I see who has been blocked?<\/h3><\/dt>\n<dd><p>The plugin logs all blocked access attempts in the database, including IP address, country, timestamp, and reason for blocking.<\/p><\/dd>\n<dt id=\"will%20this%20block%20search%20engines%3F\"><h3>Will this block search engines?<\/h3><\/dt>\n<dd><p>The plugin only blocks frontend access. Admin users and search engine bots that access your site properly should not be affected. However, be careful when blocking countries where major search engines operate.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Security: IP detection no longer trusts client-supplied headers (X-Forwarded-For, Client-IP, etc.) by default, which previously allowed spoofing to bypass blocks. A new \"Trusted Proxy Header\" setting lets you opt in to a specific header only if your site genuinely sits behind that proxy\/CDN.<\/li>\n<li>Fix: CIDR matching now supports IPv6 ranges in addition to IPv4.<\/li>\n<li>Fix: uninstall routine now correctly drops the plugin's log table (previous query used an invalid placeholder for the table name).<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>IP address blocking with CIDR support<\/li>\n<li>Country-based blocking<\/li>\n<li>IP whitelist functionality<\/li>\n<li>Access logging<\/li>\n<li>Customizable block messages<\/li>\n<li>Admin interface<\/li>\n<\/ul>","raw_excerpt":"Block users based on their IP addresses and countries to enhance website security and control access.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/334258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=334258"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/abunawim"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=334258"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=334258"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=334258"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=334258"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=334258"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=334258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}