{"id":341024,"date":"2026-07-25T16:00:48","date_gmt":"2026-07-25T16:00:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wonderful-geoblocking-countries\/"},"modified":"2026-07-25T16:00:25","modified_gmt":"2026-07-25T16:00:25","slug":"wonderful-geoblocking-countries","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/wonderful-geoblocking-countries\/","author":23357214,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Wonderful Geoblocking Countries","header_author":"Wonderful Plugins","header_description":"Blocks site access, login, or registration for visitors from selected countries, with a customizable message per area.","assets_banners_color":"","last_updated":"2026-07-25 16:00:25","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wonderfulplugins.eu\/wonderful-geoblocking-countries","header_author_uri":"https:\/\/wonderfulplugins.eu","rating":0,"author_block_rating":0,"active_installs":0,"downloads":34,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"wonderfulplugins","date":"2026-07-25 16:00:25"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3622600,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3622600,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1-de.jpg":{"filename":"screenshot-1-de.jpg","revision":3622600,"resolution":"1","location":"assets","locale":"de","width":2560,"height":4058},"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3622600,"resolution":"1","location":"assets","locale":"","width":2560,"height":3980}},"screenshots":{"1":"The settings page: database setup and per-area country lists with custom block messages."}},"plugin_section":[],"plugin_tags":[149980,88702,232176,4124,600],"plugin_category":[49,54],"plugin_contributors":[247385],"plugin_business_model":[],"class_list":["post-341024","plugin","type-plugin","status-publish","hentry","plugin_tags-block-countries","plugin_tags-country-block","plugin_tags-geoblocking","plugin_tags-geolocation","plugin_tags-security","plugin_category-maps-and-location","plugin_category-security-and-spam-protection","plugin_contributors-wonderfulplugins","plugin_committers-wonderfulplugins"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/icon-128x128.png?rev=3622600","icon_2x":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/icon-256x256.png?rev=3622600","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/screenshot-1.jpg?rev=3622600","caption":"The settings page: database setup and per-area country lists with custom block messages."}],"raw_content":"<!--section=description-->\n<p>Some sites simply do not need worldwide traffic \u2014 or keep getting spam registrations and brute-force login attempts from countries they never do business with.<\/p>\n\n<p><strong>Wonderful Geoblocking Countries<\/strong> lets you block three areas of your site independently, each with its own country list and its own message:<\/p>\n\n<ul>\n<li><strong>Site access<\/strong> \u2014 the whole public frontend.<\/li>\n<li><strong>Login<\/strong> \u2014 the wp-login.php page.<\/li>\n<li><strong>Registration<\/strong> \u2014 the user registration form.<\/li>\n<\/ul>\n\n<p>For every area you pick the mode that fits:<\/p>\n\n<ul>\n<li><strong>Block list<\/strong> \u2014 block visitors from the selected countries and allow everyone else.<\/li>\n<li><strong>Allow list<\/strong> \u2014 allow only the selected countries and block everyone else (e.g. \"only visitors from Austria, Germany and Switzerland may log in\").<\/li>\n<\/ul>\n\n<p>Blocked visitors receive an HTTP 403 response with your custom message (basic HTML allowed).<\/p>\n\n<p><strong>Built-in safety rails:<\/strong><\/p>\n\n<ul>\n<li>Logged-in administrators are never geoblocked, so you cannot lock yourself out of a site you are logged in to.<\/li>\n<li>The WordPress admin and the login page are never affected by the <em>site access<\/em> rule \u2014 login blocking is its own explicit setting.<\/li>\n<li>Visitors whose country cannot be determined are never blocked.<\/li>\n<\/ul>\n\n<p><strong>Geolocation data:<\/strong> the plugin uses the free IP2Location LITE country database (IPv4 + IPv6). The database is <em>not<\/em> bundled: you create a free account at lite.ip2location.com, paste your personal download token into the settings, and the plugin downloads the database (a few MB) onto your server. Once installed, it refreshes itself about once a month \u2014 an automatic update you can switch off at any time.<\/p>\n\n<p>Sites behind a CDN or reverse proxy can feed the real visitor IP (or a ready-made country code, e.g. from Cloudflare's <code>CF-IPCountry<\/code> header) into the plugin via the <code>wonderful_geoblocking_countries_client_ip<\/code> and <code>wonderful_geoblocking_countries_pre_country_code<\/code> filters.<\/p>\n\n<p>This plugin uses IP2Location LITE data available from https:\/\/lite.ip2location.com.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can download the IP2Location LITE geolocation database from www.ip2location.com. The download only happens when you actively configure it: you enter your personal download token and click the download button (afterwards a monthly scheduled refresh re-downloads the database with the same token). The token you obtained from your lite.ip2location.com account is sent to www.ip2location.com as part of the download request; no data about your visitors is ever transmitted. This service is provided by IP2Location.com: <a href=\"https:\/\/www.ip2location.com\/terms\">terms of use<\/a>, <a href=\"https:\/\/www.ip2location.com\/privacy\">privacy policy<\/a>.<\/p>\n\n<p>All country lookups for your visitors happen locally on your server against the downloaded database file \u2014 visitor IP addresses never leave your site.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>wonderful-geoblocking-countries<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Create a free account at <a href=\"https:\/\/lite.ip2location.com\/\">lite.ip2location.com<\/a> and copy your download token.<\/li>\n<li>Go to <strong>Settings &gt; Geoblocking Countries<\/strong>, paste the token, save, and click <strong>Download \/ update database now<\/strong>.<\/li>\n<li>Pick the countries to block per area, write your block messages, done!<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"why%20is%20the%20geolocation%20database%20not%20included%20in%20the%20plugin%3F\"><h3>Why is the geolocation database not included in the plugin?<\/h3><\/dt>\n<dd><p>The IP2Location LITE database is free but published under its own license that requires every user to register for their own copy. The download with your personal token takes less than a minute and enables automatic monthly updates.<\/p><\/dd>\n<dt id=\"what%20happens%20while%20no%20database%20is%20installed%3F\"><h3>What happens while no database is installed?<\/h3><\/dt>\n<dd><p>Nothing \u2014 no visitor is blocked. The plugin shows an admin notice until a database is installed, and visitors whose country cannot be determined are always let through.<\/p><\/dd>\n<dt id=\"can%20i%20lock%20myself%20out%3F\"><h3>Can I lock myself out?<\/h3><\/dt>\n<dd><p>Not while you are logged in: administrators are always exempt from all three rules. Only the <em>login<\/em> rule can affect you when you are logged out and your own country is on its list \u2014 the settings page warns you about exactly that.<\/p><\/dd>\n<dt id=\"my%20site%20runs%20behind%20cloudflare%20or%20another%20proxy%20%E2%80%94%20the%20detected%20country%20is%20wrong.\"><h3>My site runs behind Cloudflare or another proxy \u2014 the detected country is wrong.<\/h3><\/dt>\n<dd><p>Behind a proxy, <code>REMOTE_ADDR<\/code> is the proxy's address, not the visitor's. Use the <code>wonderful_geoblocking_countries_client_ip<\/code> filter to supply the real client IP from a header you trust, or short-circuit the lookup entirely with <code>wonderful_geoblocking_countries_pre_country_code<\/code> (e.g. return the value of Cloudflare's <code>CF-IPCountry<\/code> header).<\/p><\/dd>\n<dt id=\"does%20blocking%20also%20apply%20to%20the%20rest%20api%20and%20feeds%3F\"><h3>Does blocking also apply to the REST API and feeds?<\/h3><\/dt>\n<dd><p>The <em>site access<\/em> rule runs on every frontend request, including feeds and the REST API. The WordPress admin (including admin-ajax) and wp-login.php are excluded from it.<\/p><\/dd>\n<dt id=\"is%20any%20visitor%20data%20sent%20to%20a%20third%20party%3F\"><h3>Is any visitor data sent to a third party?<\/h3><\/dt>\n<dd><p>No. Country lookups run locally against the downloaded database file. The only external request is the database download itself, which you trigger with your own token.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Updated the bundled Select2 library from the 4.1.0 release candidate to the stable 4.1.0 release (now managed via Composer).<\/li>\n<li>Fixed the IP2Location terms-of-use link in the readme.<\/li>\n<li>Corrected the \"Tested up to\" header to a major.minor WordPress version.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Added a <code>wonderful_geoblocking_countries_country_for_ip<\/code> filter so other plugins can reuse the IP2Location country lookup.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Blocks site access, login, or registration for visitors from selected countries, with a customizable message per area.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/341024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=341024"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wonderfulplugins"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=341024"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=341024"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=341024"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=341024"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=341024"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=341024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}