{"id":365458,"date":"2026-09-22T02:09:18","date_gmt":"2026-09-22T02:09:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/witen-blocker\/"},"modified":"2026-09-22T23:56:44","modified_gmt":"2026-09-22T23:56:44","slug":"witen-blocker","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/witen-blocker\/","author":23559348,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.6.47","stable_tag":"0.6.47","tested":"7.1.2","requires":"6.2","requires_php":"8.1","requires_plugins":null,"header_name":"Witen Blocker","header_author":"Witen Labs","header_description":"Blocks abusive requests with Witen threat intelligence and optional local Warden enforcement.","assets_banners_color":"101a2b","last_updated":"2026-09-22 23:56:44","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/witenlabs.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":86,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.6.46":{"tag":"0.6.46","author":"witenlabs","date":"2026-09-22 02:08:50","revision":3706512},"0.6.47":{"tag":"0.6.47","author":"witenlabs","date":"2026-09-22 23:56:44","revision":3708268}},"upgrade_notice":{"0.6.47":"<p>Adds local protection for page-template traversal. Update WordPress core to 7.1.2 or the patched release for your branch as well.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3706552,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3706552,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3706552,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3706552,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3706552,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.6.46","0.6.47"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[131228,2439,1174,600,599],"plugin_category":[54],"plugin_contributors":[281942],"plugin_business_model":[],"class_list":["post-365458","plugin","type-plugin","status-publish","hentry","plugin_tags-blocklist","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-security","plugin_tags-spam","plugin_category-security-and-spam-protection","plugin_contributors-witenlabs","plugin_committers-witenlabs"],"banners":{"banner":"https:\/\/ps.w.org\/witen-blocker\/assets\/banner-772x250.png?rev=3706552","banner_2x":"https:\/\/ps.w.org\/witen-blocker\/assets\/banner-1544x500.png?rev=3706552","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/witen-blocker\/assets\/icon.svg?rev=3706552","icon":"https:\/\/ps.w.org\/witen-blocker\/assets\/icon.svg?rev=3706552","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Witen Blocker helps protect your WordPress site from password guessing, unwanted bots, and comment spam. Add two-factor authentication, check suspicious file changes, and review detections and blocks in your WordPress dashboard.<\/p>\n\n<p>Start with free local protection. Connect to Witen when you want blocklists informed by attacks seen across participating sites and servers.<\/p>\n\n<h4>Protect your logins<\/h4>\n\n<p>Limit repeated failed login attempts and add two-factor authentication with an authenticator app. Recovery codes give you a way back in if you lose your device.<\/p>\n\n<h4>Decide which bots can visit<\/h4>\n\n<p>Choose which recognized search crawlers, AI crawlers, and automated clients to allow or block. Manage trusted addresses and review detections before blocking.<\/p>\n\n<h4>Cut down comment spam<\/h4>\n\n<p>Catch automated submissions with hidden form fields and timing checks. These checks run on your site without sending comment text to a spam service.<\/p>\n\n<h4>Find unexpected file changes<\/h4>\n\n<p>Compare WordPress core files with official checksums, monitor changes in your content directory, and scan files for suspicious patterns. Bundled checks work without an account. Connected sites can receive maintained malware catalogs. Review findings before taking action.<\/p>\n\n<h4>Learn from attacks beyond your own site<\/h4>\n\n<p>The optional Witen service combines security reports from participating sites and servers to identify repeat attackers and maintain shared blocklists. An enrolled site can block listed IPs even if they haven't attacked that site before. Reports are processed centrally; request checks use a local blocklist.<\/p>\n\n<p>Enrollment requires a Witen account and security-event sharing. All local features are free, with no trial expiry. Hosted plans determine feeds, update frequency, and off-site backup storage.<\/p>\n\n<h4>Run on shared hosting or your own server<\/h4>\n\n<p>On shared hosting, matching blocklist requests receive an HTTP 403 response from WordPress. No server administration access is needed. On your own server, the optional Witen Warden agent can enforce IP blocks at the firewall, before blocked traffic reaches PHP.<\/p>\n\n<p><strong>Get started:<\/strong> install Witen Blocker and open <strong>Witen &gt; Settings<\/strong>. Local protection needs no account.<\/p>\n\n<p><a href=\"https:\/\/www.witenlabs.com\/docs\/wordpress\">Setup guide<\/a> | <a href=\"https:\/\/www.witenlabs.com\/pricing\">Witen plans<\/a> | <a href=\"https:\/\/wordpress.org\/support\/plugin\/witen-blocker\/\">Support<\/a><\/p>\n\n<h3>External Services<\/h3>\n\n<h4>Witen Collector<\/h4>\n\n<p>Connected features use <code>https:\/\/collector.witenlabs.com<\/code>. Enrollment exchanges your setup token and installation identity for a credential. Witen processes shared reports to identify distributed attacks and provide threat intelligence.<\/p>\n\n<p>Background sync sends events and site details (listed below) and retrieves blocklists, bot identities, signed malware catalogs, Tor exit nodes, allowlists, service status, network statistics, and feed profiles. Profile changes send your selection and site identifier; IP lookups send the queried address. Block reports include the IP, rule, outcome, request context, and site identifier.<\/p>\n\n<ul>\n<li><strong>Malware samples:<\/strong> off by default. Setting <code>WITEN_SEND_MALWARE_SAMPLES<\/code> to boolean <code>true<\/code> in <code>wp-config.php<\/code> permits file-content uploads. Scans do not require them.<\/li>\n<li><strong>Off-site .htaccess backups:<\/strong> off by default. Enabling them permits encrypted file uploads, with checksum and size, and dashboard-requested restores. Witen can decrypt the files and keeps 10 versions. Restores validate content, make a local backup, and report results. Disabling the option stops uploads and remote restores; local backups remain available.<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/witenlabs.com\/terms\">Witen terms<\/a> | <a href=\"https:\/\/witenlabs.com\/privacy\">Witen privacy policy<\/a><\/p>\n\n<pre><code>WITEN_COLLECTOR_URL selects another collector if you operate one; its operator's policies apply. Explicitly configuring `WITEN_SOCKET_PATH` authorizes sharing with local Warden, whose configuration controls onward delivery. Detecting a socket alone does not enable sharing.\n<\/code><\/pre>\n\n<h4>Cloudflare proxy ranges<\/h4>\n\n<p>Enrolled sites refresh <code>https:\/\/www.cloudflare.com\/ips-v4\/<\/code> and <code>https:\/\/www.cloudflare.com\/ips-v6\/<\/code> during background maintenance to recognize trusted proxies. Offline sites use bundled ranges. Requests send ordinary HTTPS network metadata, not WordPress visitor events or account data.<\/p>\n\n<p><a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">Cloudflare terms<\/a> | <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Cloudflare privacy policy<\/a><\/p>\n\n<h4>WordPress.org core checksums<\/h4>\n\n<p>Integrity scans request official hashes from <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code>, sending your WordPress version, locale, and ordinary HTTPS network metadata. No visitor events, account data, or site content is sent.<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/about\/privacy\/\">WordPress.org privacy policy<\/a><\/p>\n\n<p>The plugin does not remotely load executable code or frontend assets. Bundled bot references cause no remote requests or crawler DNS lookups. Collector connections use your DNS resolver. Background jobs and Apache rule checks call your own WordPress URLs.<\/p>\n\n<h3>Privacy Policy<\/h3>\n\n<p>Events stay local until enrollment or explicit Warden socket configuration. Earlier events are never uploaded retroactively. Connected intelligence requires event sharing; use offline mode or deactivate to stop it.<\/p>\n\n<p><strong>What is shared:<\/strong> IP addresses; successful and failed logins; XML-RPC, comment, registration, and 404 events; request URLs, methods, User-Agent strings, referrers, and query information; and attempted usernames, which may be email addresses. Installation reports include site name and URL, WordPress\/PHP\/plugin versions, and a random installation identifier. An observed IP is not necessarily an attacker. Reports help identify distributed attacks, relate failed logins to later successful ones, and maintain blocklists.<\/p>\n\n<p>Event reports exclude form bodies, post content, comment text, password fields, cookies, and session data. URLs and metadata can contain personal data. File samples and .htaccess backups are separate options, described above. <code>WITEN_NO_TELEMETRY<\/code> stops daily installation reports, but not connected security-event sharing.<\/p>\n\n<p><strong>Local storage:<\/strong> the delivery queue holds up to 500 events for seven days. Witen also keeps the latest 100 dashboard events and blocks, block and allow lists, and health counters. Rejected events and block-decision reports have separate diagnostic queues, each limited to 100 records or 1 MiB. Older records are removed at the limit; diagnostics otherwise remain until uninstall.<\/p>\n\n<p>Deactivation preserves settings. Uninstall removes Witen options, transients, scheduled actions, and database tables. Collector retention follows its operator's privacy policy; request collector-side deletion from that operator.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Open <strong>Plugins &gt; Add New Plugin<\/strong>, search for <strong>Witen Blocker<\/strong>, and install and activate it. You can also upload the plugin ZIP.<\/li>\n<li>Open <strong>Witen &gt; Settings<\/strong>. Review login protection, bot policies, and trusted addresses. Set up two-factor authentication in your user profile if you want to use it.<\/li>\n<li>To add shared intelligence, create a <a href=\"https:\/\/www.witenlabs.com\">Witen account<\/a>, add a WordPress site under <strong>Protected Assets<\/strong>, and enter its one-time setup token in Witen settings. Review the terms and privacy information before connecting.<\/li>\n<li>Check the connection and blocklist status after background maintenance runs.<\/li>\n<\/ol>\n\n<p>See the <a href=\"https:\/\/www.witenlabs.com\/docs\/wordpress\">setup guide<\/a> for configuration constants and Warden socket credentials.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20can%20i%20use%20without%20an%20account%3F\"><h3>What can I use without an account?<\/h3><\/dt>\n<dd><p>Login limits, two-factor authentication, comment spam checks, bot controls, file-integrity checks, bundled malware checks, and the .htaccess editor. Connecting to Witen adds hosted intelligence and reporting; it is optional.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>Request checks use local data; updates, reporting, and scans run in background jobs. Both use server resources. On quiet sites, WordPress cron may wait for a visitor before running jobs.<\/p><\/dd>\n<dt id=\"can%20i%20use%20it%20alongside%20another%20security%20plugin%3F\"><h3>Can I use it alongside another security plugin?<\/h3><\/dt>\n<dd><p>Check for overlapping two-factor, login, bot, and .htaccess settings. Test your login and site after changes. Keep WordPress, themes, and plugins updated, and maintain a backup.<\/p><\/dd>\n<dt id=\"does%20a%20scan%20finding%20mean%20my%20site%20is%20hacked%3F\"><h3>Does a scan finding mean my site is hacked?<\/h3><\/dt>\n<dd><p>Not necessarily. A changed file or suspicious pattern needs review; legitimate customizations can produce findings. Witen helps identify files to investigate. It does not automatically clean an infected site.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20witen%20is%20unavailable%3F\"><h3>What happens if Witen is unavailable?<\/h3><\/dt>\n<dd><p>Local protection continues. Cached intelligence is usable until it expires, and reports queue for background retries within the limits below. Warden socket mode does not fall back to a direct collector connection.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Yes. Each site has its own settings, connection, logs, and jobs, initialized on its first request. The main site's network administrator controls shared .htaccess. User accounts and two-factor enrollment are network-wide. Warden needs a separate caller credential for each site.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.6.47<\/h4>\n\n<ul>\n<li>Block page-template traversal attempts (CVE-2026-87902) before WordPress selects a template.<\/li>\n<li>Rewrite the directory description around protection, setup, and everyday use.<\/li>\n<\/ul>\n\n<p>See <code>changelog.txt<\/code> in the download for older releases.<\/p>","raw_excerpt":"Protect logins, block unwanted bots, reduce comment spam, and check for suspicious files. Add shared threat intelligence with Witen.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/365458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=365458"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/witenlabs"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=365458"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=365458"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=365458"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=365458"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=365458"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=365458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}