Title: Add to Allowlist
Last modified: September 22, 2026

---

# Add to Allowlist

 *  [jonahall59](https://wordpress.org/support/users/jonahall59/)
 * (@jonahall59)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/add-to-allowlist/)
 * (Free Version)
 * We use WhatConverts to track users. One of the pieces of code provided by WhatConverts
   to instert the tracking into the <head> is being deleted by Wordfence. It contains
   the address ‘s.ksrndkehqnwntyxlhgto.com’ which is where the WC code comes from.
   How do I add this to the Allowlist? If I paste this in , it will not allow me
   to save?
 * Thanks!

Viewing 7 replies - 1 through 7 (of 7 total)

 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19027105)
 * Hi [@jonahall59](https://wordpress.org/support/users/jonahall59/), thanks for
   reaching out.
 * It sounds to me like you’re logged in as an admin and trying to update a code
   snippet using a custom header/footer editor plugin (or similar feature). It is
   still possible to get false-positives when Wordfence thinks something being added
   is harmful, but you should be able to override it if you’re satisfied the code
   is actually something safe.
 * Take a look here: [https://www.wordfence.com/help/firewall/learning-mode/#what-to-do-if-a-page-is-blocked-after-learning-mode-is-complete](https://www.wordfence.com/help/firewall/learning-mode/#what-to-do-if-a-page-is-blocked-after-learning-mode-is-complete)
 * Let us know how you get on,
   Peter.
 *  Thread Starter [jonahall59](https://wordpress.org/support/users/jonahall59/)
 * (@jonahall59)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19027158)
 * Thanks – unfortunately, that didn’t work (the line of WhatConverts code was still
   removed).
 * Yes, I am logging in as an admin. We are using Themify Ultra as our theme. We
   have (for years) been using the Themify ‘Hook Content’ option to put tracking
   code onto specific pages – this has worked fine. Unfortunately, for some reason
   Wordfence seems to be disallowing that and has actively deleted that line of 
   code on every website (!) which means the tracking doesn’t work any more.
 * This is the line of code <script src=”//s.ksrndkehqnwntyxlhgto.com/XXXXX.js”>
   </script> (XXXXX is a five digit number) that gets removed. It does not bring
   up any sort of popup to allow us to confirm that this is a safe link when adding
   it to the Hook Content area. Turning the Firewall back into Learning mode makes
   no difference – it is still removed.
 * If I use a plugin (WP Code Lite), I can add the line of code to the whole site:
   it brings up the WF message allowing me to confirm this is a safe link and that
   saves and works OK, it is not removed. But unfortunately we need to add different
   code (with different numbers) to different pages. Is there any way of manually
   specifying that URL as safe either in the site backend or can you do it in your
   backend? I suspect this will affect quite a few people as WhatConverts is widely
   used.
 * Thanks very much
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [6 days, 16 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19028730)
 * Hi [@jonahall59](https://wordpress.org/support/users/jonahall59/), thank-you 
   for the extra information.
 * As WP Code Lite added the code site-wide without being blocked for you, I also
   tried the [WhatConverts](https://wordpress.org/plugins/whatconverts/) plugin 
   which doesn’t result in a block either. I appreciate those don’t change the code
   per-page as you want, but wanted to ensure WhatConverts’ scripts and the `ksrndkehqnwntyxlhgto.
   com` domain _aren’t_ the things being blocked by Wordfence. We also don’t have
   Themify or its Hook Content feature in our list of [known conflicts](https://www.wordfence.com/help/advanced/plugin-theme-conflicts/).
 * I’m sorry to hear Learning Mode doesn’t seem to solve the attempts to save the
   code snippets. If Wordfence _is_ the cause of the block, you should be able to
   see the full reasoning in your [Live Traffic](https://www.wordfence.com/help/tools/live-traffic/)
   page immediately afterwards. Wordfence logs all blocks it makes here and you 
   can filter by “Blocked” if you like, too.
 * You may find a specific firewall rule or Wordfence setting stated as the reason.
   The block reason itself is shown in red text. Feel free to paste that reason 
   here so we can look at why it’s not being added to the allowlist.
 * Thanks again,
   Peter.
 *  Thread Starter [jonahall59](https://wordpress.org/support/users/jonahall59/)
 * (@jonahall59)
 * [2 days, 21 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19031413)
 * A bit of an update.
 * We used WP Code lite (as above) to add the code to the sites. It popped up a 
   notice and we accepted it as being safe. That worked – three days later and the
   code (<script src=”//s.ksrndkehqnwntyxlhgto.com/XXXXX.js”></script>) has been
   deleted from the WP Code area! Thus causing the sites to fail again. This time
   I enabled Learning Mode on the Firewall and readded the same code. It did not
   pop up with the WF message about it not being safe this time. That seems to infer
   that the address has been whitelisted. If I tried to add the same code to the
   Themify Hook Content (in Learning Mode or not) it just deletes it very quickly.
   So if it has been whitelisted then it doesn’t work in the Hook Content block?
   Is that possible?
 * The problem is that the code (despite being apparently whitelisted) disappeared
   after three (or maybe 4) days. So now we are a bit stuck. We cannot check all
   of the numerous sites we look after every few days and then re-add the code again,
   not knowing how long it will ‘stick’. We are a bit desperate – the WhatConverts
   tracking is pretty central to what we do. So any ideas would be welcome.
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [2 days, 19 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19031492)
 * Hi [@jonahall59](https://wordpress.org/support/users/jonahall59/), thanks for
   the update.
 * I am starting to suspect that another product on your server may be flagging 
   the code snippet as unsafe and auto-removing it. CDNs, other server firewalls/
   antivirus, or products like ModSecurity could be contenders. The reason I say
   that is because once allowlisted by Wordfence, it’d either re-check if you wanted
   to allowlist it when saving the Hook Content block again, or be flagged as part
   of a scan – but _not_ removed silently.
 * I am open to Wordfence being the cause if you’re able to see any activity in 
   Live Traffic around the time you believe it was removed and can paste the block
   reason or firewall rule that was involved. We can certainly work towards a solution
   if that’s the case.
 * Thanks again,
   Peter.
 *  Thread Starter [jonahall59](https://wordpress.org/support/users/jonahall59/)
 * (@jonahall59)
 * [2 days, 19 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19031508)
 * I am starting to think you are right – I have the sever support looking at it
   this very moment.
 * Thank you for the patient help and advice. If the solution is server-related,
   I will post it here so that anyone else having the problem will know what to 
   look for!
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [2 days, 19 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19031516)
 * Thank-you. I don’t like suggesting other products, but the behavior seems different
   to what I’d expect. You may be able to find the answer sooner if your system 
   administrator or hosting support know something on your server considers WhatConverts
   to be an issue.
 * Peter.

Viewing 7 replies - 1 through 7 (of 7 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fadd-to-allowlist%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 7 replies
 * 2 participants
 * Last reply from: [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * Last activity: [2 days, 19 hours ago](https://wordpress.org/support/topic/add-to-allowlist/#post-19031516)
 * Status: not resolved