[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVpo95IpIbpjIuyo-AyFQ-2-_-g2Vqf4poyjKLoda8oI":3,"$fFXI0ueAjBCpFCxTQ1vmXGRsvocn075JHjwUjs2JyU_Q":140,"$fbvu533VcRwnIVrMzy7HG4aTvDpuafV23tw3_SVPdo5A":145},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"grantech-ip-firewall-for-abuseipdb","GranTech IP Firewall for AbuseIPDB","1.0.4","Marc Gran","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarcgran\u002F","\u003Cp>\u003Cstrong>GranTech IP Firewall for AbuseIPDB\u003C\u002Fstrong> connects your WordPress installation to the community-driven \u003Ca href=\"https:\u002F\u002Fwww.abuseipdb.com\u002F\" rel=\"nofollow ugc\">AbuseIPDB\u003C\u002Fa> database to automatically detect, block, and report abusive IP addresses before they can cause damage.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real-time IP checks\u003C\u002Fstrong> — Queries the AbuseIPDB API on sensitive endpoints (login, XML-RPC, comments).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic blocking\u003C\u002Fstrong> — IPs exceeding the configured abuse score threshold are blocked instantly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force protection\u003C\u002Fstrong> — Detects brute-force attacks on wp-login.php and XML-RPC and blocks the offending IP after N failed attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic reporting\u003C\u002Fstrong> — Reports aggressive IPs to AbuseIPDB (Brute-Force category) to contribute back to the community database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart caching\u003C\u002Fstrong> — Caches API responses to minimise daily quota consumption.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist support\u003C\u002Fstrong> — Exempt individual IPs or CIDR ranges from checks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin dashboard\u003C\u002Fstrong> — 30-day statistics, activity chart, and top offending IPs at a glance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event log\u003C\u002Fstrong> — Full history of all events, filterable by IP and event type.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manual blocklist\u003C\u002Fstrong> — Block and unblock IPs manually from the admin panel.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic cleanup\u003C\u002Fstrong> — Hourly cron job purges expired blocks and logs older than 90 days.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare support\u003C\u002Fstrong> — Automatically reads the CF-Connecting-IP header to get the real visitor IP.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>When an IP accesses a sensitive endpoint (login, XML-RPC, comment submission), the plugin queries the AbuseIPDB API.\u003C\u002Fli>\n\u003Cli>If the abuse confidence score meets or exceeds the configured threshold (default 50\u002F100), the IP is blocked automatically.\u003C\u002Fli>\n\u003Cli>If multiple failed login attempts are detected from the same IP, it is blocked and reported to AbuseIPDB as a brute-force attack.\u003C\u002Fli>\n\u003Cli>All events are recorded in the admin dashboard.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>API Requirements\u003C\u002Fh4>\n\u003Cp>A free account at \u003Ca href=\"https:\u002F\u002Fwww.abuseipdb.com\u002Fregister\" rel=\"nofollow ugc\">abuseipdb.com\u003C\u002Fa> is required.\u003Cbr \u002F>\nThe free plan includes \u003Cstrong>1,000 checks per day\u003C\u002Fstrong>, which is sufficient for most sites when combined with the built-in caching system.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the \u003Cstrong>AbuseIPDB\u003C\u002Fstrong> API (https:\u002F\u002Fapi.abuseipdb.com\u002Fapi\u002Fv2\u002F) to check and report IP addresses.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What is AbuseIPDB?\u003C\u002Fstrong>\u003Cbr \u002F>\nAbuseIPDB is a community-driven project that maintains a database of IP addresses reported for abusive behavior (spam, hacking, brute-force attacks, etc.). This plugin uses their public API to protect your WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent and when?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>IP address check:\u003C\u002Fstrong> When a visitor accesses a sensitive endpoint (wp-login.php, xmlrpc.php, comment submission), the visitor’s IP address is sent to AbuseIPDB to retrieve its abuse confidence score. This only happens when the endpoint is accessed — not on regular page visits.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP address report:\u003C\u002Fstrong> When a brute-force attack is detected (configurable number of failed login attempts), the offending IP address is reported to AbuseIPDB along with a description of the attack and your site’s URL. Reporting can be disabled in the plugin settings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>No personal data\u003C\u002Fstrong> other than IP addresses is ever transmitted to AbuseIPDB.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>AbuseIPDB Terms of Service and Privacy Policy: https:\u002F\u002Fwww.abuseipdb.com\u002Flegal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>This plugin stores visitor IP addresses in the local WordPress database for the purpose of security logging and blocking. IP addresses are personal data under GDPR.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What is stored:\u003C\u002Fstrong> IP addresses, associated ISP, country, and event type (e.g. blocked, failed login).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Why:\u003C\u002Fstrong> To protect the site from malicious activity and brute-force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How long:\u003C\u002Fstrong> Log entries are automatically deleted after 90 days. Block entries expire based on the configured duration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third parties:\u003C\u002Fstrong> IP addresses may be sent to AbuseIPDB (https:\u002F\u002Fwww.abuseipdb.com) for reputation checks and reporting. See the External Services section for details.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User rights:\u003C\u002Fstrong> Site administrators can view and delete all stored data from the plugin’s admin panel or by uninstalling the plugin.\u003C\u002Fli>\n\u003C\u002Ful>\n","Protect your WordPress site by detecting, blocking and reporting malicious IPs using the AbuseIPDB API. Includes brute-force protection.",10,253,0,"2026-07-20T10:11:00.000Z","7.0.2","6.0","8.0",[19,20,21,22,23],"abuseipdb","brute-force","firewall","ip-blocker","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fgrantech-ip-firewall-for-abuseipdb\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgrantech-ip-firewall-for-abuseipdb.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"marcgran",1,30,94,"2026-08-29T12:28:54.953Z",[38,59,81,103,123],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":15,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":52,"download_link":56,"security_score":48,"vuln_count":57,"unpatched_count":13,"last_vuln_date":58,"fetched_at":28},"limit-login-attempts-reloaded","Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention","3.3.4","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Security\u003C\u002Fa> strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.\u003C\u002Fp>\n\u003Cp>Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FS3nf8Zpbcfs?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Why Use Limit Login Attempts Security?\u003C\u002Fh4>\n\u003Cp>By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts Security helps stop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks\u003C\u002Fli>\n\u003Cli>Bot login attacks\u003C\u002Fli>\n\u003Cli>Credential stuffing attacks\u003C\u002Fli>\n\u003Cli>XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Unauthorized login attempts\u003C\u002Fli>\n\u003Cli>WooCommerce login abuse\u003C\u002Fli>\n\u003Cli>Malicious IP access attempts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.\u003C\u002Fp>\n\u003Ch4>Features Included in the Free Version\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Security & Brute Force Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit login attempts by IP address and username\u003C\u002Fli>\n\u003Cli>Automatically lock out suspicious login activity\u003C\u002Fli>\n\u003Cli>Adjustable lockout duration and retry limits\u003C\u002Fli>\n\u003Cli>Protect wp-login.php from automated attacks\u003C\u002Fli>\n\u003Cli>Prevent brute force login attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2FA \u002F Multi-Factor Authentication (MFA)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Built-in two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Add an additional layer of login protection\u003C\u002Fli>\n\u003Cli>Improve WordPress account security\u003C\u002Fli>\n\u003Cli>Secure administrator and user logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Bot Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block malicious login requests\u003C\u002Fli>\n\u003Cli>Detect suspicious login behavior\u003C\u002Fli>\n\u003Cli>Reduce bot-based login attacks\u003C\u002Fli>\n\u003Cli>Lightweight firewall-focused login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce & Plugin Compatibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Protects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce login pages\u003C\u002Fli>\n\u003Cli>XML-RPC login requests\u003C\u002Fli>\n\u003Cli>Custom login pages\u003C\u002Fli>\n\u003Cli>WordPress multisite installations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatible With:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence\u003C\u002Fli>\n\u003Cli>Sucuri\u003C\u002Fli>\n\u003Cli>Ultimate Member\u003C\u002Fli>\n\u003Cli>MemberPress\u003C\u002Fli>\n\u003Cli>WPS Hide Login\u003C\u002Fli>\n\u003Cli>Cloudflare and reverse proxy setups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Login Monitoring & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempt logs\u003C\u002Fli>\n\u003Cli>Lockout email notifications\u003C\u002Fli>\n\u003Cli>Denied attempt tracking\u003C\u002Fli>\n\u003Cli>Login retry visibility for users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Access Controls\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP safelist and denylist support\u003C\u002Fli>\n\u003Cli>Username safelist and denylist support\u003C\u002Fli>\n\u003Cli>IPv6 range support\u003C\u002Fli>\n\u003Cli>Custom IP origin configuration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Features (Start Your Free 14 Day Trial)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Upgrade to Limit Login Attempts Security Premium\u003C\u002Fa> to extend protection with cloud-based login security and advanced attack prevention.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Cloud Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time malicious IP intelligence\u003C\u002Fli>\n\u003Cli>Global denylist protection\u003C\u002Fli>\n\u003Cli>Synchronized lockouts across websites\u003C\u002Fli>\n\u003Cli>Auto IP denylist generation\u003C\u002Fli>\n\u003Cli>Cloud-based login attack mitigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced Performance Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Offload excessive failed login requests from your server\u003C\u002Fli>\n\u003Cli>Reduce server strain during attacks\u003C\u002Fli>\n\u003Cli>Improve stability under heavy attack conditions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Security Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Country-based login blocking\u003C\u002Fli>\n\u003Cli>Enhanced throttling and lockout escalation\u003C\u002Fli>\n\u003Cli>Registration page protection\u003C\u002Fli>\n\u003Cli>Successful login tracking\u003C\u002Fli>\n\u003Cli>Enhanced lockout analytics and geolocation data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Multi-Site & Team Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared safelist and denylist syncing\u003C\u002Fli>\n\u003Cli>Shared lockout protection between domains\u003C\u002Fli>\n\u003Cli>Cloud backups of IP security data\u003C\u002Fli>\n\u003Cli>CSV exports of login and IP activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Access to security-focused support specialists\u003C\u002Fli>\n\u003Cli>Faster troubleshooting and assistance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lightweight Security Built for WordPress\u003C\u002Fh4>\n\u003Cp>Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.\u003C\u002Fp>\n\u003Cp>This means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Faster performance\u003C\u002Fli>\n\u003Cli>Less server overhead\u003C\u002Fli>\n\u003Cli>Easier configuration\u003C\u002Fli>\n\u003Cli>Strong protection without unnecessary bloat\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Protect More Than Just wp-login.php\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security secures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>wp-login.php\u003C\u002Fli>\n\u003Cli>XML-RPC\u003C\u002Fli>\n\u003Cli>WooCommerce logins\u003C\u002Fli>\n\u003Cli>Custom login forms\u003C\u002Fli>\n\u003Cli>Registration pages\u003C\u002Fli>\n\u003Cli>Multisite logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Trusted by Millions of WordPress Websites\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.\u003C\u002Fp>\n\u003Cp>Whether you run:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A personal blog\u003C\u002Fli>\n\u003Cli>WooCommerce store\u003C\u002Fli>\n\u003Cli>Membership website\u003C\u002Fli>\n\u003Cli>Agency\u003C\u002Fli>\n\u003Cli>Business website\u003C\u002Fli>\n\u003Cli>Enterprise WordPress network\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.\u003C\u002Fp>\n\u003Ch4>Upgrading from the Original Limit Login Attempts Plugin?\u003C\u002Fh4>\n\u003Cp>Switching is easy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Remove the old Limit Login Attempts plugin\u003C\u002Fli>\n\u003Cli>Install Limit Login Attempts Security\u003C\u002Fli>\n\u003Cli>Your settings will remain intact\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Translation Support\u003C\u002Fh4>\n\u003Cp>Currently translated into multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Dutch\u003C\u002Fli>\n\u003Cli>Turkish\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Romanian\u003C\u002Fli>\n\u003Cli>Chinese (Traditional)\u003C\u002Fli>\n\u003Cli>Brazilian Portuguese\u003C\u002Fli>\n\u003Cli>And more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Secure Your WordPress Login Today\u003C\u002Fh4>\n\u003Cp>Install Limit Login Attempts Security and protect your WordPress website with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login security\u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)\u003C\u002Fli>\n\u003Cli>Brute force protection\u003C\u002Fli>\n\u003Cli>Firewall security\u003C\u002Fli>\n\u003Cli>Bot protection\u003C\u002Fli>\n\u003Cli>XML-RPC protection\u003C\u002Fli>\n\u003Cli>WooCommerce login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Without slowing down your website.\u003C\u002Fp>\n","WordPress login security with brute force protection, Two-factor authentication (2FA\u002FMFA), firewall, IP\u002Fcountry blocking, and login monitoring",1000000,91831747,98,1468,"2026-07-08T11:06:00.000Z","5.0","",[54,20,21,55,23],"2fa","login-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.3.3.4.zip",4,"2023-12-20 00:00:00",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":48,"num_ratings":69,"last_updated":70,"tested_up_to":15,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":76,"download_link":77,"security_score":78,"vuln_count":79,"unpatched_count":13,"last_vuln_date":80,"fetched_at":28},"gotmls","Anti-Malware Security and Brute-Force Firewall","4.23.90","Eli","https:\u002F\u002Fprofiles.wordpress.org\u002Fscheeeli\u002F","\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Download Definition Updates to protect against new threats.\u003C\u002Fli>\n\u003Cli>Run a Complete Scan to automatically remove known security threats, backdoor scripts, and database injections.\u003C\u002Fli>\n\u003Cli>Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites.\u003C\u002Fli>\n\u003Cli>Upgrade vulnerable versions of timthumb scripts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Patch your wp-login and XMLRPC to block Brute-Force and DDoS attacks.\u003C\u002Fli>\n\u003Cli>Check the integrity of your WordPress Core files.\u003C\u002Fli>\n\u003Cli>Automatically download new Definition Updates when running a Complete Scan.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Register this plugin at \u003Ca href=\"http:\u002F\u002Fgotmls.net\u002F\" rel=\"nofollow ugc\">GOTMLS.NET\u003C\u002Fa> and get access to new definitions of “Known Threats” and added features like Automatic Removal, plus patches for specific security vulnerabilities like old versions of timthumb. Updated definition files can be downloaded automatically within the admin once your Key is registered. Otherwise, this plugin just scans for “Potential Threats” and leaves it up to you to identify and remove the malicious ones.\u003C\u002Fp>\n\u003Cp>NOTICE: This plugin makes calls to GOTMLS.NET to check for updates not unlike what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is an essential part of any security plugin and this plugin can let you know when there are new plugin and definition update available. If you’re allergic to “phone home” scripts then don’t use this plugin (or WordPress at all for that matter).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Special thanks to:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Clarus Dignus for design suggestions and graphic design work on the banner image.\u003C\u002Fli>\n\u003Cli>Jelena Kovacevic and Andrew Kurtis of webhostinghub.com for providing the Spanish translation.\u003C\u002Fli>\n\u003Cli>Marcelo Guernieri for the Brazilian Portuguese translation.\u003C\u002Fli>\n\u003Cli>Umut Can Alparslan for the Turkish translation.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fmichacassola\u002F\" rel=\"nofollow ugc\">Micha Cassola\u003C\u002Fa> for the German translation.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fsitustarget\u002F\" rel=\"nofollow ugc\">Robi Erwin Setiawan\u003C\u002Fa> for the Indonesian translation.\u003C\u002Fli>\n\u003C\u002Ful>\n","This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.",100000,7863436,783,"2026-06-29T17:58:00.000Z","3.3","5.6",[74,20,21,75,23],"anti-malware","scanner","https:\u002F\u002Fgotmls.net\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgotmls.4.23.90.zip",81,11,"2026-07-09 00:00:00",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":89,"downloaded":90,"rating":91,"num_ratings":92,"last_updated":93,"tested_up_to":15,"requires_at_least":94,"requires_php":95,"tags":96,"homepage":98,"download_link":99,"security_score":100,"vuln_count":101,"unpatched_count":13,"last_vuln_date":102,"fetched_at":28},"hide-my-wp","WP Ghost (Hide My WP Ghost) – Security & Firewall","7.0.07","John Darrel","https:\u002F\u002Fprofiles.wordpress.org\u002Fjohndarrel\u002F","\u003Cp>\u003Cstrong>WP Ghost\u003C\u002Fstrong> (formerly known as \u003Cstrong>Hide My WP Ghost\u003C\u002Fstrong>) is a professional-grade, comprehensive \u003Cstrong>hack-prevention security solution for WordPress\u003C\u002Fstrong>. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and stop the hack before the reconnaissance even begins.\u003C\u002Fp>\n\u003Cp>While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), \u003Cstrong>WP Ghost focuses on Architecture\u003C\u002Fstrong>. By implementing \u003Cstrong>Paths Security and Site Hardening\u003C\u002Fstrong>, we remove the digital footprints that make your site a target for automated botnets, providing a \u003Cstrong>proactive foundation that secures your site before it can even be identified as a target\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FQMdoSN8dk1c?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>WP Ghost Global Stats:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>10 Million+ Monthly Brute-Force Attempts Blocked\u003C\u002Fli>\n\u003Cli>100 Million+ Monthly Security Threats Prevented\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Official websites:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpghost.com\u002F\" rel=\"nofollow ugc\">WP Ghost (wpghost.com)\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fhidemywpghost.com\u002F\" rel=\"nofollow ugc\">Hide My WP Ghost (hidemywpghost.com)\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Stop Attacks with Paths Security & Architectural Hardening\u003C\u002Fh3>\n\u003Cp>Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like \u002Fwp-admin or \u002Fwp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities.\u003C\u002Fp>\n\u003Cp>WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets.\u003C\u002Fp>\n\u003Ch3>Key Protections Included\u003C\u002Fh3>\n\u003Cp>WP Ghost is packed with advanced defensive mechanisms to protect your site against:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute Force Attacks\u003C\u002Fstrong>: Blocks automated password guessing at the source.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SQL Injection & XSS\u003C\u002Fstrong>: Neutralizes malicious query strings and script injections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero-Day Exploits\u003C\u002Fstrong>: Secures paths for plugins before patches are even released.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC & REST API Attacks\u003C\u002Fstrong>: Shuts down common remote-access entry points.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bot Reconnaissance\u003C\u002Fstrong>: Prevents “fingerprinting” that hackers use to map your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spam & Scrapers\u003C\u002Fstrong>: Filters malicious traffic, saving bandwidth and server load.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Over 115 Free Security Features Included\u003C\u002Fh3>\n\u003Cp>We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture.\u003C\u002Fp>\n\u003Ch4>1. Change and Secure Paths (Paths Security)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Change wp-admin & wp-login.php\u003C\u002Fstrong>: Move your login to a unique URL and show a 404 error to intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change Lost Password & Register URLs\u003C\u002Fstrong>: Secure all authentication entry points.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change wp-content & wp-includes\u003C\u002Fstrong>: Secure your core system folders from direct access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anonymize Plugins & Themes\u003C\u002Fstrong>: Change visible plugin\u002Ftheme paths so hackers can’t identify your software version.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure admin-ajax.php & REST API\u003C\u002Fstrong>: Change the \u002Fwp-json path to prevent data scraping.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Presets\u003C\u002Fstrong>: One-click activation with three preset levels — from minimal to full protection with Firewall, Brute Force, Logs, and 2FA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Test\u003C\u002Fstrong>: Verify your site loads correctly after changing paths before confirming settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Redirects\u003C\u002Fstrong>: Set unique login\u002Flogout redirects based on user roles.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Designer\u003C\u002Fstrong>: Customize your secured login page with your logo, colors, background, and 10 color schemes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>2. Next-Gen Firewall & Authentication\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>8G & 7G Firewall Filters\u003C\u002Fstrong>: High-speed, lightweight server-edge filtering to block bad bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Passkey Authentication (Passwordless 2FA)\u003C\u002Fstrong>: Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Standard 2FA (Code & Email)\u003C\u002Fstrong>: Add an extra verification layer to all user accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers\u003C\u002Fstrong>: Automatically implement CSP, HSTS, X-Frame-Options, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP & User Agent Blocking\u003C\u002Fstrong>: Manually blacklist suspicious traffic or referrers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Threats Log\u003C\u002Fstrong>: Track blocked attacks and malicious requests directly in your dashboard (limited view).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Events Log\u003C\u002Fstrong>: Monitor login activity, role changes, and user actions (limited view).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GEO Threats Map\u003C\u002Fstrong>: Visualize where attacks originate with an interactive world map showing the top 5 threat countries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Optimization Score\u003C\u002Fstrong>: Real-time 0-100 score showing exactly how hardened your site is, with actionable recommendations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary Logins\u003C\u002Fstrong>: Create time-limited access links for developers and clients without sharing passwords.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>3. Deep Hiding & Footprint Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scrub Meta Tags\u003C\u002Fstrong>: Remove WordPress version numbers and generator tags.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean HTML Comments\u003C\u002Fstrong>: Strip identifiable comments that reveal your tech stack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Admin Toolbar\u003C\u002Fstrong>: Remove the toolbar for specific roles to hide backend indicators.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Emoticons & RSD\u003C\u002Fstrong>: Remove unnecessary header links that bloat code and reveal info.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>4. Advanced Disable Options\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong>: Shut down the most common vector for DDoS and brute force.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable REST API Access\u003C\u002Fstrong>: Restrict API access to authenticated users only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Lockdown\u003C\u002Fstrong>: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Directory Browsing\u003C\u002Fstrong>: Ensure your server folders are never visible to the public.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>5. Brute Force Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Integrated ReCaptcha\u003C\u002Fstrong>: Supports Google V2, V3, Enterprise, and Math ReCaptcha.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Targeted Protection\u003C\u002Fstrong>: Enable brute force defense on Login, Signup, and WooCommerce pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Throttling\u003C\u002Fstrong>: Define your own lockout times and attempt limits.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>6. Extra Tools & Integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Magic Links\u003C\u002Fstrong>: Log in securely without a password via a one-time email link.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Text & URL Mapping\u003C\u002Fstrong>: Change any class name or URL in your source code dynamically.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CDN & Cache Support\u003C\u002Fstrong>: Works perfectly with WP Rocket, Cloudflare, and Litespeed.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Hack-Prevention Features\u003C\u002Fh4>\n\u003Cp>For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Ghost Mode\u003C\u002Fstrong>: Maximum security preset, changes all paths, hides all file extensions, and enables all hiding options in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Block Automation\u003C\u002Fstrong>: Automatically block IP addresses that trigger repeated security threats.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Copyright Protection\u003C\u002Fstrong>: Block 30+ AI training crawlers (GPTBot, ClaudeBot, PerplexityBot, and others) at the firewall level. List auto-updated with each release. Does not affect Google, Bing, or regular search visibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Security Threats Log\u003C\u002Fstrong>: Unlimited entries with filters by threat type, status, country, and time range, full-text search, pagination, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full User Events Log\u003C\u002Fstrong>: Unlimited entries with filters, search, pagination, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Event Storage\u003C\u002Fstrong>: 30-day cloud retention for audits and incident reports.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time Email Alerts\u003C\u002Fstrong>: Get notified instantly of brute-force attempts or suspicious activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geo-Security (Country Blocking)\u003C\u002Fstrong>: Block entire countries or specific paths by country.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced File Hardening\u003C\u002Fstrong>: Hide file extensions (PHP, CSS, JS, JSON), secure wp-config.php, php.ini, and debug.log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database & Server Hardening\u003C\u002Fstrong>: Fix file permissions, change database prefix, regenerate SALT keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong>: Direct access to our security experts and founder-led assistance.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpghost.com\u002Ffeatures\u002F\" rel=\"nofollow ugc\">Hide My WP Premium Feature\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Technical Compatibility\u003C\u002Fh3>\n\u003Cp>WP Ghost is engineered for the modern WordPress ecosystem:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hosting Support\u003C\u002Fstrong>: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Server Support\u003C\u002Fstrong>: Fully compatible with Nginx, Apache, LiteSpeed, and IIS.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Support\u003C\u002Fstrong>: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Stop the hack before it starts\u003C\u002Fstrong>. Join over 100,000 users who trust WP Ghost to secure their digital presence.\u003C\u002Fp>\n","Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.",80000,2693018,90,371,"2026-07-20T11:52:00.000Z","5.8","7.4",[20,21,82,97,23],"login","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhide-my-wp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhide-my-wp.7.0.07.zip",86,8,"2026-03-18 00:00:00",{"slug":104,"name":105,"version":106,"author":107,"author_profile":108,"description":109,"short_description":110,"active_installs":111,"downloaded":112,"rating":113,"num_ratings":114,"last_updated":115,"tested_up_to":116,"requires_at_least":117,"requires_php":52,"tags":118,"homepage":120,"download_link":121,"security_score":122,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"ip-geo-block","IP Geo Block","3.0.17.4","tokkonopapa","https:\u002F\u002Fprofiles.wordpress.org\u002Ftokkonopapa\u002F","\u003Cp>The more you install themes and plugins, the more likely your sites will be vulnerable, even if you \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FHardening_WordPress\" title=\"Hardening WordPress &laquo; WordPress Codex\" rel=\"nofollow ugc\">securely harden your sites\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>While WordPress.org \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fsecurity\u002F\" title=\"Security | WordPress.org\" rel=\"ugc\">provides\u003C\u002Fa> \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Fthemes\u002Ftheme-security\u002F\" title=\"Theme Security | Theme Developer Handbook | WordPress Developer Resources\" rel=\"nofollow ugc\">excellent\u003C\u002Fa> \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F\" title=\"Plugin Security | Plugin Developer Handbook | WordPress Developer Resources\" rel=\"nofollow ugc\">resources\u003C\u002Fa>, themes and plugins may often get vulnerable due to developers’ \u003Ca href=\"https:\u002F\u002Fwww.google.com\u002Fsearch?q=human+factors+in+security\" title=\"human factors in security - Google Search\" rel=\"nofollow ugc\">human factors\u003C\u002Fa> such as lack of security awareness, misuse and disuse of the best practices in those resources.\u003C\u002Fp>\n\u003Cp>This plugin focuses on insights into such developers’ human factors instead of detecting the specific attack vectors after they were disclosed. This brings a smart and powerful methods named as “\u003Cstrong>WP Zero-day Exploit Prevention\u003C\u002Fstrong>” and “\u003Cstrong>WP Metadata Exploit Protection\u003C\u002Fstrong>“.\u003C\u002Fp>\n\u003Cp>Combined with those methods and IP address geolocation, you’ll be surprised to find a bunch of malicious or undesirable access blocked in the logs of this plugin after several days of installation.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Privacy by design:\u003C\u002Fstrong>\u003Cbr \u002F>\nIP address is always encrypted on recording in logs\u002Fcache. Moreover, it can be anonymized and restricted on sending to the 3rd parties such as geolocation APIs or whois service.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Immigration control:\u003C\u002Fstrong>\u003Cbr \u002F>\nAccess to the basic and important entrances into back-end such as \u003Ccode>wp-comments-post.php\u003C\u002Fcode>, \u003Ccode>xmlrpc.php\u003C\u002Fcode>, \u003Ccode>wp-login.php\u003C\u002Fcode>, \u003Ccode>wp-signup.php\u003C\u002Fcode>, \u003Ccode>wp-admin\u002Fadmin.php\u003C\u002Fcode>, \u003Ccode>wp-admin\u002Fadmin-ajax.php\u003C\u002Fcode>, \u003Ccode>wp-admin\u002Fadmin-post.php\u003C\u002Fcode> will be validated by means of a country code based on IP address. It allows you to configure either whitelist or blacklist to \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FISO_3166-1_alpha-2#Officially_assigned_code_elements\" title=\"ISO 3166-1 alpha-2 - Wikipedia\" rel=\"nofollow ugc\">specify the countires\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FClassless_Inter-Domain_Routing\" title=\"Classless Inter-Domain Routing - Wikipedia\" rel=\"nofollow ugc\">CIDR notation\u003C\u002Fa> for a range of IP addresses and \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FAutonomous_system_(Internet)\" title=\"Autonomous system (Internet) - Wikipedia\" rel=\"nofollow ugc\">AS number\u003C\u002Fa> for a group of IP networks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Zero-day Exploit Prevention:\u003C\u002Fstrong>\u003Cbr \u002F>\nUnlike other security firewalls based on attack patterns (vectors), the original feature “\u003Cstrong>W\u003C\u002Fstrong>ord\u003Cstrong>P\u003C\u002Fstrong>ress \u003Cstrong>Z\u003C\u002Fstrong>ero-day \u003Cstrong>E\u003C\u002Fstrong>xploit \u003Cstrong>P\u003C\u002Fstrong>revention” (WP-ZEP) is focused on patterns of vulnerability. It is simple but still smart and strong enough to block any malicious accesses to \u003Ccode>wp-admin\u002F*.php\u003C\u002Fcode>, \u003Ccode>plugins\u002F*.php\u003C\u002Fcode> and \u003Ccode>themes\u002F*.php\u003C\u002Fcode> even from the permitted countries. It will protect your site against certain types of attack such as CSRF, LFI, SQLi, XSS and so on, \u003Cstrong>even if you have some vulnerable plugins and themes in your site\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Guard against login attempts:\u003C\u002Fstrong>\u003Cbr \u002F>\nIn order to prevent hacking through the login form and XML-RPC by brute-force and the reverse-brute-force attacks, the number of login attempts will be limited per IP address even from the permitted countries.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Minimize server load against brute-force attacks:\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can configure this plugin as a \u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FMust_Use_Plugins\" title=\"Must Use Plugins &laquo; WordPress Codex\" rel=\"nofollow ugc\">Must Use Plugins\u003C\u002Fa> so that this plugin can be loaded prior to regular plugins. It can massively \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002Fcodex\u002Fvalidation-timing.html\" title=\"Validation timing | IP Geo Block\" rel=\"nofollow ugc\">reduce the load on server\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Prevent malicious down\u002Fuploading:\u003C\u002Fstrong>\u003Cbr \u002F>\nA malicious request such as exposing \u003Ccode>wp-config.php\u003C\u002Fcode> or uploading malwares via vulnerable plugins\u002Fthemes can be blocked.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Block badly-behaved bots and crawlers:\u003C\u002Fstrong>\u003Cbr \u002F>\nA simple logic may help to reduce the number of rogue bots and crawlers scraping your site.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Support of BuddyPress and bbPress:\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can configure this plugin so that a registered user can login as a membership from anywhere, while a request such as a new user registration, lost password, creating a new topic and subscribing comment can be blocked by country. It is suitable for \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbuddypress\u002F\" title=\"BuddyPress &mdash; WordPress Plugins\" rel=\"ugc\">BuddyPress\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbbpress\u002F\" title=\"WordPress &rsaquo; bbPress &laquo; WordPress Plugins\" rel=\"ugc\">bbPress\u003C\u002Fa> to help reducing spams.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Referrer suppressor for external links:\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen you click an external hyperlink on admin screens, http referrer will be eliminated to hide a footprint of your site.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Multiple source of IP Geolocation databases:\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.maxmind.com\" title=\"MaxMind - IP Geolocation and Online Fraud Prevention\" rel=\"nofollow ugc\">MaxMind GeoLite2 free databases\u003C\u002Fa> (it requires PHP 5.4.0+) and \u003Ca href=\"https:\u002F\u002Fwww.ip2location.com\u002F\" title=\"IP Address Geolocation to Identify Website Visitor's Geographical Location\" rel=\"nofollow ugc\">IP2Location LITE databases\u003C\u002Fa> can be installed in this plugin. Also free Geolocation REST APIs and whois information can be available for audit purposes.\u003Cbr \u002F>\nFather more, \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002Farticle\u002Fapi-class-library.html\" title=\"CloudFlare & CloudFront API class library | IP Geo Block\" rel=\"nofollow ugc\">dedicated API class libraries\u003C\u002Fa> can be installed for CloudFlare and CloudFront as a reverse proxy service.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Customizing response:\u003C\u002Fstrong>\u003Cbr \u002F>\nHTTP response code can be selectable as \u003Ccode>403 Forbidden\u003C\u002Fcode> to deny access pages, \u003Ccode>404 Not Found\u003C\u002Fcode> to hide pages or even \u003Ccode>200 OK\u003C\u002Fcode> to redirect to the top page.\u003Cbr \u002F>\nYou can also have a human friendly page (like \u003Ccode>404.php\u003C\u002Fcode>) in your parent\u002Fchild theme template directory to fit your site design.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Validation logs:\u003C\u002Fstrong>\u003Cbr \u002F>\nValidation logs for useful information to audit attack patterns can be manageable.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Cooperation with full spec security plugin:\u003C\u002Fstrong>\u003Cbr \u002F>\nThis plugin is lite enough to be able to cooperate with other full spec security plugin such as \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" title=\"Wordfence Security &mdash; WordPress Plugins\" rel=\"ugc\">Wordfence Security\u003C\u002Fa>. See \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002Fcodex\u002Fpage-speed-performance.html\" title=\"Page speed performance | IP Geo Block\" rel=\"nofollow ugc\">this report\u003C\u002Fa> about page speed performance.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Extendability:\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can customize the behavior of this plugin via \u003Ccode>add_filter()\u003C\u002Fcode> with \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002Fcodex\u002F\" title=\"Codex | IP Geo Block\" rel=\"nofollow ugc\">pre-defined filter hook\u003C\u002Fa>. See various use cases in \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftokkonopapa\u002FWordPress-IP-Geo-Block\u002Fblob\u002Fmaster\u002Fip-geo-block\u002Fsamples.php\" title=\"WordPress-IP-Geo-Block\u002Fsamples.php at master - tokkonopapa\u002FWordPress-IP-Geo-Block - GitHub\" rel=\"nofollow ugc\">samples.php\u003C\u002Fa> bundled within this package.\u003Cbr \u002F>\nYou can also get the extension \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fddur\u002FWordPress-IP-Geo-Allow\" title=\"GitHub - ddur\u002FWordPress-IP-Geo-Allow: WordPress Plugin Exension for WordPress-IP-Geo-Block Plugin\" rel=\"nofollow ugc\">IP Geo Allow\u003C\u002Fa> by \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fddur\" title=\"ddur (Dragan) - GitHub\" rel=\"nofollow ugc\">Dragan\u003C\u002Fa>. It makes admin screens strictly private with more flexible way than specifying IP addresses.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Self blocking prevention and easy rescue:\u003C\u002Fstrong>\u003Cbr \u002F>\nWebsite owners do not prefer themselves to be blocked. This plugin prevents such a sad thing unless you force it. And futhermore, if such a situation occurs, you can \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002Fcodex\u002Fwhat-should-i-do-when-i-m-locked-out.html\" title=\"What should I do when I'm locked out? | IP Geo Block\" rel=\"nofollow ugc\">rescue yourself\u003C\u002Fa> easily.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Clean uninstallation:\u003C\u002Fstrong>\u003Cbr \u002F>\nNothing is left in your precious mySQL database after uninstallation. So you can feel free to install and activate to make a trial of this plugin’s functionality.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Attribution\u003C\u002Fh4>\n\u003Cp>This package includes GeoLite2 library distributed by MaxMind, available from \u003Ca href=\"https:\u002F\u002Fwww.maxmind.com\" title=\"MaxMind - IP Geolocation and Online Fraud Prevention\" rel=\"nofollow ugc\">MaxMind\u003C\u002Fa> (it requires PHP 5.4.0+), and also includes IP2Location open source libraries available from \u003Ca href=\"https:\u002F\u002Fwww.ip2location.com\" title=\"IP Address Geolocation to Identify Website Visitor's Geographical Location\" rel=\"nofollow ugc\">IP2Location\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Also thanks for providing the following great services and REST APIs for free.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fip-api.com\u002F\" title=\"IP-API.com - Free Geolocation API\" rel=\"nofollow ugc\">http:\u002F\u002Fip-api.com\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free for non-commercial use)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fgeoiplookup.net\u002F\" title=\"What Is My IP Address | GeoIP Lookup\" rel=\"nofollow ugc\">http:\u002F\u002Fgeoiplookup.net\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fipinfo.io\u002F\" title=\"IP Address API and Data Solutions\" rel=\"nofollow ugc\">https:\u002F\u002Fipinfo.io\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free)\u003C\u002Fli>\n\u003Cli>[https:\u002F\u002Fipapi.com\u002F](https:\u002F\u002Fipapi.com\u002F “ipapi – IP Address Lookup and Geolocation API) (IPv4, IPv6 \u002F free, need API key)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fipdata.co\u002F\" title=\"ipdata.co - IP Geolocation and Threat Data API\" rel=\"nofollow ugc\">https:\u002F\u002Fipdata.co\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free, need API key)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fipstack.com\u002F\" title=\"ipstack - Free IP Geolocation API\" rel=\"nofollow ugc\">https:\u002F\u002Fipstack.com\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free for registered user, need API key)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fipinfodb.com\u002F\" title=\"Free IP Geolocation Tools and API| IPInfoDB\" rel=\"nofollow ugc\">https:\u002F\u002Fipinfodb.com\u002F\u003C\u002Fa> (IPv4, IPv6 \u002F free for registered user, need API key)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Development\u003C\u002Fh4>\n\u003Cp>Development of this plugin is promoted at \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftokkonopapa\u002FWordPress-IP-Geo-Block\" title=\"tokkonopapa\u002FWordPress-IP-Geo-Block - GitHub\" rel=\"nofollow ugc\">WordPress-IP-Geo-Block\u003C\u002Fa> and class libraries to handle geo-location database are developed separately as “add-in”s at \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftokkonopapa\u002FWordPress-IP-Geo-API\" title=\"tokkonopapa\u002FWordPress-IP-Geo-API - GitHub\" rel=\"nofollow ugc\">WordPress-IP-Geo-API\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>All contributions will always be welcome. Or visit my \u003Ca href=\"https:\u002F\u002Fwww.ipgeoblock.com\u002F\" title=\"IP Geo Block\" rel=\"nofollow ugc\">development blog\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Known issues\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>No image is shown after drag & drop a image in grid view at “Media Library”. For more details, please refer to \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftokkonopapa\u002FWordPress-IP-Geo-Block\u002Fissues\u002F2\" title=\"No image is shown after drag & drop a image in grid view at \"Media Library\". - Issue #2 - tokkonopapa\u002FWordPress-IP-Geo-Block - GitHub\" rel=\"nofollow ugc\">this ticket at Github\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>From \u003Ca href=\"https:\u002F\u002Fmake.wordpress.org\u002Fcore\u002F2016\u002F03\u002F09\u002Fcomment-changes-in-wordpress-4-5\u002F\" title=\"Comment Changes in WordPress 4.5 – Make WordPress Core\" rel=\"nofollow ugc\">WordPress 4.5\u003C\u002Fa>, \u003Ccode>rel=nofollow\u003C\u002Fcode> had no longer be attached to the links in \u003Ccode>comment_content\u003C\u002Fcode>. This change prevents to block “\u003Ca href=\"https:\u002F\u002Fwww.owasp.org\u002Findex.php\u002FServer_Side_Request_Forgery\" title=\"Server Side Request Forgery - OWASP\" rel=\"nofollow ugc\">Server Side Request Forgeries\u003C\u002Fa>” (not Cross Site but a malicious internal link in the comment field).\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fapps.wordpress.com\u002Fmobile\u002F\" title=\"WordPress.com Apps - Mobile Apps\" rel=\"nofollow ugc\">WordPress.com Mobile App\u003C\u002Fa> can’t execute image uploading because of its own authentication system via XMLRPC.\u003C\u002Fli>\n\u003C\u002Ful>\n","It blocks spam posts, login attempts and malicious access to the back-end requested from the specific countries, and also prevents zero-day exploit.",8000,779128,84,95,"2019-01-22T03:59:00.000Z","5.0.25","3.7",[20,21,97,23,119],"vulnerability","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fip-geo-block\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fip-geo-block.3.0.17.4.zip",85,{"slug":124,"name":125,"version":126,"author":127,"author_profile":128,"description":129,"short_description":130,"active_installs":131,"downloaded":132,"rating":26,"num_ratings":133,"last_updated":134,"tested_up_to":15,"requires_at_least":51,"requires_php":95,"tags":135,"homepage":138,"download_link":139,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"botblocker-security","BotBlocker Security – Firewall & Bot Protection","1.6.21","Yevhen Leonidov","https:\u002F\u002Fprofiles.wordpress.org\u002Fglobusstudio\u002F","\u003Cp>\u003Cstrong>BotBlocker Security blocks 99% of automated attacks before WordPress even loads.\u003C\u002Fstrong> No bloat, no slowdowns, no monthly fees for core protection.\u003C\u002Fp>\n\u003Cp>If your site is hit by login brute force, spam comments, fake Googlebots, content scrapers, or XML-RPC floods, you are not alone: bots generate over 47% of all web traffic. Most security plugins react after WordPress boots, wasting CPU and memory on every bad request. \u003Cstrong>BotBlocker stops them at the door.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>Why site owners switch to BotBlocker\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Faster than the competition.\u003C\u002Fstrong> Runs on early init through three interception layers, before themes and plugins load. Server load drops during attacks instead of spiking.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smarter CAPTCHA.\u003C\u002Fstrong> 9 modes including Silent Auto-Verify – zero clicks for humans, hard wall for bots. Proprietary CAPTCHAs defeat AI-based solvers that crack reCAPTCHA for $2-3 per 1 000.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Honest free version.\u003C\u002Fstrong> Full firewall, all 9 CAPTCHA modes, full 2FA, full logging, full Multisite support. No nag screens, no crippled features.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-first.\u003C\u002Fstrong> No visitor data leaves your server. GDPR and CCPA compliant out of the box.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with everything.\u003C\u002Fstrong> Cloudflare, WP Rocket, LiteSpeed, WooCommerce, Elementor, multisite, IPv6, PHP 7.4 to 8.5.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🛡️ Core Firewall (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Three-Layer Architecture\u003C\u002Fstrong> – intercepts traffic at wp-config.php (before WordPress), MU-plugin phase, and main shield. The first layer blocks known threats without loading WordPress at all, saving 30-100ms and 5-20MB RAM per blocked request.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Web Application Firewall (WAF)\u003C\u002Fstrong> with real-time rule updates via the BotBlocker Threat Defense Feed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>2 899 User-Agent signatures\u003C\u002Fstrong> – largest blacklist among WordPress plugins – covering Scrapy, Selenium, Puppeteer, PhantomJS, curl, wget, Python, Java, Perl, and SQL injection tools\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute force protection\u003C\u002Fstrong> with progressive lockouts – 5 attempts per 15 minutes, escalating bans for repeat offenders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anti-spam\u003C\u002Fstrong> for comments, registration, contact forms – spammers blocked before they connect\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC and REST API\u003C\u002Fstrong> locked down by default with allowlist for trusted services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fake crawler detection\u003C\u002Fstrong> via FCrDNS (dual-direction DNS verification), ASN tokens, and published IP ranges – 95% effective, impossible to spoof without controlling the provider’s DNS zone\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LLM \u002F AI crawler management\u003C\u002Fstrong> – allow or block GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Bytespider via CIDR-verified IP ranges. Trusted crawlers verified, impersonators blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country, ASN, IP range, User-Agent, Referer\u003C\u002Fstrong> blocking rules with instant enforcement\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare-aware\u003C\u002Fstrong> real-IP resolution and origin bypass protection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full IPv6 support\u003C\u002Fstrong> – separate tables and logic for IPv4 and IPv6, every feature works with both\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live traffic monitor\u003C\u002Fstrong> with attack map, country, ASN, device, browser, and exact block reason for every request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in caching\u003C\u002Fstrong> via Redis and Memcached – free, auto-disable on connection failure\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔒 Login Security & 2FA (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong> compatible with Google Authenticator, Authy, 1Password, Bitwarden – TOTP standard with 10 backup codes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>9 CAPTCHA modes\u003C\u002Fstrong>: Silent Auto-Verify, Single Button, Color CAPTCHA, Images CAPTCHA, Shapes CAPTCHA (60fps Canvas), Digits CAPTCHA, Hold Button CAPTCHA, plus Google reCAPTCHA v2 and v3\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hybrid Mode\u003C\u002Fstrong> – combine any internal CAPTCHA with reCAPTCHA v3 for two-layer invisible defense\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide login URL\u003C\u002Fstrong> \u003Cem>(PRO)\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable lockout durations\u003C\u002Fstrong> with escalation for repeat offenders – failed CAPTCHA triggers short ban, repeated failure triggers 24-hour ban\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>💳 Payment Gateway Bypass (Free)\u003C\u002Fh4>\n\u003Cp>Auto-detects 25+ e-commerce platforms (WooCommerce, Easy Digital Downloads, SureCart, MemberPress, Paid Memberships Pro, Give, Dokan, CartFlows, FunnelKit, and more) and 150+ payment providers (Stripe, PayPal, Mollie, Adyen, Braintree, Square, Razorpay, Klarna, Paddle, Authorize.Net, 2Checkout, YooKassa, LiqPay, and more). \u003Cstrong>Webhooks, IPN callbacks, and payment notifications never get blocked.\u003C\u002Fstrong> Four detection layers ensure zero false positives on payment traffic.\u003C\u002Fp>\n\u003Ch4>📊 Visibility & Control (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Visual dashboard with attack map, top offenders, blocked-vs-allowed ratio, world traffic map\u003C\u002Fli>\n\u003Cli>Detailed event log with IP, country, ASN, User-Agent, and exact block reason – 54 unique event codes\u003C\u002Fli>\n\u003Cli>Health Score gauge – 42 parameters across 3 categories, 5 security levels from Critical to Secure\u003C\u002Fli>\n\u003Cli>3 security presets – Light, Strong, Full – one-click configuration\u003C\u002Fli>\n\u003Cli>Setup Wizard – 8 steps from welcome to test attack, setup in under 5 minutes\u003C\u002Fli>\n\u003Cli>8 interface languages – English, Deutsch, Español, Français, Polski, Русский, Українська + POT template\u003C\u002Fli>\n\u003Cli>Configurable retention with timezone and DST awareness\u003C\u002Fli>\n\u003Cli>Clean uninstall – drops all 16 tables, removes 40+ options, clears cron hooks. Zero leftover data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🚀 PRO Adds (Premium \u002F Pro \u002F Ultimate)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Real-time cloud threat intelligence cross-checked against global databases – 5M+ attack IPs, hundreds of thousands of bot signatures, updated daily\u003C\u002Fli>\n\u003Cli>Zero-day behavioral and heuristic detection – catches unknown attack patterns before signatures exist\u003C\u002Fli>\n\u003Cli>VPN, Tor, proxy, ASN, and hosting reputation checks\u003C\u002Fli>\n\u003Cli>Early Init Mode – filtering before WordPress Core loads, maximum resource savings during attacks\u003C\u002Fli>\n\u003Cli>Hide Login URL addon – custom admin URL, hardened wp-login.php protection\u003C\u002Fli>\n\u003Cli>Security Headers addon – HSTS, CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy, X-Content-Type-Options\u003C\u002Fli>\n\u003Cli>Speed Up WordPress addon – 14 frontend and server optimizations\u003C\u002Fli>\n\u003Cli>Malware Scanner addon – 25 patterns scanning files + 7 database tables, detects webshells, eval injections, base64-obfuscated code hidden in wp_options and post_content\u003C\u002Fli>\n\u003Cli>Priority support – 24-hour response time\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Four plans to match your traffic: \u003Cstrong>Premium\u003C\u002Fstrong> ($12\u002Fmonth, 25k cloud checks), \u003Cstrong>Pro\u003C\u002Fstrong> ($50\u002Fmonth, 100k cloud checks), \u003Cstrong>Ultimate\u003C\u002Fstrong> ($100\u002Fmonth, 250k cloud checks + emergency 24h support). Annual billing includes 1 month free. 30-day refund policy. Licensed per domain, billed securely via Freemius.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\" rel=\"nofollow ugc\">Compare plans \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>⚡ Performance & Compatibility\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero database queries\u003C\u002Fstrong> for returning visitors – 9 runtime PHP files with SHA-256 integrity signatures, loaded via \u003Ccode>include\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Measured overhead: \u003Cstrong>+3-15ms\u003C\u002Fstrong> TTFB for cached visitors, \u003Cstrong>+50-200ms\u003C\u002Fstrong> for first-time PTR lookups, \u003Cstrong>+2-4MB\u003C\u002Fstrong> memory\u003C\u002Fli>\n\u003Cli>Redis and Memcached support – free, auto-disables gracefully on connection failure\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cache plugin compatibility\u003C\u002Fstrong> – automatic \u003Ccode>DONOTCACHEPAGE\u003C\u002Fcode> and \u003Ccode>Cache-Control: no-store\u003C\u002Fcode> on verification pages. Works with WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, Hummingbird, WP Fastest Cache, Cache Enabler\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CDN and WAF compatibility\u003C\u002Fstrong> – Cloudflare, Sucuri, Incapsula, AWS CloudFront, Fastly, KeyCDN, StackPath. Multi-header real-IP resolution (CF-Connecting-IP, X-Forwarded-For, X-Real-IP)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DDoS Protection Compatibility\u003C\u002Fstrong> – automatic detection of JS-challenges from DDoS-Guard, Stormwall, Qrator. HMAC-signed AJAX responses, Circuit Breaker with automatic retry and backoff. BotBlocker is the only WordPress plugin that works correctly behind aggressive DDoS protection without manual configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite Support\u003C\u002Fstrong> – network activation, per-site data, per-site cleanup. Free on all plans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP 7.4 – 8.5\u003C\u002Fstrong> – tested across 7 PHP versions. \u003Cstrong>WordPress 5.0 – 7.0+\u003C\u002Fstrong>. Linux and Windows.\u003C\u002Fli>\n\u003Cli>GDPR and CCPA compliant – no PII collected, technical parameters only, Legitimate Interest basis (Art. 6(1)(f))\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🤝 Trusted by\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>3 000+ active installations\u003C\u002Fli>\n\u003Cli>Translated into 8 languages\u003C\u002Fli>\n\u003Cli>Tested up to WordPress 7.0 and PHP 8.5\u003C\u002Fli>\n\u003Cli>Developed and maintained by GLOBUS.studio\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>“Replaced two security plugins and a CAPTCHA plugin with one. Site is faster and the spam stopped overnight.” – WordPress.org user\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>BotBlocker Security does \u003Cstrong>not\u003C\u002Fstrong> collect or process personal data of your visitors. All cloud analysis is performed on technical parameters only (IP, headers, User-Agent). No personally identifiable information is collected, stored, or transmitted to any external service.\u003C\u002Fp>\n\u003Ch3>Support and Documentation\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Product site: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fproducts\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fproducts\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Pricing and PRO plans: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Documentation: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fdocs\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fdocs\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Contact\u002Fsupport: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fcontacts\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fcontacts\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Community: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fcommunity\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fcommunity\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later. See LICENSE.txt for details.\u003C\u002Fp>\n\u003Ch3>Credits & Authors\u003C\u002Fh3>\n\u003Cp>BotBlocker Security is developed and maintained by GLOBUS.studio.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Concept, architecture & code – Yevhen Leonidov: \u003Ca href=\"https:\u002F\u002Fleonidov.dev\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fleonidov.dev\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Code, code review – Andrii Lukashevych\u003C\u002Fli>\n\u003Cli>Code, translations – Aleksandr Kinakh\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>BotBlocker Security – The first line of defense for your WordPress site.\u003C\u002Fstrong>\u003C\u002Fp>\n","Stop bots, brute force, spam, and fake crawlers before they reach WordPress. Three-layer firewall, 9 CAPTCHAs, FCrDNS, 2FA. Setup in 60 seconds.",3000,8224,9,"2026-06-17T18:31:00.000Z",[136,20,137,21,23],"anti-spam","captcha","https:\u002F\u002Fbotblocker.top\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotblocker-security.1.6.21.zip",{"error":141,"url":142,"statusCode":143,"statusMessage":144,"message":144},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fgrantech-ip-firewall-for-abuseipdb\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":57,"versions":146},[147,155,162,169],{"version":148,"download_url":149,"svn_tag_url":150,"released_at":27,"has_diff":151,"diff_files_changed":152,"diff_lines":27,"trac_diff_url":153,"vulnerabilities":154,"is_current":151},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgrantech-ip-firewall-for-abuseipdb.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgrantech-ip-firewall-for-abuseipdb\u002Ftags\u002F1.0.3\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.2&new_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.3",[],{"version":156,"download_url":157,"svn_tag_url":158,"released_at":27,"has_diff":151,"diff_files_changed":159,"diff_lines":27,"trac_diff_url":160,"vulnerabilities":161,"is_current":151},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgrantech-ip-firewall-for-abuseipdb.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgrantech-ip-firewall-for-abuseipdb\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.1&new_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.2",[],{"version":163,"download_url":164,"svn_tag_url":165,"released_at":27,"has_diff":151,"diff_files_changed":166,"diff_lines":27,"trac_diff_url":167,"vulnerabilities":168,"is_current":151},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgrantech-ip-firewall-for-abuseipdb.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgrantech-ip-firewall-for-abuseipdb\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.0&new_path=%2Fgrantech-ip-firewall-for-abuseipdb%2Ftags%2F1.0.1",[],{"version":170,"download_url":171,"svn_tag_url":172,"released_at":27,"has_diff":151,"diff_files_changed":173,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":174,"is_current":151},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgrantech-ip-firewall-for-abuseipdb.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgrantech-ip-firewall-for-abuseipdb\u002Ftags\u002F1.0.0\u002F",[],[]]