[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHPAAd7txOip1In_aGDtDkPgOAzbq0avL7K1Iyn4fTGY":3,"$fd4403Juh-4-xcXZu3Ov1AJTRZ6zlNLiG2Jr6IK6Nng8":132,"$fiHlX-1qnY282oU32mltOtAz6M6NcuDOmuq2oj2Id8Vo":137},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":11,"rating":11,"num_ratings":11,"last_updated":12,"tested_up_to":13,"requires_at_least":14,"requires_php":15,"tags":16,"homepage":22,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":35,"analysis":25,"fingerprints":25},"smart-country-blocker","Smart Country Blocker","1.0.4","Shakib R Khan","https:\u002F\u002Fprofiles.wordpress.org\u002Fshakibrkhan\u002F","\u003Cp>\u003Cstrong>IMPORTANT: This plugin uses external third-party services (ipwho.is and ipapi.co) to determine visitor location. Please review the “External Services” section below for details on data transmission and privacy.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Smart Country Blocker is a powerful WordPress plugin that allows you to restrict access to your website based on visitor location. Block unwanted traffic from specific countries on both frontend pages and backend admin areas.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>🌍 \u003Cstrong>Complete Country List\u003C\u002Fstrong> – Select from 195+ countries worldwide\u003C\u002Fli>\n\u003Cli>🎯 \u003Cstrong>Frontend & Backend Blocking\u003C\u002Fstrong> – Block both website pages and wp-admin\u002Fwp-login.php\u003C\u002Fli>\n\u003Cli>📊 \u003Cstrong>Comprehensive Logging\u003C\u002Fstrong> – Track all blocked access attempts with IP, country, URL, and timestamp\u003C\u002Fli>\n\u003Cli>📈 \u003Cstrong>Statistics Dashboard\u003C\u002Fstrong> – View total blocks, unique IPs, and blocked countries count\u003C\u002Fli>\n\u003Cli>🔍 \u003Cstrong>Advanced Filtering\u003C\u002Fstrong> – Filter and sort logs by country, date, IP address\u003C\u002Fli>\n\u003Cli>📄 \u003Cstrong>Pagination\u003C\u002Fstrong> – Manage large log datasets with 20 records per page\u003C\u002Fli>\n\u003Cli>⚡ \u003Cstrong>Quick Remove\u003C\u002Fstrong> – Remove countries from blocked list with one click\u003C\u002Fli>\n\u003Cli>🔒 \u003Cstrong>Cache-Friendly\u003C\u002Fstrong> – Compatible with major caching plugins (see configuration below)\u003C\u002Fli>\n\u003Cli>🎨 \u003Cstrong>Customizable Block Page\u003C\u002Fstrong> – Edit blocked.php to customize the access denied page\u003C\u002Fli>\n\u003Cli>🖥️ \u003Cstrong>Easy-to-Use Interface\u003C\u002Fstrong> – Checkbox selection with search functionality\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Important: Cache Plugin Compatibility\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>CRITICAL:\u003C\u002Fstrong> If you use a caching plugin (WP Rocket, W3 Total Cache, WP Super Cache, LiteSpeed Cache, etc.), cached pages may bypass country blocking. Follow these configuration steps:\u003C\u002Fp>\n\u003Ch4>WP Rocket Configuration\u003C\u002Fh4>\n\u003Cp>WP Rocket should work automatically as the plugin sets the \u003Ccode>DONOTCACHEPAGE\u003C\u002Fcode> constant. However, for best results:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>WP Rocket\u003C\u002Fstrong> > \u003Cstrong>Settings\u003C\u002Fstrong> > \u003Cstrong>Advanced Rules\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Add this to “Never Cache URL(s)”:\u003Cbr \u002F>\n   \u003Ccode>\u002F(.*)\u003C\u002Fcode>\u003Cbr \u002F>\n(Only if you want to disable cache completely for blocked countries)\u003C\u002Fli>\n\u003Cli>The plugin automatically prevents caching for blocked visitors\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>W3 Total Cache Configuration\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Performance\u003C\u002Fstrong> > \u003Cstrong>Page Cache\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Scroll to “Never cache the following pages:”\u003C\u002Fli>\n\u003Cli>Add: \u003Ccode>*\u003C\u002Fcode> (if you want complete blocking to bypass cache)\u003C\u002Fli>\n\u003Cli>OR go to \u003Cstrong>Performance\u003C\u002Fstrong> > \u003Cstrong>General Settings\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enable “Page Cache” > “Don’t cache pages for logged in users”\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>WP Super Cache Configuration\u003C\u002Fh4>\n\u003Cp>WP Super Cache should work automatically as the plugin sets no-cache headers. To verify:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Settings\u003C\u002Fstrong> > \u003Cstrong>WP Super Cache\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Make sure “Don’t cache pages with GET parameters” is enabled\u003C\u002Fli>\n\u003Cli>The plugin sends proper no-cache headers for blocked visitors\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>LiteSpeed Cache Configuration\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>LiteSpeed Cache\u003C\u002Fstrong> > \u003Cstrong>Cache\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Under “Do Not Cache URIs”, you can add specific paths if needed\u003C\u002Fli>\n\u003Cli>The plugin sets proper cache bypass constants\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Cloudflare Configuration\u003C\u002Fh4>\n\u003Cp>If using Cloudflare:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to Cloudflare Dashboard > \u003Cstrong>Rules\u003C\u002Fstrong> > \u003Cstrong>Page Rules\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Add a rule: \u003Ccode>yoursite.com\u002F*\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Set “Cache Level” to “Bypass” (optional, only if experiencing issues)\u003C\u002Fli>\n\u003Cli>Or add IP-based rules in Cloudflare’s Firewall\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Testing After Configuration\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Always test blocking functionality:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Connect to a VPN from a blocked country\u003C\u002Fli>\n\u003Cli>Try to access your website\u003C\u002Fli>\n\u003Cli>You should see the “Access Restricted” page\u003C\u002Fli>\n\u003Cli>Check \u003Cstrong>Block Logs\u003C\u002Fstrong> in the plugin to confirm the block was logged\u003C\u002Fli>\n\u003Cli>If you can still access, clear your cache plugin cache and test again\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Ch4>Blocking Countries\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Country Blocker\u003C\u002Fstrong> in WordPress admin\u003C\u002Fli>\n\u003Cli>Use the search box to quickly find countries\u003C\u002Fli>\n\u003Cli>Check\u002Funcheck countries to block\u002Funblock\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save Changes\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Use “Select All” or “Deselect All” for bulk operations\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Quick Remove Blocked Countries\u003C\u002Fh4>\n\u003Col>\n\u003Cli>View the “Currently Blocked Countries” section at the top\u003C\u002Fli>\n\u003Cli>Click the \u003Cstrong>×\u003C\u002Fstrong> button next to any country to remove it instantly\u003C\u002Fli>\n\u003Cli>Confirm the removal in the popup\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Viewing Block Logs\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Country Blocker\u003C\u002Fstrong> > \u003Cstrong>Block Logs\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>See statistics: Total Blocks, Unique IPs, Countries Blocked, Last 7 Days\u003C\u002Fli>\n\u003Cli>Filter logs by country, sort by date\u002FIP\u002Fcountry\u003C\u002Fli>\n\u003Cli>View detailed information: IP address, country, access type (frontend\u002Fbackend), URL, timestamp\u003C\u002Fli>\n\u003Cli>Use pagination to navigate through logs\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Clearing Logs\u003C\u002Fh4>\n\u003Cp>Click \u003Cstrong>Clear All Logs\u003C\u002Fstrong> button to remove all historical block records. This cannot be undone.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin relies on third-party GeoIP services to determine visitor location based on their IP address. These services are essential for the plugin’s core functionality.\u003C\u002Fp>\n\u003Ch4>ipwho.is (Primary Service — default)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Provides IP geolocation data to identify the visitor’s country.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Every time a new visitor accesses your website from an IP address not cached in the last hour. The plugin sends the visitor’s IP address to ipwho.is API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data transmitted:\u003C\u002Fstrong> Only the visitor’s IP address is sent to the API. No personal information, cookies, or user data is transmitted.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Caching:\u003C\u002Fstrong> Results are cached for 1 hour per IP address to minimize API calls and improve performance.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service provider:\u003C\u002Fstrong> ipwho.is is a free IP geolocation service.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Website:\u003C\u002Fstrong> https:\u002F\u002Fipwho.is\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>API Documentation:\u003C\u002Fstrong> https:\u002F\u002Fipwho.is\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fipwho.is\u002F (see website footer for terms)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fipwho.is\u002F (see website footer for privacy policy)\u003C\u002Fp>\n\u003Ch4>findip.net (Optional Alternative Service)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> An alternative IP geolocation service you can use instead of ipwho.is. Requires a free API key.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> When configured as the primary service, the visitor’s IP address is sent to findip.net on each uncached lookup.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data transmitted:\u003C\u002Fstrong> Only the visitor’s IP address is sent to the API. No personal information, cookies, or user data is transmitted.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service provider:\u003C\u002Fstrong> findip.net is an IP geolocation service using GeoNames \u002F MaxMind data.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>API key:\u003C\u002Fstrong> A free account and API token are required. Sign up at https:\u002F\u002Ffindip.net\u002F and enter the token in Country Blocker > API Settings.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Website:\u003C\u002Fstrong> https:\u002F\u002Ffindip.net\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>API Documentation:\u003C\u002Fstrong> https:\u002F\u002Ffindip.net\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Ffindip.net\u002F (see website for current terms of service)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Ffindip.net\u002F (see website for privacy policy information)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> By using findip.net, you agree to their terms of service and privacy policy as outlined on their website.\u003C\u002Fp>\n\u003Ch4>ipapi.co (Fallback Service)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Acts as a backup geolocation service if the primary service (ipwho.is or findip.net) fails or is unavailable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Only when the primary service fails to respond or returns an error. The plugin automatically tries ipapi.co as a fallback.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data transmitted:\u003C\u002Fstrong> Only the visitor’s IP address is sent to the API. No personal information, cookies, or user data is transmitted.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service provider:\u003C\u002Fstrong> ipapi.co is a free IP geolocation service with rate limits (30,000 requests\u002Fmonth for free tier).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fterms\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>API Documentation:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fapi\u002F\u003C\u002Fp>\n\u003Ch4>Data Protection & Privacy\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The plugin does NOT send any personal user data, cookies, form inputs, or browsing history to external services.\u003C\u002Fli>\n\u003Cli>Only IP addresses are transmitted, which are necessary for geolocation functionality.\u003C\u002Fli>\n\u003Cli>API requests are made server-side; visitor browsers do not directly contact these services.\u003C\u002Fli>\n\u003Cli>Failed API lookups are logged locally for troubleshooting purposes.\u003C\u002Fli>\n\u003Cli>All API requests use HTTPS (SSL) encryption.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Legal Compliance\u003C\u002Fh4>\n\u003Cp>If you operate in regions with strict privacy laws (GDPR, CCPA, etc.), please be aware:\u003Cbr \u002F>\n– IP addresses may be considered personal data under some regulations.\u003Cbr \u002F>\n– Consider adding a privacy notice informing users that their IP addresses may be processed for access control.\u003Cbr \u002F>\n– The plugin logs blocked access attempts (IP + country + timestamp) in your WordPress database for security purposes.\u003C\u002Fp>\n\u003Ch3>Technical Details\u003C\u002Fh3>\n\u003Ch4>Database Table\u003C\u002Fh4>\n\u003Cp>The plugin creates \u003Ccode>wp_country_blocker_logs\u003C\u002Fcode> table with the following structure:\u003Cbr \u002F>\n– id (Primary Key)\u003Cbr \u002F>\n– ip_address (VARCHAR 45)\u003Cbr \u002F>\n– country_code (VARCHAR 2)\u003Cbr \u002F>\n– country_name (VARCHAR 100)\u003Cbr \u002F>\n– blocked_url (TEXT)\u003Cbr \u002F>\n– user_agent (TEXT)\u003Cbr \u002F>\n– access_type (VARCHAR 20) – ‘frontend’ or ‘backend’\u003Cbr \u002F>\n– blocked_at (DATETIME)\u003C\u002Fp>\n\u003Ch4>Hooks Used\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>plugins_loaded\u003C\u002Fcode> (priority -999999) – Early blocking execution\u003C\u002Fli>\n\u003Cli>\u003Ccode>admin_menu\u003C\u002Fcode> – Register admin pages\u003C\u002Fli>\n\u003Cli>\u003Ccode>admin_notices\u003C\u002Fcode> – Show cache configuration notice\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Constants Defined\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Important Note About Unprefixed Constants:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin defines industry-standard cache bypass constants that are \u003Cstrong>intentionally unprefixed\u003C\u002Fstrong> and \u003Cstrong>cannot be changed\u003C\u002Fstrong>. These constants have been the de-facto standard in the WordPress caching ecosystem for over 15 years and are recognized by virtually all caching plugins and CDN services.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why these constants MUST remain unprefixed:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>These constants are NOT WordPress core constants. They are industry standards established by the caching plugin ecosystem. WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache, and dozens of other caching\u002FCDN plugins specifically check for these \u003Cstrong>exact\u003C\u002Fstrong> constant names.\u003C\u002Fp>\n\u003Cp>Prefixing these constants (e.g., changing \u003Ccode>DONOTCACHEPAGE\u003C\u002Fcode> to \u003Ccode>WPCB_DONOTCACHEPAGE\u003C\u002Fcode>) would \u003Cstrong>break compatibility\u003C\u002Fstrong> with all major caching plugins, rendering the blocking functionality useless on cached sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Constants used for cache bypass (when blocking visitors):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>DONOTCACHEPAGE\u003C\u002Fcode> – Prevents page caching (WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache)\u003C\u002Fli>\n\u003Cli>\u003Ccode>DONOTCACHEDB\u003C\u002Fcode> – Prevents database query caching (W3 Total Cache)\u003C\u002Fli>\n\u003Cli>\u003Ccode>DONOTMINIFY\u003C\u002Fcode> – Prevents JS\u002FCSS minification (Autoptimize, WP Rocket, Fast Velocity Minify)\u003C\u002Fli>\n\u003Cli>\u003Ccode>DONOTCDN\u003C\u002Fcode> – Prevents CDN URL rewriting (CDN Enabler, W3 Total Cache CDN module)\u003C\u002Fli>\n\u003Cli>\u003Ccode>DONOTCACHEOBJECT\u003C\u002Fcode> – Prevents object caching (LiteSpeed Cache, W3 Total Cache)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These constants are set ONLY when a visitor is being blocked (403 response), not globally. They signal to caching plugins: “Do not cache this specific request.”\u003C\u002Fp>\n\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003Cbr \u002F>\n– WP Rocket Documentation: https:\u002F\u002Fdocs.wp-rocket.me\u002Farticle\u002F61-disable-page-caching\u003Cbr \u002F>\n– LiteSpeed Cache Documentation: https:\u002F\u002Fdocs.litespeedtech.com\u002Flscache\u002Flscwp\u002Fcache\u002F#do-not-cache-constants\u003C\u002Fp>\n\u003Cp>This is an \u003Cstrong>accepted exception\u003C\u002Fstrong> to WordPress naming conventions and is properly documented in the code with phpcs ignore comments.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, bug reports, or feature requests, please contact the developer.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin logs IP addresses and country information for security purposes. Ensure compliance with GDPR\u002Fprivacy laws in your jurisdiction. Consider adding a privacy notice to inform users that their IP addresses may be logged if they attempt to access from blocked countries.\u003C\u002Fp>\n","Block visitors from specific countries for both frontend and backend (wp-admin) access with comprehensive logging and reporting.",0,"2026-07-22T06:17:00.000Z","7.0.2","6.0","7.4",[17,18,19,20,21],"country-block","geo-blocking","geoip","ip-blocking","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmart-country-blocker.1.0.4.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":24,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"shakibrkhan",2,30,94,"2026-08-29T04:57:46.604Z",[36,58,78,92,113],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":15,"tags":51,"homepage":55,"download_link":56,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":57},"block-website-access-by-region-lite","Country Blocker and Geoblocker FREE","1.1.0","Simple Tools","https:\u002F\u002Fprofiles.wordpress.org\u002Fjimmyredline80\u002F","\u003Cp>\u003Cstrong>Country Blocker\u003C\u002Fstrong> is the easiest way to block website visitors by country, region, or IP address. No API keys required, no complicated setup – just activate, select countries to block, and protect your site instantly.\u003C\u002Fp>\n\u003Cp>Perfect for compliance, security, and content licensing:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>GDPR compliance\u003C\u002Fstrong> – Block EU countries to avoid cookie consent requirements\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CCPA compliance\u003C\u002Fstrong> – Block California traffic if you can’t meet data privacy requirements\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gambling & gaming sites\u003C\u002Fstrong> – Restrict access from prohibited jurisdictions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Streaming & licensed content\u003C\u002Fstrong> – Enforce geographic licensing restrictions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Financial services\u003C\u002Fstrong> – Block countries you’re not licensed to operate in\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce spam & attacks\u003C\u002Fstrong> – Block high-risk countries and VPN traffic\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Choose Country Blocker?\u003C\u002Fh3>\n\u003Cp>✅ \u003Cstrong>One-click setup\u003C\u002Fstrong> – No API keys or database downloads required\u003Cbr \u002F>\n✅ \u003Cstrong>Actually works\u003C\u002Fstrong> – Powered by our reliable geolocation server infrastructure\u003Cbr \u002F>\n✅ \u003Cstrong>VPN & proxy detection\u003C\u002Fstrong> – Optional blocking of VPNs, proxies, data centers, and hosting providers\u003Cbr \u002F>\n✅ \u003Cstrong>SEO friendly\u003C\u002Fstrong> – Automatically allows Google, Bing, and other search engine crawlers\u003Cbr \u002F>\n✅ \u003Cstrong>Won’t lock you out\u003C\u002Fstrong> – WordPress admin and login pages always remain accessible\u003Cbr \u002F>\n✅ \u003Cstrong>Privacy focused\u003C\u002Fstrong> – Minimal data storage with IP hashing for security\u003C\u002Fp>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Blocking & Access Control:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Block visitors from any country with a simple checkbox (250+ countries)\u003Cbr \u002F>\n* Optional VPN, proxy, and datacenter detection and blocking\u003Cbr \u002F>\n* Search engine crawler bypass (Google, Bing, DuckDuckGo, etc.)\u003Cbr \u002F>\n* Choose to allow or block visitors when country cannot be determined\u003Cbr \u002F>\n* Emergency bypass URL parameter for troubleshooting\u003Cbr \u002F>\n* WordPress admin and login pages are never blocked\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Geolocation:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Works instantly without API keys or configuration\u003Cbr \u002F>\n* Powered by our managed geolocation server (no setup required)\u003Cbr \u002F>\n* Cloudflare IP detection support\u003Cbr \u002F>\n* Supports proxy headers (X-Forwarded-For, X-Real-IP, CF-Connecting-IP)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Logging & Monitoring:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Track all blocked and allowed access attempts\u003Cbr \u002F>\n* View visitor country codes and decision reasons\u003Cbr \u002F>\n* Automatic log cleanup (configurable retention period)\u003Cbr \u002F>\n* Rate limiting to prevent log spam\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy & Security:\u003C\u002Fstrong>\u003Cbr \u002F>\n* IP addresses are hashed by default for privacy\u003Cbr \u002F>\n* GDPR and CCPA friendly minimal data storage\u003Cbr \u002F>\n* Configurable data retention policies\u003Cbr \u002F>\n* No tracking scripts or external cookies\u003C\u002Fp>\n\u003Ch3>Pro Version\u003C\u002Fh3>\n\u003Cp>Need more granular control? \u003Cstrong>Country Blocker Pro\u003C\u002Fstrong> includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Region-Level Blocking:\u003C\u002Fstrong>\u003Cbr \u002F>\n* 🇺🇸 Block specific US states (all 50 states + DC, Puerto Rico, Guam, US Virgin Islands)\u003Cbr \u002F>\n* 🇨🇦 Block Canadian provinces and territories\u003Cbr \u002F>\n* 🇬🇧 Block UK regions (England, Scotland, Wales, Northern Ireland)\u003Cbr \u002F>\n* 🇦🇺 Block Australian states and territories\u003Cbr \u002F>\n* 🇩🇪 Block German states (Bundesländer)\u003Cbr \u002F>\n* 🇮🇳 Block Indian states and union territories\u003Cbr \u002F>\n* 🇨🇳 Block Chinese provinces and municipalities\u003Cbr \u002F>\n* 🌍 Block entire continents with one click\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* IP whitelist – Never block specific IPs (supports CIDR notation)\u003Cbr \u002F>\n* IP blacklist – Always block specific IPs regardless of location\u003Cbr \u002F>\n* Custom block page with full color customization\u003Cbr \u002F>\n* Custom CSS editor for complete design control\u003Cbr \u002F>\n* Redirect blocked visitors to any URL\u003Cbr \u002F>\n* Advanced logging with CSV export\u003Cbr \u002F>\n* Smart log retention and database optimization\u003Cbr \u002F>\n* Priority email support\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.plugins-for-wp.com\u002Fproduct\u002Fcountry-blocker-and-geoblocker-pro\u002F\" rel=\"nofollow ugc\">Get Country Blocker Pro \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to external services for geolocation functionality and anonymous usage reporting. By using this plugin, you acknowledge that data will be sent to these third-party services.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Geolocation Service\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>To determine a visitor’s country, the plugin sends the visitor’s IP address to our geolocation server:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Simple Tools for WP Geolocation API\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: IP geolocation lookup\u003Cbr \u002F>\n* Data sent: Visitor IP address, your site URL\u003Cbr \u002F>\n* When: On each unique visitor’s first page load (cached for 24 hours)\u003Cbr \u002F>\n* Endpoint: https:\u002F\u002Fplugins-for-wp.com\u002Fwp-json\u002Fssp-geo\u002Fv1\u002Flookup\u003Cbr \u002F>\n* Privacy: IP addresses are processed only for geolocation purposes and are not stored permanently on our servers\u003Cbr \u002F>\n* Terms: https:\u002F\u002Fplugins-for-wp.com\u002Fterms\u002F\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Fplugins-for-wp.com\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Anonymous Usage Statistics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Twice daily the plugin sends aggregated blocking event statistics to our servers to help us monitor plugin health, improve geolocation accuracy, and understand how the plugin is being used:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Simple Tools for WP Reporting API\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service: Anonymous blocking event reporting\u003Cbr \u002F>\n* Data sent: Hashed visitor IP addresses (SHA-256, non-reversible), country codes, block\u002Fallow decisions, plugin version, WordPress version, PHP version, your site URL\u003Cbr \u002F>\n* When: Sent in batches twice daily (8 AM and 8 PM server time)\u003Cbr \u002F>\n* Endpoint: https:\u002F\u002Fplugins-for-wp.com\u002Fwp-json\u002Fssp-geo\u002Fv1\u002Freport-batch\u003Cbr \u002F>\n* Privacy: Hashed IPs cannot be reversed to identify individuals. No personally identifiable information is transmitted.\u003Cbr \u002F>\n* Terms: https:\u002F\u002Fplugins-for-wp.com\u002Fterms\u002F\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Fplugins-for-wp.com\u002Fprivacy\u002F\u003Cbr \u002F>\n* Opt-out: To disable usage reporting for your site, contact support@plugins-for-wp.com\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Retention:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe plugin stores minimal data on your WordPress database: hashed IP addresses (for rate limiting), country codes, access decisions (blocked\u002Fallowed), and timestamps. You can configure automatic log cleanup in settings. The plugin does not track individual visitors or create profiles.\u003C\u002Fp>\n\u003Ch3>Service Terms & Future Pricing\u003C\u002Fh3>\n\u003Cp>The geolocation service is currently provided free of charge. We are covering the server and infrastructure costs during this introductory period.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Future pricing may apply:\u003C\u002Fstrong> We reserve the right to introduce usage-based pricing for the geolocation service in the future. If pricing is introduced, it would be based on the number of geolocation requests your site makes to our servers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why this is permitted:\u003C\u002Fstrong> This plugin operates under a Software-as-a-Service (SaaS) model where the core functionality depends on our external geolocation servers. Under standard software licensing practices and the GPL license, while the plugin code itself is free and open source, external services that the plugin connects to may have their own terms, conditions, and pricing structures. This is similar to how many WordPress plugins offer free plugins that connect to paid external services (email marketing, backup storage, CDN services, etc.).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What this means for you:\u003C\u002Fstrong>\u003Cbr \u002F>\n* The plugin will continue to function as described\u003Cbr \u002F>\n* You will be notified in advance of any pricing changes\u003Cbr \u002F>\n* You are not obligated to continue using the service if pricing is introduced\u003Cbr \u002F>\n* Alternative geolocation solutions can be implemented if you choose not to use our service\u003C\u002Fp>\n\u003Cp>By installing and using this plugin, you acknowledge and accept these terms.\u003C\u002Fp>\n\u003Ch3>Privacy & Data Usage\u003C\u002Fh3>\n\u003Cp>This plugin is designed with privacy in mind:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP addresses are hashed by default before storage\u003C\u002Fli>\n\u003Cli>Only country codes and access decisions are logged, not full visitor profiles\u003C\u002Fli>\n\u003Cli>Logs can be automatically cleaned up after a configurable retention period\u003C\u002Fli>\n\u003Cli>No cookies are set on the visitor’s browser\u003C\u002Fli>\n\u003Cli>No tracking scripts are loaded\u003C\u002Fli>\n\u003Cli>Geolocation lookups are cached for 24 hours to minimize server requests\u003C\u002Fli>\n\u003Cli>Anonymous blocking statistics are sent twice daily using non-reversible hashed IPs\u003C\u002Fli>\n\u003Cli>To opt out of anonymous reporting, contact support@plugins-for-wp.com\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For GDPR compliance, the plugin blocks visitors from specified countries, which may reduce your data collection obligations. However, you should still review your complete privacy obligations with a legal professional.\u003C\u002Fp>\n","Block visitors by country in one click. Geo blocker with VPN detection, IP blocking & country restrictions. GDPR & CCPA compliance made easy.",80,1786,20,1,"2026-04-05T22:42:00.000Z","6.9.4","5.6",[52,53,18,21,54],"country-blocker","gdpr","vpn-blocker","https:\u002F\u002Fplugins-for-wp.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblock-website-access-by-region-lite.zip","2026-04-06T09:54:40.288Z",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":24,"num_ratings":68,"last_updated":69,"tested_up_to":13,"requires_at_least":70,"requires_php":71,"tags":72,"homepage":76,"download_link":77,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"workflowdone-geo-blocker","WorkflowDone Geo Blocker","1.0.7","workflowdone","https:\u002F\u002Fprofiles.wordpress.org\u002Fworkflowdone\u002F","\u003Cp>\u003Cstrong>WorkflowDone Geo Blocker\u003C\u002Fstrong> is a simple yet powerful WordPress plugin that allows you to block access to your website based on visitors’ geographical locations. Perfect for compliance, content licensing, or security purposes.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Country Blocking\u003C\u002Fstrong> – Block visitors from specific countries\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelisting\u003C\u002Fstrong> – Allow specific IP addresses regardless of country\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO-Friendly\u003C\u002Fstrong> – Automatically allows major search engine crawlers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Block Page\u003C\u002Fstrong> – Customize the message shown to blocked visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Caching\u003C\u002Fstrong> – Efficient caching to minimize geo-lookup requests\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy Setup\u003C\u002Fstrong> – Simple configuration with no technical knowledge required\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Select which countries you want to block\u003C\u002Fli>\n\u003Cli>Optionally add IP addresses that should always be allowed\u003C\u002Fli>\n\u003Cli>Enable geo-blocking\u003C\u002Fli>\n\u003Cli>Visitors from blocked countries see a friendly block page\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Become a Supporter\u003C\u002Fh4>\n\u003Cp>Love this plugin? Become a supporter and unlock all features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Whitelist Mode\u003C\u002Fstrong> – Allow only specific countries instead of blocking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Bypass\u003C\u002Fstrong> – Skip geo-blocking for logged-in administrators\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Access Logging\u003C\u002Fstrong> – Log blocked access attempts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Ranges (CIDR)\u003C\u002Fstrong> – Whitelist entire IP ranges\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Block Pages\u003C\u002Fstrong> – Create custom HTML pages or redirects\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support Email\u003C\u002Fstrong> – Display contact email on block page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>URL Exclusions\u003C\u002Fstrong> – Skip blocking for specific URLs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Crawler Rules\u003C\u002Fstrong> – Add your own crawler patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>One-time payment of $10, lifetime access!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fworkflowdone.com\u002Fproduct\u002Fadvanced-geo-blocker-pro\u002F\" rel=\"nofollow ugc\">Become a Supporter\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>This plugin uses third-party geo-location services to determine visitor countries:\u003Cbr \u002F>\n* ip-api.com – \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003Cbr \u002F>\n* ipinfo.io – \u003Ca href=\"https:\u002F\u002Fipinfo.io\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Only IP addresses are sent to these services to determine the country. No other personal data is transmitted.\u003C\u002Fp>\n\u003Cp>The plugin caches geo-location results locally to minimize external requests.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, please contact: support@workflowdone.com\u003C\u002Fp>\n\u003Cp>Website: \u003Ca href=\"https:\u002F\u002Fworkflowdone.com\" rel=\"nofollow ugc\">workflowdone.com\u003C\u002Fa>\u003C\u002Fp>\n","Block website access based on visitor's geographical location. Simple and effective geo-blocking for WordPress.",50,1330,3,"2026-06-20T20:25:00.000Z","5.0","7.2",[73,74,75,20,21],"country-blocking","geo-restriction","geoblocking","https:\u002F\u002Fworkflowdone.com\u002Fgeo-blocker","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fworkflowdone-geo-blocker.1.0.7.zip",{"slug":79,"name":80,"version":39,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":11,"downloaded":85,"rating":11,"num_ratings":11,"last_updated":86,"tested_up_to":13,"requires_at_least":87,"requires_php":15,"tags":88,"homepage":22,"download_link":91,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"cordonai-geo-access-and-redirect","CordonAI Geo Access and Redirect","CordonAI","https:\u002F\u002Fprofiles.wordpress.org\u002Fcordonai\u002F","\u003Cp>CordonAI Geo Access and Redirect lets you decide who can reach your WordPress\u003Cbr \u002F>\nsite based on the visitor’s country and IP address. Everything runs through\u003Cbr \u002F>\nstandard WordPress hooks — the plugin never modifies \u003Ccode>wp-config.php\u003C\u002Fcode>,\u003Cbr \u002F>\n    .htaccess, or any core file.\u003C\u002Fp>\n\u003Cp>Country lookups use a bundled MaxMind GeoLite2 database that ships with the\u003Cbr \u002F>\nplugin, so \u003Cstrong>no external request is made when a visitor is checked\u003C\u002Fstrong>. If you\u003Cbr \u002F>\nwant fresher data you can add a free MaxMind license key and update the\u003Cbr \u002F>\ndatabase on demand or weekly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block (or allow) front-end visitors by country and by IP address.\u003C\u002Fli>\n\u003Cli>Protect the login page and admin area by country\u002FIP, with brute-force-friendly\u003Cbr \u002F>\ndefaults — established administrators are never locked out of the dashboard.\u003C\u002Fli>\n\u003Cli>IP rules support exact addresses, wildcards (\u003Ccode>203.0.113.*\u003C\u002Fcode>) and CIDR ranges\u003Cbr \u002F>\n(\u003Ccode>203.0.113.0\u002F24\u003C\u002Fcode>), for both IPv4 and IPv6.\u003C\u002Fli>\n\u003Cli>Allow-list that always wins over any block rule.\u003C\u002Fli>\n\u003Cli>Crawler allow-list (Google, Bing, Yandex, and more) so blocking a country\u003Cbr \u002F>\nnever hurts your search visibility.\u003C\u002Fli>\n\u003Cli>Country redirects, including “keep the current path” (\u003Ccode>%PATH%\u003C\u002Fcode>) redirects.\u003C\u002Fli>\n\u003Cli>Language-prefix URL rewriting for multilingual sites (e.g. \u003Ccode>\u002Fen\u002F\u003C\u002Fcode> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>\u002Fit\u002F\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Logs and at-a-glance charts of blocked activity (24 hours \u002F 7 days \u002F 30 days).\u003C\u002Fli>\n\u003Cli>Fully customisable block screen with a live preview.\u003C\u002Fli>\n\u003Cli>Offline by design — privacy friendly, no tracking, no ads, no upsells.\u003C\u002Fli>\n\u003Cli>Optional MaxMind GeoLite2 auto-update with your own license key.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin can optionally connect to one external service, MaxMind, to update\u003Cbr \u002F>\nits bundled GeoIP database. It is used only for downloading database updates and\u003Cbr \u002F>\nis never contacted during normal visitor lookups.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>What it is and what it is used for: MaxMind GeoLite2 provides the\u003Cbr \u002F>\nIP-to-country database the plugin uses to detect a visitor’s country. The\u003Cbr \u002F>\nbundled copy works fully offline; this service is only used to download a newer\u003Cbr \u002F>\ncopy of that database when you choose to.\u003C\u002Fli>\n\u003Cli>What data is sent and when: a request is sent to\u003Cbr \u002F>\nhttps:\u002F\u002Fdownload.maxmind.com\u002Fapp\u002Fgeoip_download only when a site administrator\u003Cbr \u002F>\nhas entered a MaxMind license key and then either clicks “Update database now”\u003Cbr \u002F>\non the Settings tab or has enabled the weekly automatic update. The request\u003Cbr \u002F>\nincludes your MaxMind license key (so MaxMind can authorise the download) and,\u003Cbr \u002F>\nas with any HTTP request, your server’s IP address. No visitor data and no site\u003Cbr \u002F>\ncontent are ever sent. If you do not enter a license key, the plugin makes no\u003Cbr \u002F>\nexternal requests at all.\u003C\u002Fli>\n\u003Cli>Service provider: MaxMind, Inc.\u003Cbr \u002F>\nGeoLite2 End User License Agreement: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite2\u002Feula\u003Cbr \u002F>\nPrivacy Policy: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n","Block or allow WordPress visitors by country and IP, redirect by location, and log activity using an offline GeoIP database.",110,"2026-06-11T08:59:00.000Z","5.3",[17,89,19,90,21],"geo-redirect","ip-block","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcordonai-geo-access-and-redirect.1.1.0.zip",{"slug":93,"name":94,"version":95,"author":96,"author_profile":97,"description":98,"short_description":99,"active_installs":100,"downloaded":101,"rating":102,"num_ratings":103,"last_updated":104,"tested_up_to":105,"requires_at_least":106,"requires_php":15,"tags":107,"homepage":22,"download_link":110,"security_score":111,"vuln_count":31,"unpatched_count":11,"last_vuln_date":112,"fetched_at":26},"cf7-antispam","AntiSpam for Contact Form 7","0.7.6","Erik","https:\u002F\u002Fprofiles.wordpress.org\u002Fcodekraft\u002F","\u003Cp>Are you unsatisfied with your current antispam solution for Contact Form 7? It might be using an ineffective method to combat the specific type of bot attacks you’re facing. Fortunately, I have a solution for you!\u003Cbr \u002F>\nAntispam for Contact Form 7 is a simple yet highly effective plugin that protects your mailbox from bot flooding. Say goodbye to tedious configurations and captchas, which often lead to reduced conversions and inconvenience for genuine users. Our plugin utilizes a combination of on-page and off-page bot traps, along with an auto-learning mechanism powered by a statistical “Bayesian” spam filter called B8.\u003Cbr \u002F>\nCF7-AntiSpam seamlessly integrates with \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fflamingo\u002F\" rel=\"ugc\">Flamingo\u003C\u002Fa> and enhances its functionality. When both plugins are installed, Flamingo gains additional controls, and an extra dashboard widget is enabled.\u003C\u002Fp>\n\u003Ch3>SETUP\u003C\u002Fh3>\n\u003Cp>Basic – Install and go! No configuration, keys, or registrations are required to activate the antispam protection. In this case, some protections, such as fingerprinting, language checks, and honeypots, will be enabled.\u003Cbr \u002F>\nAdvanced – For CF7A to properly analyze the email content using its dictionary, it needs to parse the input message field of your form. To notify the antispam to check this field, you’ll need to add a “marker” to each contact form on your website. Simply add ‘flamingo_message: “[your-message]”‘ in the additional settings panel of each contact form you want to secure. This process follows the same method used with Flamingo. While this step may seem tedious, it is required for advanced text statistical analysis. Without it, the B8 filter cannot be enabled.\u003Cbr \u002F>\nGeoIP – (Optional) If you need to restrict which countries or languages can email you, you can enable this functionality. To enable GeoIP, you’ll need to agree to the GeoLite2 End User License Agreement and sign up for GeoLite2 Downloadable Databases. This will provide you with the required key to download the database. For detailed instructions, please refer to the dedicated section in the cf7-antispam plugin settings.\u003C\u002Fp>\n\u003Ch3>Antispam Available Tests\u003C\u002Fh3>\n\u003Cp>✅ Browser Fingerprinting\u003Cbr \u002F>\n✅ Language checks (Geo-ip, http headers and browser)\u003Cbr \u002F>\n✅ Honeypot\u003Cbr \u002F>\n️✅ Honeyform*\u003Cbr \u002F>\n✅ Domain Name System Blackhole List (DNSBL)\u003Cbr \u002F>\n✅ Blocklists (with automatic ban after N failed attempts, user defined ip exclusion list)\u003Cbr \u002F>\n✅ Hidden fields with encrypted unique hash\u003Cbr \u002F>\n✅ Time elapsed (with min\u002Fmax values)\u003Cbr \u002F>\n✅ Prohibited words in message\u002Femail and user agent\u003Cbr \u002F>\n✅ B8 statistical “Bayesian” spam filter\u003Cbr \u002F>\n✅ High Entropy \u002F Gibberish checks\u003Cbr \u002F>\n✅ Identity protection\u003Cbr \u002F>\n✅ Webmail protection\u003C\u002Fp>\n\u003Ch3>Extends Flamingo and turns it into a spam manager!\u003C\u002Fh3>\n\u003Cp>With this plugin, you can now review emails and train B8 to identify spam and legitimate messages. This feature proves useful, especially during the initial stages when some spam emails may slip through.\u003Cbr \u002F>\nAlready using Flamingo? Even better! Just remember to add ‘flamingo_message: “[your-message]”‘ to the advanced settings (similar to other Flamingo labels) before activating the plugin. Alternatively, you can explore the advanced options and select “rebuild dictionary.”\u003Cbr \u002F>\nUpon activating CF7A, all previously collected emails will be parsed, and B8 will learn and develop its vocabulary. This pre-trained algorithm gives you a head start. How cool is that?\u003Cbr \u002F>\nAdditional Notes:\u003Cbr \u002F>\n– A new column has been added to the right side of the Flamingo inbound page, displaying the level of spaminess for each email.\u003Cbr \u002F>\n– If you unban an email on the Flamingo “inbound” page, the corresponding IP will be removed from the blocklist. However, marking an email as spam will not blocklist the IP again.\u003Cbr \u002F>\n– Before activating this plugin, please make sure to mark all spam emails as spam in the Flamingo inbound section. This auto-training process will help the B8 algorithm.\u003Cbr \u002F>\n– If you receive a spam message, please avoid deleting it from the “ham” section. Instead, place it in the spam section to teach B8 how to differentiate between spam and legitimate messages.\u003C\u002Fp>\n\u003Ch3>B8 statistical “Bayesian” Filter\u003C\u002Fh3>\n\u003Cp>Originally created by \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGary_Robinson\" rel=\"nofollow ugc\">Gary Robinson\u003C\u002Fa> \u003Ca href=\"https:\u002F\u002Fwww.linuxjournal.com\u002Farticle\u002F6467\" rel=\"nofollow ugc\">b8 is a statistical “Bayesian”\u003C\u002Fa> spam filter implemented in PHP.\u003Cbr \u002F>\nThe B8 filter is a foundational example of \u003Cstrong>Machine Learning (ML)\u003C\u002Fstrong> for text classification, representing an early, yet powerful, statistical approach in Natural Language Processing (NLP). This approach precedes feature-weighting methods like \u003Cstrong>TF-IDF\u003C\u002Fstrong>, which in turn paved the way for modern deep learning architectures, such as \u003Cstrong>Transformers\u003C\u002Fstrong> and \u003Cstrong>GPT\u003C\u002Fstrong>.\u003Cbr \u002F>\nThe filter tells you whether a text is spam or not, using statistical text analysis. What it does is: you give b8 a text and it returns a value between 0 and 1, saying it’s ham when it’s near 0 and saying it’s spam when it’s near 1. See \u003Ca href=\"https:\u002F\u002Fnasauber.de\u002Fopensource\u002Fb8\u002Freadme.html#how-does-it-work\" rel=\"nofollow ugc\">How does it work?\u003C\u002Fa> for details about this.\u003Cbr \u002F>\nTo be able to distinguish spam and ham (non-spam), b8 first has to learn some spam and some ham texts. If it makes mistakes when classifying unknown texts or the result is not distinct enough, b8 can be told what the text actually is, getting better with each learned text.\u003Cbr \u002F>\nThis takes place on your own server without relying on third-party services.\u003Cbr \u002F>\nMore info: \u003Ca href=\"https:\u002F\u002Fnasauber.de\u002Fopensource\u002Fb8\u002F\" rel=\"nofollow ugc\">nasauber.de\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Identity protection\u003C\u002Fh3>\n\u003Cp>To fully protect the forms, it may be necessary to enable a couple of additional controls, because bots use the public data of the website to spam on it.\u003Cbr \u002F>\n– The first is user related and denies those who are not logged in the possibility of asking (sensitive) information about the user via wp-api and the protection for the xmlrpc exploit wordpress.\u003Cbr \u002F>\n– The second one is the WordPress protection that will obfuscate sensitive WordPress and server data, adding some headers in order to enhance security against xss and so on.\u003Cbr \u002F>\nWill be hidden the WordPress and WooCommerce version (wp_generator, woo_version), pingback (X-Pingback), server (nginx|apache|…) and php version (X-Powered-By), enabled xss protection headers (X-XSS-Protection), removes rest api link from header (but it will only continue to work if the link is not made public).\u003C\u002Fp>\n\u003Ch3>Mailbox Protection (Multiple Send)\u003C\u002Fh3>\n\u003Cp>Enhance email security by enabling the “Multiple Send” feature, which prevents consecutive email submissions to the user’s mailbox. This measure is effective in thwarting automated spam attempts and ensures a secure communication environment.\u003C\u002Fp>\n\u003Ch3>Security & Privacy: A Local-First Approach\u003C\u002Fh3>\n\u003Cp>AntiSpam for Contact Form 7 is built with your security and privacy as the \u003Cstrong>top priority\u003C\u002Fstrong>. Unlike many modern anti-spam solutions that rely on external cloud services or third-party subscriptions, our plugin is designed to run \u003Cstrong>entirely on your own WordPress installation\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>100% Local Processing:\u003C\u002Fstrong> All anti-spam logic, checks, and data processing are performed directly on your server. \u003Cstrong>No data is ever sent to, or stored by, any external third-party service\u003C\u002Fstrong> (including ours).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Not a Software as a Service (SaaS):\u003C\u002Fstrong> This plugin is a standalone, self-contained software solution, not an interface to a paid or subscription-based external service. Once installed, it works autonomously.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced Security:\u003C\u002Fstrong> Since there is \u003Cstrong>no central server or external API endpoint\u003C\u002Fstrong> to communicate with, your website is immune to potential risks associated with centralized services, such as Single Point of Failure or data breach risks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You retain complete control and ownership over the security of your Contact Form 7 submissions.\u003C\u002Fp>\n\u003Ch3>Privacy Notices\u003C\u002Fh3>\n\u003Cp>AntiSpam for Contact Form 7 only processes the IP but doesn’t store any personal data directly from the user input. However, it creates a dictionary of spam and ham (non-spam) words in the WordPress database.\u003Cbr \u002F>\nThis dictionary is built from words found in the submitted messages, meaning it \u003Cstrong>may contain words that were part of the user’s e-mail message or personal data\u003C\u002Fstrong>. This data is “degenerated,” which means the words might be normalized or altered before being stored.\u003Cbr \u002F>\nThe sole purpose of this word collecting is to build a dictionary used for local, decentralized spam detection.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Community support: via the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fcontact-form-7-antispam\u002F\" rel=\"ugc\">support forums\u003C\u002Fa> on wordpress.org\u003Cbr \u002F>\nBug reporting (preferred): file an issue on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ferikyo\u002Fcontact-form-7-antispam\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Contribute\u003C\u002Fh4>\n\u003Cp>We love your input! We want to make contributing to this project as easy and transparent as possible, whether it’s:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Reporting a bug\u003C\u002Fli>\n\u003Cli>Testing the plugin with different user agent and report fingerprinting failures\u003C\u002Fli>\n\u003Cli>Discussing the current state, features, improvements\u003C\u002Fli>\n\u003Cli>Submitting a fix or a new feature\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We use GitHub to host code, to track issues and feature requests, as well as accept pull requests.\u003Cbr \u002F>\nBy contributing, you agree that your contributions will be licensed under its GPLv2 License.\u003C\u002Fp>\n\u003Cp>My goal is to create an antispam that protects cf7 definitively without relying on external services. And free for everyone.\u003Cbr \u002F>\nif you want to help me, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ferikyo\u002Fcontact-form-7-antispam\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa> is the right place 😉\u003C\u002Fp>\n\u003Ch3>copyright\u003C\u002Fh3>\n\u003Cp>AntiSpam for Contact Form 7, Copyright 2021 Codekraft Studio\u003Cbr \u002F>\nAntiSpam for Contact Form 7 is distributed under the terms of the GNU GPL\u003C\u002Fp>\n\u003Cp>This program is free software: you can redistribute it and\u002For modify\u003Cbr \u002F>\nit under the terms of the GNU General Public License as published by\u003Cbr \u002F>\nthe Free Software Foundation, either version 3 of the License, or\u003Cbr \u002F>\n(at your option) any later version.\u003C\u002Fp>\n\u003Cp>This program is distributed in the hope that it will be useful,\u003Cbr \u002F>\nbut WITHOUT ANY WARRANTY; without even the implied warranty of\u003Cbr \u002F>\nMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\u003Cbr \u002F>\nSee the LICENSE file for more details.\u003C\u002Fp>\n\u003Ch4>Resources\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Contact Form 7 and Flamingo © 2021 Takayuki Miyoshi,\u003Ca href=\"https:\u002F\u002Fit.wordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"nofollow ugc\">LGPLv3 or later\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>B8 https:\u002F\u002Fnasauber.de\u002Fopensource\u002Fb8\u002F, © 2021 Tobias Leupold, \u003Ca href=\"https:\u002F\u002Fgitlab.com\u002Fl3u\u002Fb8\u002F-\u002Ftree\u002Fab26daa6b293e6aa059d24ce7cf77af6c8b9b052\u002FLICENSES\" rel=\"nofollow ugc\">LGPLv3 or later\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>GeoLite2 \u003Ca href=\"https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite2\u002Feula\" rel=\"nofollow ugc\">license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>GeoIP2 PHP API \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fmaxmind\u002FGeoIP2-php\" rel=\"nofollow ugc\">GeoIP2-php\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>chart.js https:\u002F\u002Fwww.chartjs.org\u002F, © 2021 Chart.js \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fchartjs\u002FChart.js\u002Fgraphs\u002Fcontributors\" rel=\"nofollow ugc\">contributors\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fchartjs\u002FChart.js\u002Fblob\u002Fmaster\u002FLICENSE.md\" rel=\"nofollow ugc\">MIT\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Sudden Shower in the Summer, Public domain, Wikimedia Commons https:\u002F\u002Fcommons.wikimedia.org\u002Fwiki\u002FFile:Sudden_Shower_in_the_Summer_(5759500422).jpg\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contibutions\u003C\u002Fh3>\n\u003Cp>Mirek Długosz – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ferikyo\u002Fcf7-antispam\u002Fpull\u002F30\" rel=\"nofollow ugc\">#30\u003C\u002Fa> fixes a crash that occurred when analysing flamingo metadata\u003Cbr \u002F>\nMeliEve – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-blocks\u002Fcf7-antispam\u002Fpull\u002F42\" rel=\"nofollow ugc\">#42\u003C\u002Fa> Fix “internal_server_error” when message is empty\u003Cbr \u002F>\nMeliEve – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-blocks\u002Fcf7-antispam\u002Fpull\u002F61\" rel=\"nofollow ugc\">#61\u003C\u002Fa>  Handle deferrer script loading\u003Cbr \u002F>\nZodiac1978 – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-blocks\u002Fcf7-antispam\u002Fpull\u002F67\" rel=\"nofollow ugc\">#67\u003C\u002Fa> Remove warning for unsafe email configuration w\u002Fo protection\u003Cbr \u002F>\nJohnHooks – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-blocks\u002Fcf7-antispam\u002Fpull\u002F61\" rel=\"nofollow ugc\">#66\u003C\u002Fa> Readme + plugin env\u003Cbr \u002F>\nsdellenb – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-blocks\u002Fcf7-antispam\u002Fpull\u002F163\" rel=\"nofollow ugc\">#66\u003C\u002Fa> Fix $reason parameter for calling cf7a_ban_by_ip\u003C\u002Fp>\n\u003Ch3>Special thanks\u003C\u002Fh3>\n\u003Cp>This project is tested with BrowserStack. \u003Ca href=\"https:\u002F\u002Fwww.browserstack.com\u002F\" rel=\"nofollow ugc\">Browserstack\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>MaxMind GeoIP2\u003C\u002Fh3>\n\u003Cp>This plugin on demand can enable GeoLite2 created by MaxMind, available from \u003Ca href=\"https:\u002F\u002Fwww.maxmind.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.maxmind.com\u003C\u002Fa>\u003Cbr \u002F>\nWhile enabled you may \u003Cstrong>have to mention it in the privacy policy\u003C\u002Fstrong> of your site, depending on the law regulating privacy in your state!\u003Cbr \u002F>\n* GeoIP2 databases \u003Ca href=\"https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Faccounts\u002Fcurrent\u002Fgeoip\u002Fdownloads\" rel=\"nofollow ugc\">GeoLite2 Country\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>DNSBL servers privacy policies\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>dnsbl-1.uceprotect.net \u003Ca href=\"http:\u002F\u002Fwww.uceprotect.net\u002Fen\u002Findex.php?m=13&s=0\" rel=\"nofollow ugc\">www.uceprotect.net license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>dnsbl-2.uceprotect.net \u003Ca href=\"http:\u002F\u002Fwww.uceprotect.net\u002Fen\u002Findex.php?m=13&s=0\" rel=\"nofollow ugc\">www.uceprotect.net license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>dnsbl-3.uceprotect.net \u003Ca href=\"http:\u002F\u002Fwww.uceprotect.net\u002Fen\u002Findex.php?m=13&s=0\" rel=\"nofollow ugc\">www.uceprotect.net license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>dnsbl.sorbs.net \u003Ca href=\"http:\u002F\u002Fwww.sorbs.net\u002Finformation\u002Ffaq\u002F\" rel=\"nofollow ugc\">sorbs.net license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>zen.spamhaus.org \u003Ca href=\"https:\u002F\u002Fwww.spamhaus.org\u002Forganization\u002Fdnsblusage\u002F\" rel=\"nofollow ugc\">spamhaus.org license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>bl.spamcop.net \u003Ca href=\"https:\u002F\u002Fwww.spamcop.net\u002Ffom-serve\u002Fcache\u002F297.html\" rel=\"nofollow ugc\">spamcop.net license\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>b.barracudacentral.org \u003Ca href=\"https:\u002F\u002Fwww.barracuda.com\u002Fcompany\u002Flegal\u002Ftrust-center\u002Fdata-privacy\u002Fprivacy-policy\" rel=\"nofollow ugc\">barracudacentral.org privacy-policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>dnsbl.dronebl.org \u003Ca href=\"https:\u002F\u002Fdronebl.org\u002Fdocs\u002Ffaq\" rel=\"nofollow ugc\">dronebl.org\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>all.spamrats.com \u003Ca href=\"https:\u002F\u002Fspamrats.com\u002Ftos.php\" rel=\"nofollow ugc\">spamrats.com tos\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>bl.ipv6.spameatingmonkey.net \u003Ca href=\"https:\u002F\u002Fspameatingmonkey.com\u002Ffaq\" rel=\"nofollow ugc\">spameatingmonkey.net\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Inspirations, links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Nikolai Tschacher \u003Ca href=\"https:\u002F\u002Fincolumitas.com\u002Fpages\u002FBotOrNot\u002F\" rel=\"nofollow ugc\">incolumitas.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Antoine Vastel \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fantoinevastel\u002Ffpscanner\" rel=\"nofollow ugc\">fp-scanner\u003C\u002Fa>\u002F\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fantoinevastel\u002Ffp-collect\" rel=\"nofollow ugc\">fp-collect\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Niespodd \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fniespodd\u002Fbrowser-fingerprinting\" rel=\"nofollow ugc\">niespodd\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Thomas Breuss \u003Ca href=\"https:\u002F\u002Fgist.github.com\u002Ftbreuss\u002F74da96ff5f976ce770e6628badbd7dfc\" rel=\"nofollow ugc\">tbreuss\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Domain Name System-based blackhole list \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FDomain_Name_System-based_blackhole_list\" rel=\"nofollow ugc\">wiki\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>dnsbl list \u003Ca href=\"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FComparison_of_DNS_blacklists\" rel=\"nofollow ugc\">wiki\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","A trustworthy antispam plugin for Contact Form 7. Wave goodbye to spam and keep your inbox clean!",10000,101818,84,12,"2026-04-21T00:02:00.000Z","6.9.5","6.2",[108,19,109,21],"antispam","honeypot","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcf7-antispam.0.7.6.zip",99,"2025-07-16 00:00:00",{"slug":114,"name":115,"version":116,"author":117,"author_profile":118,"description":119,"short_description":120,"active_installs":121,"downloaded":122,"rating":24,"num_ratings":123,"last_updated":124,"tested_up_to":105,"requires_at_least":70,"requires_php":71,"tags":125,"homepage":129,"download_link":130,"security_score":111,"vuln_count":47,"unpatched_count":11,"last_vuln_date":131,"fetched_at":26},"advanced-country-blocker","Advanced Country Blocker","2.3.2","brstefanovic","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrstefanovic\u002F","\u003Cp>\u003Cstrong>Advanced Country Blocker\u003C\u002Fstrong> helps you secure your WordPress site by restricting access based on the visitor’s geolocation (country) or IP address. Upon activation, the plugin detects the activating admin’s country and automatically sets that as the only allowed country. All other visitors from different countries are blocked, unless they use a secret key parameter to temporarily whitelist their IP. Country detection uses the privacy-friendly ip-api.com service by default but can be switched to a fully offline MaxMind GeoLite2 (or compatible) database file once you configure a local copy.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatically allows the admin’s country\u003C\u002Fstrong> on plugin activation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible IP-to-country lookups\u003C\u002Fstrong> – start with the built-in ip-api.com integration and optionally switch to an offline MaxMind GeoLite2 Country (or compatible) \u003Ccode>.mmdb\u003C\u002Fcode> database file.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowlist or blacklist mode\u003C\u002Fstrong> – choose whether the country list acts as an allowlist or blocklist without re-entering countries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary access\u003C\u002Fstrong> via a customizable secret URL parameter (e.g., \u003Ccode>?MySecretKey=1\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CAPTCHA Challenge\u003C\u002Fstrong> – allow blocked visitors to solve a CAPTCHA to gain temporary access (supports Google reCAPTCHA v2\u002Fv3, hCaptcha, Cloudflare Turnstile).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Activity Monitor\u003C\u002Fstrong> – live dashboard showing active visitors, recent blocks, and traffic statistics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Analytics Dashboard\u003C\u002Fstrong> – comprehensive charts and statistics about blocked attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manual blacklisting and safelisting of IPs\u003C\u002Fstrong> for added security and to accommodate uptime monitors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional email alerts\u003C\u002Fstrong> when new visitors are blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin bypass\u003C\u002Fstrong> so logged-in admins can always access the site (toggleable in the code).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detailed logging\u003C\u002Fstrong> of blocked attempts in a custom database table, displayed in the WP admin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom response controls\u003C\u002Fstrong> – personalise the block page title\u002Fmessage, choose the HTTP status (403, 410, 451) or redirect to any URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic log cleanup\u003C\u002Fstrong> with configurable retention plus a one-click “Clear Logs” button.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Use the plugin settings page (\u003Cstrong>Country Blocker\u003C\u002Fstrong> menu in WP admin) to configure the list of allowed countries, blacklisted countries, blacklisted IPs, and whether email alerts are enabled.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is open-sourced software licensed under the \u003Ca href=\"https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-3.0.html\" rel=\"nofollow ugc\">GPLv3 or later\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>By default this plugin contacts the ip-api.com geolocation service to detect visitor countries. You can disable all external lookups by switching the IP lookup method to the local MaxMind database in the settings.\u003C\u002Fp>\n","An advanced security plugin that blocks website visitors by country, with additional features like blacklisting, logging blocked attempts, admin bypas &hellip;",2000,14219,6,"2026-02-06T09:04:00.000Z",[126,127,128,20,21],"blocking","country","geolocation","https:\u002F\u002Fsparkcan.com\u002Facb.html","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-country-blocker.2.3.2.zip","2026-02-06 20:24:09",{"error":133,"url":134,"statusCode":135,"statusMessage":136,"message":136},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsmart-country-blocker\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":47,"versions":138},[139],{"version":6,"download_url":23,"svn_tag_url":140,"released_at":25,"has_diff":141,"diff_files_changed":142,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":143,"is_current":133},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsmart-country-blocker\u002Ftags\u002F1.0.4\u002F",false,[],[]]