Country & Threat-Intel Blocking

Every claim checked against a real site

COUNTRY BLOCKING, ALONGSIDE THREAT-INTEL BLOCKLISTS

Country Blocking and Threat Intelligence: Block by Geography, Block by Reputation

Most attacks against a WordPress site don’t come from somewhere you do business, and a huge share of them come from IPs already known to be malicious, hijacked networks, bulletproof hosting, scanners with a history. Country blocking stops traffic from anywhere you don’t need it, free, forever, no account or API key required. Threat-intel blocklists go further, fetched daily from real, independently maintained security research, matched locally against every visitor before they ever reach your site.

Key Features

Country Blocking

Block or allow by country across 166 countries, both IPv4 and IPv6, run as a blacklist or a whitelist depending on where your actual visitors come from. No account, no API key, no third party involved, matched entirely against local data downloaded and refreshed automatically. Free, permanently, not a limited trial of the full feature.

Threat-Intel Blocklists

Four real, independently maintained sources, IPsum with an adjustable confidence threshold, FireHOL level1, Spamhaus DROP and EDROP, and blocklist.de, each one fetched fresh daily and matched entirely on your own server. These aren't invented lists, they're the same data real security researchers and sysadmins already rely on.

Datacentre & Cloud IP Blocking

A huge share of automated attack traffic comes from cloud and datacenter infrastructure, not home broadband. This blocks known datacenter and cloud IP ranges as part of the same local matching system, catching traffic that pure country blocking alone would miss.

Proxy/CDN Header Support

Off by default, and deliberately so. Only your server's real connecting IP is trusted unless you explicitly enable and select a proxy header, like Cloudflare's CF-Connecting-IP. Trusting the wrong header by default is a real, documented way blocking gets bypassed entirely, so this stays opt-in.

Verified Crawler Exemption

Googlebot, Bingbot, Applebot, DuckDuckBot, YandexBot, and Meta's link-preview fetcher are confirmed through DNS and network-ownership checks, not by trusting whatever name a request claims to have, then exempted from every block automatically. Search visibility and shared link previews keep working exactly as they should.

Cross-Site List Sharing

Export your deny list and any IPs the canary trap has caught as a plain JSON file, import it straight into another site you manage. No account, no central server holding your data, just a file you control.
logo-big-white
Need 24/7 Protection From Cyber Attacks?
Scroll to top