Linux 软件免费装

Country Access Control by CodeCaste

开发者 codecaste
更新时间 2026年9月29日 22:14
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security country geolocation access control geo blocking

下载

1.0.1

详情介绍:

The issue we kept running into On client sites, “block visitors from these countries” sounds simple — until you look at how most tools do it. Many geolocation plugins phone home on every request, or they lean on a third-party lookup API. That means extra latency, another service in the critical path, and a privacy story that is harder to explain to a client. We also saw the other failure mode: the rule looks correct in settings, but a full-page cache (LiteSpeed, WP Rocket, Cloudflare HTML cache, host caching) keeps serving a previously allowed page to someone who should be blocked — or the reverse. What we think about it Country access control has to be local-first. The decision for a visitor should happen on your server, against data you control, without a round trip to an external API on every page view. And because the response depends on who is visiting, page caching cannot treat every visitor as if they got the same HTML. If your cache layer ignores that, geo rules will look broken even when the plugin logic is fine. Why we built this Country Access Control (the product we also call Geo Lockdown) is our answer for WordPress shops that need country allow/block rules without shipping visitor IPs to a lookup API at runtime. Lookups run against IP range data stored in your site’s MySQL/MariaDB tables. You choose when to refresh that data. Admin, login, and common WordPress endpoints stay reachable so you do not lock yourself out while testing. What you get How to use it
  1. Install and activate the plugin.
  2. Go to Settings → Country Access Control.
  3. Open the Diagnostics panel and confirm the detected IP looks right (especially if you use Cloudflare or another proxy).
  4. Click Download Latest Database so you are not relying on the limited starter dataset in production.
  5. Choose Allow or Block mode, select the countries, set the blocked response, then enable Country Access Control.
  6. Save settings, then purge your site/page cache (see below) and test from a real visitor perspective — private/incognito while logged out is the easiest check.
Things to take care of (please read this) 1. Download a full GeoIP database before you trust the results The plugin ships with a small starter dataset so it activates cleanly. That is enough to explore settings — not enough for production accuracy. Use Download Latest Database under the GeoIP Database panel. Nothing about your site or visitors is sent; only the public CSV file is fetched when an administrator clicks the button. 2. Page caching and CDNs When Country Access Control is enabled, the plugin marks front-end responses as non-cacheable for common cache plugins (including LiteSpeed Cache, WP Rocket, and WP Super Cache style APIs) and purges those caches when you save settings. That still does not cover every stack. If your host, CDN, or another plugin caches full HTML at the edge, you can get stale allow/block decisions until that cache is cleared or told not to cache HTML for the public site. After you enable the plugin or change countries / response settings: If rules still look wrong after a purge, open Diagnostics, run a Test IP, and confirm the detected IP / country before digging into theme or security-plugin conflicts. 3. Proxies, Cloudflare, and real visitor IPs If the site sits behind Cloudflare or another reverse proxy, enable Cloudflare support and/or configure trusted proxies and the correct connecting-IP header. Otherwise the plugin may see the proxy IP instead of the visitor, and country decisions will be wrong. 4. Do not test blocks while logged in as an administrator Administrator bypass is on by default (and wp-admin / wp-login are always bypassed). Turn administrator bypass off only while testing, and use a private window while logged out. 5. Honest limitation This is IP-to-country mapping, not a GPS check. VPNs, proxies, Tor, and similar tools can present an IP from another country. No IP-only system can guarantee a person’s physical location.

安装:

  1. Upload the codecaste-country-access-control folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu
  3. Go to Settings → Country Access Control
  4. Download the latest GeoIP database, choose Allow or Block mode, select countries, then enable Country Access Control
  5. Purge your page/CDN cache and verify with Diagnostics / a logged-out browser session

屏幕截图:

  • General — enable Country Access Control, choose allow/block mode, select countries, and set the blocked visitor response
  • Safety and Bypass — administrator bypass, Cloudflare support, system bypasses, Googlebot verification, and trusted proxies
  • Performance and Logging — Cache TTL, blocked-request logging, and log retention
  • Diagnostics — current IP, detected country, lookup timing, final decision, and Test IP tool
  • GeoIP Database — download the latest free DB-IP Country Lite dataset and clear the lookup cache

常见问题:

Does this plugin call an external API for every visitor?

No. Country lookups run against your local MySQL/MariaDB data. The only documented external connection is the optional, administrator-triggered DB-IP database download.

Will page caching break country blocking?

It can, if a full-page or CDN cache serves the same HTML to every visitor. The plugin asks common WordPress cache plugins not to store those responses and purges them when settings change — but you should still purge host/CDN caches after enabling or changing rules. See “Things to take care of” above.

Does this require the PHP SQLite extension?

No. GeoIP data is stored in MySQL/MariaDB tables, which every WordPress site already uses.

Can I update the IP database?

Yes. Click Download Latest Database under Settings → Country Access Control to fetch the current free DB-IP Country Lite CSV.

Will I lock myself out of wp-admin?

No. wp-admin and wp-login.php are always bypassed. Logged-in administrators can also bypass restrictions by default.

Will Googlebot be blocked outside the allowed countries?

Not when Allow verified Googlebot is enabled (default). Crawlers are verified by reverse DNS hostname and forward confirmation back to the same IP. A spoofed Googlebot User-Agent alone does not bypass the geo block.

Does it support Cloudflare or reverse proxies?

Yes. Trusted proxy/CDN headers can be configured, and Cloudflare source ranges are validated before those headers are trusted.

更新日志:

1.0.1 1.0.0