Linux 软件免费装
Banner图

DevDome Country Blocker: Geo Blocking, GeoIP Block

开发者 devdome
更新时间 2026年10月2日 06:48
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

geo blocking country blocker geo blocker geoip block whitelist country

下载

1.0.3 1.0.4

详情介绍:

DevDome Country Blocker is a geo blocker for WordPress with country block and allow lists. Block visitors by country or allow only listed countries, subject to your safety exemptions. Blocked visitors get a 403 page with your text or a redirect to another website. Geo blocking uses verified Cloudflare country headers or the free local DB-IP country database for GeoIP detection. The local database supports IPv4 and IPv6, with automatic monthly refresh. Country detection runs on your server without external lookup requests during visits. Before you geoblock visitors, use Test Mode to let everyone through and log requests that would be blocked. You can restrict by country while keeping individual IPv4 and IPv6 addresses or CIDR ranges exempt through Always Allowed Addresses. wp-admin is never blocked, and visitors whose country is unknown are always allowed. How It Knows the Country Try Before You Block Turn on Test Mode to let everyone through and log requests that would be blocked. Test hits are marked "Test" and do not increase blocked totals. Your Connection on the Overview shows your country, detection source, installed database month and address. Keep Access to Your Site Optional Login and XML-RPC Blocking Apply your country rules to wp-login.php and xmlrpc.php with separate settings. Both are off by default. Always Allowed Addresses still applies. Logged-in and crawler exemptions do not apply to these endpoints. Search Engines and Health Checks One checkbox exempts Google, Bing, DuckDuckGo and Apple crawlers, plus the DevDome health monitor, from front-end blocking. It matches their user-agent strings. Review Blocked Visits Overview tiles show blocked requests today, over 7 and 30 days, and the number of listed countries. Top Blocked Countries shows counts over 30 days. The log keeps about the last 200 hits, including Test Mode hits. It shows time, country, result, anonymized address, path without its query string, and user agent. Use Refresh Now to recalculate the totals. Clear Statistics removes every counter and logged hit after you type CLEAR. Limits Blocking applies only to requests that reach WordPress. A full-page cache or CDN can serve a cached page before the plugin runs. admin-ajax.php and REST API requests are not blocked. The user-agent exemption can be faked. On multisite, each site has separate settings, country lists and statistics, so set up each site separately. AI Agents and MCP On WordPress 6.9+, the plugin registers 8 abilities: get-status, get-settings, update-settings, get-statistics, lookup-country, update-database, refresh-summary and clear-statistics. Compatible agents and MCP clients can use them through the WordPress MCP Adapter. Every ability requires the plugin capability, manage_options by default. Older WordPress versions register none. Agents must pass confirm: true after the owner agrees to: This settings rule applies even in Test Mode. Changing only the message, redirect or response action does not require confirmation. Agent output never carries full visitor addresses, email addresses or server paths.

安装:

  1. Upload and activate the plugin.
  2. Open DevDome > Country Blocker.
  3. If using local country detection, click Download Database in Settings.
  4. Check Your Connection. Add your own reverse proxy under Trusted Proxies if needed.
  5. Choose a mode, add countries and enable Test Mode. Click Save Settings.
  6. Review the test hits. Turn Test Mode off and save when ready to block.

屏幕截图:

  • Settings: blocking modes, the searchable country picker and the blocked visitor response.
  • Safety settings: logged-in and crawler exemptions, proxy settings and Always Allowed Addresses.
  • The 403 page: a plain page displaying your message to blocked visitors.

常见问题:

Is anything paid?

The plugin's features and local DB-IP Lite database are free. No account or licence key is required for country blocking.

Can I lock myself out?

wp-admin is never blocked. The save check refuses login rules that would block your current detected country unless your address is allowed. A later change of address or country can still affect login access. Add your address to Always Allowed Addresses, or use define('DEVDCOUN_DISABLE', true); in wp-config.php to recover.

Does it slow my site down?

Country detection checks headers or searches local database files. It makes no external lookup request during a visit. Blocked hits write a counter and log entry, with occasional log cleanup. Test Mode writes log entries without blocked counters. These operations use server resources.

Why does the Overview say blocking is inactive?

The "No country source" warning means no usable country source is available. Install the local database or check your Cloudflare setup. Without a country, visitors are allowed. Off mode, an empty active list and Test Mode also block nobody.

My site is behind Nginx, Varnish or a load balancer, does it work?

Yes. List your proxy's addresses or ranges under Trusted Proxies and have it supply X-Forwarded-For. Install the local database for address lookups. Your Connection shows the address the plugin sees. Cloudflare needs no Trusted Proxies entry.

Does it work with a caching plugin or a CDN?

Only requests reaching WordPress are checked. Cached pages served before WordPress runs bypass the plugin. Configure country rules at the cache, CDN or firewall when those responses also need blocking.

Does it block the login page and XML-RPC?

Only when you enable their separate settings. Both are off by default. Allowed addresses still get through, but logged-in and crawler exemptions do not apply there.

Does it block WooCommerce checkout or REST API calls?

A checkout page can be blocked like other front-end pages. REST API and admin-ajax.php requests are exempt. The plugin does not provide a separate WooCommerce checkout rule.

Does it work on multisite?

Yes. Each site keeps its own settings, country lists, database and statistics. Configure each site separately.

What happens to a visitor whose country is unknown?

They are always allowed, including in allow-only mode.

How do I test my list before it blocks anyone?

Choose your mode and countries, enable Test Mode and save. Review Recent Blocked Hits for rows marked "Test". Exempt visitors do not produce test hits. Turn Test Mode off and save to enforce the list.

Does it block at the CDN edge?

No. It runs inside WordPress. Edge blocking needs a rule at your CDN or firewall.

What is removed on uninstall?

Deleting the plugin removes its statistics tables, settings, cached summary, database metadata, build lock, scheduled tasks and downloaded database files. Cleanup runs for every site on multisite. Unrelated files in the database folder are left alone. Shared DevDome library data is kept while another installed DevDome plugin needs it. Deactivation keeps the plugin's data and removes its schedules.

更新日志:

1.0.4 1.0.3 1.0.2 Database download: the gzip trailer (checksum and length) is verified, so a download cut off mid-stream can never replace the working database. Build lock: a stale lock is taken over and released only by its owner. Abilities: get-status reports active only when visitors are actually blocked and adds test_mode and disabled_by_constant; update-settings refuses a redirect to this site instead of silently clearing the stored one; get-settings returns the allow list, trusted proxies and redirect URL exactly as stored; clear-statistics reports when the cached totals could not be recomputed. Proxy country headers: XX and T1 count as unknown, as with Cloudflare. 1.0.1 Plugin name and plugin links corrected. 1.0.0 First release. Includes country block and allow lists, verified Cloudflare headers, a local IPv4 and IPv6 database with monthly refresh, trusted proxies, a custom 403 message or redirect, Test Mode, access safeguards, optional login and XML-RPC blocking, statistics, an anonymized hit log, 8 WordPress Abilities and the shared DevDome core 1.7.6 (DevDome Tools dashboard, optional account connection, Report this error).