DevDome Country Blocker is a geo blocker for WordPress with country block and allow lists. Block visitors by country or allow only listed countries, subject to your safety exemptions. Blocked visitors get a 403 page with your text or a redirect to another website.
Geo blocking uses verified Cloudflare country headers or the free local DB-IP country database for GeoIP detection. The local database supports IPv4 and IPv6, with automatic monthly refresh. Country detection runs on your server without external lookup requests during visits.
Before you geoblock visitors, use Test Mode to let everyone through and log requests that would be blocked. You can restrict by country while keeping individual IPv4 and IPv6 addresses or CIDR ranges exempt through Always Allowed Addresses. wp-admin is never blocked, and visitors whose country is unknown are always allowed.
How It Knows the Country
- Cloudflare: reads the country header only after checking that the connecting address belongs to a Cloudflare edge range.
- Local database: download the free DB-IP country database with one click in Settings. It supports IPv4 and IPv6. Lookups run on your server, with automatic monthly refresh through a daily scheduled check.
- CloudFront or Vercel: reads their country header only after you turn on Proxy Headers. Use it only when the site really runs behind one of them.
- Your own proxy or load balancer: enter its addresses under Trusted Proxies. The plugin reads X-Forwarded-For only when the connection comes from a listed proxy.
Try Before You Block
Turn on Test Mode to let everyone through and log requests that would be blocked. Test hits are marked "Test" and do not increase blocked totals.
Your Connection on the Overview shows your country, detection source, installed database month and address.
Keep Access to Your Site
- wp-admin is never blocked.
- Login blocking is optional. A settings save is refused if it would block the saving visitor's detected country from the login page without an allowed address.
- Logged-in users are exempt from front-end blocking by default.
- Always Allowed Addresses accepts individual addresses and CIDR ranges, for IPv4 and IPv6.
- Unknown countries are always allowed.
- Add
define('DEVDCOUN_DISABLE', true); to wp-config.php to switch all blocking off.
Optional Login and XML-RPC Blocking
Apply your country rules to wp-login.php and xmlrpc.php with separate settings. Both are off by default. Always Allowed Addresses still applies. Logged-in and crawler exemptions do not apply to these endpoints.
Search Engines and Health Checks
One checkbox exempts Google, Bing, DuckDuckGo and Apple crawlers, plus the DevDome health monitor, from front-end blocking. It matches their user-agent strings.
Review Blocked Visits
Overview tiles show blocked requests today, over 7 and 30 days, and the number of listed countries. Top Blocked Countries shows counts over 30 days.
The log keeps about the last 200 hits, including Test Mode hits. It shows time, country, result, anonymized address, path without its query string, and user agent.
Use Refresh Now to recalculate the totals. Clear Statistics removes every counter and logged hit after you type CLEAR.
Limits
Blocking applies only to requests that reach WordPress. A full-page cache or CDN can serve a cached page before the plugin runs.
admin-ajax.php and REST API requests are not blocked. The user-agent exemption can be faked. On multisite, each site has separate settings, country lists and statistics, so set up each site separately.
AI Agents and MCP
On WordPress 6.9+, the plugin registers 8 abilities: get-status, get-settings, update-settings, get-statistics, lookup-country, update-database, refresh-summary and clear-statistics. Compatible agents and MCP clients can use them through the WordPress MCP Adapter. Every ability requires the plugin capability, manage_options by default. Older WordPress versions register none.
Agents must pass
confirm: true after the owner agrees to:
- Download or update the database, or clear statistics.
- Enable login or XML-RPC blocking.
- Change who is blocked when either the current or proposed mode is not Off and its country list is nonempty. This includes mode, active country list, Test Mode, login/XML-RPC settings, logged-in or crawler exemptions, proxy settings and allowed addresses. Changes that reduce blocking also need confirmation.
This settings rule applies even in Test Mode. Changing only the message, redirect or response action does not require confirmation. Agent output never carries full visitor addresses, email addresses or server paths.
1.0.4
- Listing text updated: title, short description, tags and introduction.
- The admin page is printed without an output buffer and the Report this error button goes through wp_kses.
- Shared DevDome library 1.7.10: the one-time Report a bug hint is recorded through a nonce-checked request instead of on a page view, and the DevDome dashboard prints its icons through wp_kses.
1.0.3
- Removed the shared library update helper. The plugin no longer hooks the WordPress updater; updates come only from WordPress.org.
1.0.2
Database download: the gzip trailer (checksum and length) is verified, so a download cut off mid-stream can never replace the working database. Build lock: a stale lock is taken over and released only by its owner. Abilities: get-status reports active only when visitors are actually blocked and adds test_mode and disabled_by_constant; update-settings refuses a redirect to this site instead of silently clearing the stored one; get-settings returns the allow list, trusted proxies and redirect URL exactly as stored; clear-statistics reports when the cached totals could not be recomputed. Proxy country headers: XX and T1 count as unknown, as with Cloudflare.
1.0.1
Plugin name and plugin links corrected.
1.0.0
First release. Includes country block and allow lists, verified Cloudflare headers, a local IPv4 and IPv6 database with monthly refresh, trusted proxies, a custom 403 message or redirect, Test Mode, access safeguards, optional login and XML-RPC blocking, statistics, an anonymized hit log, 8 WordPress Abilities and the shared DevDome core 1.7.6 (DevDome Tools dashboard, optional account connection, Report this error).