| 开发者 | greyscalezone |
|---|---|
| 更新时间 | 2026年7月19日 05:33 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
ip.src in $wordfence_hot_blocklist
The recommended list name is:
wordfence_hot_blocklist
Current and historical Wordfence blocks
The plugin can synchronise:
blocked:waf.admin.example.com
Do not enter a URL, path or port.
Grey Rock does not create or update DNS records. It also does not provide a DDNS service or require DNS editing permission.
If Cloudflare hosts the DDNS record, configure the dedicated hostname
as DNS only. A proxied hostname returns Cloudflare proxy addresses
instead of the administrator's actual public address.
Grey Rock resolves public A and AAAA records. Private, loopback,
link-local, reserved and invalid addresses are rejected. Multiple valid
public results are displayed and handled separately.
Configuration procedure:
/64 and does not create inferred
CIDR allow-list entries.
In multisite, Network Admin may provide one shared DDNS hostname for
all inheriting sites. Site-specific configurations may use a separate
hostname.
A DNS-only DDNS hostname exposes its current public address through
DNS. Use a dedicated non-web hostname and consider that disclosure
before enabling the feature.
Scheduling
Grey Rock supports three scheduling methods:
wp --path=/var/www/html grey-rock-block-synchroniser-for-wordfence-and-cloudflare sync-site --due
A multisite network can use:
wp --path=/var/www/html grey-rock-block-synchroniser-for-wordfence-and-cloudflare sync-network --due
sync-network processes only sites inheriting Network Admin settings. A selected multisite site can use sync-site with WP-CLI's --url parameter.
An external scheduler may check every minute. The --due command reads the GUI interval and exits successfully without synchronizing when the interval has not elapsed or External scheduler is not selected.
The GUI buttons and --force commands run immediately regardless of scheduling method or interval. Every attempt, including a manual or failed attempt, resets the due interval.
A site-level atomic lock prevents overlapping synchronization. An abandoned lock becomes stale after 15 minutes.
Selecting External scheduler or Manual synchronization only removes only Grey Rock's synchronization event. It does not disable WordPress cron globally.
Cleanup is separate maintenance and remains scheduled hourly in all three modes.
Complete systemd, traditional cron, hosting control-panel and optional Docker Compose examples are provided in the GitHub README.
Multisite support
When network activated:
wordfence_hot_blocklist.ip.src in $wordfence_hot_blocklist.No. The existing DDNS provider remains responsible for updating DNS. Grey Rock only reads the hostname's public A and AAAA results.
A proxied hostname returns Cloudflare proxy addresses. Grey Rock needs the administrator's actual public address, so the dedicated DDNS hostname must be DNS only.
Saving the settings performs the DNS lookup. Removal occurs during the next synchronisation. The address is also excluded from future current and historical Wordfence candidates.
The last successful public addresses remain trusted for up to 24 hours. After that grace period, no stored address remains effective until a lookup succeeds.
A successful lookup replaces the previous address set. The new exact addresses become trusted and the old addresses are no longer included in the administrator allow list.
No. Each resolved IPv6 address remains an exact individual address.
No. Use a restricted Cloudflare API token.
No. Create a Cloudflare Custom Rule with the Block action in every zone that should use the list.
Yes. Account IP List mode can maintain one reusable account-level list. Each Cloudflare zone must have a Custom Rule that references the list.
Yes. It reads qualifying Wordfence WAF events recorded as blocked:waf within the configured lookback period.
1, 3, 6, 12 and 24 hours.
Yes. The historical block threshold accepts whole numbers from 1 through 100.
The plugin continues using historical Wordfence WAF events instead of terminating synchronisation.
Yes. It supports shared Network Admin settings, optional site-specific overrides, network synchronisation for inheriting sites and a combined Network Admin synchronisation log.
An inheriting site may share a Cloudflare destination with other sites. Its local log cannot determine whether another site still requires the same Cloudflare entry.
Not necessarily when WordPress WP-Cron is selected. WP-Cron is request-driven and may run late. Use External scheduler with a reliable system scheduler when timing must not depend on WordPress traffic.
No. The plugin provides ordinary WP-CLI commands. Docker Compose is only an optional deployment-specific wrapper.
The scheduler may invoke sync-site --due or sync-network --due every minute. Grey Rock reads the selected GUI interval and exits successfully without synchronizing until that interval has elapsed.
--due works only with External scheduler and obeys the configured interval. --force runs immediately regardless of the scheduling method or interval.
Grey Rock records the start of every attempt. The next --due invocation waits until the configured interval has elapsed, even when the previous attempt failed or was started manually.
Each site acquires an atomic synchronization lock. An abandoned lock becomes stale after 15 minutes.
No. It removes only Grey Rock's synchronization event. Hourly Grey Rock cleanup remains scheduled, and other WordPress cron events are unaffected.
Disable the external system timer or cron job, select WordPress WP-Cron in Grey Rock settings, select the required interval and save the settings.
No. Review and remove unwanted Cloudflare rules or list entries separately after uninstalling the plugin.
No.
success: true.grey-rock-block-synchroniser-for-wordfence-and-cloudflare.grey-rock-block-synchroniser-for-wordfence-and-cloudflare.php.assets/admin.js.grey-rock-block-synchroniser-for-wordfence-and-cloudflare.grey-rock-block-synchroniser-for-wordfence-and-cloudflare.grey_rock_ to grey_rock_.readme.txt in release packages.wfBlock::getBlocks().