| 开发者 | moveforwardltd |
|---|---|
| 更新时间 | 2026年9月11日 05:50 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
init hook, before your theme and most plugins load, and every lookup is performed locally against offline MMDB database files in your uploads directory — so no external request is made on normal page loads.
The plugin is free and open source (GPLv2 or later), maintained by Move Forward Limited. It works out of the box and no account and no paid plan is ever required to use it.
What it blocks
/wp-admin), /wp-login.php and /wp-register.php are never blocked, logged-in users are never blocked, and an emergency kill switch (WP_SENTRAIP_DISABLE_BLOCKING) can disable all blocking from wp-config.php..htaccess and index.php.sentraip.zip file and click Install Now, then Activate.sentraip folder into /wp-content/plugins/ and activate it from the Plugins menu.
Requirements: PHP 7.4+ and WordPress 6.8+. IP lookups use the MaxMind DB reader, which is bundled with the plugin.The plugin is free and open source (GPLv2 or later) and fully functional on its own. Country blocking, bot blocking (with a large built-in list), automatic spam-comment IP blocking, the IP whitelist and the opt-in free SPAM reputation dataset all work with no account at all. Additional IP-reputation datasets (VPN, TOR, PROXY, THREAT, Datacenter and composed rules) are available through the separate SentraIP PRO companion plugin, which connects to a SentraIP account — but this free plugin never requires it.
No. The plugin auto-excludes your server's country and your saved admin country. The WordPress admin area, the login page (/wp-login.php) and the registration page are never blocked, and logged-in users are never blocked — so you can always sign in and fix a rule. As a last resort you can add define( 'WP_SENTRAIP_DISABLE_BLOCKING', true ); to wp-config.php to disable all blocking.
The plugin gracefully skips any check whose database file is missing. Your site keeps working normally until the files are available.
No. All IP lookups run against local binary database files in your uploads directory. External connections are made only when downloading or refreshing a database file (on a monthly schedule, or when you trigger it manually) — the geolocation database, or the opt-in free SPAM dataset.
In wp-content/uploads/wp-sentraip/. The directory is protected by a .htaccess (Deny from all) and an index.php to prevent direct web access.
Yes. The plugin detects whether the visitor's IP is IPv4 or IPv6 and uses the matching database file, when that version is available for the dataset.
When a comment is marked as spam, the commenter's IP is recorded and blocked for 24 hours. This works entirely locally, with no external data or account.
Open /wp-login.php and sign in — login and /wp-admin are never blocked. Then edit the rule that caught you and remove your country/datacenter/IP. If you cannot reach the admin at all, add define( 'WP_SENTRAIP_DISABLE_BLOCKING', true ); to wp-config.php.
<script> (Ultra rules data) to wp_add_inline_script().full dataset (fields vpn_provider / organization), while the light file used for blocking carries just a membership flag. The plugin now downloads the full v4 file for VPN and Datacenter and enumerates names from it (IPv4 only).ip_versions) and only fetches files that exist./wp-admin, /wp-login.php and /wp-register.php are never blocked, even when your IP is in a blocklist; the site frontend stays protected.