xZeroProtect brings the power of the
xZeroProtect PHP library to WordPress with a clean admin dashboard. The plugin source is available at
github.com/webrium/xzeroprotect-wp.
What it does:
- Blocks bots, scanners, and common web attacks (SQLi, XSS, path traversal, command injection)
- Rate-limits IPs and automatically bans repeat offenders
- Verifies legitimate crawlers (Googlebot, Bingbot) via double-DNS — they're never blocked
- Tracks real visitor analytics — bot traffic is already filtered out before anything is recorded
- Shows unique visitors, top pages, device breakdown, and block reasons in a dashboard
- Zero external dependencies — no Redis, no external API, everything on disk and in your database
Dashboard includes:
- Traffic overview chart (visits, unique visitors, blocked)
- Top pages by hits and unique visitors
- Device breakdown (desktop / mobile / tablet)
- Block reason breakdown
- Real visitor log with browser, OS, and device info
- Blocked request log with attack type and reason