Title: Advanced IP Blocker
Author: IniLerm
Published: <strong>Metheven 26, 2025</strong>
Last modified: Est 29, 2026

---

Search plugins

![](https://ps.w.org/advanced-ip-blocker/assets/banner-772x250.png?rev=3323486)

![](https://ps.w.org/advanced-ip-blocker/assets/icon-256x256.png?rev=3320247)

# Advanced IP Blocker

 By [IniLerm](https://profiles.wordpress.org/inilerm/)

[Download](https://downloads.wordpress.org/plugin/advanced-ip-blocker.8.13.2.zip)

 * [Details](https://cor.wordpress.org/plugins/advanced-ip-blocker/#description)
 * [Reviews](https://cor.wordpress.org/plugins/advanced-ip-blocker/#reviews)
 *  [Installation](https://cor.wordpress.org/plugins/advanced-ip-blocker/#installation)
 * [Development](https://cor.wordpress.org/plugins/advanced-ip-blocker/#developers)

 [Support](https://wordpress.org/support/plugin/advanced-ip-blocker/)

## Description

**Advanced IP Blocker** is your all-in-one security solution to safeguard your WordPress
website from a wide range of threats. This plugin provides a comprehensive suite
of tools to automatically detect and block malicious activity, including brute-force
attacks, vulnerability scanning, and spam bots. With its intuitive interface, you
can easily manage whitelists, blocklists, and view detailed security logs to understand
exactly how your site is being protected.

> **Important Note on PHP Version:**
>  To ensure maximum security and access to all
> features, we strongly recommend using **PHP 8.1 or higher**. Some advanced features(
> like the local MaxMind database or full 2FA management via WP-CLI) require PHP
> 8.1.

**Key Features:**
 * **(NEW) File Integrity Scanner (Beta):** Instantly detect unauthorized
changes to core WordPress files and your active plugins/themes. A vital tool to 
detect malware infections or backdoor placements on your server. * **(NEW) Admin
Access Control:** Granular control over which administrators can access the plugin’s
configuration dashboard. Restrict plugin management while keeping firewall rules
intact for all editors and admins. * **(NEW) Hardening & Core Protection:** Powerful
tools to disable WordPress application passwords, turn off the dangerous built-in
file editor, block PHP execution in the uploads folder, and hide the WordPress version
from attackers. * **(NEW) Intelligent Zero-Day WAF Sync:** Automatically download
and apply critical WAF signatures from the AIB Central Server every day. Stay protected
against zero-day vulnerabilities (like wp2shell) without needing to update the plugin
manually! The rules run completely independent of your custom WAF configuration.***(
NEW) Block Ghost IPs:** Automatically block IPs without ASN and Reverse DNS to stop
anonymous traffic (Warning: Could cause false positives if rDNS is misconfigured
by ISPs). * **(NEW) Captcha Integrations (Turnstile & hCaptcha):** Seamlessly integrate
modern verification challenges like Cloudflare Turnstile and hCaptcha, with granular
control per module and a smart fallback to our invisible JS Challenge to prevent
accidental lockouts. * **(NEW) Rate Limiting Advanced Rules:** Create highly specific
rate limits for different endpoints. For example, set a strict limit with a Turnstile
challenge for `/login`, while keeping a more generous limit with a temporary block
for your main API, all without affecting the rest of the site. * **(NEW) Distributed
Attack Protection (Auto-Panic):** Automatically shields your entire site with a 
global JS challenge during massive traffic spikes, keeping your server online while
intelligently bypassing trusted bots and excluded routes. * **IP & ASN Diagnostics
Tool:** A complete Inspector tool integrated directly into the admin bar. Quickly
audit any IP or ASN against your Geolocation database, Threat Scoring system, Spamhaus
drops, and manual blocking rules in real-time. * **Advanced Rules Import/Export:**
Seamlessly migrate or backup your complex custom security rules across multiple 
WordPress websites. With full JSON validation, structural deduplication, and “cost-
zero” client-side file generation, agency users can clone their perfect firewall
setups in seconds. * **Granular JS Challenge Modes:** You can now choose exactly
how the security challenge behaves. Select “Managed” for ultimate security requiring
human interaction (a checkbox), or “Automatic” for an invisible, transparent Proof-
of-Work execution that stops bots silently. Apply different modes per module! * **
Country Selector Copy/Paste:** Say goodbye to manually selecting 50+ countries. 
You can now instantly copy and paste a raw list of 2-letter country codes directly
into Geoblocking, Geo-Challenge, and Whitelist Login fields. * **AIB Cloud Network
V3:** Upgrade to the next-generation distributed threat intelligence network. The
new API V3 provides secure, individual API Keys per site, drastically improving 
synchronization reliability, threat telemetry, and global network stability. * **
Whitelist Login Countries:** Take absolute control over administrative access. Easily
restrict your WordPress login page and XML-RPC to only allow connections from specific,
whitelisted countries, instantly blocking unauthorized foreign login attempts. ***(
IMPROVED) Bulk Import/Export for Blocked IPs & Whitelist:** Seamlessly import massive
lists of IPs via CSV or manual entry. The system now features a bulletproof “Bulk
Import” type, strict duration inheritance, and intelligent conflict resolution. ***
Internal Security & Forensics:** A complete audit suite solely for WordPress. Track
every sensitive event (plugin installs, settings changes, user logins) and monitor
your critical files for unauthorized modifications with the integrated File Integrity
Monitor. * **Activity Audit Log:** Gain complete visibility into what’s happening
on your site. Who deactivated a plugin? Who changed a setting? The Audit Log answers
these questions with timestamped, immutable records. * **Deep Scan Email Reports:**
Get a weekly security summary delivered to your inbox, detailing pending updates,
vulnerability status, and recent attack trends. * **Username Blocking & Rules:**
Gain granular control over login security. Creating Advanced Rules to block, challenge,
or score specific usernames (e.g., “admin”, “test”). * **Enhanced Lockdown Notifications:**
Distributed Lockdowns (404/403) now fully support Email and Push notifications, 
ensuring you never miss a critical security event. * **Improved Logging:** New “
Endpoint Challenge” event type provides deeper visibility into challenges served
during automated lockdowns. * **Server IP Reputation Check. Instantly audit your
web server’s IP address against major blacklists (Spamhaus, AbuseIPDB) to diagnose
SEO and email delivery issues. \* \*\*HTTP Security Headers. Easily configure essential
security headers like HSTS, X-Frame-Options, and Permissions-Policy to harden your
site against clickjacking, sniffing, and other browser-based attacks. Includes a“
Report-Only” mode for CSP. \* Site Health & Vulnerability Scanner. Audit your WordPress
environment instantly. Detects outdated plugins, insecure PHP versions, and checks
your installed plugins against a database of 30,000+ known vulnerabilities. \* \*\*
PERFORMANCE BOOST: High-Speed Community Database. Migrated the “Community Defense
Network” blocklist to a dedicated, indexed database table. This allows checking 
thousands of malicious IPs in microseconds with zero impact on site memory usage.\*\*\*
Community Defense Network. Join forces with other WordPress admins. The plugin now
shares anonymous attack data to build a global, real-time blocklist of verified 
threats. Protect your site with community-powered intelligence. \* \*\*Auto-Cleaning
Logic. Smart expiration handling ensures your blocklists stay fresh and performant,
automatically removing stale IPs from both the database and external firewalls (
Cloudflare/.htaccess). \* \*\*Cloud Edge Defense (Cloudflare). Connect your site
directly to Cloudflare’s global network. Automatically sync your blocklists to the
cloud to stop attackers before they reach your server. Zero server load protection.\*\*\*
Server-Level Firewall (.htaccess). Extreme performance upgrade. Write blocking rules
and file hardening protections directly to your .htaccess file. Blocks threats instantly
without loading PHP or WordPress. \* \*\*IMPROVED: Smart Bot Verification. Enhanced
logic to correctly identify legitimate traffic from iOS devices (iCloud Private 
Relay) and social media previews, eliminating false positives while keeping impostors
out. \* \*\*File Hardening. Protect your most sensitive files (`wp-config.php`, `
readme.html`, `.git`) at the server level with a single click. \* AbuseIPDB Integration.
Proactively block attackers before they strike. The plugin can now check visitor
IPs against AbuseIPDB’s real-time, crowdsourced database of malicious IPs and block
those with a high abuse score on their very first request. \* Edge Firewall Mode!
Protect any PHP file or standalone application within your WordPress directory (
even if it’s not part of WordPress). Ideal for securing custom scripts, legacy applications,
or folders like `/scan/`. (Requires manual configuration). \* Advanced Rules Engine!
Create powerful, custom security rules with multiple conditions (IP, Country, ASN,
URI, User-Agent, Request Method, Referer) and actions (Block, Challenge, or add 
Threat Score). \* Known Bot Verification. A powerful new security layer that uses
reverse DNS lookups to verify legitimate crawlers like Googlebot and Bingbot. This
completely neutralizes attackers who try to bypass security rules by faking their
User-Agent, assigning high threat scores to impostors. \* Verify Monitoring Bots(
IP List). A brand new feature that downloads and caches official IP lists from popular
uptime monitoring services (like UptimeRobot and Pingdom) to ensure they are never
incorrectly blocked or challenged. \* Onboarding Setup Wizard. A brand new step-
by-step wizard that guides new users through the essential security configurations(
IP whitelisting, WAF, and bot traps) in under a minute, ensuring a strong security
posture from day one. \* Major Refactor: Codebase Modernization. The entire plugin
architecture has been refactored into a modern, modular structure. Logic for admin
pages, AJAX, actions, and settings is now handled by dedicated classes, making the
plugin more stable, performant, and easier to maintain and extend in the future.\*
Advanced IP Spoofing Protection. A zero-trust “Trusted Proxies” system ensures the
plugin always identifies the true visitor IP, even behind complex setups like Cloudflare
or a custom reverse proxy. It neutralizes attacks that attempt to fake their IP,
preventing block evasion and the framing of innocent users. \* Geo-Challenge. A 
smarter way to handle traffic from high-risk countries. Instead of a hard block,
it presents a quick, invisible JavaScript challenge that stops bots but is seamless
for human visitors. This reduces unwanted traffic without affecting potential legitimate
users. \* ENHANCEMENT: Full Bulk-Action Support. IP management is now faster than
ever. Both the Whitelist and the Blocked IPs list now support full bulk actions,
allowing you to select and remove multiple entries at once, or unblock all IPs with
a single click. \* Endpoint Lockdown Mode: Automatically shields `wp-login.php` 
and `xmlrpc.php` with a JavaScript challenge during sustained distributed attacks,
preventing server overload. \* Two-Factor Authentication (2FA): Secure user accounts
with industry-standard TOTP authentication, backup codes, role enforcement, and 
a central admin management dashboard. \* IP Trust & Threat Scoring System: An intelligent
defense that assigns “threat points” to IPs for malicious actions, blocking them
only when they reach a configurable score. More accurate and context-aware than 
simple rules. \* Attack Signature Engine: Proactively stops distributed botnet attacks
by identifying and blocking the attacker’s “fingerprint” (signature) instead of 
just individual IPs. \* Web Application Firewall (WAF): Block malicious requests(
SQLi, XSS, etc.) with a customizable ruleset. \* File Integrity Monitor & Quarantine
Vault: Automatically scans WordPress core files and the uploads directory for malware,
unauthorized modifications, and hidden PHP shells. Safely neutralize threats by 
moving them to an encrypted Quarantine Vault. \* And much more: Rate Limiting, Country&
ASN Blocking (with Spamhaus support), ASN Whitelisting, Push Notifications, Google
reCAPTCHA, Honeypots, Active User Session Management, and Full WP-CLI Support.

## Screenshots

[⌊The new Security Dashboard with real-time charts and a Live Attack Map.⌉⌊The new
Security Dashboard with real-time charts and a Live Attack Map.⌉[

The new Security Dashboard with real-time charts and a Live Attack Map.

[⌊Modern and intuitive two-level navigation system for easy access to all features.⌉⌊
Modern and intuitive two-level navigation system for easy access to all features
.⌉[

Modern and intuitive two-level navigation system for easy access to all features.

[⌊The main Settings page to configure all protection modules like WAF and Rate Limiting.⌉⌊
The main Settings page to configure all protection modules like WAF and Rate Limiting
.⌉[

The main Settings page to configure all protection modules like WAF and Rate Limiting.

[⌊Powerful Web Application Firewall (WAF) with recommended rules.⌉⌊Powerful Web 
Application Firewall (WAF) with recommended rules.⌉[

Powerful Web Application Firewall (WAF) with recommended rules.

[⌊Block entire networks with ASN Blocking, powered by the Spamhaus list.⌉⌊Block 
entire networks with ASN Blocking, powered by the Spamhaus list.⌉[

Block entire networks with ASN Blocking, powered by the Spamhaus list.

[⌊Detailed Blocked IPs table with the "View Map" modal in action.⌉⌊Detailed Blocked
IPs table with the "View Map" modal in action.⌉[

Detailed Blocked IPs table with the “View Map” modal in action.

[⌊Country Blocking (Geoblocking) and Geo-Challenge with user-friendly selectors 
and smart warnings.⌉⌊Country Blocking (Geoblocking) and Geo-Challenge with user-
friendly selectors and smart warnings.⌉[

Country Blocking (Geoblocking) and Geo-Challenge with user-friendly selectors and
smart warnings.

[⌊Unified Security Log with a powerful filter to analyze all attack events.⌉⌊Unified
Security Log with a powerful filter to analyze all attack events.⌉[

Unified Security Log with a powerful filter to analyze all attack events.

[⌊Active User Session Management to monitor and terminate logged-in users.⌉⌊Active
User Session Management to monitor and terminate logged-in users.⌉[

Active User Session Management to monitor and terminate logged-in users.

[⌊Full WP-CLI support documentation, accessible from the "About" tab.⌉⌊Full WP-CLI
support documentation, accessible from the "About" tab.⌉[

Full WP-CLI support documentation, accessible from the “About” tab.

[⌊An example of a professional HTML email notification.⌉⌊An example of a professional
HTML email notification.⌉[

An example of a professional HTML email notification.

[⌊The new "Trusted Proxies" setting for advanced anti-spoofing protection.⌉⌊The 
new "Trusted Proxies" setting for advanced anti-spoofing protection.⌉[

The new “Trusted Proxies” setting for advanced anti-spoofing protection.

[⌊IP Trust & Threat Scoring System.⌉⌊IP Trust & Threat Scoring System.⌉[

IP Trust & Threat Scoring System.

[⌊Attack Signature Engine.⌉⌊Attack Signature Engine.⌉[

Attack Signature Engine.

[⌊The new Two-Factor Authentication (2FA) setup section in the user profile.⌉⌊The
new Two-Factor Authentication (2FA) setup section in the user profile.⌉[

The new Two-Factor Authentication (2FA) setup section in the user profile.

[⌊The 2FA Management tab for administrators, showing user status and reset actions.⌉⌊
The 2FA Management tab for administrators, showing user status and reset actions
.⌉[

The 2FA Management tab for administrators, showing user status and reset actions.

[⌊The 2FA prompt on the WordPress login screen after entering a correct password.⌉⌊
The 2FA prompt on the WordPress login screen after entering a correct password.⌉[

The 2FA prompt on the WordPress login screen after entering a correct password.

[⌊The new HTTP Security Headers manager.⌉⌊The new HTTP Security Headers manager.⌉[

The new HTTP Security Headers manager.

[⌊The new AIB Network manager.⌉⌊The new AIB Network manager.⌉[

The new AIB Network manager.

[⌊The new AbuseIPDB Api manager.⌉⌊The new AbuseIPDB Api manager.⌉[

The new AbuseIPDB Api manager.

## Installation

 1. Upload the `advanced-ip-blocker` folder to the `/wp-content/plugins/` directory.
 2. Activate the plugin through the ‘Plugins’ menu in WordPress.
 3. A new **“Security”** menu item will appear in your admin sidebar. All settings 
    are located there.
 4. **Crucial:** Visit `Security > Dashboard > System Status` to ensure your IP and
    your server’s IP are whitelisted. Use the one-click buttons if they are not.

## FAQ

### How does Admin Access Control work?

By default, all users with the Administrator role can access and configure Advanced
IP Blocker. If you have multiple administrators but only want specific users to 
manage security settings, you can explicitly select them in the “Hardening & Core
Protection” tab. The primary admin (ID 1) is always protected from lockouts. Other
admins will not even see the “Security” menu.

### Can I block PHP execution in the Uploads folder?

Yes! In the “Hardening & Core Protection” section, you can enable “Block PHP in 
Uploads”. The plugin will automatically place a specialized .htaccess file in your
uploads directory to prevent any uploaded scripts from being executed, which is 
a common backdoor technique used by attackers.

### What is the Intelligent Zero-Day WAF Sync?

This is a game-changing feature that automatically synchronizes your site’s Web 
Application Firewall with our Central Security Server. Once a day, the plugin securely
downloads the latest zero-day vulnerability signatures (e.g., for critical CVEs 
or widespread exploits) and injects them directly into the scanning engine. This
means your site is protected instantly against new threats without waiting for a
plugin update. Importantly, these rules run in a dedicated, invisible layer and 
will NEVER overwrite or interfere with your own custom WAF rules.

### What is Block Ghost IPs?

This feature automatically blocks incoming traffic from IP addresses that lack an
Autonomous System Number (ASN) and Reverse DNS (rDNS) record. Since legitimate traffic
almost always has these identifiers, Ghost IPs are often malicious actors trying
to hide. Please note that this can cause false positives if a legitimate Internet
Service Provider (ISP) has misconfigured their rDNS.

### What are Captcha Integrations (Turnstile & hCaptcha)?

Our new Captcha Integrations allow you to seamlessly connect modern verification
challenges like Cloudflare Turnstile and hCaptcha to your security modules. You 
can set a Global Default Engine and even apply different challenges granularly per
module. To ensure your site never breaks, it includes a smart fallback to our invisible
JS Challenge if your API keys are ever misconfigured or missing.

### How do Rate Limiting Advanced Rules work?

Instead of a single global rate limit for your entire site, Advanced Rules allow
you to define custom limits for specific URLs or endpoints. You can define the maximum
number of requests, the time window, and the specific action (like returning a 429
error, a 403 block, or triggering a Turnstile/hCaptcha challenge) for each endpoint
independently. This is ideal for protecting sensitive areas like login pages or 
APIs with stricter limits while allowing normal traffic on the rest of the site.

### What is Distributed Attack Protection (Auto-Panic)?

This feature automatically engages a global JavaScript challenge to protect your
server resources from massive spikes in malicious traffic. It monitors the number
of blocks within a specific time window and, if the threshold is reached, it shields
the entire site. Legitimate administrators, verified bots (like Googlebot), and 
explicitly excluded URLs are bypassed. You can configure the thresholds and notification
preferences under Security > Settings > Core Protections.

### What is the IP & ASN Diagnostics Tool (IP Inspector)?

It is a powerful built-in utility located in your Security menu (and top admin bar)
that allows you to manually inspect any IP address or Autonomous System Number (
ASN). It instantly cross-references the subject against your Geolocation databases,
Threat Scoring system, AbuseIPDB, Spamhaus drops, and local whitelists/blocklists.
It is the ultimate tool for investigating suspicious traffic or verifying if a legitimate
user was blocked by a specific rule.

### How does the Vulnerability Scanner work?

The scanner checks your site in two ways:
 Local Scan: Checks for outdated PHP versions,
WordPress core updates, debug mode risks, and SSL status. This runs locally and 
instantly. Deep Scan (Vulnerability Audit): Checks your installed plugins and themes
against our central database of known security vulnerabilities (CVEs). This process
is manual (you click a button) to ensure it never slows down your site during normal
operation.

### What is the new Audit Log?

The Audit Log is your site’s “black box”. It records critical administrative actions
such as plugin activations, settings changes, and file modifications. This helps
you identify “who did what and when,” which is essential for troubleshooting and
security forensics.

### How does the File Integrity Monitor (FIM) work?

The FIM acts as a forensic security layer. It takes cryptographic fingerprints of
your most critical core files (like wp-config.php) to detect unauthorized modifications.
Additionally, it recursively scans your `wp-content/uploads/` media folder to detect
and alert you of hidden PHP web shells. If an anomaly is found, you can neutralize
it instantly by sending it to the encrypted Quarantine Vault.

### Why did you move the Community Blocklist to a custom table?

To ensure maximum performance as the network grows. Storing thousands of IPs in 
standard WordPress options (wp_options) can slow down a site. By moving this data
to a dedicated, indexed database table (wp_advaipbl_community_ips), we ensure that
lookups are lightning-fast (O(1) complexity) and consume negligible memory, regardless
of how many threats we track.

### What is the Community Defense Network?

It is a collaborative security feature where users share anonymized data about verified
attacks (like SQL injections caught by the WAF or IPs flagged by AbuseIPDB). Our
central server aggregates this data to create a global blocklist of active threats.
You can choose to contribute data (“Join”) and/or use the global list to protect
your site (“Enable Blocking”).

### Does the Community Network slow down my site?

No. The data sharing happens in the background via a low-priority scheduled task(
Cron) just a few times a day. The global blocklist is downloaded locally and cached,
so checking an IP against it is instant (microseconds) and does not require external
API calls.

### How do I set up Cloud Edge Defense (Cloudflare)?

You need a free Cloudflare account and your domain must be using Cloudflare’s nameservers.

1. Go to Security > Settings > Cloud Edge Defense. 2. Enter your Cloudflare API 
Token (with “Zone > Firewall Services > Edit” permissions) and Zone ID. 3. Click“
Verify” and save. The plugin will now automatically push your blocked IPs to Cloudflare’s
Firewall. For a step-by-step guide with screenshots, click the help icon in the 
settings or visit our website.

### Is the Server-Level Firewall (.htaccess) safe?

Yes. Safety is our priority.
 1. Backups: The plugin automatically creates a timestamped
backup of your .htaccess file in a protected folder every time it writes new rules.
2. Compatibility: It automatically detects your server type and generates valid 
syntax for Apache 2.2 or 2.4. 3. Safety Limit: It includes a safety limit on the
number of IPs written to the file to prevent server memory issues.

### What if I use Nginx instead of Apache?

The “Server-Level Firewall (.htaccess)” feature relies on Apache/LiteSpeed specific
files. If you use Nginx (without Apache), these local rules will be ignored by the
server.
 Recommendation: For Nginx users, we strongly recommend enabling the Cloud
Edge Defense (Cloudflare) feature. It provides the same “pre-execution” blocking
benefits but works on any server environment since the blocking happens in the cloud.

### How should I configure the plugin for my specific website?

While every website’s security needs are unique, here is a general guide to get 
you started based on your site’s profile. For a deep dive into every feature, please
consult our [Comprehensive Feature Guide](https://advaipbl.com/comprehensive-feature-guide-advanced-ip-blocker/).

**1. Essential First Steps (For ALL Websites)**

No matter your site type, do these three things immediately after installation to
ensure a strong baseline security without locking yourself out:

 * **Whitelist Your IPs:** Go to `Security > Dashboard > System Status` and use 
   the one-click buttons to add your current IP and your server’s IP to the whitelist.
   This is the most critical step.
 * **Activate Trap Defenses:** Go to `Security > Blocking Rules`, and in the “User
   Agents” and “Honeypot URLs” tabs, copy the suggested lists into the active blocklist
   text areas. This provides immediate protection from thousands of common bots.
 * **Enable Logging:** Go to `Security > Settings > General` and ensure “Enable 
   Logging” is turned on. This gives you the visibility you need to understand what
   is happening on your site.

**2. Recommended Profiles**

Once the essentials are done, tailor the configuration to your site type:

**For a Standard Blog or Business Website:**
 Your main goal is to block automated
threats without affecting administrators. * **Enable the IP Trust & Threat Scoring
System:** This is the smartest way to block bad actors contextually. The default
point values are an excellent starting point. (Found in `Settings > IP Trust & Threat
Scoring`). * **Enable the WAF and Rate Limiting:** These are powerful proactive 
defenses. (Found in `Settings > Core Protections` and `Threshold Blocking`). * **
Enable Spamhaus ASN Protection:** Let the plugin automatically block thousands of
known malicious networks for you. (Found in `Settings > Core Protections`).

**For an E-commerce or Membership Site (WooCommerce, etc.):**
 You need to protect
your site while ensuring legitimate customers from around the world are never blocked.***
Enable Two-Factor Authentication (2FA):** This is the single best way to protect
administrator and shop manager accounts. Enforce it for these roles in `Settings
> Login & User Protection`. * **Use Geo-Challenge Instead of Geoblocking:** If you
receive attacks from a specific country but also have customers there, use the Geo-
Challenge feature instead of a hard block. This will stop bots without affecting
human users. * **CRITICAL: DO NOT USE “Whitelist Login Access”.** This feature will
lock out your customers. * **WAF Exclusions:** Double-check that URLs for your payment
gateways (like Stripe or PayPal webhooks) are in the WAF exclusion list to ensure
payments are processed correctly.

**For Any Site Using a CDN or Reverse Proxy (like Cloudflare):**
 Your top priority
is ensuring the plugin detects the correct visitor IP address. * **Configure Trusted
Proxies:** Go to `Security > Settings > IP Detection`. Add the IPs or, even better,
the ASNs of your CDN/proxy service to this list. For Cloudflare, simply add `AS13335`
on a new line. This is essential for the accuracy of all other security features.

### What is AbuseIPDB Protection and how does it work?

AbuseIPDB is a global, crowdsourced project that tracks and reports malicious IP
addresses in real-time. Our new integration allows the plugin to check the reputation
of a new, unknown visitor against this database on their first visit. If the IP 
has been recently reported by others for activities like hacking, spam, or brute-
force attacks, and its “abuse confidence score” is above your configured threshold,
the plugin will block it instantly. This acts as a proactive shield against known
bad actors, stopping them before they even have a chance to test your defenses. 
You can enable it and add your free API key under `Security > Settings > Threat 
Intelligence`.

### What is “Known Bot Verification”?

This is an advanced security feature that checks if visitors claiming to be from
major search engines (like Googlebot) are legitimate. It performs a DNS lookup to
verify their IP address. If the check fails, the visitor is identified as an “impersonator”
and receives a high threat score, preventing them from exploiting the trust given
to real crawlers. This feature is enabled by default under `Settings > Core Protections`.

### What is “Verify Monitoring Bots (IP List)”?

This feature ensures your uptime monitoring services (like UptimeRobot, Pingdom,
StatusCake, etc.) can always reach your site to check its status. By automatically
downloading and updating official IP lists from these providers, the plugin safely
whitelists them from rate limiting or blocking without exposing your site to attackers
who might spoof their user agents.

### What is “Trusted Proxies” and why do I need it?

This is a critical security feature that prevents IP spoofing. If your site is behind
a service like Cloudflare, Varnish, or another reverse proxy, the server’s direct
connection IP (`REMOTE_ADDR`) will always be the proxy’s IP, not the visitor’s. 
The real visitor IP is sent in an HTTP header (e.g., `CF-Connecting-IP`). An attacker
can fake this header. The “Trusted Proxies” setting tells the plugin: “Only trust
these headers if the request comes from an IP address I know is my proxy.” You can
add IPs, CIDR ranges, or ASNs (like `AS13335` for Cloudflare) to this list under`
Security > Settings > IP Detection`.

### What is Geo-Challenge? How is it different from Geoblocking?

**Geoblocking** is a hard block. It shows a “403 Access Denied” page to visitors
from selected countries.
 **Geo-Challenge** is a soft block. It shows a quick, automated
JavaScript test to visitors from selected countries. Legitimate humans pass instantly,
while most bots are stopped. This is useful for regions you are suspicious of but
do not want to block entirely. You can, for example, block Country A and challenge
Country B. You can configure it in `Security > Settings > Core Protections`.

### What is the difference between Automatic and Managed JS Challenge Modes?

**Automatic (Transparent execution):** The plugin runs a silent Proof-of-Work (PoW)
mathematical challenge in the background. If the visitor’s browser solves it within
5 seconds, they are automatically redirected to their destination without needing
to click anything. Great for a frictionless user experience.
 **Managed (Human interaction
required):** The visitor must manually click a checkbox (“I am human”) and optionally
wait a few seconds. This mode is the ultimate defense against advanced headless 
browsers and intelligent bots that can solve mathematical scripts but cannot simulate
human mouse interactions.

### How do I solve issues with the JavaScript challenge and caching plugins?

The JavaScript challenge (used by Geo-Challenge, Signature Engine, and Endpoint 
Lockdown) requires dynamic content. Aggressive page caching can interfere with it.
If you experience issues (like a challenge loop or a “Verification failed” error),
you must configure your caching plugin (e.g., WP Rocket, WP Fastest Cache, LiteSpeed
Cache) to **NOT** cache pages for visitors who do not have the `advaipbl_js_verified`
cookie. Most caching plugins have a setting like “Never cache pages that use this
cookie.”

### How do I solve issues with the JavaScript challenge and cookie consent (RGPD/GDPR) plugins?

Cookie consent plugins (like CookieYes) may block our security cookie from being
set. To fix this, you must go into your cookie plugin’s settings and classify the
cookie named `advaipbl_js_verified` as **“Strictly Necessary”** or “Essential”. 
This will allow the security challenge to function correctly.

### What is the new “Local Database” Geolocation Method?

For maximum performance, the plugin offers two ways to identify an IP’s location(`
Security > Settings > Geolocation`):
 1. **Real-time API (Default):** Easy to set
up and great for most websites. 2. **Local Database (Highest Performance):** Downloads
the MaxMind GeoLite2 database to your server for instant, offline lookups with zero
external API calls. Recommended for high-traffic sites. Requires a free MaxMind 
license key.

### How do I set up Two-Factor Authentication (2FA)?

 1. **Admin:** Go to `Security > Settings > Login & User Protection` and enable 2FA
    globally. You can also enforce it for specific user roles.
 2. **User:** Go to your WordPress Profile page. You will find a new section to set
    up 2FA by scanning a QR code with an authenticator app and saving your backup codes.

### What is the “Attack Signature Engine”?

This is an advanced defense that stops botnets by blocking the attacker’s “fingerprint”(
signature), not just their IP. It works in three phases you can enable in `Security
> Settings > Signature Engine`: Logging, Analysis (a background task that finds 
patterns), and Blocking (presents a JS challenge to malicious signatures). You can
manage detected signatures in `IP Management > Blocked Signatures`.

### What is the difference between the WAF, Signature Engine, and Advanced Rules?

Think of them as three layers of defense:
 1. **WAF (Web Application Firewall):**
The simplest layer. It blocks requests based on simple malicious patterns (e.g.,`
union select`). It’s fast and stops common, generic attacks. 2. **Attack Signature
Engine:** The automated layer. It looks for patterns of attack from many different
IPs (botnets) and blocks the attack’s “fingerprint” (signature) for all visitors.
You don’t create these rules; the plugin does. 3. **Advanced Rules Engine:** The
manual control layer. This is where _you_ build your own specific, multi-conditional
rules. For example: “IF the visitor is from China AND is trying to access `/wp-admin/`
THEN Block them permanently.” It gives you the ultimate power to create a security
policy tailored exactly to your site’s needs.

### How can I protect a non-WordPress folder on my site?

This plugin includes an advanced “Edge Firewall Mode” that allows you to extend 
its protection to any PHP script on your server. This is perfect for securing custom
applications or directories that are not managed by WordPress. To enable it, you
need to add a single line of code to the beginning of the PHP file you want to protect.
This manual step ensures that the protection is explicit and works on any server
environment. For a complete step-by-step guide, please see our documentation: [How to Protect Non-WordPress Folders](https://advaipbl.com/edge-firewall-mode/).

### What are HTTP Security Headers and why do I need them?

HTTP Security Headers are instructions sent by your website to the visitor’s browser.
They tell the browser how to behave to prevent specific types of attacks.
 * **HSTS:**
Forces the browser to use a secure HTTPS connection. * **X-Frame-Options:** Prevents
other sites from embedding your site in an iframe (Clickjacking protection). * **
X-Content-Type-Options:** Prevents the browser from “guessing” the file type (MIME
sniffing protection). * **Permissions-Policy:** Controls which features (camera,
mic, etc.) legitimate sites can use. You can configure all of these (and more!) 
in `Security > Settings > Security Headers`.

### What does the “Username Blocking” feature do?

It allows you to create aggressive, targeted rules to block login attempts based
on the username provided. For example, if you know you never use the username “admin”,
you can create a rule: **IF Username IS “admin” THEN Block**. This stops brute-force
attacks instantly before they can even guess a password.

### Why was the “Direct File Access” warning added for the loader file?

We improved our security compliance checks. The `advaipbl-loader.php` file is a 
special file designed to run outside of WordPress in “Edge Mode”. We added a specific
security check to ensure it can only be run via the `auto_prepend_file` mechanism
and cannot be accessed directly by a browser, further hardening the plugin against
probing.

## Reviews

![](https://secure.gravatar.com/avatar/15f6c033e2183dd6f12854c7a7b47c52e3a91f05a9ecd6872e766930f3bee32a?
s=60&d=retro&r=g)

### 󠀁[The most important plugin for our wordpress sites](https://wordpress.org/support/topic/the-most-important-plugin-for-our-wordpress-sites/)󠁿

 [anotherwebdev](https://profiles.wordpress.org/anotherwebdev/) Est 20, 2026 1 reply

At first it was a bit daunting with so many options, and once in the past it almost
locked me out, but now we use it on EVERY wordpress site we work with. Its very 
reliable and you will be surprised with the amount of new blocks that are received
daily. At this moment I’m financially very low, but I hope soon I can make a nice(
reocurring) donation, because this plugin does more for free than many paid plugins
promise. Keep it going 🙏 and thank you! ⚡⚡

![](https://secure.gravatar.com/avatar/0ee71767141828244922264f32ef6ac556b9ba8e4e8ccddd8717990c6a98d013?
s=60&d=retro&r=g)

### 󠀁[Just AWESOME!](https://wordpress.org/support/topic/just-awesome-353/)󠁿

 [nwjeff](https://profiles.wordpress.org/nwjeff/) Est 19, 2026 1 reply

This plugin has so many great, useful features and more features and enhancements
keep coming. If you are not using this plugin, you are really missing out on a lot
of protection for your website. Yes, there are other plugins that offer some of 
the same features but why use multiple plugins when AIB covers them all in just 
one plugin. Oh, and AIB is free! Thank you for all your hard work on AIB!

![](https://secure.gravatar.com/avatar/65c3250003b6e1f03b62ba4efc6d301b3d7992836fa3f3193f8fac0749661fd3?
s=60&d=retro&r=g)

### 󠀁[Technically Fantastic Security plugin](https://wordpress.org/support/topic/technically-fantastic-security-plugin/)󠁿

 [Artfuldodger](https://profiles.wordpress.org/greggwatson/) Gortheren 16, 2026 
1 reply

We currently use this plugin in over 250 client websites. It integrates well with
other firewall products and fills numerous gaps in the typical WP firewall or security
plugin. The author gives immediate and detailed responses to all questions and inquires.
The product is updated very frequently, instead of once in awhile like other products.
The developer listens to the end users and add quality features in rapid time! I
cant say enough good things about this plugin, its feature list is comprehensive,
long and every growing. Keep up the most excellent work, this a plugin to be proud
of. Oh, and its FREE! Security shouldn’t have to cost you an arm and a leg.

![](https://secure.gravatar.com/avatar/fcb7f8e68ce1bec35818e38ec6d2cb5970085c86eec63bc4a1785f27a9f8ad51?
s=60&d=retro&r=g)

### 󠀁[Fantastic tool](https://wordpress.org/support/topic/fantastic-tool-122/)󠁿

 [Dmitry Bychenko](https://profiles.wordpress.org/wpbluefox/) Gortheren 16, 2026
1 reply

Thank you, AdvIPBlocker team for creating this fantastic tool!

![](https://secure.gravatar.com/avatar/27be7e02e12a8d13cdeef61d385765fb416df1039eb9949c4fcd7da6ab3f1284?
s=60&d=retro&r=g)

### 󠀁[Exceptional Security Plugin with Unique AS-Level Blocking Capability](https://wordpress.org/support/topic/exceptional-security-plugin-with-unique-as-level-blocking-capability/)󠁿

 [bear2000](https://profiles.wordpress.org/bear2000/) Gortheren 15, 2026 2 replies

Advanced IP Blocker is one of the most reliable and technically mature security 
plugins available for WordPress. Its ability to handle AS numbers, countries, hostnames,
and IP ranges in a unified and consistent way is exceptional, and the AS‑number 
blocking feature in particular provides a level of practical effectiveness that 
other security plugins simply do not offer. The interface is clean, logically structured,
and easy to operate even when dealing with complex blocking conditions. This reflects
a high level of design discipline and engineering clarity. In real‑world use, this
plugin stands out as one of the very few that actually deliver meaningful protection
rather than superficial features. As the highest compliment, I would say that Advanced
IP Blocker is the “indispensable and unmatched choice” for anyone who needs AS‑level
defense on a WordPress site. I would like to add one request for future development.
It would greatly enhance practical security if the plugin could automatically block
IP addresses that have no AS number, no hostname, and no reverse DNS information—
the completely anonymous, unclassified IPs. This single addition would significantly
strengthen real‑world protection. I sincerely hope development continues. Excellent
work.

![](https://secure.gravatar.com/avatar/0d88e69cd5146d0a92994dbf3f629384454aa3c3a03cf59989acdfc672a5b258?
s=60&d=retro&r=g)

### 󠀁[Highly Recommended Security Plugin](https://wordpress.org/support/topic/highly-recommended-security-plugin/)󠁿

 [Pat K](https://profiles.wordpress.org/blackcapdesign/) Metheven 12, 2026 1 reply

In response to a recent spike in malicious bot-network activity, I stumbled across
this plugin while researching the benefits of using Cloudflare as a reverse-proxy
to protect agains DoS, DDoS and related attacks. I have been blown away by how effective
it has been, how intuitive it was to set up, and how feature-rich it is. I keep 
thinking ‘this is too good to be true’, but after installing this on several projects
and monitoring the impact, I have no misgivings. I highly recommend this to anyone
interested in or concerned about the recent global tsunami of malicious bot network
attacks. Works great in conjunction with Cloudflare – but can be used without Cloudflare
integration. If I could give this more than 5 stars, I would. 10 out of 5 🙂

 [ Read all 24 reviews ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/)

## Contributors & Developers

“Advanced IP Blocker” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ IniLerm ](https://profiles.wordpress.org/inilerm/)

[Translate “Advanced IP Blocker” into your language.](https://translate.wordpress.org/projects/wp-plugins/advanced-ip-blocker)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/),
check out the [SVN repository](https://plugins.svn.wordpress.org/advanced-ip-blocker/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/advanced-ip-blocker/)
by [RSS](https://plugins.trac.wordpress.org/log/advanced-ip-blocker/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 8.13.2

 * **HOTFIX:** Refactored the File Integrity Monitor engine to fetch malware signatures
   dynamically from the Central API and store them in the database. This prevents
   the plugin’s internal malware dictionary from triggering false positives in server-
   side antiviruses (e.g., CPGuard, Imunify360).
 * **NEW FEATURE:** Added a “Manage Whitelist” UI to the FIM Dashboard for manually
   excluding files from scans.
 * **ENHANCEMENT:** The FIM scanner now automatically ignores the plugin’s own directory
   to prevent false positives caused by security-related localization strings.

#### 8.13.1

 * **HOTFIX:** Refactored the File Integrity Monitor engine to store malware signatures
   as ASCII integer arrays. This eliminates false positives caused by server-side
   antiviruses (like CPGuard or Imunify360) incorrectly flagging the plugin’s internal
   malware dictionary during static scans.

#### 8.13.0

 * **NEW FEATURE:** File Integrity Monitor (Phase 2): Uploads Malware Scanner. The
   FIM now extends beyond core files to recursively scan the `wp-content/uploads/`
   directory for suspicious executable files (e.g., hidden `.php` shells), alerting
   administrators immediately without causing false positives on legitimate index
   files.
 * **NEW FEATURE:** Quarantine Vault. A secure backend interface to safely encrypt
   and isolate malicious or suspicious files detected by the File Integrity Monitor,
   preventing them from being executed by attackers while preserving them for forensic
   analysis.
 * **NEW FEATURE:** Advanced Payload Logging. The WAF and Block engines now capture,
   sanitize, and log the raw HTTP payload (POST data) of malicious requests, providing
   invaluable context for administrators investigating complex attacks like SQL 
   injections or XSS.
 * **ENHANCEMENT:** The FIM alert notification system now dynamically checks your
   security configuration and will append a highly visible recommendation to enable“
   Block PHP in Uploads” if an anomaly is detected and the feature is currently 
   disabled.
 * **ENHANCEMENT:** FIM alert emails now feature color-coded event types for improved
   scannability (e.g., orange for suspicious files, red for deleted core files).
 * **ENHANCEMENT:** Modernized Admin UI. Redesigned all configuration inputs across
   the plugin to feature dynamic floating labels, sleek borderless designs, and 
   premium dark background filters for a better user experience.
 * **ENHANCEMENT:** Optimized Local WAF Rules. Refined the default and suggested
   regular expressions (e.g. Path Traversal) to be highly precise, eliminating false
   positives caused by overly aggressive legacy patterns (like `/?author=` or trailing
   hyphens).
 * **BUGFIX:** Resolved a persistent PHPCS linting error (`OutputNotEscaped`) in
   the WAF status tag renderer.

#### 8.12.2

 * **NEW FEATURE:** File Integrity Scanner (Phase 1). A brand new security module
   designed to scan WordPress core files, active plugins, and themes against their
   official WordPress.org checksums to detect unauthorized modifications or malware
   infections.
 * **BUGFIX:** Resolved a critical race-condition flaw in the centralized `block_ip_instantly`
   engine. Stale database locks (e.g., from interrupted script executions) would
   silently prevent the plugin from executing new blocks, affecting Thresholds, 
   Threat Scores, and Advanced Rules.
 * **BUGFIX:** The “Threshold Reached” block notifications (Email and Push) now 
   correctly display the dynamic number of errors that triggered the block (e.g.,
   4) instead of a hardcoded “1”.
 * **ENHANCEMENT:** The threshold blocking engine (404, 403, and Login) has been
   modernized to use the centralized blocking architecture and bypass legacy option
   tables, significantly improving performance on high-traffic sites.
 * **ENHANCEMENT:** Minor UI improvements in the Security Dashboard layout and Environmental
   Summary panel.

#### 8.12.1

 * **NEW FEATURE:** Community Minimum Threat Score. You can now define how many 
   unique community reports an IP must have before your local plugin imports and
   blocks it, drastically reducing false positives from the global network.
 * **ENHANCEMENT:** Upgraded the AIB Central API integration to retrocompatibly 
   support Threat Scores. The local IP Inspector now displays real-time community
   report counts directly in the UI.
 * **ENHANCEMENT:** Manual ASN blocks are no longer transmitted to the AIB Community
   Network, preventing edge-case configurations from polluting the global threat
   database.
 * **BUGFIX:** Resolved a critical logical flaw where failures or rate-limits in
   external Geolocation APIs (e.g., ipquery.io fallback) would falsely classify 
   legitimate servers without rDNS as Ghost IPs.
 * **BUGFIX:** Fixed a character encoding issue (mojibake) that caused emojis in
   Distributed Attack Protection (Auto-Panic) webhook notifications to render incorrectly
   in Slack and Discord.

#### 8.12.0

 * **ENHANCEMENT:** Tested and verified full compatibility with the upcoming WordPress
   7.1 core release.
 * **ENHANCEMENT:** Brand new CDN Manager architecture with a Quick Add dropdown
   to easily auto-fill trusted proxies like Cloudflare and QUIC.cloud.
 * **SECURITY:** Added Zero-Day WAF rules for recent critical vulnerabilities including
   Wishlist Member X (CVE-2026-12949) and User Profile Builder (CVE-2026-15826).
 * **NEW FEATURE:** Admin Access Control. You can now restrict access to the plugin’s
   configuration dashboard to specific administrators. Users not on the allowed 
   list will not see the Security menu, while User ID 1 is always protected against
   lockouts.
 * **NEW FEATURE:** Hardening & Core Protections. Added a new section to securely
   hide the WordPress version, disable the built-in file editor, disable application
   passwords, disable ImageMagick (Imagick), and block PHP execution in the uploads
   folder via a managed `.htaccess`.
 * **ENHANCEMENT:** Central Telemetry Update. The plugin now securely transmits 
   the adoption rate of the new Hardening features (including Restricted Admins)
   for aggregated community statistics.
 * **ENHANCEMENT:** Audit Logging. Changes to the authorized administrators list
   are now tracked and logged in the Activity Audit Log.
 * **BUGFIX:** Resolved HTML rendering bug in the Admin Access Control multi-select
   field.
 * **BUGFIX:** Fixed PHPCS warnings in the uninstaller file regarding interpolated
   variables and standard filesystem writes.
 * **BUGFIX:** Resolved Content Security Policy (CSP) console errors on challenge
   pages caused by Cloudflare Web Analytics (beacon.min.js) auto-injection.
 * **BUGFIX:** Ensured the Zero-Day WAF Lightweight Ping cron task is properly cleared
   upon plugin deactivation and uninstallation.
 * **BUGFIX:** Zero-Day WAF synchronization now preserves informational comments
   for the UI while correctly excluding them from both the active WAF engine evaluation
   and the rules count log.
 * **BUGFIX:** Fixed an issue where importing settings templates failed on Windows
   server environments (like XAMPP) due to backslashes being stripped from temporary
   upload file paths.
 * **BUGFIX:** Updated hardcoded URLs in email templates and system redirects to
   correctly point to the new top-level `admin.php` menu structure instead of the
   legacy `options-general.php` location.
 * **IMPROVEMENT:** Removed emojis from WordPress admin notices and email templates
   to prevent character encoding issues on certain server environments, keeping 
   them exclusively for push webhook notifications (Slack, Discord, etc.).
 * **IMPROVEMENT:** The “Unblock ALL IPs” bulk action now properly resets the Threat
   Score of all unblocked IPs to 0, ensuring consistent UX with individual unblocking
   and preventing immediate re-blocking upon minor infractions.

## Meta

 *  Version **8.13.2**
 *  Last updated **14 our ago**
 *  Active installations **2,000+**
 *  WordPress version ** 5.9 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.1 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/advanced-ip-blocker/)
 * Tags
 * [2FA](https://cor.wordpress.org/plugins/tags/2fa/)[firewall](https://cor.wordpress.org/plugins/tags/firewall/)
   [Geoblocking](https://cor.wordpress.org/plugins/tags/geoblocking/)[security](https://cor.wordpress.org/plugins/tags/security/)
   [WAF](https://cor.wordpress.org/plugins/tags/waf/)
 *  [Advanced View](https://cor.wordpress.org/plugins/advanced-ip-blocker/advanced/)

## Ratings

 4.8 out of 5 stars.

 *  [  23 5-star reviews     ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/?filter=2)
 *  [  1 1-star review     ](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/advanced-ip-blocker/reviews/)

## Contributors

 *   [ IniLerm ](https://profiles.wordpress.org/inilerm/)

## Support

Issues resolved in last two months:

     11 out of 12

 [View support forum](https://wordpress.org/support/plugin/advanced-ip-blocker/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://donate.stripe.com/bJe00kaIP89O1wFfargUM00)