{"id":341024,"date":"2026-07-25T16:00:48","date_gmt":"2026-07-25T16:00:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wonderful-geoblocking-countries\/"},"modified":"2026-09-21T11:57:38","modified_gmt":"2026-09-21T11:57:38","slug":"wonderful-geoblocking-countries","status":"publish","type":"plugin","link":"https:\/\/cn.wordpress.org\/plugins\/wonderful-geoblocking-countries\/","author":23357214,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Wonderful Geoblocking Countries","header_author":"Wonderful Plugins","header_description":"Blocks site access, login, or registration for visitors from selected countries, with a customizable message per area.","assets_banners_color":"","last_updated":"2026-09-21 11:57:38","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wonderfulplugins.eu\/wonderful-geoblocking-countries","header_author_uri":"https:\/\/wonderfulplugins.eu","rating":0,"author_block_rating":0,"active_installs":0,"downloads":291,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"wonderfulplugins","date":"2026-07-25 16:00:25","revision":3622600},"1.0.3":{"tag":"1.0.3","author":"wonderfulplugins","date":"2026-09-02 11:47:22","revision":3677901},"1.1.0":{"tag":"1.1.0","author":"wonderfulplugins","date":"2026-09-21 11:57:38","revision":3705534}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3622600,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3622600,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2","1.0.3","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1-de.jpg":{"filename":"screenshot-1-de.jpg","revision":3705534,"resolution":"1","location":"assets","locale":"de","width":2560,"height":4548},"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3705534,"resolution":"1","location":"assets","locale":"","width":2560,"height":4388}},"screenshots":{"1":"The settings page: country database and optional VPN list, per-area country lists, VPN blocking and custom block messages."}},"plugin_section":[],"plugin_tags":[281831,88702,232176,4124,600],"plugin_category":[49,54],"plugin_contributors":[247385],"plugin_business_model":[],"class_list":["post-341024","plugin","type-plugin","status-publish","hentry","plugin_tags-block-vpn","plugin_tags-country-block","plugin_tags-geoblocking","plugin_tags-geolocation","plugin_tags-security","plugin_category-maps-and-location","plugin_category-security-and-spam-protection","plugin_contributors-wonderfulplugins","plugin_committers-wonderfulplugins"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/icon-128x128.png?rev=3622600","icon_2x":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/icon-256x256.png?rev=3622600","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/wonderful-geoblocking-countries\/assets\/screenshot-1.jpg?rev=3705534","caption":"The settings page: country database and optional VPN list, per-area country lists, VPN blocking and custom block messages."}],"raw_content":"<!--section=description-->\n<p>Some sites simply do not need worldwide traffic \u2014 or keep getting spam registrations and brute-force login attempts from countries they never do business with.<\/p>\n\n<p><strong>Wonderful Geoblocking Countries<\/strong> lets you block three areas of your site independently, each with its own country list and its own message:<\/p>\n\n<ul>\n<li><strong>Site access<\/strong> \u2014 the whole public frontend.<\/li>\n<li><strong>Login<\/strong> \u2014 the wp-login.php page.<\/li>\n<li><strong>Registration<\/strong> \u2014 the user registration form.<\/li>\n<\/ul>\n\n<p>For every area you pick the mode that fits:<\/p>\n\n<ul>\n<li><strong>Block list<\/strong> \u2014 block visitors from the selected countries and allow everyone else.<\/li>\n<li><strong>Allow list<\/strong> \u2014 allow only the selected countries and block everyone else (e.g. \"only visitors from Austria, Germany and Switzerland may log in\").<\/li>\n<\/ul>\n\n<p>On top of that, every area can <strong>also block visitors who use a VPN service<\/strong> \u2014 regardless of which country their VPN server is in. Without this, anyone could get around a country rule with a VPN.<\/p>\n\n<p>Blocked visitors receive an HTTP 403 response with your custom message (basic HTML allowed).<\/p>\n\n<p><strong>Built-in safety rails:<\/strong><\/p>\n\n<ul>\n<li>Logged-in administrators are never geoblocked, so you cannot lock yourself out of a site you are logged in to.<\/li>\n<li>The WordPress admin and the login page are never affected by the <em>site access<\/em> rule \u2014 login blocking is its own explicit setting.<\/li>\n<li>Visitors whose country cannot be determined are never blocked.<\/li>\n<\/ul>\n\n<p><strong>Two free data sources, stored on your server:<\/strong><\/p>\n\n<ul>\n<li><strong>Country database (required)<\/strong> \u2014 the free IP2Location LITE country database (IPv4 + IPv6). It is <em>not<\/em> bundled: you create a free account at lite.ip2location.com, paste your personal download token into the settings, and the plugin downloads the database (a few MB) onto your server. It refreshes itself about once a month.<\/li>\n<li><strong>VPN list (optional)<\/strong> \u2014 the free <a href=\"https:\/\/github.com\/X4BNet\/lists_vpn\">X4BNet VPN list<\/a> (MIT license) with the IP ranges of the common VPN providers. Switch it on with one checkbox \u2014 no account or token needed. The plugin downloads it (about 200 KB) onto your server and refreshes it every week. Only needed if you use the <em>VPN<\/em> option of an area.<\/li>\n<\/ul>\n\n<p>Both updates run automatically and can be switched off at any time; the <em>Download \/ update databases now<\/em> button fetches both at once.<\/p>\n\n<p>Sites behind a CDN or reverse proxy can feed the real visitor IP (or a ready-made country code, e.g. from Cloudflare's <code>CF-IPCountry<\/code> header) into the plugin via the <code>wonderful_geoblocking_countries_client_ip<\/code> and <code>wonderful_geoblocking_countries_pre_country_code<\/code> filters.<\/p>\n\n<p>This plugin uses IP2Location LITE data available from https:\/\/lite.ip2location.com. The optional VPN list is provided by X4BNet (https:\/\/github.com\/X4BNet\/lists_vpn) under the MIT license.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to two external services. Both are only contacted to download data files onto your server; no data about your visitors is ever transmitted.<\/p>\n\n<p><strong>IP2Location (country database).<\/strong> The plugin downloads the IP2Location LITE geolocation database from www.ip2location.com. The download only happens when you actively configure it: you enter your personal download token and click the download button (afterwards a monthly scheduled refresh re-downloads the database with the same token). The token you obtained from your lite.ip2location.com account is sent to www.ip2location.com as part of the download request. This service is provided by IP2Location.com: <a href=\"https:\/\/www.ip2location.com\/terms\">terms of use<\/a>, <a href=\"https:\/\/www.ip2location.com\/privacy-policy\">privacy policy<\/a>.<\/p>\n\n<p><strong>GitHub (VPN list, optional).<\/strong> Only if you enable the <em>VPN list<\/em>, the plugin downloads the two text files of the X4BNet VPN list (<code>ipv4.txt<\/code> and <code>ipv6.txt<\/code> from https:\/\/github.com\/X4BNet\/lists_vpn) from raw.githubusercontent.com \u2014 when you click the download button and then once a week. The request contains no personal data besides the usual technical connection data (your server's IP address). This service is provided by GitHub, Inc.: <a href=\"https:\/\/docs.github.com\/en\/site-policy\/github-terms\/github-terms-of-service\">terms of service<\/a>, <a href=\"https:\/\/docs.github.com\/en\/site-policy\/privacy-policies\/github-general-privacy-statement\">privacy statement<\/a>.<\/p>\n\n<p>All lookups for your visitors (country and VPN) happen locally on your server against the downloaded files \u2014 visitor IP addresses never leave your site.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>wonderful-geoblocking-countries<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Create a free account at <a href=\"https:\/\/lite.ip2location.com\/\">lite.ip2location.com<\/a> and copy your download token.<\/li>\n<li>Go to <strong>Settings &gt; Geoblocking Countries<\/strong>, paste the token, save, and click <strong>Download \/ update database now<\/strong>.<\/li>\n<li>Optional: tick <em>VPN list<\/em>, save, and download again to also block VPN users.<\/li>\n<li>Pick the countries to block per area (and tick <em>VPN<\/em> where you want to block VPN users), write your block messages, done!<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"why%20is%20the%20geolocation%20database%20not%20included%20in%20the%20plugin%3F\"><h3>Why is the geolocation database not included in the plugin?<\/h3><\/dt>\n<dd><p>The IP2Location LITE database is free but published under its own license that requires every user to register for their own copy. The download with your personal token takes less than a minute and enables automatic monthly updates.<\/p><\/dd>\n<dt id=\"what%20happens%20while%20no%20database%20is%20installed%3F\"><h3>What happens while no database is installed?<\/h3><\/dt>\n<dd><p>Nothing \u2014 no visitor is blocked. The plugin shows an admin notice until a database is installed, and visitors whose country cannot be determined are always let through.<\/p><\/dd>\n<dt id=\"can%20i%20lock%20myself%20out%3F\"><h3>Can I lock myself out?<\/h3><\/dt>\n<dd><p>Not while you are logged in: administrators are always exempt from all three rules. Only the <em>login<\/em> rule can affect you when you are logged out and your own country is on its list \u2014 the settings page warns you about exactly that.<\/p><\/dd>\n<dt id=\"my%20site%20runs%20behind%20cloudflare%20or%20another%20proxy%20%E2%80%94%20the%20detected%20country%20is%20wrong.\"><h3>My site runs behind Cloudflare or another proxy \u2014 the detected country is wrong.<\/h3><\/dt>\n<dd><p>Behind a proxy, <code>REMOTE_ADDR<\/code> is the proxy's address, not the visitor's. Use the <code>wonderful_geoblocking_countries_client_ip<\/code> filter to supply the real client IP from a header you trust, or short-circuit the lookup entirely with <code>wonderful_geoblocking_countries_pre_country_code<\/code> (e.g. return the value of Cloudflare's <code>CF-IPCountry<\/code> header).<\/p><\/dd>\n<dt id=\"does%20blocking%20also%20apply%20to%20the%20rest%20api%20and%20feeds%3F\"><h3>Does blocking also apply to the REST API and feeds?<\/h3><\/dt>\n<dd><p>The <em>site access<\/em> rule runs on every frontend request, including feeds and the REST API. The WordPress admin (including admin-ajax) and wp-login.php are excluded from it.<\/p><\/dd>\n<dt id=\"how%20does%20vpn%20blocking%20work%2C%20and%20how%20reliable%20is%20it%3F\"><h3>How does VPN blocking work, and how reliable is it?<\/h3><\/dt>\n<dd><p>Tick <em>VPN list<\/em> under <em>Databases<\/em> and download it, then tick <em>VPN<\/em> in every area where VPN users should be blocked. A visitor whose IP lies in a range of a known VPN provider is then blocked \u2014 regardless of the country and even in allow-list mode (otherwise a VPN server in an allowed country would be a way in).<\/p>\n\n<p>The X4BNet list covers the IP ranges of the common commercial VPN providers and is updated daily. No free list catches every VPN, though: small or self-hosted VPNs, Tor and residential proxies are usually not included. Logged-in administrators are never blocked, VPN or not.<\/p><\/dd>\n<dt id=\"why%20not%20the%20ip2proxy%20lite%20database%3F\"><h3>Why not the IP2Proxy LITE database?<\/h3><\/dt>\n<dd><p>We tried it: the free IP2Proxy LITE edition only lists open public proxies \u2014 no VPN servers and no Tor exits (those are reserved for the paid edition) \u2014 and is more than 1 GB in size. The X4BNet list is a few hundred KB and actually recognises VPN providers.<\/p><\/dd>\n<dt id=\"can%20other%20plugins%20use%20the%20vpn%20list%3F\"><h3>Can other plugins use the VPN list?<\/h3><\/dt>\n<dd><p>Yes. Once the VPN list is installed:<\/p>\n\n<pre><code>$is_vpn = apply_filters( 'wonderful_geoblocking_countries_is_vpn_ip', null, $ip );\n<\/code><\/pre>\n\n<p>It returns <code>true<\/code> or <code>false<\/code>, and the default (<code>null<\/code>) while the VPN list is disabled or not installed.<\/p><\/dd>\n<dt id=\"is%20any%20visitor%20data%20sent%20to%20a%20third%20party%3F\"><h3>Is any visitor data sent to a third party?<\/h3><\/dt>\n<dd><p>No. Country lookups run locally against the downloaded database file. The only external request is the database download itself, which you trigger with your own token.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added: VPN blocking. Every area (site access, login, registration) can now also block visitors who use a VPN service, regardless of their country. It uses the free X4BNet VPN list (optional, about 200 KB, no token needed), which the plugin downloads onto your server and refreshes every week.<\/li>\n<li>Added: <code>wonderful_geoblocking_countries_is_vpn_ip<\/code> filter so other plugins can reuse the VPN list.<\/li>\n<li>Improved: the database section of the settings page is clearer \u2014 the required country database and the optional VPN list each show their own status, and one button updates both.<\/li>\n<li>Improved: the settings page shows whether your current IP is on the VPN list.<\/li>\n<li>Improved: downloaded databases are validated before they replace the installed file, and archives are unpacked without loading them into memory.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Fixed: the 1.0.2 release package was missing the bundled Select2 library (the build skipped the production dependencies), so the country lists on the settings page rendered as plain multi-select boxes. The build process now always ships it.<\/li>\n<li>Improved: mode, countries and block message of each area are now collapsible on the settings page \u2014 expanded while the area is enabled, collapsed otherwise (still one click away, so you can configure an area before switching it on). The page is much easier to read.<\/li>\n<li>Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Updated the bundled Select2 library from the 4.1.0 release candidate to the stable 4.1.0 release (now managed via Composer).<\/li>\n<li>Fixed the IP2Location terms-of-use link in the readme.<\/li>\n<li>Corrected the \"Tested up to\" header to a major.minor WordPress version.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Added a <code>wonderful_geoblocking_countries_country_for_ip<\/code> filter so other plugins can reuse the IP2Location country lookup.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Blocks site access, login, or registration for visitors from selected countries or VPN services, with a custom message per area.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/341024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=341024"}],"author":[{"embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wonderfulplugins"}],"wp:attachment":[{"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=341024"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=341024"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=341024"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=341024"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=341024"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/cn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=341024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}