Advanced IP Blocker
by IniLerm 4.8 (25 reviews)

Advanced IP Blocker

A complete WordPress security firewall: blocks IPs, bots, countries & ASN. Includes an intelligent WAF, Threat Scoring, Geo-Challenge, and 2FA.

Advanced IP Blocker ranks #4,560 among WordPress.org plugins with 2,000+ active installations, is #332 of 4,529 in the Security category, a 4.8/5 rating from 25 reviews, and was last updated Sep 16, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.1
v8.13.8 Current Version v8.13.8
Updated 2 days ago Last Update on 16 Sep, 2026
Refreshed 11 hours ago Last Refreshed on
#332 of 4,529 in Security Top 10% by installs Downloads +35.7% this week Actively maintained
View on WordPress.org
Rank
#4,560
No change
Active Installs
2K+
-30.1%
KW Avg Position
22
2.6 worse
Downloads
89K
+24 today
Support Resolved
100%
No change
Rating
96%
Review 4.8 out of 5
4.8 (25 reviews)

Next Milestone 3K

Total Progress 91.9%
2K+ 3K+
318
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 81 more installs to reach 3K+

Rank Changes

4,550 4,567 4,584 4,600 4,617 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
4,544 4,574 4,604 4,633 4,663 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Current #4,560
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 200 400 600 800 1K 1.2K 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
0 200 400 600 800 1K 1.2K 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.8
25 reviews
Overall 96%
5
24 (96%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
1 (4%)

Support Threads Overview

Resolved
Unresolved
10
Total Threads
10
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

1 known vulnerability on record · 1 in the last 24 months · checked 1 month ago

  1. Advanced IP Blocker [advanced-ip-blocker] < 8.10.8

    CVE-2026-42739 · Fixed in v8.10.8

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and administrators who need to protect their site from malicious traffic. It blocks IPs, bots, countries, and ASNs while offering a web application firewall, threat scoring, geo-challenges, and two-factor authentication.

  • Web Application Firewall (WAF)
  • Threat Scoring system
  • Geo-Challenge for high-risk countries
  • Two-Factor Authentication (2FA)
  • Country & ASN Blocking
  • Cloudflare Edge Defense integration
  • File Integrity Monitor
  • AbuseIPDB Integration

Frequently Asked Questions

Common questions about Advanced IP Blocker

By default, all users with the Administrator role can access and configure Advanced IP Blocker. If you have multiple administrators but only want specific users to manage security settings, you can explicitly select them in the "Hardening & Core Protection" tab. The primary admin (ID 1) is always protected from lockouts. Other admins will not even see the "Security" menu.
Yes! In the "Hardening & Core Protection" section, you can enable "Block PHP in Uploads". The plugin will automatically place a specialized .htaccess file in your uploads directory to prevent any uploaded scripts from being executed, which is a common backdoor technique used by attackers.
This is a game-changing feature that automatically synchronizes your site's Web Application Firewall with our Central Security Server. Once a day, the plugin securely downloads the latest zero-day vulnerability signatures (e.g., for critical CVEs or widespread exploits) and injects them directly into the scanning engine. This means your site is protected instantly against new threats without waiting for a plugin update. Importantly, these rules run in a dedicated, invisible layer and will NEVER overwrite or interfere with your own custom WAF rules.
This feature automatically blocks incoming traffic from IP addresses that lack an Autonomous System Number (ASN) and Reverse DNS (rDNS) record. Since legitimate traffic almost always has these identifiers, Ghost IPs are often malicious actors trying to hide. Please note that this can cause false positives if a legitimate Internet Service Provider (ISP) has misconfigured their rDNS.
Our new Captcha Integrations allow you to seamlessly connect modern verification challenges like Cloudflare Turnstile and hCaptcha to your security modules. You can set a Global Default Engine and even apply different challenges granularly per module. To ensure your site never breaks, it includes a smart fallback to our invisible JS Challenge if your API keys are ever misconfigured or missing.
Instead of a single global rate limit for your entire site, Advanced Rules allow you to define custom limits for specific URLs or endpoints. You can define the maximum number of requests, the time window, and the specific action (like returning a 429 error, a 403 block, or triggering a Turnstile/hCaptcha challenge) for each endpoint independently. This is ideal for protecting sensitive areas like login pages or APIs with stricter limits while allowing normal traffic on the rest of the site.
This feature automatically engages a global JavaScript challenge to protect your server resources from massive spikes in malicious traffic. It monitors the number of blocks within a specific time window and, if the threshold is reached, it shields the entire site. Legitimate administrators, verified bots (like Googlebot), and explicitly excluded URLs are bypassed. You can configure the thresholds and notification preferences under Security > Settings > Core Protections.
It is a powerful built-in utility located in your Security menu (and top admin bar) that allows you to manually inspect any IP address or Autonomous System Number (ASN). It instantly cross-references the subject against your Geolocation databases, Threat Scoring system, AbuseIPDB, Spamhaus drops, and local whitelists/blocklists. It is the ultimate tool for investigating suspicious traffic or verifying if a legitimate user was blocked by a specific rule.
The scanner checks your site in two ways: Local Scan: Checks for outdated PHP versions, WordPress core updates, debug mode risks, and SSL status. This runs locally and instantly. Deep Scan (Vulnerability Audit): Checks your installed plugins and themes against our central database of known security vulnerabilities (CVEs). This process is manual (you click a button) to ensure it never slows down your site during normal operation.
The Audit Log is your site's "black box". It records critical administrative actions such as plugin activations, settings changes, and file modifications. This helps you identify "who did what and when," which is essential for troubleshooting and security forensics.

Sign In / Register

You need to sign in or register to use this feature.