Blockary – Access Firewall

Blockary – Access Firewall

Details
View on WordPress

Blockary blocks visitors by country and stops password guessing on the login page.

The country rule works as a block list or as an allow list. You pick the countries on the settings page. The plugin reads the country from the Cloudflare header or from a local copy of the free “IP to Country Lite” database from DB-IP. Visitors from the whitelist, from private networks, and visitors with a valid login cookie always pass.

The login protection counts failed logins per address and per username. An address that reaches the limit gets a temporary ban. The ban time grows with each ban, and a permanent ban follows after a number of temporary bans. The plugin can also lock a username, show the same error for a wrong username and a wrong password, hide usernames from visitors, and turn off XML-RPC.

The plugin makes its blocking decision as soon as WordPress loads the plugins. Blocked requests do not reach the theme. A log on the settings page shows the blocked requests, the failed logins, and the bans.

Optional: run the decision before the other plugins

A small loader file in the folder wp-content/mu-plugins moves the decision before WordPress loads the other plugins. Blocked requests then cost less and stay invisible to the other plugins. The plugin does not write that file itself. You download it on the settings page and copy it into the folder by hand, for example with SFTP. The settings page shows the exact path. The loader runs the decision only while the plugin is active. Without the plugin it does nothing. When you delete the plugin, delete the loader file too. When the settings page shows “Outdated” for the loader, download the file again and replace the copy.

Recovery

If a rule locks you out, add this line to wp-config.php:

define( 'BLOCKARY_DISABLE', true );

The plugin then blocks nothing until you remove the line.

External services

The plugin downloads the country database “IP to Country Lite” from DB-IP when you select the local database as the country source. The download runs once after you select that source and then once a month through WP-Cron. You can also start it on the settings page.

The request goes to https://download.db-ip.com/free/. The request carries only the name of the database file for the current month. It carries no data about your site or your visitors. The database is licensed under CC BY 4.0. The settings page shows the attribution link that the license requires.

Terms and privacy policy of DB-IP: https://db-ip.com/about and https://db-ip.com/privacy.php

The plugin sends no other request to an external service.

Details

Plugin code:
blockary
Plugin version:
1.0.0
Author:
Outdated:
No
WP version:
6.4 or higher
PHP version:
8.1 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-10-05
Rating:
Times rated:
0
brute-force
country-block
firewall
login-protection
security