Deerwood Country Access makes geographic access control easy to manage from WordPress.
Choose which countries may access your site, detect and rate-limit repeat offenders, and optionally connect Cloudflare with a one-click OAuth authorization so unwanted traffic can be stopped at the edge before it reaches WordPress.
New installations are preconfigured for “Allow selected countries only” with Canada and the United States selected. Protection remains OFF until an administrator enables it.
CF-IPCountry detection when available.Country Access is focused on geographic and IP access control. It does not replace a complete WordPress malware scanner or security suite.
Country Access can restrict access to your website at both the WordPress and Cloudflare edge levels. Incorrect country, IP, or Cloudflare rule settings can prevent you or other legitimate visitors from reaching the site.
Before enabling or changing protection, confirm that your own country is allowed and consider using the administrator safety window and trusted IP features. If you intentionally block your current country, make sure you have another recovery method available.
Country Access includes safeguards intended to reduce accidental lockouts, but no safeguard can guarantee access under every hosting, proxy, network, Cloudflare, or configuration scenario. Site administrators are responsible for reviewing and testing their access rules and maintaining appropriate backups and recovery access.
Country Access is provided without warranty, to the extent permitted by applicable law. Deerwood Media and the plugin contributors are not responsible for website downtime, lost traffic, lost revenue, data loss, third-party service behavior, or other damages resulting from the installation, configuration, use, or inability to use the plugin.
This notice does not replace or limit the terms of the GPL license.
Country Access can communicate with external services. These integrations are documented here so site owners know when data leaves the WordPress installation.
Cloudflare integration is optional and begins only after an administrator explicitly clicks the Cloudflare authorization control and approves the requested permissions.
Country Access uses Cloudflare for country information supplied in request headers and, when authorized, to identify the site’s Cloudflare zone and create/update/remove the plugin’s managed WAF protection rule. OAuth tokens and Cloudflare zone/account identifiers are stored in the WordPress database.
Cloudflare:
https://www.cloudflare.com/
Cloudflare Privacy Policy:
https://www.cloudflare.com/privacypolicy/
Cloudflare Terms:
https://www.cloudflare.com/website-terms/
Country Access is an independent plugin and is not affiliated with or endorsed by Cloudflare, Inc.
To provide the one-click Cloudflare connection, Country Access sends the administrator through the publisher-operated OAuth relay at:
https://auth.deerwoodmedia.com/
During an OAuth connection, the relay receives OAuth/PKCE transaction data, the WordPress return URL, and the site’s hostname so it can complete the Cloudflare authorization flow and return the administrator to the correct WordPress site. The relay is used only when an administrator explicitly starts Cloudflare authorization.
The relay is operated by Deerwood Media:
https://deerwoodmedia.com/
When an administrator explicitly enables the geolocation fallback and Cloudflare does not provide a usable country code, Deerwood Country Access sends the visitor IP address to the IPWhois ipwho.is service to determine a country code. Results are cached in WordPress for seven days to reduce repeat requests.
IPWhois:
https://ipwhois.io/
IPWhois Privacy Policy:
https://ipwhois.io/privacy
IPWhois Terms of Service:
https://ipwhois.io/terms
Site owners should review the external-service policies and their own privacy obligations before enabling features that process visitor IP addresses.
Country Access can store security-event information, including visitor IP addresses, in the local WordPress database when logging is enabled. Exact IP addresses are required for repeat-offender detection, local rate limiting, trusted-IP handling, and optional Cloudflare edge blocking.
Detailed logs are automatically removed according to the configured retention period. The default retention period is 30 days.
When the administrator explicitly enables fallback geolocation and Cloudflare does not provide a country code, the visitor IP address is sent to IPWhois to determine the country. Results are cached locally for seven days.
When an administrator explicitly connects Cloudflare, Country Access stores the resulting OAuth credentials and Cloudflare zone/account identifiers in the WordPress database so it can manage the Country Access edge-protection rule.
Country Access 1.0 does not send blocked-request logs or repeat-offender telemetry to a central Country Access threat database.