Advanced IP Blocker

Por IniLerm
(11 avaliações)
Baixar
  • Versão:
    8.8.2
  • Última atualização:
    há 9 dias
  • Instalações ativas:
    mais de 800
  • Versão do WordPress:
    6.7 ou maior
  • Testado até o WordPress:
    6.9.1
  • Versão do PHP:
    8.1 ou maior
  • Tags:

Hospedagem WordPress com plugin Advanced IP Blocker

Onde devo hospedar o plugin Advanced IP Blocker?

Este plugin pode ser hospedado em qualquer hospedagem que possua WordPress configurado. Recomendamos fortemente utilizar uma hospedagem seguro, com servidores otimizados para WordPress, como o serviço de hospedagem de sites da MCO2.

Hospedando o plugin Advanced IP Blocker em um provedor seguro

A MCO2, além de configurar e instalar o WordPress na versão mais atual para seus clientes, disponibiliza o plugin WP SafePress, um mecanismo exclusivo que protege e melhora seu site conjuntamente.

Por que a Hospedagem WordPress funciona melhor na MCO2?

A Hospedagem WordPress funciona melhor pois a MCO2 possui servidores otimizados para WordPress. A instalação de WordPress é diferente de uma instalação trivial, pois habilita imediatamente recursos como otimização automática de imagens e fotos, proteção da página de login, bloqueio de atividades suspeitas diretamente no firewall, cache avançado e HTTPS ativado por padrão. São recursos que potencializam seu WordPress para a máxima segurança e o máximo desempenho.

Advanced IP Blocker is your all-in-one security solution to safeguard your WordPress website from a wide range of threats. This plugin provides a comprehensive suite of tools to automatically detect and block malicious activity, including brute-force attacks, vulnerability scanning, and spam bots. With its intuitive interface, you can easily manage whitelists, blocklists, and view detailed security logs to understand exactly how your site is being protected.

Important Note on PHP Version:
To ensure maximum security and access to all features, we strongly recommend using PHP 8.1 or higher. Some advanced features (like the local MaxMind database or full 2FA management via WP-CLI) require PHP 8.1.

Key Features:
* (NEW) Internal Security & Forensics: A complete audit suite solely for WordPress. Track every sensitive event (plugin installs, settings changes, user logins) and monitor your critical files for unauthorized modifications with the integrated File Integrity Monitor.
* (NEW) Activity Audit Log: Gain complete visibility into what’s happening on your site. Who deactivated a plugin? Who changed a setting? The Audit Log answers these questions with timestamped, immutable records.
* (NEW) Deep Scan Email Reports: Get a weekly security summary delivered to your inbox, detailing pending updates, vulnerability status, and recent attack trends.
* Username Blocking & Rules: Gain granular control over login security. Creating Advanced Rules to block, challenge, or score specific usernames (e.g., “admin”, “test”).
* Enhanced Lockdown Notifications: Distributed Lockdowns (404/403) now fully support Email and Push notifications, ensuring you never miss a critical security event.
* Improved Logging: New “Endpoint Challenge” event type provides deeper visibility into challenges served during automated lockdowns.
* Server IP Reputation Check. Instantly audit your web server’s IP address against major blacklists (Spamhaus, AbuseIPDB) to diagnose SEO and email delivery issues.
* **HTTP Security Headers.
Easily configure essential security headers like HSTS, X-Frame-Options, and Permissions-Policy to harden your site against clickjacking, sniffing, and other browser-based attacks. Includes a “Report-Only” mode for CSP.
* Site Health & Vulnerability Scanner. Audit your WordPress environment instantly. Detects outdated plugins, insecure PHP versions, and checks your installed plugins against a database of 30,000+ known vulnerabilities.
* **PERFORMANCE BOOST: High-Speed Community Database. Migrated the “Community Defense Network” blocklist to a dedicated, indexed database table. This allows checking thousands of malicious IPs in microseconds with zero impact on site memory usage.
* **WordPress 6.9 Ready. Fully tested and compatible with the latest WordPress core update.
* **Community Defense Network. Join forces with other WordPress admins. The plugin now shares anonymous attack data to build a global, real-time blocklist of verified threats. Protect your site with community-powered intelligence.
* **Auto-Cleaning Logic. Smart expiration handling ensures your blocklists stay fresh and performant, automatically removing stale IPs from both the database and external firewalls (Cloudflare/.htaccess).
* **Cloud Edge Defense (Cloudflare). Connect your site directly to Cloudflare’s global network. Automatically sync your blocklists to the cloud to stop attackers before they reach your server. Zero server load protection.
* **Server-Level Firewall (.htaccess). Extreme performance upgrade. Write blocking rules and file hardening protections directly to your .htaccess file. Blocks threats instantly without loading PHP or WordPress.
* **IMPROVED: Smart Bot Verification. Enhanced logic to correctly identify legitimate traffic from iOS devices (iCloud Private Relay) and social media previews, eliminating false positives while keeping impostors out.
* **File Hardening.
Protect your most sensitive files (wp-config.php, readme.html, .git) at the server level with a single click.
* AbuseIPDB Integration. Proactively block attackers before they strike. The plugin can now check visitor IPs against AbuseIPDB’s real-time, crowdsourced database of malicious IPs and block those with a high abuse score on their very first request.
* Edge Firewall Mode! Protect any PHP file or standalone application within your WordPress directory (even if it’s not part of WordPress). Ideal for securing custom scripts, legacy applications, or folders like /scan/. (Requires manual configuration).
* Advanced Rules Engine! Create powerful, custom security rules with multiple conditions (IP, Country, ASN, URI, User-Agent) and actions (Block, Challenge, or add Threat Score).
* Known Bot Verification. A powerful new security layer that uses reverse DNS lookups to verify legitimate crawlers like Googlebot and Bingbot. This completely neutralizes attackers who try to bypass security rules by faking their User-Agent, assigning high threat scores to impostors.
* Onboarding Setup Wizard. A brand new step-by-step wizard that guides new users through the essential security configurations (IP whitelisting, WAF, and bot traps) in under a minute, ensuring a strong security posture from day one.
* Major Refactor: Codebase Modernization. The entire plugin architecture has been refactored into a modern, modular structure. Logic for admin pages, AJAX, actions, and settings is now handled by dedicated classes, making the plugin more stable, performant, and easier to maintain and extend in the future.
* Advanced IP Spoofing Protection. A zero-trust “Trusted Proxies” system ensures the plugin always identifies the true visitor IP, even behind complex setups like Cloudflare or a custom reverse proxy. It neutralizes attacks that attempt to fake their IP, preventing block evasion and the framing of innocent users.
* Geo-Challenge. A smarter way to handle traffic from high-risk countries. Instead of a hard block, it presents a quick, invisible JavaScript challenge that stops bots but is seamless for human visitors. This reduces unwanted traffic without affecting potential legitimate users.
* ENHANCEMENT: Full Bulk-Action Support. IP management is now faster than ever. Both the Whitelist and the Blocked IPs list now support full bulk actions, allowing you to select and remove multiple entries at once, or unblock all IPs with a single click.
* Endpoint Lockdown Mode: Automatically shields wp-login.php and xmlrpc.php with a JavaScript challenge during sustained distributed attacks, preventing server overload.
* Two-Factor Authentication (2FA): Secure user accounts with industry-standard TOTP authentication, backup codes, role enforcement, and a central admin management dashboard.
* IP Trust & Threat Scoring System: An intelligent defense that assigns “threat points” to IPs for malicious actions, blocking them only when they reach a configurable score. More accurate and context-aware than simple rules.
* Attack Signature Engine (Beta): Proactively stops distributed botnet attacks by identifying and blocking the attacker’s “fingerprint” (signature) instead of just individual IPs.
* Web Application Firewall (WAF): Block malicious requests (SQLi, XSS, etc.) with a customizable ruleset.
* And much more: Rate Limiting, Country & ASN Blocking (with Spamhaus support), ASN Whitelisting, Push Notifications, Google reCAPTCHA, Honeypots, Active User Session Management, and Full WP-CLI Support.

Capturas de tela

The new Security Dashboard with real-time charts and a Live Attack Map.

The new Security Dashboard with real-time charts and a Live Attack Map.

Modern and intuitive two-level navigation system for easy access to all features.

Modern and intuitive two-level navigation system for easy access to all features.

The main Settings page to configure all protection modules like WAF and Rate Limiting.

The main Settings page to configure all protection modules like WAF and Rate Limiting.

Powerful Web Application Firewall (WAF) with recommended rules.

Powerful Web Application Firewall (WAF) with recommended rules.

Block entire networks with ASN Blocking, powered by the Spamhaus list.

Block entire networks with ASN Blocking, powered by the Spamhaus list.

Detailed Blocked IPs table with the

Detailed Blocked IPs table with the "View Map" modal in action.

Country Blocking (Geoblocking) and Geo-Challenge with user-friendly selectors and smart warnings.

Country Blocking (Geoblocking) and Geo-Challenge with user-friendly selectors and smart warnings.

Unified Security Log with a powerful filter to analyze all attack events.

Unified Security Log with a powerful filter to analyze all attack events.

Active User Session Management to monitor and terminate logged-in users.

Active User Session Management to monitor and terminate logged-in users.

Full WP-CLI support documentation, accessible from the

Full WP-CLI support documentation, accessible from the "About" tab.

An example of a professional HTML email notification.

An example of a professional HTML email notification.

The new

The new "Trusted Proxies" setting for advanced anti-spoofing protection.

IP Trust & Threat Scoring System.

IP Trust & Threat Scoring System.

Attack Signature Engine (Beta).

Attack Signature Engine (Beta).

The new Two-Factor Authentication (2FA) setup section in the user profile.

The new Two-Factor Authentication (2FA) setup section in the user profile.

The 2FA Management tab for administrators, showing user status and reset actions.

The 2FA Management tab for administrators, showing user status and reset actions.

The 2FA prompt on the WordPress login screen after entering a correct password.

The 2FA prompt on the WordPress login screen after entering a correct password.

The new HTTP Security Headers manager.

The new HTTP Security Headers manager.

The new AIB Network manager.

The new AIB Network manager.

The new AbuseIPDB Api manager.

The new AbuseIPDB Api manager.

Plugins semelhantes

Wordfence Security – Firewall, Malware Scan, and Login Security
(4.748 avaliações)

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.

Really Simple Security – Segurança simples e eficiente (anteriormente Really Simple SSL)
(8.793 avaliações)

Melhore facilmente a segurança do site com o reforço de segurança do WordPress, autenticação de dois fatores (2FA), proteção de acesso, detecção de vulnerabilidades e geração de certificados SSL.

Jetpack – WP Security, Backup, Speed, & Growth
(2.373 avaliações)

Aprimore sua segurança no WP com ferramentas avançadas de um clique, como backup, WAF e verificação de malware. Inclui as ferramentas essenciais gratuitas como estatísticas, CDN e compartilhamento em redes sociais.

Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
(1.423 avaliações)

Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.

Loginizer
(1.014 avaliações)

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

All-In-One Security (AIOS) – Security and Firewall
(1.685 avaliações)

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.