Skip to content
WordPress.org

هزاره گی

  • Themes
  • Plugins
  • News
  • About
  • Contact
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

WTB Firewall

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

WTB Firewall

By wtbplugins
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

WTB Firewall is a lightweight but powerful WordPress firewall plugin designed to help you protect your site from unwanted visitors, brute-force attacks and malicious traffic.

The plugin allows you to define clear access rules, automatically block suspicious behaviour, and correctly detect real visitor IP addresses even when your site is behind a proxy or CDN.

Core Features

  • Manual IP allow and block rules
  • Country-based access control
  • Automatic blocking after repeated authentication failures
  • Built-in rate limiting to protect your site from excessive requests and abuse
  • 404 monitoring to detect and block traffic generating repeated missing-page errors
  • Proxy support with trusted header detection
  • Lightweight design with minimal performance impact
  • Clean WordPress-native admin interface

Why use WTB Firewall?

Many WordPress security plugins include dozens of features that add complexity and overhead. WTB Firewall focuses on essential firewall functionality so you can:

  • Stop brute-force login attempts
  • Restrict access from unwanted regions
  • Block abusive visitors quickly
  • Ensure accurate IP detection behind proxies or CDNs
  • Keep your site fast while improving security

Designed for Performance

WTB Firewall is built with performance and reliability in mind. Rules are processed efficiently, unnecessary background tasks are avoided, and the plugin integrates cleanly with WordPress without slowing down your site.

Screenshots

Easily block or allow connections from any country.
Easily block or allow connections from any country.
Automatic blocking configuration for repeated authentication failures.
Automatic blocking configuration for repeated authentication failures.
Manual IP allow and block configuration screen.
Manual IP allow and block configuration screen.

Installation

  1. Upload the plugin files to the /wp-content/plugins/wtb-firewall directory, or install the plugin through the WordPress plugins screen.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open the firewall settings from the WordPress admin menu.
  4. Review the included quickstart guide to configure the firewall safely and correctly for your setup.

FAQ

Does this plugin slow down my site?

No. WTB Firewall is designed to be lightweight and focuses only on essential firewall functionality. It avoids heavy scans, background tasks and unnecessary processing.

Can I block specific IP addresses?

Yes. You can manually allow or block individual IP addresses directly from the plugin settings.

Can I block visitors from specific countries?

Yes. The plugin supports country-based access rules so you can restrict or allow traffic from selected regions.

Does the plugin protect against brute-force login attacks?

Yes. WTB Firewall can automatically block visitors who fail authentication too many times within a defined period.

Will this work if my site is behind Cloudflare or another CDN?

Yes. The plugin supports proxies. It can detect real visitor IP addresses using trusted headers when your site is behind services like Cloudflare or load balancers.

Can users fake their IP address through headers?

The plugin includes proxy handling logic and trusted header settings to help prevent IP spoofing and ensure accurate detection when proxies are used.

Is this a full security suite like some other plugins?

No. WTB Firewall focuses specifically on firewall functionality. It does not include malware scanning or file integrity checks, which keeps it lightweight and efficient.

Where can I get support?

You can ask questions in the WordPress.org support forum for this plugin. A quickstart guide is included to help you get started, and full documentation will be published on our website in the near future.

Reviews

Simple, efficient and practical and light

wpdanilo ژوئن 18, 2026
Wtb Firewall does everything it says on the tin: it filters out “annoying” IPs, imposes a general access limit, 404 errors, searches for obtuse bots and does it efficiently and simply, without weighing down Wordpress. Thanks for this software!
Read all 1 review

Contributors & Developers

“WTB Firewall” is open source software. The following people have contributed to this plugin.

Contributors
  • wtbplugins

Translate “WTB Firewall” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.2

  • Updated the included country IP database.

1.1.1

  • Moved generating country rules to a wp-cron job.

1.1

  • Added rate limiting to restrict excessive requests from a single IP.
  • Added 404 monitoring to detect and block IPs generating excessive 404 errors.

1.0.1

  • Minor improvements to WAF script

1.0.0

  • Initial release

Meta

  • Version 1.1.2
  • Last updated 1 هفته ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.0
  • PHP version 8.1 or higher
  • Language
    English (US)
  • Tags
    brute force protectionfirewallIP-blockinglogin protectionsecurity
  • Advanced View

Ratings

5 out of 5 stars.
  • 1 5-star review 5 stars 1
  • 0 4-star reviews 4 stars 0
  • 0 3-star reviews 3 stars 0
  • 0 2-star reviews 2 stars 0
  • 0 1-star reviews 1 star 0

Your review

See all reviews

Contributors

  • wtbplugins

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

هزاره گی

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
رمز شعر است.
The WordPress® trademark is the intellectual property of the WordPress Foundation.