Block or allow by country
Block visitors from the countries you list, or allow only listed countries and block everyone else. Each mode keeps its own list in a searchable country picker, so a block list never turns into an allow list by accident.
DevDome Country Blocker blocks visitors from listed countries or allows only the countries you list. It reads verified Cloudflare country headers or a free local DB-IP database, lets you test a list before it blocks anyone and keeps your own access safe.
Free and GPL licensed, reviewed by the WordPress.org plugin team.
Choose a block list or an allow list, pick how the country is detected and decide what blocked visitors see. Safety exemptions keep administrators, search engines and your own address in.
Block visitors from the countries you list, or allow only listed countries and block everyone else. Each mode keeps its own list in a searchable country picker, so a block list never turns into an allow list by accident.
Behind Cloudflare the plugin reads the country header only after checking that the connecting address belongs to a published Cloudflare edge range. No setting is needed and a forged header is ignored.
Download the free DB-IP country database with one click in Settings. It covers IPv4 and IPv6, lookups run on your server during a visit and a daily scheduled check refreshes it monthly. No external lookup request per visitor.
Turn on Test Mode and every visitor gets through while the requests that would have been blocked are logged and marked Test. Review them in Recent Blocked Hits, then turn Test Mode off to start blocking.
Blocked visitors see a plain 403 page with your own message, or are redirected to another website. The response is sent with no-cache headers and a noindex tag.
wp-admin is never blocked, logged-in users are exempt from front-end blocking by default and Always Allowed Addresses accepts single addresses and CIDR ranges for IPv4 and IPv6. A save that would lock you out of the login page is refused.
List your own reverse proxy or load balancer under Trusted Proxies, trust CloudFront or Vercel headers when the site runs there, exempt Google, Bing, DuckDuckGo and Apple crawlers with one checkbox, and apply the rules to wp-login.php and xmlrpc.php with separate settings.
Overview tiles show blocked requests today and over 7 and 30 days, Top Blocked Countries and the last 200 hits with anonymized addresses. On WordPress 6.9 or newer, 8 abilities let authorised AI agents read status, change settings, look up a country and clear statistics.
Pick a detection source, choose a mode and countries, test the list, then enforce it.
Install DevDome Country Blocker from WordPress.org and activate it. Open DevDome Tools > Country Blocker. Behind Cloudflare nothing more is needed; otherwise download the free local database in Settings.
Pick Block listed countries or Allow listed countries only, add countries in the picker and choose the 403 message or a redirect. Add your own address to Always Allowed Addresses.
Turn on Test Mode and save. Check Recent Blocked Hits for rows marked Test. When the list looks right, turn Test Mode off and save to start blocking.
Behind Cloudflare it reads the country header after verifying the connection comes from a Cloudflare edge range. Otherwise it searches the free local DB-IP database you download in Settings. Behind your own proxy, list the proxy under Trusted Proxies so X-Forwarded-For is believed. CloudFront and Vercel headers are read only when you turn on Proxy Headers.
wp-admin is never blocked and logged-in users are exempt from front-end blocking by default. Login blocking is off by default, and a settings save that would block your own detected country from the login page without an allowed address is refused. If you still lose access, add define('DEVDCOUN_DISABLE', true); to wp-config.php to switch all blocking off.
Choose your mode and countries, enable Test Mode and save. Every visitor gets through and the requests that would have been blocked appear in Recent Blocked Hits marked Test. They are not counted as blocked. Turn Test Mode off and save to enforce the list.
They are always allowed, including in allow-only mode. Without a country there is no basis to block, and a lookup gap must never take your site offline for real visitors.
Country detection checks headers or searches the local database files on your server. It makes no external lookup request during a visit. A blocked hit writes a counter and a log entry.
Only requests that reach WordPress are checked. Cached pages served before WordPress runs bypass the plugin. When those responses also need blocking, configure country rules at the cache, CDN or firewall. The plugin does not block at the CDN edge.
Yes. Each site keeps its own settings, country lists, database and statistics, so configure each site separately.
No account or licence key is needed for country blocking, and the local DB-IP Lite database is free. The database download comes from db-ip.com and the Cloudflare address ranges from cloudflare.com. The shared DevDome dashboard fetches the plugin catalog, and an optional account connection or an error report you submit contacts DevDome.
Everything you need before you install, with no account required.
Install DevDome Country Blocker from WordPress.org (Plugins, Add New, search for DevDome Country Blocker) or upload the ZIP, then activate it.
No account is needed for country blocking. Connecting a free DevDome account through the DevDome Tools dashboard is optional.
Open DevDome Tools > Country Blocker. Behind Cloudflare the country header is read automatically after the connecting address is verified against the Cloudflare ranges. On any other hosting, download the free local DB-IP database with one click in Settings; it covers IPv4 and IPv6 and refreshes monthly.
Choose Block listed countries or Allow listed countries only, add countries in the picker and choose what blocked visitors get: a 403 page with your message or a redirect to another website. Put your own address on Always Allowed Addresses.
Turn on Test Mode and save: nobody is blocked and the requests that would have been blocked appear in Recent Blocked Hits marked Test. Turn Test Mode off and save to enforce the list. Login and XML-RPC blocking are separate settings, both off by default.
Country detection makes no external request during a visit: it reads a verified Cloudflare header or searches the local database files on your server. The log keeps about the last 200 blocked hits with anonymized addresses (IPv4 keeps the first three numbers, IPv6 the first 48 bits), the path without its query string and the user agent.
The local database is downloaded from db-ip.com (about 10 MB) when you install it and on the monthly refresh; the Cloudflare edge ranges are fetched from cloudflare.com. The shared DevDome Dashboard fetches the plugin catalog from devdome.com, sending only the bundled core version. Pressing Report this error sends DevDome the error text, site address and plugin version.
Optional account connection sends your site address, a generated site ID and a generated secret site token to DevDome. Subsequent account checks send the same identifiers. Nothing about your visitors is sent to DevDome.
Updates for the WordPress.org edition come only from WordPress.org, like any other directory plugin. This edition contains no self-hosted updater.
Deactivating stops all blocking while preserving settings and statistics. Deleting the plugin removes its statistics tables, settings, cached summary, database metadata, build lock, scheduled tasks and the downloaded database files, for every site on multisite.
The Overview says blocking is inactive or shows No country source: no usable country source is available. Install the local database or check the Cloudflare setup. Without a country every visitor is allowed. Off mode, an empty active list and Test Mode also show blocking as inactive.
Behind Nginx, Varnish or a load balancer every visitor shows the same address: list the proxy's addresses or ranges under Trusted Proxies and have it supply X-Forwarded-For. Your Connection on the Overview shows the address the plugin sees. Cloudflare needs no Trusted Proxies entry.
Blocked visitors still see cached pages: pages served by a cache or CDN before WordPress runs bypass the plugin. Add the country rule at the cache, CDN or firewall as well.
You are locked out of the login page: add define('DEVDCOUN_DISABLE', true); to wp-config.php, log in, add your address to Always Allowed Addresses and remove the line.
Still stuck? Ask on the WordPress.org support forum or use the DevDome contact form. For a security problem, use the Report a security issue tab instead.
Read from the live release feed, so it always describes the version you can download today.
Please tell us before telling anyone else, and we will fix it and credit you if you want the credit. Use the contact form and say it is a security report, so it gets read first.
We are a small team, so we will not pretend to a 24/7 security desk or a guaranteed response time. We will read it, reply, and tell you honestly what we are doing about it.
Install DevDome Country Blocker from WordPress.org, activate it and open DevDome Tools > Country Blocker to choose your countries and test the list.