DevDome Country Blocker WordPress plugin

Control who reaches your site, by country

DevDome Country Blocker blocks visitors from listed countries or allows only the countries you list. It reads verified Cloudflare country headers or a free local DB-IP database, lets you test a list before it blocks anyone and keeps your own access safe.

Free and GPL licensed, reviewed by the WordPress.org plugin team.

No account needed for country blocking
IPv4 + IPv6 in the free local database
Monthly automatic database refresh
8 AI abilities on WordPress 6.9 or newer

Geo blocking that you can try before it blocks

Choose a block list or an allow list, pick how the country is detected and decide what blocked visitors see. Safety exemptions keep administrators, search engines and your own address in.

Block or allow by country

Block visitors from the countries you list, or allow only listed countries and block everyone else. Each mode keeps its own list in a searchable country picker, so a block list never turns into an allow list by accident.

Verified Cloudflare detection

Behind Cloudflare the plugin reads the country header only after checking that the connecting address belongs to a published Cloudflare edge range. No setting is needed and a forged header is ignored.

Free local GeoIP database

Download the free DB-IP country database with one click in Settings. It covers IPv4 and IPv6, lookups run on your server during a visit and a daily scheduled check refreshes it monthly. No external lookup request per visitor.

Test Mode before enforcing

Turn on Test Mode and every visitor gets through while the requests that would have been blocked are logged and marked Test. Review them in Recent Blocked Hits, then turn Test Mode off to start blocking.

A 403 page or a redirect

Blocked visitors see a plain 403 page with your own message, or are redirected to another website. The response is sent with no-cache headers and a noindex tag.

Keep your own access

wp-admin is never blocked, logged-in users are exempt from front-end blocking by default and Always Allowed Addresses accepts single addresses and CIDR ranges for IPv4 and IPv6. A save that would lock you out of the login page is refused.

Proxies, crawlers and optional login blocking

List your own reverse proxy or load balancer under Trusted Proxies, trust CloudFront or Vercel headers when the site runs there, exempt Google, Bing, DuckDuckGo and Apple crawlers with one checkbox, and apply the rules to wp-login.php and xmlrpc.php with separate settings.

Statistics and AI abilities

Overview tiles show blocked requests today and over 7 and 30 days, Top Blocked Countries and the last 200 hits with anonymized addresses. On WordPress 6.9 or newer, 8 abilities let authorised AI agents read status, change settings, look up a country and clear statistics.

From installation to a tested country list

Pick a detection source, choose a mode and countries, test the list, then enforce it.

  1. 1

    Install and pick a country source

    Install DevDome Country Blocker from WordPress.org and activate it. Open DevDome Tools > Country Blocker. Behind Cloudflare nothing more is needed; otherwise download the free local database in Settings.

  2. 2

    Choose a mode and your countries

    Pick Block listed countries or Allow listed countries only, add countries in the picker and choose the 403 message or a redirect. Add your own address to Always Allowed Addresses.

  3. 3

    Test, then enforce

    Turn on Test Mode and save. Check Recent Blocked Hits for rows marked Test. When the list looks right, turn Test Mode off and save to start blocking.

Frequently asked questions

How does the plugin know a visitor's country?

Behind Cloudflare it reads the country header after verifying the connection comes from a Cloudflare edge range. Otherwise it searches the free local DB-IP database you download in Settings. Behind your own proxy, list the proxy under Trusted Proxies so X-Forwarded-For is believed. CloudFront and Vercel headers are read only when you turn on Proxy Headers.

Can I lock myself out?

wp-admin is never blocked and logged-in users are exempt from front-end blocking by default. Login blocking is off by default, and a settings save that would block your own detected country from the login page without an allowed address is refused. If you still lose access, add define('DEVDCOUN_DISABLE', true); to wp-config.php to switch all blocking off.

How do I test my list before it blocks anyone?

Choose your mode and countries, enable Test Mode and save. Every visitor gets through and the requests that would have been blocked appear in Recent Blocked Hits marked Test. They are not counted as blocked. Turn Test Mode off and save to enforce the list.

What happens to a visitor whose country is unknown?

They are always allowed, including in allow-only mode. Without a country there is no basis to block, and a lookup gap must never take your site offline for real visitors.

Does it slow my site down?

Country detection checks headers or searches the local database files on your server. It makes no external lookup request during a visit. A blocked hit writes a counter and a log entry.

Does it work with a caching plugin or a CDN?

Only requests that reach WordPress are checked. Cached pages served before WordPress runs bypass the plugin. When those responses also need blocking, configure country rules at the cache, CDN or firewall. The plugin does not block at the CDN edge.

Does it work on multisite?

Yes. Each site keeps its own settings, country lists, database and statistics, so configure each site separately.

Do I need an account, and does it contact external services?

No account or licence key is needed for country blocking, and the local DB-IP Lite database is free. The database download comes from db-ip.com and the Cloudflare address ranges from cloudflare.com. The shared DevDome dashboard fetches the plugin catalog, and an optional account connection or an error report you submit contacts DevDome.

Documentation

Everything you need before you install, with no account required.

Installing

Install DevDome Country Blocker from WordPress.org (Plugins, Add New, search for DevDome Country Blocker) or upload the ZIP, then activate it.

No account is needed for country blocking. Connecting a free DevDome account through the DevDome Tools dashboard is optional.

Setting it up

Open DevDome Tools > Country Blocker. Behind Cloudflare the country header is read automatically after the connecting address is verified against the Cloudflare ranges. On any other hosting, download the free local DB-IP database with one click in Settings; it covers IPv4 and IPv6 and refreshes monthly.

Choose Block listed countries or Allow listed countries only, add countries in the picker and choose what blocked visitors get: a 403 page with your message or a redirect to another website. Put your own address on Always Allowed Addresses.

Turn on Test Mode and save: nobody is blocked and the requests that would have been blocked appear in Recent Blocked Hits marked Test. Turn Test Mode off and save to enforce the list. Login and XML-RPC blocking are separate settings, both off by default.

Install Country Blocker from WordPress.org

Install DevDome Country Blocker from WordPress.org, activate it and open DevDome Tools > Country Blocker to choose your countries and test the list.

More from the DevDome suite

All plugins
DevDome Analytics: Visitor Tracker, Site Stats & Bot Detection
Visitor tracking statistics: site stats, visitor stats, pageviews, sources, bot detection and outbound click reports. Free DevDome account required.
DevDome Site Monitor
One health score for every WordPress site, with alerts before visitors notice.
DevDome Bot Protection
Detect and block bad bots without ever touching the good ones that rank you.