IP and network rules
Block or allow IPv4, IPv6, and network ranges. Inspect local rules and cached blocklists to understand how an address will be handled.
Witen for Matomo
Control abusive requests, limit repeated login failures, and check files for unexpected changes. Manage IP rules, bot policies, and security activity from your Matomo dashboard.
Version 0.2.19. Free download after sign-in. Local protection works without enrollment or a paid plan.
Matomo On-Premise 5.13–5.x · PHP 8.1+ · Linux/Unix. Includes the PHP SDK; Composer is not required on your server.
Witen evaluates requests to Matomo, including its login and tracking endpoints. It protects the Matomo server itself; websites you track need their own security controls.
Block or allow IPv4, IPv6, and network ranges. Inspect local rules and cached blocklists to understand how an address will be handled.
Choose policies for named crawlers, AI services, and monitors. Set a category default, then make exceptions for the services you use.
Limit repeated failed logins and set a separate ban duration. Successful authentication clears the matching login limit.
See recent security events, block reasons, and daily blocked requests. Search the local log and compare up to 30 days of block counts.
Run local scans for suspicious code. Create a baseline from a trusted installation and compare it with later changes, without rewriting or deleting files.
Connect your account for shared IP blocklists and security updates. Check the connection in Diagnostics and choose separately whether to share security events.
Local rules, bundled bot policies, login limits, and the block chart work without connecting to Witen. If you want shared intelligence, enroll the plugin with a one-time token from your account.
Connecting includes security-event sharing, which is required to use the Witen service. The plugin explains what it sends before you connect. Warden is optional: use its local socket when you want the plugin to work with host protection.
See free and paid hosted plansplugins/Witen, then activate Witen in plugin administration.You need Matomo Super User access and writable private storage outside the web root. This release supports Matomo On-Premise 5.13 through 5.x; Matomo for WordPress and Matomo 6 are outside its compatibility range.