Skip to content

Witen for Matomo

Security for your Matomo server

Control abusive requests, limit repeated login failures, and check files for unexpected changes. Manage IP rules, bot policies, and security activity from your Matomo dashboard.

Version 0.2.19. Free download after sign-in. Local protection works without enrollment or a paid plan.

Matomo On-Premise 5.13–5.x · PHP 8.1+ · Linux/Unix. Includes the PHP SDK; Composer is not required on your server.

Control requests to Matomo

Witen evaluates requests to Matomo, including its login and tracking endpoints. It protects the Matomo server itself; websites you track need their own security controls.

IP and network rules

Block or allow IPv4, IPv6, and network ranges. Inspect local rules and cached blocklists to understand how an address will be handled.

Choose which bots to allow

Choose policies for named crawlers, AI services, and monitors. Set a category default, then make exceptions for the services you use.

Login protection

Limit repeated failed logins and set a separate ban duration. Successful authentication clears the matching login limit.

Review blocked requests

See recent security events, block reasons, and daily blocked requests. Search the local log and compare up to 30 days of block counts.

Check files for unexpected changes

Run local scans for suspicious code. Create a baseline from a trusted installation and compare it with later changes, without rewriting or deleting files.

Optional shared intelligence

Connect your account for shared IP blocklists and security updates. Check the connection in Diagnostics and choose separately whether to share security events.

Start with local protection

Local rules, bundled bot policies, login limits, and the block chart work without connecting to Witen. If you want shared intelligence, enroll the plugin with a one-time token from your account.

Connecting includes security-event sharing, which is required to use the Witen service. The plugin explains what it sends before you connect. Warden is optional: use its local socket when you want the plugin to work with host protection.

See free and paid hosted plans

Install and check your setup

  1. Download the ZIP and compare its checksum with the Downloads page.
  2. Extract it into Matomo’s plugins directory as plugins/Witen, then activate Witen in plugin administration.
  3. Review IP rules, bot policies, and login limits in Witen. Use monitoring for request patterns you want to assess before blocking.
  4. If you connect your account, use Diagnostics to verify the heartbeat and blocklist updates.

You need Matomo Super User access and writable private storage outside the web root. This release supports Matomo On-Premise 5.13 through 5.x; Matomo for WordPress and Matomo 6 are outside its compatibility range.

Questions about Witen for Matomo

Does this protect the websites tracked by Matomo?
Witen protects the Matomo installation, including requests to its login and tracking endpoints. It does not add protection to a separate website just because Matomo tracks it.
Does it work with Matomo Cloud?
This plugin is for Matomo On-Premise installations where you can install plugins and manage server storage. It is not a Matomo Cloud integration.
Do I need Warden or a paid plan?
No. Local IP rules, bot policies, login limits, and file checks work without Warden or a paid plan. Connecting to Witen adds shared intelligence and includes security-event sharing. You can use local protection without enrolling.
Will it change my analytics data?
Witen evaluates incoming requests; it does not rewrite stored analytics. Requests you block before Matomo handles them will not reach the tracker, so review bot policies and use monitoring when assessing a rule.