Skip to content

Witen Blocker for WordPress

Protect logins. Control bots. Check suspicious files.

Witen Blocker adds IP blocking, login protection, bot policies, and file scans to your WordPress dashboard. It works on shared hosting without root access.

Version 0.6.47. WordPress 6.2+ · PHP 8.1+. Free from the WordPress Plugin Directory. No Witen account needed to install.

Already using WP fail2ban? Compare it with Witen Blocker.

Security controls inside WordPress

Limit repeated login attempts

Detect repeated login failures and apply local limits. Review authentication activity alongside the plugin’s block reasons.

Choose which bots to allow

Set policies for crawlers, AI services, monitors, and attack tools. Allow the services you use and review the rest before blocking them.

Scan files for suspicious changes

Run file and malware checks, then inspect the affected paths and findings. A scan finding is something to investigate, not proof that every flagged file is malicious.

Review blocked requests

See security events and blocked IPs in the dashboard. Keep trusted addresses allowed and remove a local block when needed.

Add shared intelligence when you need it

Connect the plugin with a one-time setup token from your Witen account to receive shared IP blocklists and report security activity. Choose a plan for the number of connected sites you run and the shared data you need.

Warden is optional. If you administer the Linux host, it can use the plugin’s reports alongside other service logs and apply blocks at the host firewall.

See free and paid hosted plans

Get started from your dashboard

  1. Open Plugins → Add New Plugin and search for “Witen Blocker”.
  2. Install and activate Witen Blocker.
  3. Review Witen Settings, trusted addresses, and bot policies.
  4. If you want shared intelligence, connect your account and check that updates are arriving.

Questions about Witen Blocker

Does it work without Warden or root access?
Yes. The plugin evaluates requests inside WordPress and can apply its own IP and login rules. Warden is only needed if you also want Witen to manage blocks at the Linux firewall.
Is a paid plan required?
No. The plugin’s local features do not require a paid plan. A hosted plan controls shared intelligence updates and how many sites you connect.
Will the scanner remove files?
The scanner reports suspicious files and changes for you to review. It does not automatically clean an infected site or guarantee that every malicious file will be found.
Can I use it with a reverse proxy?
Yes, but the client IP configuration needs to match your proxy. Otherwise rules may apply to the proxy address instead of the visitor. Follow the setup guide and check trusted addresses before enabling blocking.