=== WP GEO Website Protection (by SiteGuarding.com) ===
Contributors: SiteGuarding
Donate link: https://www.siteguarding.com/en/buy-service/antivirus-site-protection
Tags: security, geo blocking, block country, firewall, brute force
Requires at least: 4.6
Tested up to: 7.1.1
Requires PHP: 7.2
Stable tag: 4.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Block or redirect visitors by country and by IP address, on the front end and in wp-admin. Detailed logs and statistics.

== Description ==

WP GEO Website Protection limits access to your website by the country a
visitor's IP address belongs to, and by the address itself.

Almost every brute force attempt against a WordPress login comes from a country
nobody on your team works from. Allowing only the countries you actually work
from is the single most effective thing you can do about that, and it takes one
minute to set up.

**What it does**

* Block visitors from the countries you choose, on the public site
* Block access to wp-admin and wp-login.php separately from the public site
* Block or allow single addresses, wildcards, CIDR ranges and IPv6
* Always allow the search engine crawlers, in one click
* Redirect a country to a page, another domain, or the same path on another domain
* Rewrite the language segment in URLs per country
* Charts and a searchable log of everything that was blocked or redirected
* A block page you can put your own logo and wording on

**How it works**

Every visitor arrives with an IP address. The plugin looks that address up in a
MaxMind country database stored on your own server and applies your rules.
Nothing about your visitors is sent anywhere: no external service is contacted
during a lookup.

The check runs before WordPress loads, which is what makes the admin area
protection worth having - a blocked request never reaches WordPress at all.

**Free and full version**

The free version blocks up to 5 countries and 5 redirect rules. The full
version removes the limits and adds the IP lists, the custom block page and
automatic country database updates.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/` or install it from the Plugins screen
2. Activate it
3. Open GEO Protection in the admin menu and follow the four steps on the Overview tab

The plugin adds three lines to `wp-config.php` so it can filter requests before
WordPress starts. If that file is read-only, the Settings tab shows the lines
to add by hand.

== Frequently Asked Questions ==

= I blocked my own country and cannot get in =

Create an empty file called `geodebug.txt` in your WordPress root over FTP.
That disables the guard completely, so you can log in and fix the rules. Delete
it afterwards.

= Will this stop search engines from indexing my site? =

Only if you block a country Google or Bing crawls from without allowing them
first. The front-end tab has a one click button that adds the published crawler
ranges to the allow list. Use it before you turn protection on.

= Does it slow the site down? =

The country of a visitor is resolved once and cached in a cookie for a day. No
external request is made at any point during a page view.

= Does it work behind Cloudflare or a proxy? =

Yes. The visitor address is taken from the usual proxy headers when they are
present.

== Screenshots ==

1. Overview: protection state, activity and plugin health
2. Front-end protection with the country picker
3. Activity and logs
4. The page a blocked visitor sees

== Changelog ==

= 4.0 =
Full rewrite. The admin interface, the request guard and the update mechanism
were all rebuilt.

* Security: the country cookie is now signed with a per-site secret. The old
  one was an unkeyed md5 any visitor could compute, which let anybody walk
  through a country block.
* Security: the `geo_check` cookie is gone. Its value was handed to every
  allowed visitor and disabled all checks, so it worked as a shareable bypass.
* Security: the visitor URL shown in the log is sanitised and escaped. It used
  to be printed raw, which allowed stored XSS from an anonymous visitor.
* Security: wp-config.php and .htaccess are never chmod'ed to 0666 any more.
  wp-config.php is backed up before the first change and written atomically.
* Security: the update check verifies versions with version_compare and installs
  through the WordPress updater instead of unzipping a download over itself.
* IP rules: CIDR ranges and IPv6 are supported. Short rules no longer match more
  addresses than intended.
* Deactivating the plugin now really stops the filtering; 3.x left the
  wp-config.php include in place.
* The GEO database, the event queue and the plugin state moved to
  wp-content/uploads, so a plugin update no longer deletes them.
* The country database is fetched on first install, verified by checksum, and
  refreshed by WP-Cron rather than during a visitor's page view.
* The SiteGuarding agent is installed through the shared connector and is never
  replaced with an older version.
* The .htaccess rewrite block is removed: it fought with permalink rules and its
  cookie condition was a bypass.
* Interface: Semantic UI, jQuery, Highcharts and four icon font themes removed.
  The plugin assets went from 4.5 MB to about 300 KB, they load only on the
  plugin's own screen, and nothing is fetched from Google Fonts.
* Country list fixed: Kyrgyzstan and Niger were mislabelled, three codes were
  duplicated, and Congo (Democratic Republic) was missing.
* Activity records are trimmed on a schedule. The cleanup existed in 3.x but was
  never called.
* Free version limits are now 5 countries and 5 redirects, matching the other
  SiteGuarding plugins.
* Tested with WordPress 7.1.1 and PHP 7.2 to 8.5.

= 3.0 =
Previous release.

== Upgrade Notice ==

= 4.0 =
Security and performance release. Review your IP lists after upgrading: CIDR
and IPv6 now work, and short rules match more precisely than before.
