OpenCart Extension

OpenCart GEO Website Protection

OpenCart GEO Website Protection is the security module that limits access to your store from unwanted countries and IP addresses. Control who can open your storefront and your admin panel based on geographic location.

Last Update: 11 Oct 2026
Version: 2.0.0
Compatibility: OpenCart 3.0.x / 4.0.2 - 4.1

Geographic Access Control for OpenCart

The module restricts access to your OpenCart store based on the country a visitor's IP address belongs to. Block whole countries on the storefront, keep the admin panel open only to the countries your team works from, or send visitors from a country to a local version of your store.

Most attacks on online stores target the admin login. Limiting the admin panel to your own countries removes almost all brute force attempts, and the check runs before OpenCart starts, so blocked traffic costs your server almost nothing.

Country lookups use a database stored on your own server. No visitor data is sent to any external service.

Main Features

  • Block countries on the storefront. Visitors from the countries you select see a short block page instead of your store.
  • Protect the admin panel. Allow the OpenCart admin login only from the countries your team works from. The login form itself is protected too.
  • GEO redirects. Send visitors from a country to another page of your store or to another website, keeping the page they asked for if you want.
  • Block and allow lists by IP address. Exact addresses, wildcards and CIDR ranges, for IPv4 and IPv6.
  • Search engines stay in. Add the address ranges of Google, Bing and other crawlers to the allow list with one click.
  • Payment callbacks keep working. Exclude pages such as payment and delivery callbacks from filtering.
  • Works behind Cloudflare and reverse proxies. The real visitor address is read only from trusted proxies, so visitors cannot fake their country.
  • Activity log and charts. See who was blocked or redirected over the last 24 hours, 7 days and 30 days.
  • Custom block page. Your logo and your own text, with a live preview.
  • Easy to set up. One page, clear switches, and a warning before you lock yourself out.

What is new in version 2.0.0

Version 2.0.0 is a complete update of GEO Website Protection for OpenCart 3 and OpenCart 4. It fixes a security issue: a visitor could set their own IP address with an HTTP header such as X-Forwarded-For or CF-Connecting-IP and get past country blocking. Forwarded headers are now read only from a trusted proxy, and stores behind Cloudflare keep working with no setup.

The module has a new interface with separate switches for the storefront and the admin panel, a country picker with search and continents, activity charts and a live preview of the block page. IP rules accept exact addresses, wildcards and CIDR ranges for IPv4 and IPv6, and rules saved by version 1.x are converted automatically. The check runs before OpenCart starts, works on PHP 8, and keeps your settings when you update.

Screenshots

Free vs Full Version

Feature Free Version Full Version
Storefront protection by country Up to 5 countries
Admin panel protection by country Up to 5 countries
Block and allow lists by IP address, wildcard and CIDR range
Search engine crawler ranges in one click
GEO redirects by country Up to 5 countries
Never filter selected storefront pages (payment callbacks)
Activity log and charts
Custom block page with your logo and text
GEO database updates By hand, once every 30 days
Remove the Protected by link
Support and help Email only

Protect Your OpenCart Store by Location

Download the free version to get started with geographic access control, or get the full version for unlimited countries and IP lists.

Installation

OpenCart 3.0.x
1. Extensions > Installer: upload opencart_geoprotection3.ocmod.zip.
2. Extensions > Extensions > Modules: find GEO Website Protection, click Install, then Edit.

OpenCart 4.0.2 to 4.1
1. Extensions > Installer: upload siteguardinggeoprotection.ocmod.zip and click Install. Keep the file name as it is: OpenCart 4 uses it to install the module.
2. Extensions > Extensions > Modules: find GEO Website Protection, click Install, then Edit.

Updating from an earlier version
OpenCart 3: upload the new file in Extensions > Installer, then open the module page once. Your settings are kept and converted.
OpenCart 4: uninstall the module in Extensions > Extensions > Modules, uninstall and delete the old package in Extensions > Installer, then install the new one. Your settings are kept.

Requirements
OpenCart 3.0.x with PHP 7.0 or newer, or OpenCart 4.0.2 to 4.1 with PHP 8.0 or newer. During installation the module adds one line to config.php and keeps a copy of the original file, so config.php must be writable at that moment.

Live Chat Support
Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience. See our policy Accept