

A Tor visitor blocked before reaching the site: the branded block page every high-risk visitor sees, with the block reason.
Predax Security is a VPN, proxy, Tor and bot blocker for WordPress that doesn’t stop there: a built-in firewall, login-lockout protection, country blocking and spam and disposable-email rejection are all included, switch by switch. It checks every visitor’s IP address as they arrive and turns away the ones you don’t want — before they can log in, register, comment or load a page.
Most attacks on WordPress sites — brute-force logins, fake registrations, comment spam, vulnerability scans — arrive over VPNs, open proxies, Tor or rented servers. Predax spots those connections in real time, gives each IP a 0–100 risk score, and blocks by the rules you choose.
See what Predax knows about your own IP — free, no signup.
Off by default. A fresh install sends nothing anywhere. Pick a protection level in the setup wizard and the plugin starts working; until then it does nothing.
Every one of these is a switch. Turn on what you need.
Decide whether GPTBot, ClaudeBot, PerplexityBot or AhrefsBot can access your site. Predax checks each crawler’s real network, not a user-agent header anyone can fake — so a crawler that ignores robots.txt is still turned away. Search engines such as Google and Bing are allowed by default.
Security dashboard with live activity and top targeted paths · Threat Log with CSV export · Custom branded block page · IP and CIDR allow/deny lists · XML-RPC and REST API protection · Settings import/export · WP-CLI commands for automation
Click Connect with Predax in the setup wizard and your free account and API key are created for you — nothing to copy or paste. The free plan includes 5,000 IP checks a month (1,000 a day) with full VPN, proxy, Tor and datacenter detection. No credit card.
Verified search engine crawlers are never counted against your allowance, so being crawled by Google or Bing costs you nothing.
Busier sites can move to a paid plan for a bigger monthly allowance — same plugin, same settings, same key.
This plugin connects to external services. By installing and activating this plugin you agree to the terms of each service you enable.
This plugin transmits visitor IP addresses to the Predax API (https://predax.io) for real-time threat detection and risk scoring.
What is sent: The visitor’s IP address; optionally their timezone (when timezone mismatch detection is enabled and visitor protection is active); and, when disposable-email screening is enabled, the domain part of the email address entered at registration (for example “gmail.com”) — never the email address itself, and never the part before the @. The mailbox-level checks (role account, random-looking name) run locally on your own server.
When it is sent: On each page load, login attempt, registration, or comment submission, subject to your configured protection settings. IP results are cached for up to 1 hour and email-domain results for up to 6 hours, so repeat visits do not generate additional API calls.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Used to check whether the email provider entered at registration is a disposable/throwaway service, against a server-side list of thousands of domains (the plugin’s built-in list covers only ~50).
What is sent: the domain part of the registration email address only — for example gmail.com. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.
When it is sent: during user registration, and only while the Disposable Email Addresses setting is set to Flag or Block. If the API is unreachable, the plugin falls back to its built-in local list and the registration proceeds normally. Email-domain results are cached for up to 6 hours per domain.
Endpoint: POST https://predax.io/api/v1/validate/email
Plan usage: email-domain lookups count against your Predax plan allowance, the same as IP checks. Results are cached per domain for 6 hours and the built-in list is checked first, so in practice this is roughly one lookup per new email provider your visitors use.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Used to show the “API Usage” meter on the plugin dashboard, and only when an API key is saved.
What is sent: your Predax API key (as the authentication header). No visitor data is sent.
When it is sent: when an administrator views the Predax Security dashboard. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.
Endpoint: GET https://predax.io/api/v1/auth/usage
Privacy Policy: https://predax.io/privacy
Shown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the “why are you deactivating?” prompt.
What is sent: the plugin slug, the plugin version, and a single pre-defined reason code you select (e.g. “it blocked real visitors”). No site URL, no email address, no visitor data, and no IP address are sent.
When it is sent: only when you select a reason and click “Send & deactivate”. Clicking “Skip & deactivate” sends nothing at all.
Endpoint: POST https://predax.io/api/v1/feedback/deactivation
Privacy Policy: https://predax.io/privacy
The Community Threat Network is opt-in and disabled by default. No block or monitor events are sent to the community network unless you enable it yourself in Settings Predax Security Advanced.
When — and only when — you explicitly enable it, anonymised block and monitor events (containing: IP address, action taken, block reason, country code, and risk score) are sent to the Predax API at predax.io. This data is used to build a shared threat database that improves detection accuracy for all sites in the network. You can turn community reporting back off at any time in the same settings screen.
When reCAPTCHA v3 is enabled (Settings Protection reCAPTCHA), this plugin loads the reCAPTCHA script from google.com and sends form submission tokens to google.com/recaptcha for verification. Google may collect data according to their privacy policy. You must provide your own reCAPTCHA site key and secret key.
Google Privacy Policy: https://policies.google.com/privacy
reCAPTCHA Terms: https://policies.google.com/terms
When browser fingerprint scoring is enabled (Settings Protection Fingerprint Scoring), this plugin collects screen resolution, timezone, platform string, WebGL renderer, and plugin count from the visitor’s browser on the login page. Fingerprint data is used locally to score bot likelihood and is stored in WordPress only while the login form is being submitted, then discarded. The visitor’s timezone may be included in the API request to detect timezone mismatch when that feature is enabled.
All cookies set by this plugin are functional service cookies, not tracking cookies, and are only written when the relevant feature is explicitly enabled by the site administrator:
ipsentry_tz — carries the visitor’s browser timezone to the Predax API when timezone-mismatch detection is active. Written from ipsentry-tz.js on the front-end. Expires after 24 hours. SameSite=Lax. Only set when an API key is configured AND visitor or login protection is enabled.ips_jsc — JavaScript challenge solve token. Written from js-challenge.js when a visitor passes the challenge. Expires after 24 hours. SameSite=Lax. Only set when the JavaScript Challenge feature is enabled.No tracking or advertising cookies are written by this plugin.
By activating this plugin and entering an API key, you agree to the Predax Terms of Service and Privacy Policy. You are responsible for ensuring your use of visitor IP data complies with applicable privacy laws (GDPR, CCPA, etc.) and your own site’s privacy policy.