WP-Ban
WP-Ban

WP-Ban

3.7/5 (27 ratings) 8K+ active installs Updated Aug 9, 2026
Settings -> WP-Ban, the Settings tab: the six lists a visitor is matched against

Settings -> WP-Ban, the Settings tab: the six lists a visitor is matched against

Banned visitors are served a custom message instead of your site. You can ban by IP address, IP range, host name, user agent or referrer URL, exclude specific addresses from ever being banned, and see how many times each banned visitor has tried to get in. Wildcards are supported throughout.

Everything is configured under Settings -> Ban, on three tabs: Stats for the attempt counters, Settings for the ban lists and the visitor IP options, and Templates for the banned message. The plugin will not let you ban the address, host name or user agent you are currently browsing with, so a wildcard that would lock you out of your own site is refused at save time and the screen says which entry it dropped.

Features

  • Ban by IP address, IP range, host name, user agent or referrer URL
  • Wildcards in every list except IP ranges and the exclude list
  • IPv4 and IPv6, including IPv6 ranges
  • An exclude list that wins over every other list
  • Your own banned message, as a complete HTML document, with a live preview
  • A sortable, paginated count of how many times each banned visitor has tried
  • Self-ban protection that protects whoever is saving, not just a user called “admin”

Donations

I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations.

Usage

Go to Settings -> Ban. The screen has three tabs and opens on Stats.

On the Settings tab, fill in the lists you want. Every list matches the whole value, so use * where you want a partial match: 192.168.1.* bans that whole block, EmailSiphon* bans every user agent starting with that name.

IP ranges are written as start-end, one per line. IPv4 and IPv6 are both supported, but a single range cannot mix the two.

The Templates tab holds the banned message on its own, because it is a whole HTML document and burying it under six textareas made the screen a wall.

The Stats tab is the attempt counters, twenty rows at a time, sortable by address or by attempts. Tick the rows you want cleared and use the bulk action, or tick Reset every IP ban stat and the total to start again.

All three tabs write the same wp_ban_options row, so saving one never disturbs what the other two hold.

WP-CLI

wp ban list
wp ban list ips
wp ban add ips 192.168.1.100
wp ban add ips '192.168.1.*'
wp ban add ips_range 192.168.1.1-192.168.1.255
wp ban remove ips 192.168.1.100 --yes
wp ban check 192.168.1.55
wp ban stats
wp ban reset --all --yes

The lists are ips, ips_range, hosts, referers, user_agents and exclude_ips — the same six the Settings tab shows, in the same order. Quote any entry containing a *, or the shell will try to expand it into filenames.

wp ban check runs the same match every visitor's request runs, against an address you name, and reports whether it would be banned and by which list. Ranges and wildcards cover far more than they look like they do, so this is worth running before you add one and after you have. It writes nothing and counts nothing, so an address you check does not appear in `wp ban stats`.

wp ban remove and `wp ban reset` ask before they act; pass `--yes` in a script.

Two differences from the screen. The Settings tab refuses to add an entry that matches the administrator saving it, and a shell has no visitor to protect, so the command adds what you tell it to — check first. And the Stats tab shows a host name per row, which the command does not, because that is a DNS lookup per address and the screen only pays it for the rows it is displaying.

Filters

Use wp_ban_enabled to skip the ban check for some requests:

add_filter( 'wp_ban_enabled', function ( $enabled ) {
    return ! defined( 'REST_REQUEST' ) || ! REST_REQUEST;
} );

Use wp_ban_denied to do something else when a visitor is turned away:

add_action( 'wp_ban_denied', function ( $ip, $status ) {
    error_log( 'WP-Ban turned away ' . $ip );
}, 10, 2 );

Use wp_ban_capability to hand the screen to a capability other than manage_options:

add_filter( 'wp_ban_capability', function ( $capability, $context ) {
    return 'edit_pages';
}, 10, 2 );

The other four are wp_ban_ipaddress (the address a request is attributed to), wp_ban_status_code (the HTTP status the ban page is served with), wp_ban_protect_self (whether self-ban protection runs) and wp_ban_trust_proxy (whether the usual forwarding headers may be trusted).