BlackSwan | Block External Request
Block unwanted external HTTP requests in WordPress. Blacklist/whitelist management, resource blocking, and one-click pause.
Use with caution
BlackSwan works, but test it on a staging site before relying on it in 2026. It runs on 40+ sites, is rated 5/5 and was last updated 6 months ago, and scores 52/100 on our health check.
- Small user base (40+ active installs)
- Very few reviews so far
- Only tested up to WordPress 6.8 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where BlackSwan stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| blacklist | >100 |
| block http requests | #47 |
| external requests | #10 |
| performance | >100 |
| whitelist | #86 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About BlackSwan | Block External Request
From the official readme · v2.9.3Description
BlackSwan Block External Request gives you granular control over every outgoing connection your WordPress site makes — both server-side PHP requests and browser-loaded JS/CSS resources.
WordPress, plugins, and themes constantly send background HTTP requests: update checks, license pings, analytics, font downloads, CDN calls, and more. On slow servers or restricted hosting environments, these requests can add seconds to every admin page load.
This plugin lets you block what you don’t need and keep what you do.
What it does
Server-side HTTP Blocking (PHP)
Intercepts outgoing wp_remote_get / wp_remote_post calls via the pre_http_request filter. Add domains to the blacklist and they’ll be blocked before the request is even made. Whitelist specific URL patterns to let essential requests through (e.g. plugin update API).
Browser-side Resource Blocking (JS/CSS by Domain)
Deregisters enqueued JavaScript and CSS files loaded from blacklisted external domains. Toggle separately for admin panel and public frontend. Your own site’s assets are never touched.
Block Specific Resources (by URL)
Block individual JS or CSS files by full URL, partial path, or even just a filename — works for both local and external resources. Per-item backend/frontend toggle. Perfect for removing unwanted plugin assets without editing code.
Features
- Blacklist & whitelist with inline edit, delete, and delete-all
- Block external JS/CSS by domain (backend, frontend, or both)
- Block specific resources by URL pattern (local or external)
- One-click pause/resume — instantly disable all blocking
- Safe mode via
?bswan-safe=1— emergency bypass for any admin page - Settings page auto-bypasses resource blocking so you never lock yourself out
- Export/import all settings as a single JSON file
- AJAX-powered save — no page reloads
- Query Monitor integration — detect, activate, or install from settings
- All settings stored as a single JSON option with
autoload=nofor performance - Fully standalone — zero external dependencies (inline Lucide SVG icons)
- Modern liquid glass UI with dot-grid background
- WordPress native postbox layout with collapsible sections
- Translation-ready with full text domain support
Who is this for?
- Sites on slow or restricted hosting where external calls cause timeouts
- Developers debugging performance issues
- Agencies managing client sites that don’t need update checks
- Anyone who wants a faster wp-admin experience
Developer Hooks
Four filters are available for developers to customize blocking behavior programmatically. These run on every page load and merge with the values from the settings page.
BlackSwan\block_external_request\block_url_list
Filter the array of blocked domain strings. Each entry is matched via strpos() against the full request URL.
add_filter( 'BlackSwan\block_external_request\block_url_list', function( $domains ) {
$domains[] = 'analytics.example.com';
return $domains;
});
BlackSwan\block_external_request\whitelist_urls
Filter the array of whitelisted URL patterns. If a blocked URL also matches a whitelist pattern (via strpos()), the request is allowed through.
add_filter( 'BlackSwan\block_external_request\whitelist_urls', function( $patterns ) {
$patterns[] = '//api.example.com/v2/license';
return $patterns;
});
Whitelist patterns take priority over blacklist domains. Both filters accept and return a flat array of strings.
BlackSwan\block_external_request\blocked_resources
Filter the array of specific JS/CSS resources to block. Each entry is an associative array with url, backend, and frontend keys. The url is matched via strpos() against each registered script/style source.
add_filter( 'BlackSwan\block_external_request\blocked_resources', function( $resources ) {
$resources[] = array( 'url' => 'some-plugin/tracking.js', 'backend' => false, 'frontend' => true );
return $resources;
});
BlackSwan\block_external_request\cdn_replacements
Filter the array of CDN replacement rules. Each entry is an associative array with pattern, cdn, backend, and frontend keys. When an enqueued asset source contains the pattern, it is replaced with the cdn URL.
add_filter( 'BlackSwan\block_external_request\cdn_replacements', function( $replacements ) {
$replacements[] = array( 'pattern' => '/wp-includes/js/jquery/jquery.min.js', 'cdn' => 'https://cdn.example.com/jquery/3.7.1/jquery.min.js', 'backend' => false, 'frontend' => true );
return $replacements;
});
Links
Copyright
BlackSwan Block External Request is free software distributed under the terms of the GNU General Public License v2 or later.
Copyright (c) AmirhpCom — amirhp.com
This plugin is developed and maintained by BlackSwan Lab.
You are free to use, modify, and distribute this plugin under the GPLv2 license. The developers are not responsible for any issues caused by misconfigured blocking rules. Always maintain proper backups before making changes to your site’s HTTP request behavior.
Installation
- Upload the
blackswan-block-external-requestfolder to/wp-content/plugins/ - Activate the plugin through the Plugins menu in WordPress
- Go to Settings → Block External Request to configure
Or install directly from WordPress:
- Go to Plugins → Add New
- Search for “BlackSwan Block External Request”
- Click Install Now, then Activate
The plugin comes pre-configured with a sensible default blacklist and whitelist. You can customize everything from the settings page.
Frequently asked questions
Will this break my site?
It depends on what you block. The default blacklist blocks common domains that slow down the admin panel (wordpress.org, google.com, yoast.com, etc.). The default whitelist ensures plugin update API calls still work. If something breaks, use the Pause button or Safe Mode to quickly restore access.
What’s the difference between the three blocking sections?
Server-side HTTP (PHP) — Blocks background requests made by WordPress via PHP. These are invisible to the browser (update checks, API calls, license pings). Browser-side by Domain — Dequeues JS/CSS files loaded from blacklisted external domains (e.g. Google Fonts, CDN libraries). Block Specific Resources — Dequeues individual JS/CSS files by matching any part of their URL. Works for local files too.
I blocked something and now I can’t access wp-admin
Add ?bswan-safe=1 to any admin URL (e.g. yoursite.com/wp-admin/?bswan-safe=1). This bypasses all blocking for that page load. The plugin settings page also automatically skips resource blocking.
Does this affect the frontend?
Server-side HTTP blocking applies everywhere. Browser-side resource blocking and specific resource blocking have separate toggles for backend and frontend — you control where each applies.
Where are settings stored?
All settings are stored as a single JSON value in wp_options with autoload=no for optimal performance. No separate database tables.
Can I export/import settings between sites?
Yes. The Export/Import panel in the sidebar lets you download all settings as a JSON file and import it on another site.
How can I contribute?
We welcome contributions! You can: Report bugs or suggest features on WordPress.org Support or GitHub Issues Submit pull requests on GitHub Translate the plugin via WordPress.org Translate Rate the plugin 5 stars if you find it useful
Changelog
Release date: 2026-04-13 | 1405-01-24 Fixed Translation Added fontawesome to exclude list Added cdn.jsdelivr.net to exclude list Added unpkg.com to exclude list Added googletagmanager.com to exclude list Added cdnjs.cloudflare.com to exclude list Added fonts.googleapis.com to exclude list Added fonts.gstaticn.com to exclude list Set some default options ON by default
2.9.3
- Release date: 2026-04-13 | 1405-01-24
- Fixed Translation
- Added
fontawesometo exclude list - Added
cdn.jsdelivr.netto exclude list - Added
unpkg.comto exclude list - Added
googletagmanager.comto exclude list - Added
cdnjs.cloudflare.comto exclude list - Added
fonts.googleapis.comto exclude list - Added
fonts.gstaticn.comto exclude list - Set some default options ON by default
2.9.0
- Added “Disable All Emoji” option: removes WordPress emoji detection script, emoji styles, TinyMCE emoji plugin, and DNS prefetch hints for the emoji CDN — eliminating outgoing requests to s.w.org
2.8.0
- Expanded the default blacklist with 30+ additional domains commonly responsible for license checks, telemetry, and update pings (e.g. freemius.com, themeforest.com, cloudflare.com, wpbakery.com, xtemos.com, premio.io, nextendweb.com, objectcache.pro, rocketcdn.me, ipinfo.io, paypal.com, and several Iranian plugin/theme vendors)
2.7.0
- Documented all four developer filters with full examples (
block_url_list,whitelist_urls,blocked_resources,cdn_replacements) - Improved readme files for WordPress.org publishing
2.6.7
- Added at-a-glance overview panel at the top of the settings page with 5 stat cards (HTTP blocking, browser resources, specific resources, CDN replacements, avatars) for non-technical users
- All technical configuration metaboxes now hidden behind a “Configure & Advanced Settings” toggle, collapsed by default, state remembered in localStorage
- Moved “Reset to Defaults” into its own dedicated sidebar metabox with a clear destructive-action warning
- Fixed confirm dialog line breaks (were showing as literal \n on some browsers)
2.6.6
- Added “Reset to Defaults” button in Export/Import panel with a destructive-action warning notice and two-step confirmation before wiping settings
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best BlackSwan alternatives
All blacklist plugins →FAQ
BlackSwan | Block External Request: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 6, 2026
Is BlackSwan free?
Yes. BlackSwan is free to download and use from the official WordPress.org plugin directory.
Is BlackSwan safe to use in 2026?
BlackSwan works, but test it on a staging site before relying on it in 2026. It runs on 40+ sites, is rated 5/5 and was last updated 6 months ago, and scores 52/100 on our health check.
How many websites use BlackSwan?
BlackSwan is active on 40+ WordPress websites and has been downloaded 2,020 times since it launched in October 2022. It was downloaded 101 times in the last 30 days.
Does BlackSwan work with WordPress 7.1?
BlackSwan is officially tested up to WordPress 6.8.11, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does BlackSwan need?
BlackSwan requires PHP 5.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was BlackSwan last updated?
The latest version, 2.9.3, was released on April 13, 2026 (6 months ago).
Who makes BlackSwan?
BlackSwan is developed and maintained by BlackSwanDev.
What are the best alternatives to BlackSwan?
The most popular alternatives to BlackSwan are Gravity Forms Email Blackli… (10K+ installs), Block List Updater (3K+ installs) and Blacklist Manager (2K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card
![Collapsed Settings page [EN]](https://ps.w.org/blackswan-block-external-request/assets/screenshot-1.png?rev=3491398)
![Collapsed Settings page [FA]](https://ps.w.org/blackswan-block-external-request/assets/screenshot-2.png?rev=3491398)
![Expanded Settings page [EN]](https://ps.w.org/blackswan-block-external-request/assets/screenshot-3.png?rev=3491401)
![Expanded Settings page [FA]](https://ps.w.org/blackswan-block-external-request/assets/screenshot-4.png?rev=3491401)
