GranTech IP Firewall for AbuseIPDB
Protect your WordPress site by detecting, blocking and reporting malicious IPs using the AbuseIPDB API. Includes brute-force protection.
Solid choice
GranTech IP Firewall for AbuseI… is a solid plugin choice in 2026, with a few things worth checking first. It runs on 60+ sites, is rated 5/5 and was last updated 1 week ago, and scores 79/100 on our health check.
- Actively developed — last update 1 week ago
- Tested with the latest WordPress (7.1)
- Small user base (60+ active installs)
- Very few reviews so far
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where GranTech IP Firewall for Ab… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| abuseipdb | #1 |
| Brute Force | #90 |
| firewall | #22 |
| ip blocker | #11 |
| security | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About GranTech IP Firewall for AbuseIPDB
From the official readme · v1.3.0Description
GranTech IP Firewall for AbuseIPDB connects your WordPress installation to the community-driven AbuseIPDB database to automatically detect, block, and report abusive IP addresses before they can cause damage — now with a completely redesigned interface and proactive blacklist protection.
Key Features
- Real-time IP checks — Queries the AbuseIPDB API only on sensitive endpoints (wp-login.php, wp-admin, xmlrpc.php, comment submissions, and the JWT/users REST routes) and blocks IPs exceeding your abuse score threshold. Regular page views and front-end traffic never trigger an API call.
- Daily blacklist sync — Optionally downloads the 10,000 worst-reputation IPs once a day and blocks them instantly, without spending any check quota. Proactive protection before the first attack.
- Brute-force protection — Detects attacks on wp-login.php and XML-RPC and blocks the offending IP after N failed attempts.
- Automatic reporting — Reports attacking IPs to AbuseIPDB (Brute-Force + Web App Attack categories) with a fully customizable, privacy-safe public comment: your site URL and usernames are never exposed by default. Optionally reports comment spammers too (Blog Spam category) when a comment is marked as spam.
- False-positive protection — IPs on the official AbuseIPDB whitelist (Googlebot, Bingbot, major CDNs) are never blocked.
- Tor blocking — Optionally block Tor exit nodes on sensitive endpoints regardless of score.
- Email alerts — Get notified when a brute-force attack is blocked (throttled to one email per attacking IP per hour).
- Redesigned admin interface — Modern dashboard with status hero, light & dark themes, API quota indicator, rich IP checker (usage type, distinct reporters, last report), 30-day activity chart and top offenders.
- Investigation tools — See the community’s own reports behind any score, scan whole CIDR ranges for reported addresses, and withdraw your own reports if an IP was flagged by mistake.
- One-click actions — Block any IP straight from the event log or from a range scan; every IP links to its AbuseIPDB page for instant investigation.
- Dashboard widget — Key security stats at a glance on the main WordPress dashboard.
- Contributor badge — Display your AbuseIPDB contributor badge with the
[granipfi_badge]shortcode or a widget; sites that link to AbuseIPDB can request “supporter” status, which comes with higher daily API limits. - Event log — Full filterable history, with configurable retention period.
- Whitelist support — Exempt IPs or CIDR ranges (IPv4 and IPv6) from checks.
- Smart quota management — Response caching, automatic backoff when the daily quota is exhausted, and no API calls for trusted logged-in users.
- Reverse proxy support — Optional trusted-proxy mode for Cloudflare and load balancers (disabled by default to prevent IP spoofing).
- Accessibility — WCAG-conscious interface: AA contrast in both themes, keyboard navigation, screen reader support, reduced-motion and high-contrast modes.
How It Works
- Once a day (optional), the plugin syncs the AbuseIPDB blacklist locally — the worst 10,000 IPs are blocked instantly with zero API cost.
- When any other IP accesses a sensitive endpoint (login, XML-RPC, comment submission), the plugin queries the AbuseIPDB API.
- If the abuse confidence score meets or exceeds your threshold (default 50/100), the IP is blocked automatically. Whitelisted crawlers like Googlebot are always allowed.
- If multiple failed login attempts are detected from the same IP, it is blocked and reported back to AbuseIPDB, and you can receive an email alert.
- Everything is recorded in a redesigned dashboard with real-time statistics.
API Requirements
A free account at abuseipdb.com is required.
The free plan includes 1,000 checks per day plus daily blacklist downloads — more than enough for most sites when combined with the built-in caching, blacklist sync and smart quota management.
External Services
This plugin connects to the AbuseIPDB API (https://api.abuseipdb.com/api/v2/) to check and report IP addresses.
What is AbuseIPDB?
AbuseIPDB is a community-driven project that maintains a database of IP addresses reported for abusive behavior (spam, hacking, brute-force attacks, etc.). This plugin uses their public API to protect your WordPress site.
What data is sent and when?
- IP address check: When a visitor accesses a sensitive endpoint (wp-login.php, xmlrpc.php, comment submission), the visitor’s IP address is sent to AbuseIPDB to retrieve its abuse confidence score. This only happens when the endpoint is accessed — not on regular page visits.
- IP address report: When a brute-force attack is detected (configurable number of failed login attempts), the offending IP address is reported to AbuseIPDB along with a generic description of the attack. For privacy, your site URL and usernames are NOT included by default (the comment template is customizable). Reporting can be disabled in the plugin settings.
- Blacklist download: If the daily blacklist sync option is enabled, the plugin downloads the AbuseIPDB blacklist once a day. No visitor data is sent in this request.
- Comment spam report (optional, off by default): When enabled, the IP address of a comment classified as spam (by an anti-spam filter or by a moderator) is reported to AbuseIPDB with a generic description. The comment text and author details are never sent, and comments from registered users are never reported.
- Contributor badge (optional): If you enter your AbuseIPDB user ID and place the
[granipfi_badge]shortcode or widget, your visitors’ browsers load the badge image from abuseipdb.com (https://www.abuseipdb.com/contributor/). Nothing is loaded unless you place the shortcode or widget yourself.
No personal data other than IP addresses is ever transmitted to AbuseIPDB.
- AbuseIPDB Terms of Service and Privacy Policy: https://www.abuseipdb.com/legal
Privacy Policy
This plugin stores visitor IP addresses in the local WordPress database for the purpose of security logging and blocking. IP addresses are personal data under GDPR.
- What is stored: IP addresses, associated ISP, country, and event type (e.g. blocked, failed login).
- Why: To protect the site from malicious activity and brute-force attacks.
- How long: Log entries are automatically deleted after a configurable retention period (90 days by default, minimum 7). Block entries expire based on the configured duration.
- Third parties: IP addresses may be sent to AbuseIPDB (https://www.abuseipdb.com) for reputation checks and reporting. See the External Services section for details.
- User rights: Site administrators can view and delete all stored data from the plugin’s admin panel or by uninstalling the plugin.
Installation
- Upload the
grantech-ip-firewall-for-abuseipdbfolder to the/wp-content/plugins/directory. - Activate the plugin through the Plugins menu in WordPress.
- Go to IP Shield → Settings in the WordPress admin menu and paste your AbuseIPDB API key.
- Adjust the score threshold and brute-force parameters to suit your needs.
- Done — your site is now protected.
Recommended Settings
- Block threshold: 50 (blocks IPs with >50% abuse probability)
- Block duration: 24 hours
- Attempts before block: 5
- Time window: 10 minutes
- API cache: 60 minutes
- Report brute-force: Enabled
Frequently asked questions
Do I need a paid AbuseIPDB account?
No. The free plan includes 1,000 checks per day, which is more than enough for most sites when the caching system is enabled.
Will it block legitimate users?
It is unlikely. The plugin only queries the API on sensitive endpoints, never on regular page views. IPs on the official AbuseIPDB whitelist (Googlebot, Bingbot, major CDNs) are never blocked, and logged-in users with editing capabilities are skipped entirely, so you cannot lock yourself out of wp-admin. You can also add your own IPs or CIDR ranges to the plugin whitelist — recommended before activating.
What if my IP gets blocked?
You can log into the admin panel and remove the IP from IP Shield → Blocklist. If you cannot access the admin panel, add your IP to the whitelist directly in the database: UPDATE wp_options SET option_value = 'a:1:{i:0;s:X:"YOUR.IP.HERE";}' WHERE option_name = 'granipfi_whitelist';
Is it compatible with Cloudflare?
Yes. Enable the “Trust proxy headers” option in Settings and the plugin will read the CF-Connecting-IP header to obtain the real visitor IP. It is disabled by default for security (proxy headers can be spoofed on sites that are not behind a proxy).
Can I block IPs manually?
Yes. From IP Shield → Blocklist you can add any IP with a custom reason. Manual blocks are permanent by default.
How do I uninstall cleanly?
Deactivate and delete the plugin from the WordPress admin panel. All database tables (wp_abuseipdb_log, wp_abuseipdb_blocklist and wp_granipfi_blacklist) and options are removed automatically via uninstall.php.
For Developers
The plugin exposes the following hooks: granipfi_report_comment (filter) — Modify the public comment sent to AbuseIPDB. Receives the comment, the targeted username and the attempt count. granipfi_block_message (filter) — Replace the HTML shown on the 403 block page. granipfi_brute_force_detected (action) — Fires when a brute-force attack is blocked. Receives the IP, username and attempt count. granipfi_access_denied (action) — Fires just before a request is denied. Receives the IP and the internal reason. granipfi_comment_spam_report (filter) — Modify the public comment sent to AbuseIPDB for…
Changelog
Adds the AbuseIPDB contributor badge, opt-in comment spam reporting, better report categories, accessible confirmations and a Catalan translation.
1.3.0
- New: AbuseIPDB contributor badge — show it with the
[granipfi_badge]shortcode or the “AbuseIPDB Contributor Badge” widget. Sites that link to AbuseIPDB can request “supporter” status (with higher daily API limits) by contacting AbuseIPDB; it is not granted automatically. Fully opt-in: nothing is shown until you enter your user ID and place the shortcode or widget. - New: Opt-in reporting of comment spammers to AbuseIPDB (Blog Spam category). Only comments actually classified as spam are reported — on submission by an anti-spam filter such as Akismet, or when a moderator marks them as spam. Registered users and private IP ranges are never reported, and the comment text is never sent.
- Improvement: Login brute-force reports now use categories 18 + 21 (Brute-Force + Web App Attack), as AbuseIPDB recommends for attacks on WordPress.
- Improvement: Destructive actions (remove from blocklist, block a whole range, withdraw reports) now use accessible inline confirmations instead of native browser dialogs. This also removes the remaining inline JavaScript handlers and translates a confirmation message that was hardcoded in English.
- New: Catalan (ca) translation.
1.2.0
- New: The live IP checker now shows the evidence behind a score — the community’s own recent reports (date, reporter country and comment) in a collapsible panel, plus the resolved hostnames.
- New: IP range scanner (Tools) — check a whole subnet against AbuseIPDB (up to /24 on the free plan), see every reported address sorted by score, and block them individually or all at once with a single button. Blocks respect your configured block duration, skip whitelisted IPs, and you stay on the scan results after blocking.
- New: “Withdraw my reports” tool — deletes the reports your own account submitted for an IP, useful when an address was reported by mistake (e.g. after a proxy misconfiguration).
- New: Configurable report history window (1-365 days, default 90) — lower values focus on currently active threats and reduce false positives.
- New: Configurable blacklist size (100-10,000 IPs) for the daily sync, so small hosting plans can keep the local table light.
- Fix: Removed the WooCommerce
wc-ajaxendpoint from firewall checks — store traffic no longer consumes API quota. - Fix: Readme accuracy — corrected the admin menu name (IP Shield), the full list of protected endpoints, and documented all four public hooks for developers.
1.1.0
- New: One-time dismissible “What’s new” banner on the plugin Dashboard after each update, summarizing the highlights.
- New: Daily AbuseIPDB blacklist sync (opt-in) — downloads the worst-reputation IPs (up to 10,000) once a day into a local table and blocks them instantly on sensitive endpoints, without spending check quota.
- New: The official AbuseIPDB whitelist is now respected — whitelisted IPs (search engine crawlers, major CDNs) are never blocked, preventing false positives like blocking Googlebot.
- New: Richer live IP check — now shows usage type, domain, distinct reporters, last-reported date and whitelist/Tor badges.
- New: Completely redesigned admin interface — modern dual theme (light by default, dark via system preference), GranTech brand identity (teal + navy), status hero on the Dashboard, toggle switches, Dashicons instead of emojis, section navigation in Settings, and refined tables, cards and charts.
- Accessibility: All WCAG improvements preserved and extended — AA contrast verified in both themes, teal focus rings, forced-colors and reduced-motion support, 40px+ touch targets.
- Fix: Live IP check was broken by a JavaScript syntax error — now working again.
- Security: The AbuseIPDB API key is no longer printed in the Settings page HTML source; leave the field empty to keep the saved key.
- Security: Numeric settings are now clamped server-side (e.g. a score threshold of 0 — which would block every visitor — can no longer be saved).
- Fix: Multi-line report comment templates no longer lose their line breaks when saved.
- New: Option to block Tor exit nodes on sensitive endpoints (opt-in), using the isTor flag already returned by the AbuseIPDB API.
- New: AbuseIPDB daily API quota indicator on the Dashboard (remaining/limit with color coding), captured from the API response headers.
- New: Block button directly in the Event Log rows for one-click blocking of suspicious IPs.
- New: Configurable log retention period in Settings (default 90 days, minimum 7).
- Improvement: Automatic backoff when the daily API quota is exhausted (HTTP 429) — API checks pause until the quota resets at midnight UTC, keeping your site fast.
- Improvement: API check timeout reduced from 10s to 5s so visitors never wait long if AbuseIPDB is slow; reports keep the 10s timeout.
- Improvement: Authenticated users with editing capabilities are no longer checked against the API — saves quota and prevents locking yourself out of wp-admin.
- Improvement: Comment IP checks now require the real wp-comments-post.php endpoint, so unrelated forms with a “comment” field no longer trigger API calls.
1.0.5
- New: IP addresses in the Blocklist, Event Log and Dashboard are now clickable — they open the corresponding AbuseIPDB check page (abuseipdb.com/check/{IP}) in a new tab for quick investigation. (Thanks for the suggestion!)
- New: Option to report XML-RPC attacks to AbuseIPDB (opt-in) — IPs exceeding the failed-attempts limit via XML-RPC are reported with categories Brute-Force + Web App Attack, using a vector-specific privacy-safe comment.
- Fix: Added missing translators comments to email notification strings (plugin checker warnings).
1.0.4
- Security: IP detection no longer trusts proxy headers (X-Forwarded-For, CF-Connecting-IP) by default — prevents IP spoofing. New “Trust proxy headers” option for sites behind Cloudflare or a load balancer.
- Privacy: AbuseIPDB report comments no longer include the site URL or targeted username by default — reports are publicly visible on abuseipdb.com.
- New: Customizable report comment template in Settings with placeholders: {attempts}, {window}, {username}, {site}.
- New: granipfi_report_comment filter for developers to programmatically modify report comments.
- New: Email alerts — get notified when a brute-force attack is blocked (throttled to one per attacking IP per hour, configurable recipient).
- New: Dashboard widget — at-a-glance security stats on the main WordPress admin dashboard.
- Fix: “Repair database tables” button now works — the handler was never registered.
- Fix: CIDR whitelist now supports IPv6 ranges (previously IPv4-only).
- Fix: Cron cleanup is rescheduled automatically if it goes missing after a migration.
- Fix: Activation now records DB version to prevent unnecessary table recreation.
- Fix: Added missing event types (xmlrpc_blocked, xmlrpc_probe, report_failed) to the event log filter and styles.
- Fix: Spanish (es_ES) translation completed and aligned with the official WordPress.org es_ES glossary (informar, malintencionado, avisos, Escritorio, ajustes, caduca…).
- Performance: is_blocked() result cached per-IP for 60 seconds — avoids a DB query on every request.
- Performance: Dashboard statistics cached for 5 minutes — avoids 3 heavy GROUP BY queries on every page load.
1.0.3
- Fix: Removed .gitignore file not permitted in WordPress.org plugin repository.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
GranTech IP Firewall for AbuseIPDB: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 11, 2026
Is GranTech IP Firewall for AbuseI… free?
Yes. GranTech IP Firewall for AbuseI… is free to download and use from the official WordPress.org plugin directory.
Is GranTech IP Firewall for AbuseI… safe to use in 2026?
GranTech IP Firewall for AbuseI… is a solid plugin choice in 2026, with a few things worth checking first. It runs on 60+ sites, is rated 5/5 and was last updated 1 week ago, and scores 79/100 on our health check.
How many websites use GranTech IP Firewall for AbuseI…?
GranTech IP Firewall for AbuseI… is active on 60+ WordPress websites and has been downloaded 923 times since it launched in May 2026. It was downloaded 264 times in the last 30 days.
Does GranTech IP Firewall for AbuseI… work with WordPress 7.1?
Yes. The developer has tested GranTech IP Firewall for AbuseI… up to WordPress 7.1.3, the latest release. It requires WordPress 6.0 or newer.
What PHP version does GranTech IP Firewall for AbuseI… need?
GranTech IP Firewall for AbuseI… requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was GranTech IP Firewall for AbuseI… last updated?
The latest version, 1.3.0, was released on October 3, 2026 (1 week ago).
Who makes GranTech IP Firewall for AbuseI…?
GranTech IP Firewall for AbuseI… is developed and maintained by Marc Gran.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card