NexiGuard – IP & Geo Access Control
Restrict website access by IP addresses, CIDR ranges, countries, and regions.
Use with caution
NexiGuard works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where NexiGuard stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| access-control | >100 |
| firewall | >100 |
| geo block | >100 |
| ip block | >100 |
| security | >100 |
About NexiGuard – IP & Geo Access Control
From the official readme · v1.0.1Description
NexiGuard – IP & Geo Access Control is a public WordPress access control plugin for administrators who need to restrict site access using local IP rules and optional GeoIP data.
Features include:
- Block List mode: visitors matching rules are blocked.
- Allow List mode: only visitors matching rules are allowed.
- Exact IP address rules.
- CIDR range rules for IPv4 and IPv6.
- Country and region/state rules when a GeoIP provider is configured.
- Optional blocking for the frontend, login page, REST API, and XML-RPC.
- 403, 404, or custom blocked responses.
- Custom blocked messages with plain text and basic safe HTML.
- Safe visitor IP detection using REMOTE_ADDR by default.
- Optional Cloudflare visitor IP detection.
- Optional trusted proxy header support.
- Bulk import for IP/CIDR rules.
- Export and import settings as JSON.
- Optional minimal blocked-attempt logs.
- Admin lockout protection and an emergency bypass constant.
Privacy and GeoIP
IP blocking works without any third-party service. Country and region blocking requires either a readable local GeoIP database or an explicitly configured API provider.
Visitor IP addresses are not sent externally unless an administrator selects API provider mode and configures an API endpoint. Optional logs store only date/time, IP address, matched rule type, and requested path.
Admin safety
NexiGuard is disabled by default after activation. Logged-in administrators are never blocked by default. The admin screen displays the detected admin IP and requires confirmation before adding an IP/CIDR rule that matches it.
Emergency bypass: define NEXIGUARD_DISABLE as true in wp-config.php to stop all blocking.
External Services
NexiGuard does not contact any external service by default.
If an administrator selects API provider mode and configures an API endpoint, NexiGuard sends a GET request to that administrator-configured endpoint to look up country and region data for visitor IP addresses. The visitor IP address is sent in the configured URL using the {ip} placeholder or as an ip query parameter. If an API key is configured, it is sent as a Bearer token in the Authorization header.
Because the API endpoint is entered by the site administrator, the site owner is responsible for reviewing that provider’s terms of service and privacy policy before enabling API provider mode.
Local IP and CIDR blocking do not use any external service. MaxMind mode reads a local database file and does not send visitor IPs externally.
License
NexiGuard – IP & Geo Access Control is licensed under GPL-2.0-or-later.
Installation
- Upload the
nexiguard-ip-geo-access-controlfolder to/wp-content/plugins/. - Activate NexiGuard – IP & Geo Access Control from the Plugins screen.
- Go to NexiGuard in the WordPress admin menu.
- Review the detected admin IP and source.
- Add IP, CIDR, country, or region rules.
- Enable protection after confirming the desired access mode and request contexts.
Frequently asked questions
Does NexiGuard work without a third-party service?
Yes. Exact IP and CIDR blocking work locally without any external dependency.
Do country and region rules require a provider?
Yes. Country and region rules require a local GeoIP database or an explicitly configured API provider.
Are visitor IPs sent to external services?
No, not by default. Visitor IPs are sent externally only when an administrator selects API provider mode and configures an API endpoint.
Does the plugin trust proxy headers by default?
No. The plugin uses REMOTE_ADDR by default. Cloudflare and proxy header support are disabled until an administrator enables them.
What is Allow List mode?
Allow List mode blocks visitors unless they match one of your configured IP, CIDR, country, or region rules. Use it carefully.
What data is logged?
Only blocked attempts are logged, and only when logging is enabled. Logs contain date/time, IP address, matched rule type, and requested path.
How can I avoid an accidental lockout?
Logged-in administrators are excluded by default, and matching the current admin IP requires confirmation. You can also define NEXIGUARD_DISABLE as true in wp-config.php.
Changelog
Initial public release of NexiGuard – IP & Geo Access Control.
1.0.1
- Enhancement: Completely redesigned the admin interface with premium glassmorphism aesthetics, dynamic header banners, and enhanced interactive elements.
- Enhancement: Added real-time JS validation and type badges to data tables.
1.0.0
- Initial public release.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best NexiGuard alternatives
All access-control plugins →FAQ
NexiGuard – IP & Geo Access Control: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is NexiGuard free?
Yes. NexiGuard is free to download and use from the official WordPress.org plugin directory.
Is NexiGuard safe to use in 2026?
NexiGuard works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
How many websites use NexiGuard?
NexiGuard is active on <10 WordPress websites and has been downloaded 242 times since it launched in June 2026. It was downloaded 66 times in the last 30 days.
Does NexiGuard work with WordPress 7.1?
Yes. The developer has tested NexiGuard up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does NexiGuard need?
NexiGuard requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was NexiGuard last updated?
The latest version, 1.0.1, was released on August 22, 2026 (1 month ago).
Who makes NexiGuard?
NexiGuard is developed and maintained by Nexiby LLC.
What are the best alternatives to NexiGuard?
The most popular alternatives to NexiGuard are PublishPress Capabilities:… (100K+ installs), Restrict User Access (10K+ installs) and PublishPress Permissions: A… (10K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card



