{"id":354907,"date":"2026-09-10T21:50:48","date_gmt":"2026-09-10T21:50:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sentraip\/"},"modified":"2026-09-10T21:50:35","modified_gmt":"2026-09-10T21:50:35","slug":"sentraip","status":"publish","type":"plugin","link":"https:\/\/su.wordpress.org\/plugins\/sentraip\/","author":23543461,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.6","stable_tag":"1.1.6","tested":"7.1","requires":"6.8","requires_php":"7.4","requires_plugins":null,"header_name":"SentraIP","header_author":"Move Forward Ltd.","header_description":"Protect your WordPress site by blocking traffic based on country, region, city, bots, VPN, TOR, SPAM, PROXY, THREAT, and Datacenter sources.","assets_banners_color":"070113","last_updated":"2026-09-10 21:50:35","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/sentraip.com","header_author_uri":"https:\/\/mforward.eu","rating":0,"author_block_rating":0,"active_installs":0,"downloads":59,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.6":{"tag":"1.1.6","author":"moveforwardltd","date":"2026-09-10 21:50:35","revision":3690562}},"upgrade_notice":{"1.0.22":"<p>Maintenance and compliance release. Blocking still follows the datasets your token grants; reconnect your token from Settings if you have not done so since 1.0.21.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3690553,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690553,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690553,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690553,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.6"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3690553,"resolution":"1","location":"assets","locale":"","width":1381,"height":940},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3690553,"resolution":"2","location":"assets","locale":"","width":1381,"height":2359},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3690553,"resolution":"3","location":"assets","locale":"","width":1381,"height":1617},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3690553,"resolution":"4","location":"assets","locale":"","width":1381,"height":1490},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3690553,"resolution":"5","location":"assets","locale":"","width":1381,"height":945},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3690553,"resolution":"6","location":"assets","locale":"","width":1381,"height":942},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3690553,"resolution":"7","location":"assets","locale":"","width":1381,"height":2070}},"screenshots":{"1":"Dashboard \u2014 blocked and blockable traffic charts and the blocker simulator.","2":"Statistics \u2014 total blocked traffic over time and a breakdown by type.","3":"Blockable Traffic \u2014 traffic that was allowed through but matches a dataset you could block, with per-category counters and top-10 tables.","4":"Countries \u2014 block visitors by country, grouped by continent; your own country is always excluded.","5":"Bots \u2014 block well-known crawlers, scanners and attack tools by User-Agent.","6":"Geolocation database \u2014 choose a free IP-to-country provider (DB-IP, MaxMind or IP2Location) and download it locally.","7":"Settings \u2014 master on\/off switches per category, response code, proxy headers, IP whitelist and emergency recovery."}},"plugin_section":[],"plugin_tags":[166108,1174,4124,1192,600],"plugin_category":[49,54],"plugin_contributors":[280145],"plugin_business_model":[],"class_list":["post-354907","plugin","type-plugin","status-publish","hentry","plugin_tags-bot-protection","plugin_tags-firewall","plugin_tags-geolocation","plugin_tags-ip-blocking","plugin_tags-security","plugin_category-maps-and-location","plugin_category-security-and-spam-protection","plugin_contributors-moveforwardltd","plugin_committers-moveforwardltd"],"banners":{"banner":"https:\/\/ps.w.org\/sentraip\/assets\/banner-772x250.png?rev=3690553","banner_2x":"https:\/\/ps.w.org\/sentraip\/assets\/banner-1544x500.png?rev=3690553","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sentraip\/assets\/icon-128x128.png?rev=3690553","icon_2x":"https:\/\/ps.w.org\/sentraip\/assets\/icon-256x256.png?rev=3690553","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-1.png?rev=3690553","caption":"Dashboard \u2014 blocked and blockable traffic charts and the blocker simulator."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-2.png?rev=3690553","caption":"Statistics \u2014 total blocked traffic over time and a breakdown by type."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-3.png?rev=3690553","caption":"Blockable Traffic \u2014 traffic that was allowed through but matches a dataset you could block, with per-category counters and top-10 tables."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-4.png?rev=3690553","caption":"Countries \u2014 block visitors by country, grouped by continent; your own country is always excluded."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-5.png?rev=3690553","caption":"Bots \u2014 block well-known crawlers, scanners and attack tools by User-Agent."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-6.png?rev=3690553","caption":"Geolocation database \u2014 choose a free IP-to-country provider (DB-IP, MaxMind or IP2Location) and download it locally."},{"src":"https:\/\/ps.w.org\/sentraip\/assets\/screenshot-7.png?rev=3690553","caption":"Settings \u2014 master on\/off switches per category, response code, proxy headers, IP whitelist and emergency recovery."}],"raw_content":"<!--section=description-->\n<p>SentraIP filters unwanted visitors before they reach your WordPress application layer. Blocking runs on the WordPress <code>init<\/code> hook, before your theme and most plugins load, and every lookup is performed locally against offline MMDB database files in your uploads directory \u2014 so no external request is made on normal page loads.<\/p>\n\n<p>The plugin is free and open source (GPLv2 or later), maintained by Move Forward Limited. It works out of the box and <strong>no account and no paid plan is ever required<\/strong> to use it.<\/p>\n\n<h4>What it blocks<\/h4>\n\n<ul>\n<li><strong>Country (geolocation) blocking<\/strong> \u2014 block visitors by country. You download a free IP-to-country database from a provider of your choice (DB-IP, MaxMind GeoLite2 or IP2Location LITE); your own admin country and your server's country are excluded automatically so you never lock yourself out.<\/li>\n<li><strong>Bot blocking<\/strong> \u2014 block well-known crawlers, scanners and attack tools (Googlebot, GPTBot, SemrushBot, AhrefsBot, ClaudeBot and many more) by User-Agent. Requests with an empty or missing User-Agent can also be blocked.<\/li>\n<li><strong>Spam-comment IP blocking<\/strong> \u2014 IPs from comments marked as spam (manually, by bulk action, or by Akismet) are blocked automatically for 24 hours. This needs no external data at all.<\/li>\n<li><strong>Free SPAM reputation dataset (opt-in)<\/strong> \u2014 optionally download a free SPAM IP reputation database to block known spam sources. Entirely opt-in, no account required.<\/li>\n<li><strong>IP whitelist<\/strong> \u2014 approved IPs and CIDR ranges are never blocked, so you can always guarantee your own access.<\/li>\n<li><strong>Statistics &amp; Blockable Traffic insights<\/strong> \u2014 see what was blocked over time, and see allowed traffic that matched a dataset so you can decide what to start filtering.<\/li>\n<li><strong>Blocker Simulator<\/strong> \u2014 test what the blocker would do for any IP \/ User-Agent, without blocking anything.<\/li>\n<li><strong>Configurable response<\/strong> \u2014 return 403, 404, 410, 444 or 503 for blocked requests.<\/li>\n<li><strong>Proxy-aware<\/strong> \u2014 behind Cloudflare or a reverse proxy, enable \"Trust Proxy Headers\" so the real visitor IP is used for every check.<\/li>\n<li><strong>Lockout-safe by design<\/strong> \u2014 the WordPress admin (<code>\/wp-admin<\/code>), <code>\/wp-login.php<\/code> and <code>\/wp-register.php<\/code> are never blocked, logged-in users are never blocked, and an emergency kill switch (<code>WP_SENTRAIP_DISABLE_BLOCKING<\/code>) can disable all blocking from <code>wp-config.php<\/code>.<\/li>\n<li><strong>Secure storage<\/strong> \u2014 database files live in a protected uploads subdirectory guarded by <code>.htaccess<\/code> and <code>index.php<\/code>.<\/li>\n<\/ul>\n\n<h4>Advanced datasets (optional add-on)<\/h4>\n\n<p>Additional IP-reputation datasets \u2014 VPN, TOR, PROXY, THREAT and Datacenter blocking, per-provider VPN blocklists, and composed AND\/OR rules \u2014 are available through a separate companion plugin, <strong>SentraIP PRO<\/strong>, which connects to a SentraIP account. This free plugin is fully functional on its own and never requires the add-on. See https:\/\/sentraip.com for details.<\/p>\n\n<h4>How it works<\/h4>\n\n<p>Choose a geolocation provider on the <strong>Geolocation<\/strong> page and download the country database (a monthly WordPress cron keeps it fresh). Configure your rules under <strong>Countries<\/strong>, <strong>Bots<\/strong> and <strong>Settings \u2192 Blocking Controls<\/strong>. Every request is then checked locally against the offline database files \u2014 there is no per-request external call.<\/p>\n\n<h3>External services<\/h3>\n\n<p>To keep visitor lookups fast and offline, this plugin downloads database files from a few third-party services. Understanding which services are contacted, and what data is sent, is important for your privacy and legal compliance. No external request is made on normal visitor page loads \u2014 only when a database is downloaded or refreshed, and only for the features you opt into.<\/p>\n\n<p><strong>Free SPAM dataset (opt-in, no account required)<\/strong><\/p>\n\n<p>The free version can download a SentraIP SPAM reputation database to block known spam sources. This is entirely opt-in and needs no API token or account.<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> downloading and monthly refreshing the free SPAM MMDB database used for blocking.<\/li>\n<li><strong>When data is sent:<\/strong> only after you enable the free SPAM dataset on the <strong>SentraIP \u2192 Settings<\/strong> page. Nothing is downloaded on activation or without your consent, and no request is made on normal visitor page loads.<\/li>\n<li><strong>What data is sent:<\/strong> your site host name and a public key generated for your installation (used to authorise the download). The plugin generates a key pair locally, registers only the public key with SentraIP (<code>app.sentraip.com<\/code>), and signs each download request; the private key never leaves your server. No visitor IP address or personal data is sent.<\/li>\n<li><strong>If you do not enable it:<\/strong> SPAM blocking still works \u2014 IP addresses from comments you mark as spam are blocked automatically, with no external request. The dataset is an optional enhancement, not a requirement.<\/li>\n<li><strong>Service site \/ terms:<\/strong> https:\/\/sentraip.com<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/www.mforward.eu\/privacy-policy\/ (Terms: https:\/\/sentraip.com\/plugin-terms-of-service\/)<\/li>\n<\/ul>\n\n<p><strong>Sharing spam-comment IPs with SentraIP (opt-in, off by default)<\/strong><\/p>\n\n<p>You can optionally let SentraIP collect the IP addresses of comments you mark as spam, to help improve protection for every site using SentraIP.<\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> contributing your spam-comment IPs to SentraIP's shared reputation data.<\/li>\n<li><strong>When data is sent:<\/strong> only after you tick <strong>Share spam IPs with SentraIP<\/strong> on the <strong>SentraIP \u2192 Settings<\/strong> page. It is off by default; with the box unticked nothing is ever shared and the feed endpoint refuses all requests.<\/li>\n<li><strong>What data is sent:<\/strong> only the IP addresses recorded from comments you marked as spam (a ~15-day window). No comment content, author names, e-mails or other personal data are sent. SentraIP reads the list over an authenticated request signed with its own key; your site verifies that signature before responding.<\/li>\n<li><strong>If you do not enable it:<\/strong> spam-comment IP blocking still works locally on your site exactly as before \u2014 this option only governs sharing.<\/li>\n<li><strong>Service site \/ terms:<\/strong> https:\/\/sentraip.com<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/www.mforward.eu\/privacy-policy\/ (Terms: https:\/\/sentraip.com\/plugin-terms-of-service\/)<\/li>\n<\/ul>\n\n<p><strong>Geolocation database providers (opt-in)<\/strong><\/p>\n\n<p>Country blocking needs an IP geolocation database, which you download from one free third-party provider that you choose on the <strong>SentraIP \u2192 Geolocation<\/strong> page. No provider is selected by default and no geolocation download happens until you explicitly opt in by choosing one. Once a provider is configured, its database is also refreshed automatically once a month by a WordPress cron job. The database is queried locally on your server; no visitor data is sent to these providers at request time.<\/p>\n\n<ul>\n<li><strong>DB-IP<\/strong> (https:\/\/db-ip.com) \u2014 recommended, no registration. Downloads from <code>download.db-ip.com<\/code>. No credential is sent. Terms: https:\/\/db-ip.com\/tos.php<\/li>\n<li><strong>MaxMind GeoLite2<\/strong> (https:\/\/www.maxmind.com) \u2014 requires a free account. Downloads from <code>download.maxmind.com<\/code>; your MaxMind license key is sent to authenticate the download. Privacy: https:\/\/www.maxmind.com\/en\/privacy-policy<\/li>\n<li><strong>IP2Location LITE<\/strong> (https:\/\/lite.ip2location.com) \u2014 requires a free account. Downloads from <code>www.ip2location.com<\/code>; your IP2Location download token is sent to authenticate the download. Terms: https:\/\/www.ip2location.com\/terms<\/li>\n<\/ul>\n\n<p>See the attribution notes below for the data licences of each provider.<\/p>\n\n<h3>Attributions<\/h3>\n\n<p>Depending on the geolocation provider you choose, this product includes data that requires attribution:<\/p>\n\n<ul>\n<li>DB-IP: IP Geolocation by DB-IP (https:\/\/db-ip.com), licensed under CC-BY 4.0.<\/li>\n<li>MaxMind: This product includes GeoLite2 data created by MaxMind, available from https:\/\/www.maxmind.com.<\/li>\n<li>IP2Location: This product uses IP2Location LITE data available from https:\/\/lite.ip2location.com.<\/li>\n<\/ul>\n\n<p>The bundled MaxMind DB reader library is distributed under the Apache License 2.0.<\/p>\n\n<p>The admin charts are drawn by a small self-contained SVG renderer bundled with the plugin (admin\/js\/wp-sentraip-charts.js) \u2014 no third-party JavaScript charting library is used.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In your WordPress admin go to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Choose the <code>sentraip.zip<\/code> file and click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<li>Open <strong>SentraIP \u2192 Geolocation<\/strong>, choose a free IP-to-country provider (DB-IP needs no account) and download the database.<\/li>\n<li>Configure your blocking rules under <strong>Countries<\/strong> and <strong>Bots<\/strong>, and the master switches under <strong>Settings \u2192 Blocking Controls<\/strong>.<\/li>\n<li>(Optional) On <strong>SentraIP \u2192 Settings<\/strong>, enable the free SPAM reputation dataset.<\/li>\n<\/ol>\n\n<p>Manual installation: extract the <code>sentraip<\/code> folder into <code>\/wp-content\/plugins\/<\/code> and activate it from the <strong>Plugins<\/strong> menu.<\/p>\n\n<p>Requirements: PHP 7.4+ and WordPress 6.8+. IP lookups use the MaxMind DB reader, which is bundled with the plugin.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20the%20plugin%20free%3F%20do%20i%20need%20an%20account%3F\"><h3>Is the plugin free? Do I need an account?<\/h3><\/dt>\n<dd><p>The plugin is free and open source (GPLv2 or later) and fully functional on its own. Country blocking, bot blocking (with a large built-in list), automatic spam-comment IP blocking, the IP whitelist and the opt-in free SPAM reputation dataset all work with <strong>no account at all<\/strong>. Additional IP-reputation datasets (VPN, TOR, PROXY, THREAT, Datacenter and composed rules) are available through the separate <strong>SentraIP PRO<\/strong> companion plugin, which connects to a SentraIP account \u2014 but this free plugin never requires it.<\/p><\/dd>\n<dt id=\"will%20this%20block%20my%20own%20access%3F\"><h3>Will this block my own access?<\/h3><\/dt>\n<dd><p>No. The plugin auto-excludes your server's country and your saved admin country. The WordPress admin area, the login page (<code>\/wp-login.php<\/code>) and the registration page are never blocked, and logged-in users are never blocked \u2014 so you can always sign in and fix a rule. As a last resort you can add <code>define( 'WP_SENTRAIP_DISABLE_BLOCKING', true );<\/code> to <code>wp-config.php<\/code> to disable all blocking.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20database%20files%20are%20not%20downloaded%20yet%3F\"><h3>What happens if the database files are not downloaded yet?<\/h3><\/dt>\n<dd><p>The plugin gracefully skips any check whose database file is missing. Your site keeps working normally until the files are available.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20make%20external%20requests%20on%20every%20page%20load%3F\"><h3>Does the plugin make external requests on every page load?<\/h3><\/dt>\n<dd><p>No. All IP lookups run against local binary database files in your uploads directory. External connections are made only when downloading or refreshing a database file (on a monthly schedule, or when you trigger it manually) \u2014 the geolocation database, or the opt-in free SPAM dataset.<\/p><\/dd>\n<dt id=\"where%20are%20the%20database%20files%20stored%3F\"><h3>Where are the database files stored?<\/h3><\/dt>\n<dd><p>In <code>wp-content\/uploads\/wp-sentraip\/<\/code>. The directory is protected by a <code>.htaccess<\/code> (<code>Deny from all<\/code>) and an <code>index.php<\/code> to prevent direct web access.<\/p><\/dd>\n<dt id=\"does%20it%20support%20ipv6%3F\"><h3>Does it support IPv6?<\/h3><\/dt>\n<dd><p>Yes. The plugin detects whether the visitor's IP is IPv4 or IPv6 and uses the matching database file, when that version is available for the dataset.<\/p><\/dd>\n<dt id=\"what%20is%20the%20spam%20comment%20ip%20blocking%3F\"><h3>What is the spam comment IP blocking?<\/h3><\/dt>\n<dd><p>When a comment is marked as spam, the commenter's IP is recorded and blocked for 24 hours. This works entirely locally, with no external data or account.<\/p><\/dd>\n<dt id=\"how%20do%20i%20recover%20if%20a%20rule%20locks%20me%20out%3F\"><h3>How do I recover if a rule locks me out?<\/h3><\/dt>\n<dd><p>Open <code>\/wp-login.php<\/code> and sign in \u2014 login and <code>\/wp-admin<\/code> are never blocked. Then edit the rule that caught you and remove your country\/datacenter\/IP. If you cannot reach the admin at all, add <code>define( 'WP_SENTRAIP_DISABLE_BLOCKING', true );<\/code> to <code>wp-config.php<\/code>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>All statistics features now work for everyone: the configurable retention, the \"Clear all statistics\" reset, the full CSV export and the high-rate non-blocked traffic view are no longer restricted \u2014 they record and run locally on your own site, so they are part of the free plugin.<\/li>\n<li>Fixed the Privacy Policy and Terms links and the third-party provider links in the readme, which pointed to pages that returned a 404.<\/li>\n<li>SentraIP can now reliably read the spam-comment IP feed even if its own address happens to be on the site's blocklist: requests genuinely signed by SentraIP (Ed25519, verified against a public key fetched from the service and cached) bypass the block and authorise the feed endpoint. Works with or without a SentraIP account.<\/li>\n<li>Added an explicit opt-in (Settings \u2192 Security) to share the IPs of comments you mark as spam with SentraIP to improve protection for everyone. It is off by default; with it disabled nothing is shared and the feed endpoint refuses all requests.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Statistics: the Blockable-Traffic timeline query now passes its LIKE pattern through a bound parameter (esc_like), completing the prepared-SQL hardening. No functional change.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Statistics queries now use $wpdb-&gt;prepare() with the %i identifier placeholder for table names, fully parameterising every custom query (WordPress.org prepared-SQL compliance). No functional change.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>WordPress.org coding-standards compliance: replaced discouraged filesystem calls with the WordPress APIs (wp_delete_file(), WP_Filesystem::move()), replaced mt_rand() with wp_rand(), sanitized all request input inline, prefixed uninstall globals, and audited the statistics table queries. No functional change.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed the Statistics hourly drill-down (click a day bar) always showing \"No data\": the hourly rows were matched against formatted \"HH:00\" labels instead of the raw hour numbers stored in the database, so no bar was ever drawn.<\/li>\n<li>The daily chart\/insights cache is now fully cleared on update (including the per-day drill-down entries), so a plugin update never serves data built by the previous version.<\/li>\n<li>Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>SentraIP is now a standalone free plugin: it blocks by country, known bots and custom User-Agent strings, spam-comment IPs (24h), and an opt-in free SPAM reputation dataset \u2014 no account required. The paid datasets (VPN, TOR, PROXY, THREAT, Datacenter and composed rules) moved to the separate SentraIP PRO add-on.<\/li>\n<li>Free SPAM dataset: the download now succeeds when the IPv4 file is fetched (the dataset is published as IPv4-only); a missing per-version file is treated as \"not published yet\" instead of an error.<\/li>\n<li>Rebuilt the blocking pipeline around an extension architecture: each block type is a self-contained extension evaluated by a collect-all pipeline.<\/li>\n<li>The IP whitelist (approved IPs\/ranges are never blocked) is now available to everyone.<\/li>\n<li>Scheduled tasks are reconciled automatically after an in-place update \u2014 no need to deactivate\/reactivate the plugin to pick up newly added cron jobs.<\/li>\n<li>Added a link to sentraip.com on the Dashboard and Settings pages so you can discover the optional SentraIP PRO add-on (shown only when PRO is not installed).<\/li>\n<li>Replaced the bundled Chart.js library with a small self-contained SVG chart renderer, removing a large minified third-party bundle from the plugin.<\/li>\n<\/ul>\n\n<h4>1.0.25<\/h4>\n\n<ul>\n<li>Fixed ULTRA plan being treated as a lesser tier for advanced statistics: since ULTRA includes everything in PRO, ULTRA accounts now correctly get the granular (hourly + rate) statistics, the retention settings, the reset action, the full data export and the enhanced continent\/region\/city country view \u2014 previously these were shown only to PRO and ULTRA users were downgraded to the free view. The statistics export now also reports the actual plan name.<\/li>\n<li>Replaced all direct cURL calls in the plugin's own code with the WordPress HTTP API (wp_remote_get) for dataset downloads, resolve probes and the geolocation database download.<\/li>\n<li>Moved the remaining inline admin <code>&lt;script&gt;<\/code> (Ultra rules data) to wp_add_inline_script().<\/li>\n<li>Hardened IP whitelist validation: CIDR prefix lengths are now checked against the address family (\/32 max for IPv4, \/128 max for IPv6), so invalid ranges such as 192.0.2.1\/64 are rejected.<\/li>\n<li>Removed the explicit load_plugin_textdomain() call; WordPress loads plugin translations automatically.<\/li>\n<li>Translation files (.po\/.mo) are no longer bundled \u2014 translations are delivered via translate.wordpress.org; only the .pot template ships for translators.<\/li>\n<li>Updated the bundled Chart.js library to 4.5.1.<\/li>\n<\/ul>\n\n<h4>1.0.24<\/h4>\n\n<ul>\n<li>Fixed Datacenter blocking: the whitelist is now honoured. When Datacenter blocking is enabled in Settings, datacenter IPs are blocked unless their provider name is on the Datacenter whitelist (or belongs to the server's own datacenter). The check now reads the \"full\" datacenter dataset (v4 and v6 when installed) as the single source of truth for both membership and the provider name \u2014 so the blocker and the dashboard Blocker Simulator behave identically. Previously the name was read from the flag-only \"light\" file, so the whitelist never matched and every datacenter IP was blocked.<\/li>\n<li>Fixed inconsistent Datacenter blocking between IPv4 and IPv6: when a datacenter IP's provider name cannot be resolved (e.g. an IPv6 address with no \"full\" IPv6 dataset), the whitelist cannot be applied, so the request is now allowed instead of being silently blocked. This makes IPv6 behave like IPv4 for whitelisted providers.<\/li>\n<li>The downloader now also fetches the \"full\" IPv6 datasets for VPN and Datacenter when the SentraIP API publishes them, so provider\/datacenter names can be resolved for IPv6 clients and the whitelist works fully on IPv6. Previously only the \"full\" IPv4 file was downloaded.<\/li>\n<li>Compliance with the WordPress.org Plugin Directory guidelines:<\/li>\n<li>Renamed the plugin to \"SentraIP\" (text domain \"sentraip\") so the name and directory slug no longer begin with the reserved term \"wp\".<\/li>\n<li>Documented the freemium model: the plugin is GPL and free; TOR and SPAM datasets are available on the free SentraIP account, other datasets on paid plans. The free account now grants the TOR and SPAM datasets by default.<\/li>\n<li>Removed the duplicate TOR\/SPAM\/PROXY\/THREAT toggles from the Rules page; these are managed under Settings \u2192 Blocking Controls.<\/li>\n<li>Added leakix, the l9 scanner family and many other scanner\/attack tool signatures to the default bot list.<\/li>\n<li>Chart.js is now bundled with the plugin and served locally instead of being loaded from an external CDN.<\/li>\n<li>Geolocation is now fully opt-in: no provider is selected by default and no third-party geolocation database is downloaded until you choose a provider on the Geolocation page.<\/li>\n<li>Expanded the \"External services\" documentation: geolocation download hosts (DB-IP, MaxMind, IP2Location), when they are contacted, and which credentials are sent; documented the optional spam-IP REST feed.<\/li>\n<li>Added Apache-2.0 licence notices to the bundled MaxMind DB reader files.<\/li>\n<li>Trimmed the bundled MaxMind reader to the pure-PHP library actually used at runtime: the build now excludes the native C extension source, its .phpt tests and package metadata (no development tools shipped), while keeping all required LICENSE\/NOTICE files.<\/li>\n<li>Fixed the STARTER plan to grant TOR, SPAM and PROXY, matching the official SentraIP plans.<\/li>\n<li>Updated \"Requires at least\" (6.8) and \"Tested up to\" (7.0).<\/li>\n<\/ul>\n\n<h4>1.0.23<\/h4>\n\n<ul>\n<li>Fixed the VPN and Datacenter provider lists, which were empty: provider\/datacenter names live only in the <code>full<\/code> dataset (fields vpn_provider \/ organization), while the <code>light<\/code> file used for blocking carries just a membership flag. The plugin now downloads the <code>full<\/code> v4 file for VPN and Datacenter and enumerates names from it (IPv4 only).<\/li>\n<\/ul>\n\n<h4>1.0.22<\/h4>\n\n<ul>\n<li>Added the required readme.txt and a full GPLv2 LICENSE file for the WordPress.org Plugin Directory.<\/li>\n<li>Hardened output escaping across admin pages and switched uninstall queries to prepared statements.<\/li>\n<li>Namespaced cache keys (transients) and completed cron cleanup on uninstall.<\/li>\n<li>Removed unused admin pages and their dead handlers\/assets.<\/li>\n<\/ul>\n\n<h4>1.0.21<\/h4>\n\n<ul>\n<li>Dataset-driven architecture: blocking and configuration pages now follow the datasets your token grants, not the plan name.<\/li>\n<li>Retention by entitlement: installed database files for granted datasets are never deleted when a listing is empty or partial.<\/li>\n<li>Downloader reads available IP versions (<code>ip_versions<\/code>) and only fetches files that exist.<\/li>\n<li>Configurable retention (7\u201390 days, default 30) for Blockable Traffic data.<\/li>\n<li>Settings: removed the \"External Services\" and \"SentraIP API\" boxes.<\/li>\n<li>Recovery: <code>\/wp-admin<\/code>, <code>\/wp-login.php<\/code> and <code>\/wp-register.php<\/code> are never blocked, even when your IP is in a blocklist; the site frontend stays protected.<\/li>\n<li>Updated Italian, Spanish, French and German translations.<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Blockable Traffic (Insights) page, Blocker Simulator, recovery section and translations.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Spam comment IP collector \u2014 blocks IPs from spam comments for 24 hours.<\/li>\n<li>REST debug endpoint for testing the blocking pipeline.<\/li>\n<li>Bot check now blocks requests with empty or missing User-Agent.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: country and bot blocking, reputation datasets, VPN\/Datacenter blocking, composed rules, statistics dashboard and internationalization.<\/li>\n<\/ul>","raw_excerpt":"Block unwanted traffic by country, known bots, custom User-Agents and spam-comment IPs, using fast offline MMDB lookups. No account required.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/354907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=354907"}],"author":[{"embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/moveforwardltd"}],"wp:attachment":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=354907"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=354907"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=354907"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=354907"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=354907"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=354907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}