[WordPress] 外掛分享: Predax Security – Block VPN, Proxy, Tor & Bot Traffic

首頁外掛目錄 › Predax Security – Block VPN, Proxy, Tor & Bot Traffic
WordPress 外掛 Predax Security – Block VPN, Proxy, Tor & Bot Traffic 的封面圖片
全新外掛
安裝啟用
尚無評分
14 天前
最後更新
問題解決
WordPress 5.8+ PHP 7.4+ v1.15.0 上架:2026-05-24

內容簡介

Predax Security 外掛能有效阻擋 VPN、代理伺服器、Tor 使用者及機器人流量,防止潛在攻擊,保護您的 WordPress 網站安全。透過即時風險評分,您可以靈活設定阻擋條件,確保網站不受威脅。

【主要功能】
• 實時風險評分系統,評估訪客 IP
• 阻擋匿名連線,如 VPN 和 Tor
• 自訂阻擋條件,依國家或風險分數
• 內建防火牆,攔截攻擊嘗試
• 鎖定重複失敗登入的風險 IP
• 拒絕假註冊和垃圾留言

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.15.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Predax Security – Block VPN, Proxy, Tor & Bot Traffic」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Block bots, VPNs, Tor users, proxies and high-risk visitors before they can attack your WordPress site.
Most WordPress attacks — brute-force logins, fake registrations, comment spam, vulnerability scans — come from anonymised connections: VPNs, open proxies, Tor exit nodes, and rented datacenter servers. Predax Security identifies those visitors the moment they arrive and stops the risky ones at the door, before they can log in, register, comment, or even load a page.
Every visitor IP is checked in real time against a continuously-updated threat intelligence database of known VPN providers, open proxies, Tor exit nodes, datacenter ranges, and web crawlers, and given a 0–100 risk score. You choose exactly what gets blocked — by category, by country, or by risk score threshold.
Privacy-first by design: on a fresh install the plugin is off by default — no visitor data is sent anywhere until you explicitly enable a protection preset via the setup wizard or the Settings → Protection tab.
What it turns away

Hidden connections — visitors arriving over a VPN, proxy or Tor, if you choose to block them.
Servers pretending to be people — traffic from rented cloud machines rather than home broadband.
Known bad addresses — IPs with a history of attacking other sites.
Countries you do not serve — block or allow by country, or by whole region.
Attack attempts — a built-in firewall catches injection, scanner and file-probe requests.
Password guessers — repeated failed logins are locked out, faster for risky addresses than ordinary ones.
Fake signups and spam — throwaway email addresses and bot comments are rejected.

Each of these is a switch you set. Nothing is blocked until you choose a protection level.
Choose which crawlers may access your site — enforced, not requested
robots.txt is a request a crawler can ignore. Blocking by user-agent trusts a header any
script can fake. Predax blocks crawlers by the IP ranges their operators publish, checked
on your own server on every request — so a crawler that ignores robots.txt still gets a 403.
Three independent switches, all set to allow by default:

Search engines (Googlebot, Bingbot, DuckDuckBot, Applebot) — allowed and protected:
verified search crawlers stay exempt from your other category rules, so your rankings are
never collateral damage.
AI crawlers (GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, PerplexityBot) — your
content, your call.
SEO crawlers (AhrefsBot) — they use your bandwidth to build third-party analytics
products. Blocking them does not affect your own search rankings.

A visitor that merely claims a crawler’s user-agent gets no special treatment in either
direction: unverified traffic passes through your normal risk rules, where fake-bot detection
handles impersonators.
Note that this covers crawlers whose operators publish their IP ranges. Crawlers that publish
no ranges (for example CCBot, Amazonbot or Bytespider) are judged by the normal bot and risk
rules instead.
Blocking that never quietly costs you visitors or rankings
The real risk of any blocking rule isn’t the attacker it misses — it’s the genuine reader it turns away without you ever finding out. Predax Security is built to make that failure mode visible and reversible:

Verified search engines are exempt from category rules. Googlebot, Bingbot, and other crawlers confirmed by reverse DNS are never blocked by your VPN, proxy, datacenter, country, region, or risk-score rules. Search engines crawl from datacenter IP ranges, so a datacenter rule would otherwise turn them away — and over time cost your site its search rankings. Threat rules still apply to everyone: Tor, known-malicious IPs, the firewall, your own blocklist, and active lockouts block an IP regardless of what its reverse DNS says.
Wrongly-blocked visitors can tell you. A visitor stopped by one of your category rules can report that they’re genuine. The report appears in the Threat Log with the full risk detail for their IP beside it, so you can judge it in context — and a report never unblocks anyone on its own; you always decide. Visitors blocked for actual attacks (firewall signatures, honeypot traps, known-malicious IPs, brute-force lockouts) never see this option at all.
One-click allow-listing. Approve any IP straight from the Threat Log instead of copying it into a settings field. A reader caught by an over-strict rule can be let back in as fast as they were turned away.

The dashboard already separates attacks stopped from visitors turned away by your own category rules — and on a typical site the large majority of screened traffic is bots and datacenter infrastructure rather than people. You can see exactly what your settings are doing, and undo any block that shouldn’t have happened, without leaving the log.
Key Features

Per-crawler policy — allow or block search engines, AI crawlers (GPTBot, ClaudeBot, PerplexityBot) and SEO crawlers (AhrefsBot) independently, enforced by each operator’s published IP ranges rather than the spoofable user-agent header
Security Dashboard — real-time overview with blocking activity chart, threat breakdown, top targeted paths, protection status, and country analysis
Real-time VPN/Proxy/Tor/Datacenter detection — checks every visitor against live threat intelligence
Search-engine safe — verified crawlers (Googlebot, Bingbot) are exempt from category rules, so screening doesn’t affect how your site is crawled and indexed
Risk score thresholds — block IPs above a configurable risk score (0–100)
Country geo-blocking — block or allow specific countries and regions
Login protection — block high-risk IPs from attempting to log in
Registration protection — stop fraudulent account creation
Comment protection — block spam and bot comments at source
Visitor protection — optionally check all page visitors (with 1-hour caching to minimise API calls)
XML-RPC & REST API protection — extend blocking to XML-RPC calls and REST API requests
Disposable email blocking — reject registrations using throwaway email services
Custom block page — show a branded 403 page instead of the default WordPress error
Whitelist/blacklist — override decisions for individual IPs or CIDR ranges
One-click allow-listing — approve any IP directly from the Threat Log, no settings field to edit
Visitor reports — visitors blocked by a category rule can tell you they’re genuine; reports land in the Threat Log with full risk detail for your decision
Threat log — view and export all blocked events with IP, reason, and timestamp
Event tracking — log successful checks for audit and analytics
Settings import/export — back up and restore your configuration as a JSON file
WP-CLI commands — manage whitelists, blacklists, and run IP tests from the command line

Free Tier
Click “Connect with Predax” in the setup wizard to create your free account and link your API key automatically — no separate sign-up step, no key to copy or paste. The free plan includes:

1,000 IP checks per day
5,000 IP checks per month
VPN, proxy, Tor, and datacenter detection
Country and region data

No credit card required.
More Power With Paid Plans
The free tier is plenty for small sites, but busier sites use up the included checks faster. Paid plans raise the monthly limit from 5,000 up to 25 million IP checks, with higher request rates and bulk lookups. The dashboard shows your live usage each month, so you can see exactly when it’s time to upgrade — same plugin, same settings, just a bigger allowance on your existing API key.
How It Works

You install the plugin and connect your site during the Setup Wizard. Click “Connect with Predax” to create your free account (or log into an existing one) and link your API key automatically — no key to copy or paste. Prefer to do it manually? You can still paste in an existing API key instead.
You pick a protection preset in the Setup Wizard (or enable individual protections from Settings → Protection). This is the explicit opt-in — no data leaves the site until you do this.
A visitor makes a request to your site.
Predax checks their IP against the threat intelligence API (results cached between 5 minutes and 1 hour per IP, following the lifetime the API recommends).
If the risk score exceeds your threshold, the visitor is blocked with a configurable message.
All block events are logged in the WordPress database for review.

WP-CLI Commands
wp ipsentry status — show current configuration and threat counts
wp ipsentry test-ip — run a live API check on any IP
wp ipsentry whitelist add — add an IP or CIDR to the whitelist
wp ipsentry whitelist remove — remove from whitelist
wp ipsentry blacklist add — add an IP or CIDR to the blacklist
wp ipsentry log --limit=20 — view recent threat log entries

Third Party Services
This plugin connects to external services. By installing and activating this plugin you agree to the terms of each service you enable.
Predax API
This plugin transmits visitor IP addresses to the Predax API (https://predax.io) for real-time threat detection and risk scoring.
What is sent: The visitor’s IP address; optionally their timezone (when timezone mismatch detection is enabled and visitor protection is active); and, when disposable-email screening is enabled, the domain part of the email address entered at registration (for example “gmail.com”) — never the email address itself, and never the part before the @. The mailbox-level checks (role account, random-looking name) run locally on your own server.
When it is sent: On each page load, login attempt, registration, or comment submission, subject to your configured protection settings. IP results are cached for up to 1 hour and email-domain results for up to 6 hours, so repeat visits do not generate additional API calls.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Email Domain Screening (only when disposable-email screening is enabled)
Used to check whether the email provider entered at registration is a disposable/throwaway service, against a server-side list of thousands of domains (the plugin’s built-in list covers only ~50).
What is sent: the domain part of the registration email address only — for example gmail.com. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.
When it is sent: during user registration, and only while the Disposable Email Addresses setting is set to Flag or Block. If the API is unreachable, the plugin falls back to its built-in local list and the registration proceeds normally. Email-domain results are cached for up to 6 hours per domain.
Endpoint: POST https://predax.io/api/v1/validate/email
Plan usage: email-domain lookups count against your Predax plan allowance, the same as IP checks. Results are cached per domain for 6 hours and the built-in list is checked first, so in practice this is roughly one lookup per new email provider your visitors use.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Account Usage Lookup (admin pages only)
Used to show the “API Usage” meter on the plugin dashboard, and only when an API key is saved.
What is sent: your Predax API key (as the authentication header). No visitor data is sent.
When it is sent: when an administrator views the Predax Security dashboard. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.
Endpoint: GET https://predax.io/api/v1/auth/usage
Privacy Policy: https://predax.io/privacy
Deactivation Feedback (optional, admin-initiated)
Shown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the “why are you deactivating?” prompt.
What is sent: the plugin slug, the plugin version, and a single pre-defined reason code you select (e.g. “it blocked real visitors”). No site URL, no email address, no visitor data, and no IP address are sent.
When it is sent: only when you select a reason and click “Send & deactivate”. Clicking “Skip & deactivate” sends nothing at all.
Endpoint: POST https://predax.io/api/v1/feedback/deactivation
Privacy Policy: https://predax.io/privacy
Community Threat Network (opt-in, disabled by default)
The Community Threat Network is opt-in and disabled by default. No block or monitor events are sent to the community network unless you enable it yourself in Settings → Predax Security → Advanced.
When — and only when — you explicitly enable it, anonymised block and monitor events (containing: IP address, action taken, block reason, country code, and risk score) are sent to the Predax API at predax.io. This data is used to build a shared threat database that improves detection accuracy for all sites in the network. You can turn community reporting back off at any time in the same settings screen.
Google reCAPTCHA
When reCAPTCHA v3 is enabled (Settings → Protection → reCAPTCHA), this plugin loads the reCAPTCHA script from google.com and sends form submission tokens to google.com/recaptcha for verification. Google may collect data according to their privacy policy. You must provide your own reCAPTCHA site key and secret key.
Google Privacy Policy: https://policies.google.com/privacy
reCAPTCHA Terms: https://policies.google.com/terms
Browser Fingerprinting
When browser fingerprint scoring is enabled (Settings → Protection → Fingerprint Scoring), this plugin collects screen resolution, timezone, platform string, WebGL renderer, and plugin count from the visitor’s browser on the login page. Fingerprint data is used locally to score bot likelihood and is stored in WordPress only while the login form is being submitted, then discarded. The visitor’s timezone may be included in the API request to detect timezone mismatch when that feature is enabled.
Cookies set by this plugin
All cookies set by this plugin are functional service cookies, not tracking cookies, and are only written when the relevant feature is explicitly enabled by the site administrator:

ipsentry_tz — carries the visitor’s browser timezone to the Predax API when timezone-mismatch detection is active. Written from ipsentry-tz.js on the front-end. Expires after 24 hours. SameSite=Lax. Only set when an API key is configured AND visitor or login protection is enabled.
ips_jsc — JavaScript challenge solve token. Written from js-challenge.js when a visitor passes the challenge. Expires after 24 hours. SameSite=Lax. Only set when the JavaScript Challenge feature is enabled.

No tracking or advertising cookies are written by this plugin.
By activating this plugin and entering an API key, you agree to the Predax Terms of Service and Privacy Policy. You are responsible for ensuring your use of visitor IP data complies with applicable privacy laws (GDPR, CCPA, etc.) and your own site’s privacy policy.

延伸相關外掛

文章
Filter
Mastodon