Allow the right networks.
Add individual IPv4 or IPv6 addresses, or CIDR ranges for an office or VPN.
For WordPress
Choose which networks can see your WordPress site.
Restrict WordPress visitors to an IP allowlist, with individual addresses, CIDR ranges and configurable role exceptions.
From $9 / year
Version 1.0.0 · Annual subscription
View full screenshot What it does
Add individual IPv4 or IPv6 addresses, or CIDR ranges for an office or VPN.
The login page remains accessible. Signed-in administrators bypass the restriction, and additional bypass roles are configurable.
Write the access-denied message visitors see when their address isn't allowed.
View screenshot 2 Annual licenses
Prices in USD. Billed annually.
An active license is required to use the plugin.
1 Site
$9 / year
Up to 1 site
2-5 Sites
$10 / year
Up to 5 sites
6-10 Sites
$30 / year
Up to 10 sites
Unlimited
$50 / year
Unlimited sites
Manage existing licenses and downloads · Changelog & older versions
Before you install
No. The login page remains accessible so administrators can sign in from another network.
Yes. Use the public IP address or CIDR range visitors actually connect from, such as the outward-facing address of an office or VPN.
No. It restricts requests handled by WordPress. Server rules, hosting access controls and cache configuration need to be handled separately.
The plugin reads common forwarding headers. Your hosting or proxy must supply a trustworthy visitor address; verify that configuration before relying on IP restrictions.